Parameters used to establish application communication

By generating an AKMA identifier containing a mobile country code, a mobile network code, a routing indicator, and a random number, the problem of improper key identifier selection in wireless communication networks is solved, secure communication between user equipment and application function entities is ensured, and the security and flexibility of wireless networks are improved.

CN115280715BActive Publication Date: 2025-09-12ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202080098403.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-03-31
Publication Date
2025-09-12
Estimated Expiration
2040-03-31

AI Technical Summary

Technical Problem

In existing wireless communication networks, during secure communication between user equipment and application function entities, a key identifier is insufficient to correctly select an appropriate authentication server function instance, resulting in an inability to effectively establish secure communication.

Method used

The AKMA process is used to identify the user device by generating an AKMA identifier containing the mobile country code, mobile network code, routing indicator and random number, and storing the identifier after successful primary authentication to derive the anchor key for application authentication and key management during the application session establishment process to ensure secure communication.

Benefits of technology

The invention realizes the correct selection of the authentication server function instance in the secure communication process between the user equipment and the application function entity, ensures the establishment and maintenance of the secure communication, and improves the security and flexibility of the wireless network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115280715B_ABST
    Figure CN115280715B_ABST
Patent Text Reader

Abstract

A method for establishing secure communications in a wireless network is described. In one example aspect, a wireless communication method includes: generating, by a first functional entity, a first identifier using at least a mobile country code, a mobile network code, and a random number, the first identifier configured to be used to establish secure communications for a first device; and transmitting the first identifier to the first device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates generally to wireless communications. Background Art

[0002] Efforts are currently underway to define the next generation of wireless communication networks that offer greater deployment flexibility, support for a vast array of devices and services, and diverse technologies for efficient bandwidth utilization. The next generation of wireless communication networks is also expected to deploy new core networks that provide additional services and flexibility beyond currently available core networks. Summary of the Invention

[0003] The present invention provides techniques for improving the security procedures for protecting application sessions between user equipment and application function entities in a wireless network.

[0004] In an example embodiment of the disclosed technology, a wireless communication method includes: generating, by a first functional entity, a first identifier using at least a mobile country code, a mobile network code, and a random number, the first identifier being configured to be used to establish secure communication for a first device; and transmitting the first identifier to the first device.

[0005] In another example embodiment of the disclosed technology, a wireless communication method includes: generating, by a first functional entity or a first device, a first identifier using a mobile country code, a mobile network code, a random number, and an indicator, the first identifier being configured to be used to establish secure communication for the first device; and transmitting the first identifier to the first device.

[0006] In another example embodiment of the disclosed technology, a wireless communication method includes: generating, by a first device, a first identifier using a mobile country code, a mobile network code, a random number, and a routing indicator, the first identifier being configured to be used to establish secure communication for the first device; and storing, by the first device, the first identifier for subsequent requests to an application function entity.

[0007] In another example embodiment of the disclosed technology, a wireless communication method includes: upon completing primary authentication, obtaining an intermediate key stored at a first functional entity and a first device; generating an anchor key for application authentication and key management based on the intermediate key; generating a first identifier using a mobile country code, a mobile network code, a routing indicator, an anchor functional entity identifier for application authentication and key management, a random number, and a first device identifier; storing the first identifier and the anchor key for application authentication and key management; and using the first identifier to establish secure communication for the first device.

[0008] In yet another exemplary embodiment of the disclosed technology, the above method is embodied in the form of processor-executable codes and stored in a computer-readable program medium.

[0009] In yet another example embodiment of the disclosed technology, a device configured or operable to perform the above method is disclosed.

[0010] These and other aspects and embodiments thereof are described in more detail in the drawings, description and claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1A An example of a wireless communication system is shown.

[0012] Figure 1B An example architecture for a basic network model for Application Authentication and Key Management (AKMA) is shown.

[0013] Figure 2 The derivation of the AKMA root key during User Equipment (UE) registration is shown.

[0014] Figure 3 Shows the anchor key (K AKMA )'s Application Function (AF) key generation example.

[0015] Figure 4 is a flow chart illustrating an example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0016] Figure 5 is a flow chart illustrating another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0017] Figure 6 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0018] Figure 7 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0019] Figure 8 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0020] Figure 9 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0021] Figure 10 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0022] Figure 11is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0023] Figure 12 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0024] Figure 13 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0025] Figure 14 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0026] Figure 15 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0027] Figure 16 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0028] Figure 17 is a flow chart illustrating an example of a wireless communication method based on some embodiments of the disclosed technology.

[0029] Figure 18 is a flow chart illustrating another example of a wireless communication method based on some embodiments of the disclosed technology.

[0030] Figure 19 is a flow chart illustrating another example of a wireless communication method based on some embodiments of the disclosed technology.

[0031] Figure 20 is a flow chart illustrating another example of a wireless communication method based on some embodiments of the disclosed technology.

[0032] Figure 21 is a block diagram representation of a portion of a radio station according to which one or more embodiments of the present technology may be applied. DETAILED DESCRIPTION

[0033] Figure 1AAn example of a wireless communication system (e.g., an LTE, 5G, or New Radio (NR) cellular network) is shown, which includes a radio access node 120 and one or more user equipment (UE) 111, 112, and 113. In some embodiments, downlink transmissions (141, 142, 143) include control plane messages that include a processing order for processing multiple user plane functions. This may be followed by uplink transmissions (131, 132, 133) based on the processing order received by the UE. Similarly, the user plane functions may be processed by the UE for downlink transmissions based on the received processing order. The UE may be, for example, a smartphone, a tablet, a mobile computer, a machine-to-machine (M2M) device, a terminal, a mobile device, an Internet of Things (IoT) device, and the like.

[0034] This patent document uses examples based on the 3GPP New Radio (NR) network architecture and 5G protocols only to facilitate understanding, and the disclosed techniques and embodiments can be practiced in other wireless systems that use different communication protocols other than the 3GPP protocols.

[0035] Figure 1B An example architecture of a basic network model for application authentication and key management (AKMA) is shown, including a network exposure function (NEF), an AKMA anchor function (AAnF), a unified data management (UDE), an authentication server function (AUSF), an access and mobility management function (AMF), and an application function (AF). In some embodiments, the network model may include network functions within the 5G core architecture control plane, and such network functions may use a service-based interface for their interactions.

[0036] The AKMA framework can be used to support secure communication and data exchange between the UE and the application server. In the example AKMA architecture, the results of the primary / access authentication can be used to perform AKMA authentication to protect the communication between the UE and the application server. In this example architecture, when the UE communicates with the application server, the secure communication between the UE and the application server can be achieved with the help of the application key K AF In the application session establishment process based on the example AKMA architecture, the UE uses the key identifier to request the AKMA application function to establish the application key K AF Application key K AF From such as K AUSF The intermediate key is derived from the AKMA anchor key K AKMA Export, where K AKMA From K AUSF Export.

[0037] During the session establishment process, the key identifier included in the request information is sent from the user equipment (UE) to the AKMA anchor function (AAnF). The AKMA anchor function (AAnF) sends a request including the AKMA key identifier sent by the UE to the authentication server function (AUSF) to obtain the K for the specific user equipment (UE). AKMA However, because the key identifier does not include any information related to a specific authentication server function (AUSF) instance, the AKMA anchor function (AAnF) cannot correctly select the appropriate authentication server function (AUSF) instance based on the key identifier. Therefore, the key identifier is not sufficient to establish secure communication between the user equipment (UE) and the AKMA application function.

[0038] Figure 2 The derivation of the AKMA root key during User Equipment (UE) registration is shown.

[0039] Application Authentication and Key Management (AKMA) requires new logical entities such as the AKMA Anchor Function (AAnF). The AAnF is an anchor function in the Home Public Land Mobile Network (HPLMN) that generates key material to be used between the UE and the AF and maintains the User Equipment (UE) Application Authentication / Key Management (AKMA) context to be used for subsequent bootstrapping requests. There is no separate authentication of the UE supporting AKMA functionality. Instead, it reuses the 5G Primary Authentication process performed during UE registration to authenticate the UE. A successful 5G Primary Authentication results in the intermediate key K AUSF Stored at the AUSF and the UE.

[0040] like Figure 2 As shown, as part of the UE registration process, the UE and the Authentication Server Function (AUSF) can obtain the intermediate key (e.g., K AUSF )Generate AKMA anchor key (K AKMA ) and the associated key identifier. K AKMA The key identifier is used to identify the UE's K from which other AKMA keys are derived. AKMA Key. Since the AKMA key is based on an intermediate key from the master authentication run (such as K AUSF ), AKMA keys can only be refreshed by running a new master certification.

[0041] Figure 3 Shows the anchor key (K AKMA )'s Application Function (AF) key generation example.

[0042] In some embodiments, the UE includes the derived AKMA key identifier in a message to initiate communication with the AKMA application function (AKMA AF). If the AKMA application function (AApF) does not have an active context associated with the key identifier, the AF sends a request with the key identifier to the AKMA anchor function (AAnF) to request the application function-specific AKMA key for the UE. The AF also includes its identity (AF Id) in the request.

[0043] If the AKMA Anchor Function (AAnF) has the Application Function (AF) specific key (K AF ), then it uses K AF If not held, the AKMA Anchor Function (AAnF) checks if it has the UE-specific K identified by the AKMA Key Identifier. AKMA Key. If the AKMA anchor key (K AKMA ) is available in the AKMA Anchor Function (AAnF), then the AKMA Anchor Function (AAnF) is derived from the AKMA Anchor Key (K AKMA ) Export AF specific AKMA key (K AF ), and using the AF specific key (K AF ) and life cycle to respond to the application function (AF).

[0044] If the AKMA anchor key (K AKMA ) is not available, the AKMA anchor function (AAnF) sends a request including an AKMA key identifier to the authentication server function (AUSF) to obtain the AKMA anchor key (K AKMA ). The Authentication Server Function (AUSF) uses the K identified by the key identifier AKMA The AKMA Anchor Function (AAnF) receives the AKMA Anchor Key (K AKMA ) derives the application function (AF) specific key (K AF ), and using the AF specific key (K AF ) and life cycle to respond to the application function (AF).

[0045] Some embodiments of the disclosed technology may be used to improve the process of establishing secure communications to protect application sessions between UEs and AKMA application functions. In some implementations, an application authentication and key management (AKMA) identifier (ID) may be used for the application session establishment process.

[0046] Figure 4 is a flow chart illustrating an example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0047] In some embodiments of the disclosed technology, a data management function (such as a unified data management entity (UDM)) can generate an application authentication and key management (AKMA) identifier (AKMAID) for an application session establishment process. The AKMA identifier (AKMAID) can be used to identify the AKMA process for a UE or can be used as an identifier to identify an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) can include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) can include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). Herein and hereinafter, the UE identifier is used to identify the user equipment. In some embodiments, the AKMA identifier (AKMA ID) can include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMA ID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMA ID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMA ID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a UE identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a Mobile Country Code (MCC), a Mobile Network Code (MNC), an Authentication Server Function identifier, an Application Authentication and Key Management Anchor Function (AAnF) identifier, and a random number (RAND).In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a UE identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). Here, the RAND may be generated by base64encode (RAND).

[0048] In some embodiments of the disclosed technology, after a successful primary authentication, a unified data management entity (UDM) generates and stores an AKMA identifier (AKMAID), which includes an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home public land mobile network (HPLMN), the routing indicator is used to route network signaling with the AKMAID to the unified data management (UDM) instance, and the RAND is a random number assigned by the UDM to the UE.

[0049] In some embodiments of the disclosed technology, the UDM is configured to perform a UE parameter update (UPU) procedure and send the AKMAID as UE parameter update (UPU) data to the UE through the UE parameter update (UPU) procedure.

[0050] In some embodiments of the disclosed technology, the UE is configured to use AKMAID for application session establishment.

[0051] like Figure 4 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple processes 401-414.

[0052] At 401, a successful 5G master authentication results in the authentication server function key (K AUSF ) is stored at the Authentication Server Function (AUSF) and the User Equipment (UE). As part of the UE registration process, the UE and AUSF generate the AKMA anchor key (K AKMA ) and the associated key identifier. Here, K AKMA From K AUSF Export.

[0053] At 402a, the AUSF notifies the Unified Data Management (UDM) about the result and time of the authentication process with the User Equipment (UE) using a service-based interface request (such as Nudm_UE Authentication_Result confirmation request). This includes the Subscription Permanent Identifier (SUPI), the timestamp of the authentication, the authentication type (e.g., EAP method or 5G-AKA), and the serving network name.

[0054] At 402b, the UDM generates an AKMA identifier (AKMAID) for the UE, which is implemented based on some embodiments of the disclosed technology. The AKMAID is an identifier used by the UE for subsequent requests to the application function entity (AF). The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. In some embodiments of the disclosed technology, the AKMAID may include an MCC, an MNC, a routing indicator, and a RAND, where the MCC (Mobile Country Code) uniquely identifies the country, the MNC (Mobile Network Code) identifies the home PLMN (Public Land Mobile Network), the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is a random number assigned by the UDM to the UE (e.g., a RAND number used for authentication). The UDM stores the AKMAID and the authentication server function identifier (AUSFID) together with the UE's authentication status (e.g., subscription permanent identifier (SUPI), authentication result, timestamp, and serving network name).

[0055] At 402c, the UDM replies to the AUSF with a service-based interface response, such as a Nudm_UE Authentication_Result confirmation response.

[0056] At 403 , the UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE through the UE parameter update procedure.

[0057] At 404, the UE receives the AKMAID and compares it with the K AKMA and K AKMA The identifier is stored together.

[0058] At 405 , the UE starts communication with the AF using an application session establishment request, and in some embodiments of the disclosed technology, the application session establishment request includes an AKMAID.

[0059] At 406, the Application Function (AF) sends a key request with the AKMAID received from the UE to the AKMA Anchor Function (AAnF) to request the AF-specific key for the UE. The AF also includes its identity (eg, AF identifier) ​​in the request.

[0060] At 407, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in AAnF, then AAnF proceeds to 411. If K AKMAIf not available, the AAnF sends a service-based interface request (such as Nudm_UEAuth_ResultStatus request) to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the SUPI of the UE. The AAnF provides the AKMAID.

[0061] At 408, the UDM retrieves the identifier of the authentication server function (AUSF) instance (that has authenticated the UE) and the UE's SUPI information based on the AKMAID. The UDM sends a service-based interface response (such as a Nudm_UEAuth_ResultStatus response) that includes the AUSF instance identifier and UE Subscription Permanent Identifier (SUPI) of the last AUSF that has reported a successful primary authentication to the UDM.

[0062] At 409, the AAnF sends a key request to the AUSF by providing the UE SUPI.

[0063] At 410, the AUSF retrieves the AKMA anchor key (K AKMA ) and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0064] At 411, AAnF is based on K AKMA The derived application key (K AF ). AAnF can set K AF Expiration time.

[0065] At 412, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF Here, AAnF ID indicates the identification of AAnF.

[0066] At 413, the AF sends an application session establishment response message to the UE. The response message may include K AF The key expiration time.

[0067] At 414, the UE AKMA And derive K AF .

[0068] Figure 5 is a flow chart illustrating another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0069] In some embodiments of the disclosed technology, a data management function (such as a unified data management entity (UDM)) may generate an AKMA identifier (AKMAID) for an application session establishment procedure, which may be used to identify an AKMA procedure for a UE or may be used as an identifier to identify an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, and a random number (RAND) for authentication. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a Mobile Country Code (MCC), a Mobile Network Code (MNC), an Authentication Server Function identifier, an Application Authentication and Key Management Anchor Function (AAnF) identifier, and a random number (RAND).

[0070] In some embodiments of the disclosed technology, after a successful primary authentication, a unified data management entity (UDM) generates and stores an AKMA identifier (AKMAID), which includes an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home public land mobile network (HPLMN), the routing indicator is used to route network signaling with the AKMAID to the unified data management (UDM) instance, and the RAND is a random number assigned by the UDM to the UE.

[0071] In some embodiments of the disclosed technology, the UDM is configured to send an AKMA identifier (AKMAID) to an authentication server function (AUSF), and the AUSF is configured to store the AKMAID. The UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE via the UE parameter update procedure. The UE uses the AKMAID during its application session establishment process.

[0072] like Figure 5 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple processes 501-514.

[0073] At 501, a successful 5G master authentication results in the authentication server function key (KAUSF ) is stored at the Authentication Server Function (AUSF) and the UE. As part of the UE registration process, the UE and AUSF generate the AKMA anchor key (K AKMA ) and the associated key identifier. Here, K AKMA From K AUSF Export.

[0074] At 502a, the AUSF notifies the Unified Data Management (UDM) about the result and time of the authentication process with the User Equipment (UE) using a service-based interface request (such as Nudm_UE Authentication_Result confirmation request). This includes the Subscription Permanent Identifier (SUPI), the timestamp of the authentication, the authentication type (e.g., EAP method or 5G-AKA), and the serving network name.

[0075] At 502b, the UDM generates an AKMA identifier (AKMAID) for the UE, which is implemented based on some embodiments of the disclosed technology. The AKMAID is an identifier used by the UE for subsequent requests to the application function entity (AF). The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. In some embodiments of the disclosed technology, the AKMAID may include an MCC, an MNC, a routing indicator, and a RAND, where the MCC (Mobile Country Code) uniquely identifies the country, the MNC (Mobile Network Code) identifies the home PLMN (Public Land Mobile Network), the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is a random number assigned by the UDM to the UE (e.g., a RAND number used for authentication). The UDM stores the AKMAID and the authentication server function identifier (AUSFID) together with the UE's authentication status (e.g., subscription permanent identifier (SUPI), authentication result, timestamp, and serving network name).

[0076] At 502c, the UDM replies to the AUSF with a service-based interface response, such as a Nudm_UEAuthentication_Result confirmation response including the AKMAID.

[0077] At 502d, the AUSF receives the AKMAID and compares it with the UE's K AKMA and K AKMA Identifiers are stored.

[0078] At 503 , the UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE through the UE parameter update procedure.

[0079] At 504, the UE receives the AKMAID and compares it with the K AKMA and K AKMA The identifier is stored together.

[0080] At 505 , the UE starts communication with the AF using an application session establishment request, and in some embodiments of the disclosed technology, the application session establishment request includes an AKMAID.

[0081] At 506, the Application Function (AF) sends a key request with the AKMAID received from the UE to the AKMA Anchor Function (AAnF) to request the AF-specific key for the UE. The AF also includes its identity (eg, AF identifier) ​​in the request.

[0082] At 507, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in AAnF, then AAnF proceeds to 511. If K AKMA Not available, the AAnF sends a service-based interface request (such as Nudm_UEAuth_ResultStatus request) to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE. The AAnF provides the AKMAID.

[0083] At 508, the UDM retrieves information of the identifier of the AUSF instance that has authenticated the UE based on the AKMAID. The UDM sends a service-based interface response (such as Nudm_UEAuth_ResultStatus response) including the AUSF instance identifier of the last AUSF that has reported a successful primary authentication to the UDM.

[0084] At 509, the AAnF sends a key request including the AKMAID to the AUSF.

[0085] At 510, AUSF retrieves K based on AKMAID. AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0086] At 511, AAnF is based on K AKMA And derive K AF . AAnF can set K AF Expiration time.

[0087] At 512, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF Here, AAnF ID indicates the identification of AAnF.

[0088] At 513, AF receives AAnF ID, K AF and key expiration time and store it together with AKMAID, and send application session establishment response information to UE. The response information may include K AF The key expiration time.

[0089] At 514, the UE performs the AKMA And derive K AF .

[0090] Figure 6 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0091] In some embodiments of the disclosed technology, a data management function (such as an authentication server function entity (AUSF)) generates an AKMA identifier (AKMAID) for the application session establishment process, which can be used to identify the AKMA process for the UE or can be used as an identifier to identify the AKMA anchor key.

[0092] In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a Mobile Country Code (MCC), a Mobile Network Code (MNC), a Routing Indicator, and a Random Number (RAND).

[0093] In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). Here, the RAND may be generated by base64encode(RAND).

[0094] In some embodiments of the disclosed technology, after a successful primary authentication, the AUSF generates an AKMA identifier (AKMAID) including an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home public land mobile network (HPLMN), the routing indicator is used to route network signaling with the AKMAID to a unified data management (UDM) instance, and the RAND is a random number assigned by the AUSF to the UE.

[0095] In some embodiments of the disclosed technology, the AUSF is configured to send an AKMA identifier (AKMAID) to a unified data management entity (UDM), and the UDM stores the AKMAID.

[0096] The UDM performs the UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE through the UE parameter update procedure. The UE uses the AKMAID during its application session establishment process.

[0097] like Figure 6 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple processes 601-615.

[0098] At 601, a successful 5G master authentication results in the authentication server function key (K AUSF ) is stored at AUSF and UE. As part of the UE registration process, the UE and AUSF generate an AKMA anchor key (K AKMA ) and the associated key identifier. Here, K AKMA From K AUSF Export.

[0099] At 602, the AUSF generates an AKMA identifier (AKMAID) for the UE. The AKMAID is an identifier used by the UE for subsequent requests towards the Application Function (AF). The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. In some embodiments of the disclosed technology, the AKMAID may include an MCC, an MNC, a routing indicator, and a RAND, where the MCC (Mobile Country Code) uniquely identifies the country, the MNC (Mobile Network Code) identifies the home PLMN (Public Land Mobile Network), the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is a random number that the Authentication Server Function (AUSF) has assigned to the UE.

[0100] At 603a, the AUSF notifies the Unified Data Management (UDM) about the result and time of the authentication process with the UE using a service-based interface request (such as Nudm_UE Authentication_Result confirm request). This includes the subscription permanent identifier (SUPI), the timestamp of the authentication, the authentication type (e.g., EAP method or 5G-AKA), the serving network name, and the AKMAID.

[0101] At 603b, the UDM stores the AKMAID and the AKMA identifier (AKMAID) together with the UE's authentication status (eg, SUPI, authentication result, timestamp, and serving network name).

[0102] At 603c, the UDM replies to the AUSF with a service-based interface response, such as a Nudm_UE Authentication_Result confirmation response.

[0103] At 604 , the UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE through the UE parameter update procedure.

[0104] At 605, the UE receives the AKMAID and compares it with the K AKMA and K AKMA The identifier is stored together.

[0105] At 606, the UE starts communication with the AF using an application session establishment request, and in some embodiments of the disclosed technology, the application session establishment request includes an AKMAID.

[0106] At 607, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF-specific key for the UE. The AF also includes its identity (eg, AF identifier) ​​in the request.

[0107] At 608, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in AAnF, then AAnF proceeds to 612, which will be discussed below. AKMA If not available, the AAnF sends a service-based interface request (such as a Nudm_UEAuth_ResultStatus request) to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the SUPI of the UE. The AAnF provides the AKMAID.

[0108] At 609, the UDM retrieves information of the identifier of the AUSF instance that has authenticated the UE and the SUPI of the UE based on the AKMAID. The UDM sends a service-based interface response (such as a Nudm_UEAuth_ResultStatus response) that includes the AUSF instance identifier and the User Equipment (UE) Subscription Permanent Identifier (SUPI) of the last AUSF that has reported a successful primary authentication to the UDM.

[0109] At 610, the AAnF sends an AKMA key request to the AUSF by providing the SUPI.

[0110] At 611, the AUSF retrieves K based on the SUPI. AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0111] At 612, AAnF is based on K AKMA And derive K AF .AAnFSetK AF Expiration time.

[0112] At 613, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF Here, AAnF ID indicates the identification of AAnF.

[0113] At 614, the AF receives the AAnF ID, K AF and key expiration time and stores it together with AKMAID, and sends application session establishment response information to UE. The response information includes K AF The key expiration time.

[0114] At 615, the UE performs the AKMA And derive K AF .

[0115] Figure 7 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0116] In some embodiments of the disclosed technology, a data management function (such as an authentication server function (AUSF)) generates an AKMA identifier (AKMAID) for an application session establishment process, which can be used to identify the AKMA process for a UE or can be used as an identifier to identify an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, and a random number (RAND) for authentication. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND) for authentication. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND) for authentication. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a Mobile Country Code (MCC), a Mobile Network Code (MNC), an Authentication Server Function identifier, an Application Authentication and Key Management Anchor Function (AAnF) identifier, and a random number (RAND).In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). Here, the RAND may be generated by base64encode (RAND).

[0117] In some embodiments of the disclosed technology, after a successful primary authentication, the AUSF generates and stores an AKMA identifier (AKMAID), which includes an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home public land mobile network (HPLMN), the routing indicator is used to route network signaling with the AKMAID to a unified data management (UDM) instance, and the RAND is a random number assigned by the AUSF to the UE.

[0118] In some embodiments of the disclosed technology, the AUSF sends the AKMAID to a unified data management entity (UDM), and the UDM stores the AKMAID.

[0119] In some embodiments of the disclosed technology, the UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE through the UE parameter update procedure. The UE uses the AKMAID during its application session establishment process.

[0120] like Figure 7 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple operations 701-715.

[0121] At 701, a successful 5G master authentication results in the authentication server function key (K AUSF ) is stored at AUSF and UE. As part of the UE registration process, the UE and AUSF generate an AKMA anchor key (K AKMA ) and the associated key identifier. K AKMA From K AUSF Export.

[0122] At 702, the Authentication Server Function (AUSF) generates an AKMA Identifier (AKMAID) for the UE. The AKMAID is an identifier used by the UE for subsequent requests towards the Application Function (AF). The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. In some embodiments, the AKMA Identifier (AKMAID) may include, among other things, a Mobile Country Code (MCC), a Mobile Network Code (MNC), a Routing Indicator, and a Random Number (RAND). Here, the MCC uniquely identifies the country, the MNC identifies the home PLMN, the Routing Indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is a random number assigned by the AUSF to the UE. The AUSF compares the AKMAID to the K AKMA and K AKMA The identifier is stored together.

[0123] At 703a, the AUSF notifies the Unified Data Management (UDM) about the result and time of the authentication process with the UE using a service-based interface request (such as Nudm_UE Authentication_Result confirmation request). This includes SUPI, timestamp of authentication, authentication type (e.g., EAP method or 5G-AKA), serving network name, and AKMAID.

[0124] At 703b, the UDM stores the AKMAID and the Authentication Server Function Identifier (AUSFID) together with the UE's authentication status (eg, SUPI, authentication result, timestamp, and serving network name).

[0125] At 703c, the UDM replies to the AUSF with a service-based interface response, such as a Nudm_UE Authentication_Result confirmation response.

[0126] At 704 , the UDM performs a User Equipment Parameter Update (UPU) procedure and sends the AKMAID as User Equipment Parameter Update (UPU) data to the UE through the UE parameter update procedure.

[0127] At 705, the UE receives the AKMAID and compares it with the K AKMA and K AKMA The identifier is stored together.

[0128] At 706, the UE starts communication with the AF using an application session establishment request including the AKMAID.

[0129] At 707, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF-specific key for the UE. The AF also includes its identity (eg, AF identifier) ​​in the request.

[0130] At 708, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 712, which will be discussed below. AKMA If not available, the AAnF sends a service-based interface request (such as a Nudm_UEAuth_ResultStatus request) to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE. The AAnF provides the AKMAID.

[0131] At 709, the UDM retrieves information of the identifier of the AUSF instance that has authenticated the UE based on the AKMAID. The UDM sends a service-based interface response (such as Nudm_UE Auth_Response status response) that includes the AUSF instance identifier of the last AUSF that has reported a successful primary authentication to the UDM.

[0132] At 710, the AAnF sends an AKMA key request to the AUSF by providing the AKMAID.

[0133] At 711, AUSF retrieves K based on AKMAID. AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0134] At 712, AAnF is based on K AKMA And derive K AF . AAnF can set K AF Expiration time.

[0135] At 713, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF and key expiration time.

[0136] At 714, the AF receives the AAnF ID, K AF and key expiration time and stores it together with AKMAID, and sends application session establishment response information to UE. The response information includes K AF The key expiration time.

[0137] At 715, the UE performs the AKMA And derive K AF .

[0138] Figure 8 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0139] like Figure 8 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple operations 801-813.

[0140] At 801, a successful 5G master authentication results in the authentication server function key (K AUSF ) is stored at the Authentication Server Function (AUSF) and the User Equipment (UE). As part of the UE registration process, the UE and AUSF generate the AKMA anchor key (K AKMA ) and the associated key identifier. In some embodiments, K AKMA From K AUSF Export.

[0141] At 802a, the AUSF notifies the Unified Data Management (UDM) of the result and timing of the authentication process with the UE using a service-based interface request such as Nudm_UE Authentication_Result confirmation request. This includes the SUPI, the timestamp of the authentication, the authentication type (e.g., EAP method or 5G-AKA), and the serving network name.

[0142] In some embodiments of the disclosed technology, a data management function (such as a unified data management entity (UDM)) may generate an application authentication and key management (AKMA) identifier (AKMAID) for an application session establishment process, which may be used to identify an AKMA process for a UE or may be used as an identifier for identifying an AKMA anchor key. In some implementations, the AKMA identifier (AKMAID) may include, among other things, a combination of a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier (AUSFID), and a random number (RAND), or a combination of a mobile country code (MCC), a mobile network code (MNC), a routing indicator, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other aspects, a combination of a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier (AUSFID), a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND), or a combination of a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other aspects, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND) for authentication. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND).Here, RAND may be generated by base64encode(RAND).

[0143] In some embodiments of the disclosed technology, after a successful primary authentication, a unified data management entity (UDM) generates and stores an AKMA identifier (AKMAID) that includes a combination of a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier (AUSFID), and a random number (RAND), or a combination of a mobile country code (MCC), a mobile network code (MNC), a routing indicator, and a random number (RAND). In some embodiments of the disclosed technology, after a successful primary authentication, a unified data management entity (UDM) generates and stores an AKMA identifier (AKMAID) that includes a combination of a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier (AUSFID), a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND), or a combination of a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a Mobile Country Code (MCC), a Mobile Network Code (MNC), an Authentication Server Function identifier, an Application Authentication and Key Management Anchor Function (AAnF) identifier, a User Equipment (UE) identifier (such as a Universal Public Subscription Identifier (GPSI) or other UE identifier), and a Random Number (RAND). Here, the MCC uniquely identifies the country, the MNC identifies the home PLMN, the AUSFID is an identifier of the AUSF, the RAND is a random number that the UDM has assigned to the UE, and the routing indicator is used to route network signaling with the AKMAID to the AUSF instance.Here, RAND may be generated by base64encode(RAND).

[0144] In some embodiments of the disclosed technology, the UDM is configured to send the AKMAID to the AUSF, and the AUSF stores the AKMAID.

[0145] The UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as UPU data to the UE through the UE parameter update procedure.

[0146] In some embodiments of the disclosed technology, the UE uses AKMAID during its application session establishment process.

[0147] At 802b, the UDM generates an AKMA identifier (AKMAID) for the UE, as implemented in some embodiments of the disclosed technology. The AKMAID is an identifier used by the UE in subsequent requests to the Application Function (AF). The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. In an embodiment of the disclosed technology, the AKMAID may include an MCC, an MNC, an AUSFID, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the AUSFID is an identifier of the AUSF, and the RAND is a random number assigned to the UE by the UDM. In another embodiment of the disclosed technology, the AKMAID may include an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and the RAND is a random number assigned to the UE by the UDM. The UDM stores the AKMAID along with the UE's authentication status (SUPI, authentication result, timestamp, and serving network name).

[0148] At 802c, the UDM replies to the AUSF with a service-based interface response, such as a Nudm_UEAuthentication_Result confirmation response including the AKMAID.

[0149] At 803, the AUSF receives the AKMAID and compares it to the K AKMA and K AKMA The identifier is stored together.

[0150] At 804 , the UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE through the UE parameter update procedure.

[0151] At 805, the UE receives the AKMAID and compares it with the K AKMAand K AKMA The identifier is stored together.

[0152] At 806, the UE starts communication with the AF using an application session establishment request, which includes the AKMAID.

[0153] At 807, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF-specific key for the UE. The AF also includes its identity (AF identifier) ​​in the request.

[0154] At 808, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 810, which will be discussed below. AKMA If it is not available, AAnF sends a key request including AKMAID to AUSF.

[0155] At 809, AUSF retrieves K based on AKMAID. AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0156] At 810, AAnF is based on K AKMA And derive K AF .AAnFSetK AF Expiration time.

[0157] At 811, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF Here, AAnF ID indicates the identification of AAnF.

[0158] At 812, the AF receives the AAnF ID, K AF and key expiration time and store it together with AKMAID, and send application session establishment response information to UE. The response information may include K AF The key expiration time.

[0159] At 813, the UE AKMA And derive K AF .

[0160] Figure 9is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0161] In some embodiments of the disclosed technology, a data management function (such as an authentication server function (AUSF)) may generate an application authentication and key management (AKMA) identifier (AKMAID) for an application session establishment process, which may be used to identify an AKMA process for a UE or may be used as an identifier for identifying an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a combination of a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier (AUSFID), and a random number (RAND), or a combination of a mobile country code (MCC), a mobile network code (MNC), a routing indicator, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other aspects, a combination of a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier (AUSFID), a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND), or a combination of a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other aspects, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). Here, the RAND may be generated by base64encode(RAND).

[0162] In some embodiments of the disclosed technology, after a successful primary authentication, the AUSF generates and stores an AKMAID, which includes an MCC, an MNC, an AUSFID, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the AUSFID is an identifier of the AUSF, and the RAND is a random number assigned to the UE by the UDM. The AKMAID may also include an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and the RAND is a random number assigned to the UE by the UDM. In some embodiments of the disclosed technology, after a successful primary authentication, the AUSF generates and stores an AKMA identifier (AKMAID), which includes a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier (AUSFID), a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier) ​​and a random number (RAND), or a combination of a mobile country code (MCC), a mobile network code (MNC), a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier) ​​and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other aspects, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND).Here, MCC uniquely identifies the country, MNC identifies the home PLMN, AUSFID is the identifier of the AUSF, RAND is the random number that the UDM has assigned to the UE, and the routing indicator is used to route network signaling with the AKMAID to the AUSF instance. Here, RAND can be generated by base64encode(RAND).

[0163] In some embodiments of the disclosed technology, the AUSF sends the AKMAID to the UDM, and the UDM stores the AKMAID.

[0164] The UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as UPU data to the UE through the UE parameter update procedure. The UE uses the AKMAID to establish an application session.

[0165] like Figure 9 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple operations 901-913.

[0166] At 901, a successful 5G master authentication results in the authentication server function key (K AUSF ) is stored at the Authentication Server Function (AUSF) and the User Equipment (UE). As part of the UE registration process, the UE and AUSF generate the AKMA anchor key (K AKMA ) and the associated key identifier. In some embodiments, K AKMA From K AUSF Export.

[0167] At 902, the AUSF generates an AKMA identifier (AKMAID) for the UE. The AKMAID is an identifier used by the UE for subsequent requests towards the Application Function (AF). The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. In some embodiments of the disclosed technology, the AKMAID may include a combination of an MCC, an MNC, an AUSFID, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home Public Land Mobile Network (PLMN), the AUSFID is an identifier of the Authentication Server Function (AUSF), and the RAND is a random number assigned to the UE by the AUSF. The AKMAID may also include a combination of an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and the RAND is a random number assigned to the UE by the UDM. The AUSF combines the AKMAID with the K AKMA and K AKMA The identifier is stored together.

[0168] At 903a, the AUSF notifies the Unified Data Management (UDM) about the result and time of the authentication process with the UE using a service-based interface request (such as Nudm_UE Authentication_Result confirmation request). This includes SUPI, timestamp of authentication, authentication type (e.g., EAP method or 5G-AKA), serving network name, and AKMAID.

[0169] At 903b, the UDM stores the AKMAID together with the UE's authentication status (eg, SUPI, authentication result, timestamp, and serving network name).

[0170] At 903c, the UDM replies to the AUSF with a service-based interface response, such as a Nudm_UE Authentication_Result confirmation response.

[0171] At 904 , the UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as UE parameter update (UPU) data to the UE through the UE parameter update procedure.

[0172] At 905, the UE receives the AKMAID and compares it with the K AKMA and K AKMA The identifier is stored together.

[0173] At 906, the UE starts communicating with the application function (AF) using an application session establishment request, which includes the AKMAID.

[0174] At 907, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF specific key for the UE. The AF also includes its identity (AF identifier) ​​in the request.

[0175] At 908, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 910, which will be discussed below. AKMA Not available, AAnF sends AKMA key request to AUSF by providing AKMAID.

[0176] At 909, AUSF retrieves K based on AKMAID. AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and KAKMA identifier and stores it along with the AKMAID.

[0177] At 910, AAnF is based on K AKMA And derive K AF .AAnFSetK AF Expiration time.

[0178] At 911, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF and key expiration time. Here, AAnF ID is the identifier of AAnF.

[0179] At 912, the AF sends an application session establishment response message to the UE. The response message includes K AF The key expiration time.

[0180] At 913, the UE AKMA And derive K AF .

[0181] Figure 10 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0182] In some embodiments of the disclosed technology, a data management function (such as a unified data management entity (UDM)) may generate an AKMA identifier (AKMAID) for an application session establishment procedure, which may be used to identify an AKMA procedure for a UE or may be used as an identifier to identify an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a combination of an MCC, a MNC, an AUSFID, and a RAND, or a combination of an MCC, an MNC, a routing indicator, and a RAND. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a combination of an MCC, an MNC, an AUSFID, and a RAND, or a combination of an MCC, an MNC, a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a RAND. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND).

[0183] In some embodiments of the disclosed technology, after a successful primary authentication, a unified data management entity (UDM) generates and stores a combination of MCC, MNC, AUSFID and RAND (where MCC uniquely identifies the country, MNC identifies the home PLMN, AUSFID is an identifier of the AUSF, and RAND is a random number assigned to the UE by the UDM) or a combination of MCC, MNC, a routing indicator and RAND (where MCC uniquely identifies the country, MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and RAND is a random number assigned to the UE by the UDM) as the AKMAID. In some embodiments of the disclosed technology, after successful primary authentication, a unified data management entity (UDM) generates and stores a combination of MCC, MNC, AUSFID, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier) ​​and RAND (where MCC uniquely identifies the country, MNC identifies the home PLMN, AUSFID is an identifier of the AUSF, and RAND is a random number assigned to the UE by the UDM) or a combination of MCC, MNC, routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier) ​​and RAND (where MCC uniquely identifies the country, MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and RAND is a random number assigned to the UE by the UDM) as the AKMAID.

[0184] In some embodiments of the disclosed technology, the UDM is configured to send the AKMAID to an authentication server function (AUSF), and the AUSF is configured to store the AKMAID.

[0185] The UDM performs the UE parameter update (UPU) procedure and sends the AKMAID as user equipment parameter update (UPU) data to the UE through the UE parameter update procedure. The UE uses the AKMAID during its application session establishment process.

[0186] In some embodiments of the disclosed technology, the authentication server function entity (AUSF) may alternatively generate a combination of MCC, MNC, AUSFID and RAND or a combination of MCC, MNC, routing indicator and RAND as the AKMAID. In some embodiments of the disclosed technology, the authentication server function entity (AUSF) may alternatively generate a combination of MCC, MNC, AUSFID, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier) ​​and RAND or a combination of MCC, MNC, routing indicator and RAND as the AKMAID.

[0187] In some embodiments of the disclosed technology, after a successful primary authentication, the AUSF generates and stores a combination of MCC, MNC, AUSFID and RAND (wherein the MCC uniquely identifies the country, the MNC identifies the home PLMN, the AUSFID is an identifier of the AUSF, and the RAND is a random number assigned to the UE by the UDM) or a combination of MCC, MNC, a routing indicator and RAND (wherein the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and the RAND is a random number assigned to the UE by the UDM) as the AKMAID. In some embodiments of the disclosed technology, after successful primary authentication, the AUSF generates and stores a combination of MCC, MNC, AUSFID, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier) ​​and RAND (wherein the MCC uniquely identifies the country, the MNC identifies the home PLMN, the AUSFID is an identifier of the AUSF, and the RAND is a random number assigned to the UE by the UDM) or a combination of MCC, MNC, a routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier) ​​and RAND (wherein the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and the RAND is a random number assigned to the UE by the UDM) as the AKMAID.

[0188] In some embodiments of the disclosed technology, the AUSF sends the AKMAID to the UDM, and the UDM stores the AKMAID. The UDM performs a UE parameter update (UPU) procedure and sends the AKMAID as UPU data to the UE via the UE parameter update procedure. The UE uses the AKMAID during its application session establishment process.

[0189] like Figure 10 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple operations 1001-1013.

[0190] At 1001, a successful 5G master authentication results in the authentication of the server function key (K AUSF ) is stored at the Authentication Server Function (AUSF) and the UE. The UE and UDM store the RAND generated and used in the Authentication Vector (AV) in the primary authentication. As part of the UE registration process, the UE and AUSF generate the AKMA anchor key (K AKMA ) and the associated key identifier. K AKMA From K AUSF Export.

[0191] At 1002a, the UE generates an AKMAID. The AKMAID is an identifier that will be used by the UE for subsequent requests to the Application Function (AF). The AKMAID can only be refreshed by running a new primary authentication, so the lifetime of the AKMAID cannot be shorter than the time interval between primary authentications. In some embodiments, the AKMAID includes a combination of an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is generated and used in the authentication vector (AV) in the primary authentication. The UE combines the AKMAID with the K AKMA and K AKMA The identifier is stored together.

[0192] At 1002b, the UDM generates an AKMAID. The AKMAID is an identifier used by the UE for subsequent requests towards the AF. The AKMAID can only be refreshed by running a new primary authentication, so the lifetime of the AKMAID cannot be shorter than the time interval between primary authentications. The AKMAID may include a combination of an MCC, an MNC, a routing indicator, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the AUSF instance, and the RAND is generated and used in the authentication vector (AV) in the primary authentication. The UDM stores the AKMAID and the AUSF identifier (AUSFID) together with the UE's authentication status (e.g., SUPI, authentication result, timestamp, and serving network name).

[0193] At 1003, the UE starts communication with the AF using an application session establishment request, which includes the AKMAID.

[0194] At 1004, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF-specific key for the UE. The AF also includes its identity (eg, AF identifier) ​​in the request.

[0195] At 1005, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 1009, which will be discussed below. AKMA If not available, the AAnF sends a service-based interface request (such as a Nudm_UEAuth_ResultStatus request) to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the UE's Subscription Permanent Identifier (SUPI). The AAnF provides the AKMAID.

[0196] At 1006, the UDM retrieves information of the identifier of the AUSF instance that has authenticated the UE and the UE's SUPI based on the AKMAID. The UDM sends a Nudm_UEAuth_ResultStatus response including the AUSF instance identifier and UE SUPI of the last AUSF that has reported a successful primary authentication to the UDM.

[0197] At 1007, the AAnF sends a key request to the AUSF by providing the UE SUPI.

[0198] At 1008, AUSF retrieves K based on SUPI AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0199] At 1009, AAnF is based on K AKMA And derive K AF . AAnF can set K AF Expiration time.

[0200] At 1010, AAnF sends a key response message to AF. The response message includes AAnF ID, K AF and key expiration time. Here, AAnF ID is the identifier of AAnF.

[0201] At 1011, AF receives AAnF ID, K AF and key expiry time and stores it along with the AKMAID.

[0202] At 1012, the AF sends an application session establishment response message to the UE. The response message includes K AF The key expiration time.

[0203] At 1013, the UE performs the following operations based on K AKMA And derive K AF .

[0204] Figure 11 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0205] like Figure 11 As shown, application session establishment based on some embodiments of the disclosed technology may include multiple operations 1101-1113.

[0206] In some embodiments of the disclosed technology, a UE may generate an AKMA identifier (AKMAID) for an application session establishment procedure, which may be used to identify an AKMA procedure for the UE or may be used as an identifier to identify an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a combination of an MCC, an MNC, an AUSFID, and a RAND, or a combination of an MCC, an MNC, a routing indicator, and a RAND. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a combination of an MCC, an MNC, an AUSFID, a user equipment (UE) identifier (such as a Universal Public Subscription Identifier (GPSI) or other UE identifier), and a RAND, or a combination of an MCC, an MNC, a routing indicator, and a RAND. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND).

[0207] At 1101, successful 5G master authentication results in authentication of the server function key (K AUSF ) is stored at the AUSF and UE. The UE and UDM will generate and use the RAND stored in the authentication vector (AV) in the primary authentication. As part of the UE registration process, the UE and AUSF generate the AKMA anchor key (K AKMA ) and the associated key identifier. K AKMA From K AUSF Export.

[0208] At 1102a, the UE generates an AKMAID. The AKMAID is an identifier used by the UE for subsequent requests towards the AF. The AKMAID can only be refreshed by running a new primary authentication, so the lifetime of the AKMAID cannot be shorter than the time interval between primary authentications. The AKMAID may include a combination of an MCC, an MNC, a routing indicator, a user equipment (UE) identifier (such as a Universal Public Subscription Identifier (GPSI) or other UE identifier), and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is generated and used in the authentication vector (AV) in the primary authentication. The UE combines the AKMAID with the K AKMA and K AKMA The identifier is stored together.

[0209] In one embodiment, after a successful primary authentication, the UE generates and stores a combination of MCC, MNC, routing indicator, and RAND as the AKMAID, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is generated and used in the authentication vector (AV) in the primary authentication.

[0210] In another embodiment, after a successful primary authentication, the UDM and UE generate and store a combination of the MCC, MNC, routing indicator, user equipment (UE) identifier (such as the Universal Public Subscription Identifier (GPSI) or other UE identifier), and RAND as the AKMAID, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is generated and used in the authentication vector (AV) in the primary authentication. The UE uses the AKMAID during its application session establishment process.

[0211] At 1102b, the UDM stores the RAND and AUSFID along with the UE's authentication status (e.g., SUPI, authentication result, timestamp, and serving network name). The RAND is generated and used in the authentication vector (AV) in the primary authentication.

[0212] In some embodiments, the UDM stores the RAND generated and used in the Authentication Vector (AV) in the Master Authentication.

[0213] In some implementations, the UE uses the AKMAID during its application session establishment process.

[0214] At 1103, the UE starts communicating with the AF using an application session establishment request, which includes the AKMAID.

[0215] At 1104, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF specific key for the UE. The AF also includes its identity (AF identifier) ​​in the request.

[0216] At 1105, the AAnF checks whether it has the UE-specific K based on the AKMAID. AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 1109, which will be discussed below. AKMA If not available, the AAnF obtains the RAND from the AKMAID. The AAnF then sends a Nudm_UEAuth_ResultStatus request to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the UE's SUPI. The AAnF provides the RAND.

[0217] At 1106, the UDM retrieves information of the identifier of the AUSF instance that has authenticated the UE and the UE's SUPI based on the RAND. The UDM sends a Nudm_UEAuth_ResultStatus response including the AUSF instance identifier of the last AUSF that has reported a successful primary authentication to the UDM, and the UE SUPI.

[0218] At 1107, the AAnF sends a key request to the AUSF by providing the UE SUPI.

[0219] At 1108, the AUSF retrieves K based on the SUPI. AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0220] At 1109, AAnF is based on K AKMA And derive K AF In some embodiments, AAnF sets K AF Expiration time.

[0221] At 1110, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF and key expiration time. AAnF ID is the identifier of AAnF.

[0222] At 1111, AF receives AAnF ID, K AFand key expiry time and stores it along with the AKMAID.

[0223] At 1112, the AF sends an application session establishment response message to the UE. In some embodiments, the response message includes K AF The key expiration time.

[0224] At 1113, the UE AKMA And derive K AF .

[0225] Figure 12 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0226] In some embodiments of the disclosed technology, the UE generates and stores a combination of the MCC, MNC, routing indicator, and RAND as an AKMAID, which can be used to identify an AKMA procedure for the UE or can be used as an identifier to identify an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) can include, among other things, a combination of the MCC, MNC, AUSFID, and RAND. In some embodiments of the disclosed technology, the UE generates and stores a combination of the MCC, MNC, routing indicator, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and RAND as an AKMAID, which can be used to identify an AKMA procedure for the UE or can be used as an identifier to identify an AKMA anchor key. In some embodiments, the AKMA identifier (AKMAID) can include, among other things, a combination of the MCC, MNC, AUSFID, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and RAND. In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), an authentication server function identifier, an application authentication and key management anchor function (AAnF) identifier, and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a mobile country code (MCC), a mobile network code (MNC), a routing indicator, an application authentication and key management anchor function (AAnF) identifier, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a random number (RAND). In some embodiments, the AKMA identifier (AKMAID) may include, among other things, a Mobile Country Code (MCC), a Mobile Network Code (MNC), an Authentication Server Function identifier, an Application Authentication and Key Management Anchor Function (AAnF) identifier, a User Equipment (UE) identifier (such as a General Public Subscription Identifier (GPSI) or other UE identifier), and a random number (RAND).

[0227] After a successful primary authentication, the UE generates and stores a combination of MCC, MNC, routing indicator, user equipment (UE) identifier (such as Universal Public Subscription Identifier (GPSI) or other UE identifier) ​​and RAND as the AKMAID, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is generated and used in the authentication vector (AV) in the primary authentication.

[0228] After a successful primary authentication, the UDM stores the RAND generated and used in the Authentication Vector (AV) in the primary authentication. The UE uses the AKMAID during its application session establishment.

[0229] In some embodiments, AAnF generates a new RAND and a new AKMAID.

[0230] In some embodiments, the UE generates a new RAND and a new AKMAID. In some embodiments, the UE may update the old AKMAID with the received new AKMAID.

[0231] At 1201, successful 5G master authentication results in K AUSF Stored at AUSF and UE. The UE and UDM will store RAND, which is generated and used in the authentication vector (AV) in the primary authentication. As part of the UE registration process, the UE and AUSF generate the AKMA anchor key (K AKMA ) and the associated key identifier. K AKMA From K AUSF Export.

[0232] At 1202a, the UE generates an AKMAID. Here, the AKMAID is an identifier used by the UE in subsequent requests towards the AF. The AKMAID may include a combination of the MCC, MNC, routing indicator, and RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, and the RAND is generated and used in the authentication vector (AV) in the primary authentication. The UE combines the AKMAID with the K AKMA and K AKMA The identifier is stored together.

[0233] At 1202b, the UDM stores the RAND and AUSFID along with the UE's authentication status (eg, SUPI, authentication result, timestamp, and serving network name). The RAND is generated and used in the authentication vector (AV) in the primary authentication.

[0234] At 1203, the UE starts communicating with the AF using an application session establishment request, which includes the AKMAID.

[0235] At 1204, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF-specific key for the UE. The AF also includes its identity (AF identifier) ​​in the request.

[0236] At 1205, the AAnF checks whether it has a UE-specific K based on the AKMAID. AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 1209, which will be discussed below. AKMA If not available, the AAnF obtains the RAND from the AKMAID. The AAnF then sends a Nudm_UEAuth_ResultStatus request to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the UE's SUPI. The AAnF provides the RAND.

[0237] At 1206, the UDM retrieves information of the identifier of the AUSF instance that has authenticated the UE and the UE's SUPI based on the RAND. The UDM sends a Nudm_UEAuth_ResultStatus response including the AUSF instance identifier of the last AUSF that has reported a successful primary authentication to the UDM, and the UE SUPI.

[0238] At 1207, the AAnF sends a key request to the AUSF by providing the UE SUPI.

[0239] At 1208, AUSF retrieves K based on SUPI AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0240] At 1209, the AAnF generates a new RAND and a new AKMAID based on the new RAND. In some embodiments, the new AKMAID may include a combination of MCC, MNC, routing indicator, and new RAND, wherein the MCC, MNC, and routing indicator are identical to the corresponding parts of the old AKMAID. This means that the new AKMAID can only be obtained by updating the old RAND in the old AKMAID with the new RAND. The AAnF will K AKMA and K AKMAThe identifier is stored with the new AKMAID and the old AKMAID is deleted. AAnF is based on K AKMA And derive K AF .AAnFSetK AF Expiration time. AAnF can also be based on K AKMA and the new RAND generated by AAnF to derive K AF .

[0241] At 1210, AAnF sends a key response message to AF. The key response message includes AAnF ID, new RAND or new AKMAID, K AF and key expiration time. Here, AAnF ID is the identifier of AAnF.

[0242] At 1211, AF receives AAnF ID, K AF and key expiry time and stores it along with the AKMAID.

[0243] At 1212, the AF sends an application session establishment response message to the UE. The response message includes a new RAND or a new AKMAID and K AF The key expiration time.

[0244] At 1213, the UE updates the old AKMID with the received new AKMAID, or the UE generates a new AKMAID based on the received new RAND. In some embodiments, the new AKMAID includes a combination of MCC, MNC, routing indicator and new RAND, wherein the MCC, MNC and routing indicator are the same as the corresponding parts of the old AKMAID, so the new AKMAID can only be obtained by updating the old RAND in the old AKMAID with the new RAND. The UE will K AKMA and K AKMA The identifier is stored together with the new AKMAID and the old AKMAID is deleted. AKMA And derive K AF UE can also be based on K AKMA and the received new RAND generated by AAnF to derive K AF .

[0245] Figure 13 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0246] At 1301, successful 5G master authentication results in K AUSFStored at AUSF and UE. UE and UDM store RAND generated and used in the Authentication Vector (AV) in the Master Authentication. As part of the UE registration process, UE and AUSF generate the AKMA Anchor Key (K AKMA ) and the associated key identifier. K AKMA From K AUSF Export.

[0247] At 1302a, the UE generates an AKMAID. The AKMAID is an identifier used by the UE for subsequent requests towards the AF. The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. In some embodiments, the AKMAID includes a combination of an MCC, an MNC, a routing indicator, an AAnF ID, and a RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, the AAnF ID is an identifier used to identify the AAnF entity, and the RAND is generated and used in the authentication vector (AV) in the primary authentication. The UE combines the AKMAID with the K AKMA and K AKMA The identifier is stored together.

[0248] At 1302b, the UDM stores the RAND and AUSFID along with the UE's authentication status (e.g., SUPI, authentication result, timestamp, and serving network name). The RAND is generated and used in the authentication vector (AV) in the primary authentication.

[0249] At 1303, the UE starts communication with the AF using an application session establishment request. The request includes the AKMAID.

[0250] At 1304, the AF sends a key request with the AKMAID received from the UE to the AAnF to request the AF-specific key for the UE. The AF also includes its identity (AF identifier) ​​in the request.

[0251] At 1305, the AAnF checks whether it has the UE-specific K AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 1309, which will be discussed below. AKMA If not available, the AAnF obtains the RAND from the AKMAID. The AAnF then sends a Nudm_UEAuth_ResultStatus request to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the UE's SUPI. The AAnF provides the RAND.

[0252] At 1306, the UDM retrieves information of the identifier of the AUSF instance that has authenticated the UE and the UE's SUPI based on the RAND. The UDM sends a Nudm_UEAuth_ResultStatus response including the AUSF instance identifier of the last AUSF that reported a successful primary authentication to the UDM and the UE SUPI.

[0253] At 1307, the AAnF sends a key request to the AUSF by providing the UE SUPI.

[0254] At 1308, the AUSF retrieves K based on the SUPI. AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0255] At 1309, AAnF is based on K AKMA And derive K AF . AAnF can set K AF Expiration time.

[0256] At 1310, AAnF sends a key response message to AF. The key response message includes AAnF ID, K AF and key expiration time. AAnF ID is the identifier of AAnF.

[0257] At 1311, AF receives AAnF ID, K AF and key expiry time and stores it along with the AKMAID.

[0258] At 1312, the AF sends an application session establishment response message to the UE. The response message may include K AF The key expiration time.

[0259] At 1313, the UE AKMA And derive K AF .

[0260] Figure 14 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0261] At 1401, successful 5G master authentication results in K AUSFStored at AUSF and UE. UE and UDM store RAND generated and used in the Authentication Vector (AV) in the Master Authentication. As part of the UE registration process, UE and AUSF generate the AKMA Anchor Key (K AKMA ). K AKMA From K AUSF In some embodiments, a successful 5G primary authentication results in K AUSF Stored at AUSF and UE. UE generates and stores RAND generated by base64encode. As part of the UE registration process, UE and AUSF generate AKMA anchor key (K AKMA ). K AKMA From K AUSF Export.

[0262] At 1402a, the UE generates an AKMAID. The AKMAID is an identifier used by the UE for subsequent requests towards the AF. The AKMAID may include a combination of the MCC, MNC, routing indicator, AAnF ID, a user equipment (UE) identifier (such as the Universal Public Subscription Identifier (GPSI) or other UE identifier), and RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, the AAnF ID is an identifier used to identify the AAnF entity, and the RAND is generated and used in the authentication vector (AV) in the primary authentication. The UE stores the AKMAID and K AKMA and K AKMA Identifier. In some embodiments, AKMAID may also include a combination of MCC, MNC, routing indicator, AAnF ID, user equipment (UE) identifier (such as Universal Public Subscription Identifier (GPSI) or other UE identifier) ​​and RAND, where MCC uniquely identifies the country, MNC identifies the home PLMN, routing indicator is used to route network signaling with AKMAID to the UDM instance, AAnFID is an identifier used to identify the AAnF entity, and RAND is generated by base64encode. The UE stores AKMAID and K AKMA and K AKMA In some embodiments, the AKMAID may also include a combination of an AAnF ID, a user equipment (UE) identifier (such as a universal public subscription identifier (GPSI) or other UE identifier), and a RAND, wherein the AAnF ID is an identifier used to identify an AAnF entity (such as an AAnF domain name), and the RAND is generated by base64encode. The UE combines the AKMAID with the K AKMA and K AKMA The identifier is stored together.

[0263] At 1402b, the UDM stores the RAND and AUSFID along with the UE's authentication status (e.g., SUPI, authentication result, timestamp, and serving network name). The RAND is generated and used in the authentication vector (AV) in the primary authentication.

[0264] At 1403, the UE starts communicating with the AF using an application session establishment request. The request includes the AKMAID.

[0265] At 1404, the AF sends a key request with the AKMAID received from the UE to the AAnF to request an AF-specific key for the UE. The AF also includes its identity (eg, AF identifier) ​​in the request. The AF may select the AAnF based on the AKMAID.

[0266] At 1405, the AAnF checks whether it has the UE-specific K AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 1409, which will be discussed below. AKMA If the AAnF is not available, the AAnF obtains the RAND and / or UE identifier from the AKMAID. The AAnF then sends a Nudm_UEAuth_ResultStatus request to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the SUPI of the UE. The AAnF provides the RAND and / or UE identifier. In some embodiments, the AAnF checks whether it has the UE-specific K from the AKMAID. AKMA If K AKMA is available in the AAnF, the AAnF proceeds to operation 1409, which will be discussed below. AKMA If not available, the AAnF sends a Nudm_UEAuth_ResultStatus request to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE and the SUPI of the UE. The AAnF provides the AKMAID.

[0267] At 1406, the UDM retrieves information about the identifier of the AUSF instance that has authenticated the UE and the SUPI of the UE based on the RAND and / or the UE identifier. The UDM sends a Nudm_UEAuth_ResultStatus response that includes the AUSF instance identifier of the last AUSF that reported a successful primary authentication to the UDM and the UE SUPI. In some embodiments, the UDM retrieves information about the identifier of the AUSF instance that has authenticated the UE and the SUPI of the UE based on the AKMAID. The UDM sends a Nudm_UEAuth_ResultStatus response that includes the AUSF instance identifier of the last AUSF that reported a successful primary authentication to the UDM and the UE SUPI.

[0268] At 1407, the AAnF sends a key request to the AUSF by providing the UE SUPI.

[0269] At 1408, AUSF retrieves K based on SUPI AKMA and K AKMA identifier, and then K AKMA and K AKMA The identifier is sent to AAnF. AAnF receives K AKMA and K AKMA identifier and stores it along with the AKMAID.

[0270] At 1409, the AAnF generates a new RAND by base64encode(RAND), and generates a new AKMAID based on the new RAND. The new AKMAID may include a combination of MCC, MNC, routing indicator, AAnF ID, user equipment (UE) identifier (such as Universal Public Subscription Identifier (GPSI) or other UE identifiers) and the new RAND, wherein the MCC, MNC, routing indicator and AAnF ID are the same as the corresponding parts of the old AKMAID. AKMA and K AKMA The identifier is stored with the new AKMAID and the old AKMAID is deleted. AAnF is based on K AKMA And derive K AF . AAnF can set K AF Expiration time. AAnF can also be based on K AKMA and the new RAND generated by AAnF to derive K AF .

[0271] At 1410, AAnF sends a key response message to AF. The key response message may include AAnF ID, new RAND or new AKMAID, K AFand key expiration time. AAnF ID is the identifier of AAnF, and AAnF ID can be a domain name, namely AAnF_server_domain_name.

[0272] At 1411, AF receives AAnF ID, K AF and key expiry time and stores it along with the AKMAID.

[0273] At 1412, the AF sends an application session establishment response message to the UE. The response message may include a new RAND or a new AKMAID and K AF In some implementations, the AF sends an application session establishment response message to the UE. The response message may include a new RAND or a new AKMAID (AKMAID=base64encode(RAND)@AAnF_server_domain_name) and K AF The key expiration time.

[0274] At 1413, the UE updates the old AKMID with the received new AKMAID. In another embodiment, the UE generates a new AKMAID based on the received new RAND, and the new AKMAID includes a combination of MCC, MNC, routing indicator, AAnF ID, user equipment (UE) identifier and new RAND, wherein the MCC, MNC, routing indicator and AAnF ID are the same as the corresponding parts of the old AKMAID. The UE generates a new AKMAID based on the received new RAND, and the new AKMAID includes a combination of MCC, MNC, routing indicator, AAnF ID, user equipment (UE) identifier and new RAND. AKMA and K AKMA The identifier is stored together with the new AKMAID and the old AKMAID can be deleted. AKMA And derive K AF UE can also be based on K AKMA and the received new RAND (generated by AAnF) to derive K AF .

[0275] Figure 15 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0276] At 1501, successful 5G master authentication results in K AUSF Stored at the AUSF and UE. The UE stores the RAND generated and used in the Authentication Vector (AV) in the primary authentication. The UDM can store the RAND generated and used in the Authentication Vector (AV) in the primary authentication.

[0277] At 1502a, the AUSF notifies the UDM about the result and time of the authentication process with the UE using Nudm_UE Authentication_Result confirmation request. This includes SUPI, timestamp of authentication, authentication type (e.g., EAP method or 5G-AKA), and serving network name.

[0278] At 1502b, the UDM replies to the AUSF with a Nudm_UE Authentication_Result confirmation response including the AAnF ID. The AAnF ID may be stored in the UDM as part of the UE's subscription.

[0279] At 1503a, the UE generates a K for the UE. AKMA and key identifier AKMAID. AKMAID is an identifier used by the UE for subsequent requests towards the AF. AKMAID consists of a combination of MCC, MNC, routing indicator, AAnF ID and RAND, where MCC uniquely identifies the country, MNC identifies the home PLMN, routing indicator is used to route network signaling with AKMAID to the UDM instance, AAnF ID is an identifier used to identify the AAnF entity, and RAND is generated and used in the authentication vector (AV) in the primary authentication. The UE combines AKMAID with K AKMA The AAnF ID may be stored in the USIM as part of the UE subscription.

[0280] At 1503b, the AUSF generates K for the UE. AKMA and key identifier AKMAID. AKMAID is an identifier used by the UE for subsequent requests towards the AF. AKMAID may include a combination of MCC, MNC, routing indicator, AAnF ID and RAND, where MCC uniquely identifies the country, MNC identifies the home PLMN, routing indicator is used to route network signaling with AKMAID to the UDM instance, AAnF ID is an identifier used to identify the AAnF entity, and RAND is generated and used in the authentication vector (AV) in the primary authentication. The AUSF combines AKMAID with K AKMA Store together.

[0281] Figure 16 is a flow chart illustrating yet another example process performed by components of a communication system in accordance with some embodiments of the disclosed technology.

[0282] At 1601, successful 5G master authentication results in K AUSFStored at AUSF and UE. The UE and UDM store the RAND generated and used in the Authentication Vector (AV) in the primary authentication. As part of the UE registration process, the UE and AUSF generate and store the AKMA anchor key (K AKMA ) and the associated key identifier AKMAID. K AKMA From K AUSF Export. The AKMAID is an identifier used by the UE for subsequent requests towards the AF. The AKMAID can only be refreshed by running a new primary authentication. This means that the AKMAID lifetime cannot be shorter than the time interval between primary authentications. The AKMAID may consist of a combination of the MCC, MNC, routing indicator, AAnF ID and RAND, where the MCC uniquely identifies the country, the MNC identifies the home PLMN, the routing indicator is used to route network signaling with the AKMAID to the UDM instance, the AAnF ID is an identifier used to identify the AAnF entity, and the RAND is generated and used in the Authentication Vector (AV) in the primary authentication.

[0283] At 1602, the UE starts communication with the AF using an application session establishment request. The request includes the AKMAID.

[0284] At 1603, the AF sends a key request with the AKMAID received by the UE to the AAnF to request the AF-specific key for the UE. The AF also includes its identity (AF identifier) ​​in the request.

[0285] At 1604, the AAnF checks whether it has the UE-specific K AKMA If K AKMA is available in AAnF, then AAnF proceeds to step 1608. If K AKMA If not available, the AAnF obtains the RAND from the AKMAID. The AAnF then sends a Nudm_UEAuth_ResultStatus request to the UDM to retrieve the identifier of the most recent AUSF that authenticated the UE and the UE's SUPI. The AAnF provides the RAND.

[0286] The UDM retrieves information of the identifier of the AUSF instance that authenticated the UE based on the RAND at 1605. The UDM sends a Nudm_UEAuth_ResultStatus response including the AUSF instance identifier of the last AUSF that reported a successful primary authentication to the UDM.

[0287] At 1606, the AAnF sends a key request to the AUSF by providing the AKMAID.

[0288] At 1607, AUSF retrieves K based on AKMAID. AKMA and K AKMA identifier, and then K AKMA Send to AAnF. AAnF receives and stores K AKMA and AKMAID.

[0289] At 1608, AAnF is based on K AKMA And derive K AF . AAnF can set K AF Expiration time.

[0290] At 1609, AAnF sends a key response message to AF. The key response message includes K AF and key expiration time.

[0291] At 1610, AF receives K AF and key expiry time and stores it along with the AKMAID.

[0292] At 1611, the AF sends an application session establishment response message to the UE. The response message may include K AF The key expiration time.

[0293] At 1612, the UE AKMA And derive K AF .

[0294] Figure 1717 is a flowchart illustrating an example of a wireless communication method based on some embodiments of the disclosed technology. The wireless communication method 1700 includes: at 1710, generating, by a first functional entity, a first identifier using at least a mobile country code, a mobile network code, and a random number, the first identifier configured to be used to establish secure communications for a first device; and, at 1720, transmitting the first identifier to the first device. In some embodiments, the first device comprises a user equipment (UE). In some embodiments, the first identifier is further based on at least one of a routing indicator (e.g., a Routing Indicator) or an authentication server function identifier. In some embodiments of the disclosed technology, the first identifier comprises an AKMAID, as discussed above. In some embodiments, a mobile country code (e.g., an MCC) is used to identify the country in which the first functional entity is executed, a mobile network code (e.g., an MNC) is used to identify a home public land mobile network, a random number (e.g., a RAND) is assigned by the first functional entity for use with the first device, a routing indicator is used to route network signaling for authentication and key management, and an authentication server function identifier (e.g., an AUSF ID) is used to identify the authentication server function entity (e.g., an AUSF). In some implementations, the first identifier is generated according to an architecture for application authentication and key management (eg, AKMA).

[0295] In mobile network services designed to support authentication and key management, a set of functional entities can be deployed in the mobile network. Such functional entities include the Network Exposure Functional Entity (NEF), the AKMA Anchor Functional Entity (AAnF), the Unified Data Management Entity (UDE), the Authentication Server Functional Entity (AUSF), the Access and Mobility Management Functional Entity (AMF), and the Application Functional Entity (AF). The functional entities interact with each other using service-based interfaces.

[0296] In some embodiments, the first identifier is transmitted to the first device by a unified data management entity (e.g., UDE) performing a parameter update procedure for the first device. In some embodiments, the first functional entity stores the first identifier. In some embodiments, the first device stores the first identifier.

[0297] In some embodiments, the wireless communication method 1700 further includes: sending, by the first functional entity, the first identifier to the second functional entity. In some embodiments, the second functional entity is configured to store the first identifier.

[0298] In some embodiments, the second functional entity is an authentication server functional entity (eg, AUSF).

[0299] In some embodiments, the first functional entity includes an authentication server function entity (e.g., AUSF) that communicates with at least one of a network exposure function entity (e.g., NEF), an application authentication and key management anchor function entity (e.g., AAnF), a unified data management entity (e.g., UDE), an access and mobility management function entity (e.g., AMF), or an application function entity (e.g., AF). In some embodiments, the second functional entity includes a unified data management entity (e.g., UDE).

[0300] In some embodiments, the first identifier is generated upon completion of the primary authentication. In some embodiments, the first device is configured to use the first identifier to establish secure communication with the application function (eg, AF).

[0301] In some embodiments, the first identifier is further based on an Application Authentication and Key Management Anchor Function (AAnF) identifier. In some embodiments, the first identifier is used to identify an Application Authentication and Key Management (AKMA) process for a first device (such as a UE). In some embodiments, the first identifier is used as an identifier for identifying an Application Authentication and Key Management (AKMA) anchor key.

[0302] Figure 18 18 is a flowchart illustrating another example of a wireless communication method based on some embodiments of the disclosed technology. The wireless communication method 1800 includes: at 1810, a first functional entity or a first device uses a mobile country code, a mobile network code, a random number, and an indicator to generate a first identifier, the first identifier being configured to establish secure communication for the first device; and at 1820, transmitting the first identifier to the first device.

[0303] In some embodiments of the disclosed technology, the first identifier includes the AKMAID discussed above. In some embodiments, the indicator includes a routing indicator. In some embodiments, a mobile country code (e.g., MCC) is used to identify the country in which the first functional entity is executed, a mobile network code (e.g., MNC) is used to identify the home public land mobile network, a random number (e.g., RAND) is assigned by the first functional entity for authentication, and a routing indicator (e.g., RoutingIndicator) is used to route network signaling with authentication and key management. In some embodiments, the first identifier is generated according to an architecture for application authentication and key management (AKMA).

[0304] In some embodiments, the first functional entity stores the first identifier. In some embodiments, the first device stores the first identifier. In some embodiments, the first functional entity includes a unified data management entity (e.g., UDM) that communicates with at least one of a network exposure function entity (e.g., NEF), an application authentication and key management anchor function entity (e.g., AAnf), an authentication server function entity (e.g., AUSF), an access and mobility management function entity (e.g., AMF), or an application function entity (e.g., AF).

[0305] In some embodiments, the first identifier is generated upon completion of primary authentication. In some embodiments, the first device is configured to use the first identifier to establish secure communication with a network function within wireless communication. In some embodiments, the first device comprises a user equipment (UE). In some embodiments, a unified data management entity (e.g., UDM) and the user equipment (UE) store the first identifier.

[0306] In some embodiments, the random number is included in an authentication vector to be used in primary authentication. In some embodiments, an authentication and key management anchor function (e.g., AAnF) is applied to generate a new random number (e.g., a new RAND) to generate a new first identifier. In some embodiments, the first device updates the first identifier using the new random number.

[0307] In some embodiments, the first functional entity includes a unified data management entity (e.g., UDM), and the first device includes a user equipment (UE), and the UDM and the UE store a first identifier configured to establish secure communications for the first device. In some embodiments, the UDM and the UE generate and store the first identifier upon completing primary authentication. In some embodiments, the indicator is a routing indicator, such that network signaling is routed to the unified data management instance using the indicator.

[0308] Figure 19 19 is a flowchart illustrating another example of a wireless communication method based on some embodiments of the disclosed technology. The wireless communication method 1900 includes: at 1910, a first device generates a first identifier using a mobile country code, a mobile network code, a random number, and a routing indicator, the first identifier being configured to establish secure communication for the first device; and at 1920, the first device stores the first identifier for subsequent requests to an application function entity.

[0309] In some embodiments, the wireless communication method 1900 further includes: causing the first device to cause the unified data management entity to store the random number. In some embodiments, the random number is generated and used in an authentication vector in the primary authentication.

[0310] In some embodiments of the disclosed technology, the first identifier includes the AKMAID discussed above. In some implementations, the first identifier is updated by an Application Authentication and Key Management (AKMA) anchor function entity (e.g., AAnF) using a new random number (e.g., new RAND) generated by the AKMA anchor function entity. In some implementations, the AKMA anchor function entity is configured to use the new random number and the AKMA anchor key (e.g., K AKMA ) to derive the application key (e.g., K AF ).

[0311] In some embodiments, the wireless communication method 1500 further includes: updating the first identifier by the first device using a new random number generated by an Application Authentication and Key Management (AKMA) anchor function entity.

[0312] In some embodiments, the first device is a user equipment (UE).In some embodiments, the first device is configured to use the first identifier during application session establishment.

[0313] In some embodiments, the first identifier is further based on an Application Authentication and Key Management Anchor Function (AAnF) identifier. In some embodiments, a mobile country code is used to identify the country in which the first functional entity operates, a mobile network code is used to identify the home public land mobile network, a random number is assigned by the first functional entity to be used for authentication, a routing indicator is used to route network signaling with authentication and key management, and an Application Authentication and Key Management Anchor Function (AAnF) identifier is used to identify the Application Authentication and Key Management Anchor Function (AAnF) functional entity. In some embodiments, the first identifier is used to identify an Application Authentication and Key Management (AKMA) process for the first device. In some embodiments, the first identifier is used as an identifier for identifying an Application Authentication and Key Management (AKMA) anchor key.

[0314] Figure 202000 is a flowchart illustrating another example of a wireless communication method based on some embodiments of the disclosed technology. The wireless communication method 2000 includes: at 2010, upon completing primary authentication, obtaining an intermediate key stored at a first functional entity and a first device; at 2020, generating an anchor key for application authentication and key management based on the intermediate key; at 2030, generating a first identifier using a mobile country code, a mobile network code, a routing indicator, an anchor functional entity identifier for application authentication and key management, a random number, and a first device identifier; at 2040, storing the first identifier and the anchor key for application authentication and key management; and at 2050, establishing secure communication for the first device using the first identifier. In some embodiments, the first device identifier is a UE identifier.

[0315] In some embodiments, the first functional entity comprises an authentication server functional entity. In some embodiments, the intermediate key comprises an authentication server function key (K AUSF In some embodiments, an anchor function entity identifier for application authentication and key management is used to identify an AKMA anchor function (AAnF) entity. In some embodiments, using the first identifier to establish secure communication for the first device includes causing the application function entity to transmit a key request including the first identifier to the AAnF entity.

[0316] In some embodiments, establishing secure communications for the first device using the first identifier includes causing the AAnF entity to derive an application function key based on an anchor key used for application authentication and key management.

[0317] In some embodiments, using the first identifier to establish secure communication for the first device further comprises causing the first device to derive an application function key based on an anchor key for application authentication and key management. In some embodiments, using the first identifier to establish secure communication for the first device comprises generating a new first identifier using a mobile country code, a mobile network code, a routing indicator, an anchor function entity identifier for application authentication and key management, and a new random number.

[0318] In some embodiments, using the first identifier to establish secure communication for the first device further comprises causing the first device to update the first identifier with the new first identifier.

[0319] In some embodiments, the wireless communication method 2000 further includes: causing the authentication server function entity to notify the unified data management entity of a result of the primary authentication. In some embodiments, the first device is a user equipment.

[0320] Figure 21is a block diagram representation of a portion of a radio station according to one or more embodiments of the present technology to which it may be applied. A radio station 2105 (such as a base station or a wireless device (or UE)) may include processor electronics 2110 (such as a microprocessor) that implements one or more of the wireless technologies presented in this document. The radio station 2105 may include transceiver electronics 2115 to send and / or receive wireless signals via one or more communication interfaces (such as antenna 2120). The radio station 2105 may include other communication interfaces for transmitting and receiving data. The radio station 2105 may include one or more memories (not explicitly shown) configured to store information such as data and / or instructions. In some embodiments, the processor electronics 2110 may include at least a portion of the transceiver electronics 715. In some embodiments, at least some of the disclosed techniques, modules, or functions are implemented using the radio station 2105.

[0321] Some embodiments described herein are described in the general context of methods or processes, which can be implemented in one embodiment by a computer program product, embodied in a computer-readable medium including computer-executable instructions such as program code, and executed by a computer in a network environment. Computer-readable media may include removable and non-removable storage devices, including but not limited to: read-only memory (ROM), random access memory (RAM), compact discs (CD), digital versatile discs (DVD), etc. Therefore, computer-readable media may include non-transitory storage media. Generally, program modules may include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. Computer or processor executable instructions, associated data structures, and program modules represent examples of program code for performing the steps of the methods disclosed herein. A specific sequence of such executable instructions or associated data structures represents an example of corresponding actions for implementing the functions described in such steps or processes.

[0322] Some of the disclosed embodiments can be implemented as devices or modules using hardware circuits, software or a combination thereof. For example, a hardware circuit implementation may include discrete analog and / or digital components that are, for example, integrated as a part of a printed circuit board. Alternatively or additionally, the disclosed components or modules may be implemented as application specific integrated circuits (ASICs) and / or field programmable gate arrays (FPGAs). Some embodiments may additionally or alternatively include a digital signal processor (DSP), which is a specialized microprocessor with an architecture optimized for the operational needs of digital signal processing associated with the functions disclosed herein. Similarly, the various components or subcomponents within each module may be implemented in software, hardware or firmware. Connectivity between modules and / or components within the modules may be provided using any of the connection methods and media known in the art, including but not limited to communication via the internet, wired or wireless networks using appropriate protocols.

[0323] Although this document contains many details, these details should not be interpreted as limitations on the scope of the claimed invention or what may be claimed, but rather as descriptions of features specific to particular embodiments. Certain features described in this document in the context of separate embodiments may also be implemented in combinations of single embodiments. Conversely, the various features described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. In addition, although features may be described above as working in a specific combination or even in the combination initially claimed, in some cases one or more features from the claimed combination may be separated from the combination, and the claimed combination may involve variations of sub-combinations or sub-combinations. Similarly, although operations are depicted in a particular order in the accompanying drawings, this should not be understood as requiring that the operations be performed in the specific order shown or in a continuous order, or that all of the operations shown be performed to achieve the desired result.

[0324] Only a few implementations and examples are described, and other implementations, enhancements, and variations can be made based on what is described and illustrated in this disclosure.

Claims

1. A method for wireless communication, comprising: a first identifier is generated by a first functional entity, the first identifier is configured to be used to establish secure communication for a first device, the first identifier includes at least a mobile country code, a mobile network code, and a random number, the mobile country code identifies a country in which the first functional entity is operated, the mobile network code identifies a home public land mobile network, and the random number allocated by the first functional entity is used for the first device, wherein the first functional entity includes a unified data management entity that communicates with at least one of a network open functional entity, an application authentication and key management anchor functional entity, an authentication server functional entity, an access and mobility management functional entity, and an application functional entity; and A first identifier is transmitted to the first device.

2. The method according to claim 1, wherein The first device is further configured to generate the first identifier.

3. The method according to claim 1, wherein The first identifier is further based on at least one of a routing indicator or an authentication server function identifier.

4. The method according to claim 1, wherein The first identifier is further based on an Application Authentication and Key Management Anchor Function AAnF identifier.

5. The method according to claim 1, wherein The first identifier is also based on a user equipment (UE) identifier.

6. The method according to any one of claims 1 to 5, wherein The first identifier is used to identify an Application Authentication and Key Management (AKMA) procedure for the first device.

7. The method according to any one of claims 1 to 5, wherein The first identifier is used as an identifier for identifying an Application Authentication and Key Management (AKMA) anchor key.

8. The method according to claim 1, wherein The transmission of the first identifier to the first device is performed by a unified data management entity performing a parameter update procedure for the first device.

9. The method according to claim 1, wherein At least one of the first functional entity or the first device stores the first identifier.

10. The method according to claim 1, further comprising: The first functional entity sends the first identifier to the second functional entity.

11. The method according to claim 10, wherein: The second functional entity is configured to store the first identifier.

12. The method according to claim 10, wherein: The second functional entity is an authentication server functional entity.

13. The method according to any one of claims 1 to 5 and 8 to 12, wherein The first identifier is generated when the primary authentication is completed.

14. The method according to any one of claims 1 to 5 and 8 to 12, wherein The first device is configured to establish secure communication with an application function using the first identifier.

15. The method according to any one of claims 1 to 5 and 8 to 12, wherein The first device includes user equipment UE.

16. The method according to any one of claims 1 to 5 and 8 to 12, wherein The random number is included in an authentication vector to be used in primary authentication.

17. The method according to any one of claims 1 to 5, 8 to 12, wherein The application authentication and key management anchor function entity generates a new random number to generate a new first identifier.

18. The method according to claim 17, wherein The first device updates the first identifier using the new random number.

19. A method for wireless communication, comprising: A first device receives a first identifier generated by a first functional entity from the first functional entity, and the first identifier is configured to be used to establish secure communication for the first device, the first identifier comprising at least a mobile country code, a mobile network code, a random number, and a routing identifier, the mobile country code identifying a country in which the first functional entity operates, the mobile network code identifying a home public land mobile network, and the random number allocated by the first functional entity being used for the first device, wherein the first functional entity comprises a unified data management entity configured to communicate with at least one of a network open functional entity, an application authentication and key management anchor functional entity, an authentication server functional entity, an access and mobility management functional entity, and an application functional entity; storing, by the first device, the first identifier for subsequent requests; and Initiate communication with an application function entity using an application session establishment request including the first identifier.

20. The method according to claim 19, wherein The first identifier is further based on an Application Authentication and Key Management Anchor Function AAnF identifier.

21. The method according to claim 19, wherein The first identifier is also based on a user equipment (UE) identifier.

22. The method according to any one of claims 19 to 21, wherein The routing indicators are used to route network signaling with authentication and key management.

23. The method according to any one of claims 19 to 21, wherein The first identifier is used to identify an Application Authentication and Key Management (AKMA) procedure for the first device.

24. The method according to any one of claims 19 to 21, wherein The first identifier is used as an identifier for identifying an Application Authentication and Key Management (AKMA) anchor key.

25. The method according to claim 24, further comprising: The first device causes the unified data management entity to store the random number.

26. The method according to claim 25, wherein The random number is generated and used in the authentication vector in the primary authentication.

27. The method according to claim 25, wherein The first identifier is updated by an Application Authentication and Key Management (AKMA) anchor function entity using a new random number generated by the AKMA anchor function entity.

28. The method according to claim 27, wherein The AKMA anchor function entity is configured to derive an application key using the new random number and an AKMA anchor key.

29. The method of claim 25, further comprising: The first device updates the first identifier using a new random number generated by an Application Authentication and Key Management (AKMA) anchor function entity.

30. The method according to any one of claims 19 to 21, wherein The first device is a user equipment.

31. The method according to any one of claims 19 to 21, wherein The first device is configured to use the first identifier during an application session establishment process.

32. An apparatus for wireless communication, comprising a memory and a processor, wherein the processor reads code from the memory and implements the method according to any one of claims 1 to 31.

33. A computer-readable program storage medium having stored thereon code which, when executed by a processor, causes the processor to implement the method according to any one of claims 1 to 31.