Authentication Server Function Selection in Authentication and Key Agreement
By using the first network function to retrieve the identifier of the authentication terminal from the third network function in the case of AKMA dual registration, the problem of difficulty in selecting AUSF is solved, and the accuracy and efficiency of terminal identity authentication and key management are achieved.
Patent Information
- Application Number
- CN202080098518.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-28
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-04-28
AI Technical Summary
In the case of AKMA dual registration, there is difficulty in selecting AUSF because the key identifier does not contain information related to the specific AUSF instance, which may cause AAnF to fail to properly select the appropriate AUSF instance.
Receiving a request through the first network function, an identifier of the second network function that authenticates the terminal is retrieved from the third network function. The request includes a parameter, and a response is sent from the first network function to the third network function, the response includes an identifier of the second network function, and the second network function authenticates the terminal identified based on the parameter.
AUSF selection in AKMA dual registration situation is realized, ensuring the accuracy and efficiency of terminal identity authentication and key management.
Smart Images

Figure CN115398946B_ABST
Abstract
Description
Technical Field
[0001] This patent application generally relates to digital communications. Background Art
[0002] Mobile communication technologies are pushing the world towards an increasingly interconnected and networked society. The rapid development of mobile communication and technological progress have led to a greater demand for capacity and connectivity. Other aspects such as energy consumption, device cost, spectral efficiency, and latency are also important for meeting the requirements of various communication scenarios. Various technologies, including new methods for providing higher quality of service, are under discussion. Summary of the Invention
[0003] This patent application discloses methods, systems, and devices related to data communication, and more specifically, discloses techniques related to AUSF selection in the case of dual registration in AKMA.
[0004] In one exemplary aspect, a method for data communication is disclosed. The method includes: receiving, by a first network function, a request to retrieve an identifier of a second network function that has authenticated a terminal from a third function, the request including a parameter. The method further includes: sending, by the first network function, a response to a third network function, the response including the identifier of the second network function that has authenticated the terminal identified based on the parameter.
[0005] In another exemplary aspect, a method for data communication is disclosed. The method includes: sending, by a first network function, a request to retrieve an identifier of a second network function that has authenticated a terminal from a third network function, the request including a parameter. The method further includes: receiving, by the first network function, a response from the third network function, the response including the identifier of the second network function that has authenticated the terminal identified based on the parameter.
[0006] In another exemplary aspect, a communication device is disclosed, the communication device including a processor. The processor is configured to implement the methods described herein.
[0007] In yet another exemplary aspect, the various techniques described herein may be embodied as processor-executable code and stored on a computer-readable program medium.
[0008] Some embodiments may preferably implement the following solutions written in clause format.
[0009] 1. A solution for data communication, comprising: receiving, by a first network function, a request to retrieve an identifier of a second network function that has authenticated a terminal from a third function, the request including parameters; and sending, by the first network function, a response to the third network function, the response including the identifier of the second network function, where the second network function has authenticated the terminal identified based on the parameters.
[0010] 2. The solution according to clause 1, wherein the first network function includes a Unified Data Management (UDM) function.
[0011] 3. The solution according to any one of clauses 1 and 2, wherein the second network function includes an Authentication Server Function (AUSF).
[0012] 4. The solution according to any one of clauses 1, 2, and 3, wherein the third network function includes an Authentication and Key Management Application (AKMA) Anchor Function (AAnF).
[0013] 5. The solution according to clause 1, wherein the response includes a Subscriber Permanent Identifier (SUPI).
[0014] 6. The solution according to clause 1, wherein the parameters include a serving network name.
[0015] 7. The solution according to clause 1, wherein the request includes an identifier of the terminal.
[0016] 8. The solution according to clause 1, wherein the parameters include a serving network name network identifier.
[0017] 9. The solution according to any one of clauses 1, 2, 3, and 5, further comprising: identifying, by the first network function, a record in a database, the record in the database corresponding to the second network function that has authenticated the terminal based on the parameters; and retrieving, by the first network function, the identifier of the second network function that has authenticated the terminal, and retrieving the SUPI included in the record of the database.
[0018] 10. The solution according to any one of clauses 1, 3, 4, and 5, wherein the third network function is configured to: send a key request message to a second network function, the second network function being identified based on the identifier of the second network function that has authenticated the terminal, the key request message including the SUPI.
[0019] 11. The solution according to clauses 1, 3, and 4, wherein the second network function is configured to receive an AKMA key identifier, an identifier of the terminal, and the parameter from a fourth network function.
[0020] 12. The solution according to clause 11, wherein the fourth network function is an AKMA application function (AF).
[0021] 13. The solution according to any one of clauses 11 and 12, wherein the fourth network function is configured to receive the AKMA key identifier, the identifier of the terminal, and the parameter from the terminal.
[0022] 14. A solution for data communication, comprising: sending, by a first network function, a request to retrieve an identifier of a second network function that has authenticated a terminal from a third network function, the request including a parameter; and receiving, by the first network function, a response from the third network function, the response including the identifier of the second network function that has authenticated the terminal identified based on the parameter.
[0023] 15. The solution according to clause 14, wherein the first network function includes an authentication and key management application (AKMA) anchor function (AAnF).
[0024] 16. The solution according to any one of clauses 14 to 15, wherein the second network function includes an authentication server function (AUSF).
[0025] 17. The solution according to any one of clauses 14 to 16, wherein the third network function includes a unified data management (UDM) function.
[0026] 18. The solution according to clause 14, wherein the response includes a subscriber permanent identifier (SUPI).
[0027] 19. The solution according to clause 14, wherein the parameter includes a serving network name.
[0028] 20. The solution according to clause 14, wherein the request includes an identifier of the terminal.
[0029] 21. The solution according to clause 14, wherein the parameter includes a serving network name network identifier.
[0030] 22. The solution according to any one of clauses 14 to 18, wherein the third network function is configured to: identify a record in a database, the record in the database corresponding to the second network function that has authenticated the terminal based on the parameter; and retrieve the identifier of the second network function that has authenticated the terminal, and retrieve the SUPI included in the record of the database.
[0031] 23. The solution according to any one of clauses 14 to 18 further includes: the first network function sending a key request message to a second network function, the second network function being identified based on the identifier of the second network function that has authenticated the terminal, the key request message including the SUPI.
[0032] 24. The solution according to any one of clauses 14 and 20 further includes: the first network function receiving an AKMA key identifier, an identifier of the terminal, and the parameter from a fourth network function.
[0033] 25. The solution according to clause 24, wherein the fourth network function includes an AKMA application function.
[0034] 26. The solution according to any one of clauses 24 and 25, wherein the fourth network function is configured to receive the AKMA key identifier, the identifier of the terminal, and the parameter from the terminal.
[0035] 27. A device for communication, the device including a processor configured to execute the solution according to any one of clauses 1 to 26.
[0036] 28. A non-transitory computer-readable medium having code stored thereon, which when executed by a processor causes the processor to implement the solution according to any one of clauses 1 to 26.
[0037] Details of one or more embodiments are set forth in the accompanying appendices, drawings, and the following description. Other features should be apparent from the description, drawings, and clauses. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] Figure 1 is an example signaling flow for the AF key generation process.
[0039] Figure 2 is an example signaling process for the KAF derivation process.
[0040] Figure 3 is a block diagram of an example AKMA architecture.
[0041] Figure 4 It is a block diagram of an example key hierarchy of AKMA.
[0042] Figure 5 It is an example signaling procedure for deriving the AKMA root key during UE registration.
[0043] Figure 6 It is an example signaling procedure for AUSF selection in the case of AKMA dual registration.
[0044] Figure 7 It is an example method for AUSF selection in the case of AKMA dual registration.
[0045] Figure 8 It shows an example of a wireless communication system in which the techniques according to one or more embodiments of the present technology can be applied.
[0046] Figure 9 It is a block diagram representation of a part of a hardware platform. Detailed implementation
[0047] The development of the new generation of wireless communication - 5G New Radio (NR) communication is part of an ongoing evolution of mobile broadband to meet the requirements of growing network demands. NR will provide greater throughput to allow more users to connect simultaneously. Other aspects such as energy consumption, device cost, spectral efficiency, and latency are also important for meeting the needs of various communication scenarios.
[0048] The Authentication and Key Management for Applications (AKMA) framework can be used to support secure communication and data exchange between a UE and an application server. In the AKMA architecture, AKMA authentication can be the result of primary / access authentication to protect the communication between the UE and the application server.
[0049] The application function (AF) key generation process can be provided according to Figure 1 Provided. Figure 1 It is an example signaling procedure for the AF key generation process.
[0050] When a user equipment (UE) (or simply referred to as a "terminal") initiates communication with an AKMA AF, it can include the derived AKMA key identifier in the message.
[0051] The AKMA Key Identifier (ID) (KAKMA ID) can be used to locate the Authentication Server Function (AUSF). The KAKMA is stored in the Authentication Server Function (AUSF) and can also be used to locate the KAKMA in that AUSF. However, since the key identifier may not include any information related to a specific AUSF instance, the AAnF may not correctly select an appropriate AUSF instance based on the key identifier.
[0052] In many cases, attempts to solve this problem can include invoking the Unified Data Management (UDM) node to locate the AUSF that holds the KAKMA. The key ID in this attempt can be designed to include UE ID information (e.g., the Generic Public Subscription Identifier (GPSI)).
[0053] As Figure 1 shown, as a prerequisite, the UE 102 and the AKMA Application Function 108 can implement the primary authentication and establishment (110) of the AKMA key. The UE 102 can send an Application Session Establishment Request (AKMA Key ID) (112) to the AKMA Application Function 108.
[0054] The AKA Application Function 108 can send a key request (114) including the AKMA Key ID and the AF identifier to the AANF 106. The AANF 106 can send an AKMA key request (116) including the AKMA Key ID to the AUSF 104. The AUSF 104 can send an AKMA key response (118) including the K-AKMA to the AANF 106. The AANF 106 can derive the AF key from the K-AKMA (120).
[0055] The AANF 106 can send a key response (122) including the AF key and the timeout to the AKMA Application Function 108. The AKMA Application Function 108 can send an Application Session Establishment Response (124) to the UE 102.
[0056] Figure 2 is an example signaling process for the KAF export procedure. The AKMA Anchor Function (AAnF) can check whether it has a UE-specific KAKMA key identified by the KAKMA key identifier. If the KAKMA is available in the AAnF, the AAnF can continue to derive the KAKMA and the key from the KAKMA. If the KAKMA is not available, the AAnF can select a suitable UDM for the UE via the NRF based on the home network identifier and the routing indicator included in the KAKMA key identifier and / or the GPSI received from the AF.
[0057] AAnF may send a Nudm_UEAuth_ResultStatus request to the UDM to retrieve the identifier of the most recent AUSF that has authenticated the UE. AAnF may provide the UE identifier. If AAnF only has the UE GPSI provided by the AF in step 3, AAnF may include the GPSI. If AAnF has obtained the UE GPSI and its corresponding subscribed permanent identifier (SUPI) from a previous interaction with the UDM, it may include the SUPI.
[0058] The UDM may check whether AAnF has provided the GPSI or SUPI as the UE identifier. If AAnF has provided the GPSI, the UDM may convert the GPSI to SUPI and shall use the SUPI to retrieve the information of the identifier of the AUSF instance that has authenticated the UE. If AAnF has provided the GPSI as the UE identifier, the UDM may send a Nudm_UEAuth_ResultStatus response that includes the AUSF instance identifier of the last AUSF that reported a successful primary authentication to the UDM and the UE SUPI. The UE SUPI may be provided for subsequent AKMA key requests to the AUSF and for future AUSF selection processes for the same UE via the UDM.
[0059] By providing the UE SUPI, AAnF may send a KAKMA key request to the AUSF. However, in the case where the UE has two separate registrations on both 3GPP and non-3GPP accesses to two public land mobile networks (PLMNs), there may be two AUSF instances that have authenticated the UE. Therefore, the SUPI may be used to retrieve the information of the identifier of the AUSF instance that has not successfully authenticated the UE in the Nudm_UEAuth_ResultStatusResponse message. A query in the UDM may hit the results of two AUSF instances, but it may not be possible to identify which one holds the KAKMA.
[0060] As Figure 2 shown, as a prerequisite, the UE 202 and the AUSF 204 may implement a primary authentication process (212). The UE 202 may derive the KAKMA and the KAKMA key ID (214). The UE 202 may send an application session establishment request including the GPSI and the KAKMA key ID to the AF 210 (216). The AF 210 may perform AANF selection (218). The AF 210 may send a KAF key request including the GPSI, the KAKMA key ID, and the AF identifier to the AANF 208 (220).
[0061] The AANF 208 can perform UDM selection (222). The AANF 208 can send a Nudm_UEAuth_ResultStatusRequest message (224) including the GPSI and SUPI to the UDM 206. The UDM 206 can send a Nudm_UEAuth_ResultStatusResponse message (226) including the AUSFID and SUPI to the AANF 208. The AANF 208 can send an AKMA key request (228) including the SUPI to the AUSF 204. The AUSF 204 can derive KAKMA and the KAKMA key ID (230).
[0062] The AUSF 204 can send an AKMA key response (232) including the KAKMA and the KAKMA key ID to the AANF 208. The AANF 208 can derive KAKMA and the key from KAKMA (234). The AANF 208 can send a KAF key response (236) including the KAF, the KAF timeout period, and the KAF freshness parameter to the AF 210. The AF 210 can send an application session establishment response (238) to the UE 202. Then, the UE can derive the KAF from the KAKMA (240).
[0063] Figure 3 is a block diagram of an example AKMA architecture 300. The architecture 300 can include any one of the NEF, AAnF, AUSF, AMF, AF, RAN, and UE. These nodes can be connected via any one of Nnef, Naanf, Nausf, Namf, Naf, N1, N2, and UA*.
[0064] Figure 4 is a block diagram of an example key hierarchy of AKMA400. The key hierarchy can include any one of KAUSF, KAKMA, and KAF. The HPLMN can include the AUSF and the AAnF. The hierarchy can include any one of the AF and the ME.
[0065] The AKMA service may require a new logical entity: the AKMA anchor function (AAnF). The AAnF can include an anchor function in the home public land mobile network (HPLMN), which can generate key material to be used between the UE and the AF and maintain the UE AKMA context to be used for subsequent bootstrapping requests.
[0066] There may not be a separate UE authentication to support the AKMA functionality. Instead, the AKMA functionality can reuse the primary authentication process performed during UE registration to authenticate the UE. A successful primary authentication can result in the KAUSF being stored at the AUSF and the UE.
[0067] Figure 5 FIG. 500 is an example signaling flow for deriving the AKMA root key during UE registration. The UE 502 and the AUSF 506 can perform a primary authentication (508). The UE 502 and / or the AUSF 506 can generate the K-AKMA (510, 512) based on the K-AUSF. The UE 502 and / or the AUSF 506 can generate a key identifier for the K-AKMA (514, 416). As part of the UE registration process, the UE and the AUSF can generate the AKMA anchor key (KAKMA) and an associated key identifier based on the KAUSF. The KAKMA key identifier can identify the KAKMA key of the UE, from which other AKMA keys are derived.
[0068] System Overview
[0069] Wireless devices have become ubiquitous, and users are increasingly relying on wireless communication for the transmission and reception of confidential data. Examples of confidential data include data from phone conversations, financial transactions, etc. For the upcoming 5G deployment, data security has become even more important, not only because of the increasing use of wireless communication, but also because many wireless devices will be in close proximity to each other and will be able to receive (at the physical layer level) signals from adjacent wireless devices. In addition, different from today's wireless systems, due to more dense deployments, wireless devices may move in the coverage areas of different base stations. Therefore, enhanced security while allowing seamless mobility will be particularly important for the successful operation of wireless technologies.
[0070] The techniques described in this application will enable the solution of these technical problems and other problems.
[0071] This embodiment relates to a method and system for AUSF selection in the case of AKMA dual registration. Figure 6 FIG. 600 is an example signaling flow for AUSF selection in the case of AKMA dual registration.
[0072] In step 612, the UE 602, AUSF 604, UDM 606, and / or AANF 608 may perform a primary authentication process, which includes the UDM and the UE storing RAN information. Successful 5G primary authentication may result in KAUSF being stored at the AUSF and the UE. The UDM may store the RAND generated and used in the authentication vector (AV) in the primary authentication, and store the AUSF ID with the UE's authentication status (e.g., SUPI, authentication result, timestamp, and serving network name). The UE may store the RAND generated and used in the authentication vector (AV) in the primary authentication.
[0073] In step 614, the UE 602 may generate KAKMA, and KAKMA ID = MCC, MNC, routing indicator, AaNFID, and / or RAND. The UE may generate the AKMA anchor key (KAKMA) after or as part of the UE registration process. KAKMA may be derived from KAUSF. In addition, the UE may generate the AKMA anchor key identifier KAKMA ID.
[0074] The KAKMA ID may include an identifier for subsequent requests by the UE to the AF. The KAKMA ID may include a combination of MCC, MNC, routing indicator, AAnF ID, and RAND, where the MCC may uniquely identify a country, the MNC may identify the home PLMN, the routing indicator may be used to route network signaling with the KAKMA ID to the UDM instance, the AAnF ID may be an identifier for identifying the AAnF entity, or in the initial case (when the UE has no information about the AAnF), the AAnF ID may be a default value, and the RAND may be generated and used in the authentication vector (AV) in the primary authentication. The UE may store the KAKMA and the KAKMA identifier KAKMA ID.
[0075] In step 616, the UE 602 may send an application session establishment request message to the AF 610 including the KAKMA ID, UE ID, and / or SNN. The UE may use the application session establishment request to initiate communication with the AF. The request may include the KAKMA ID, UE ID, and serving network name (SNN) of the network to which the UE is registered and for which AKMA is enabled.
[0076] In step 618, the AF 610 may send a KAF key request with the KAKMA key ID, UE ID, and / or SNN to the AANF 608. The AF may send a key request with the KAKMA ID, UE ID, and SNN received from the UE to the AAnF to request an AF-specific key for the UE. The AF may also include its identity (e.g., AF identifier) in this request. The AF may select the AAnF based on the KAKMA ID.
[0077] In step 620, the AANF 608 may send a Nudm_UEAuth_ResultsStatusRequest message including either the UE ID or the SNN to the UDM 606. The AAnF may check whether it has a UE-specific KAKMA key by the KAKMA ID. If the KAKMA is available in the AAnF, the AAnF may proceed to operation step 630, which will be discussed in more detail below. If the KAKMA is not available, the AAnF may send a Nudm_UEAuth_ResultsStatusRequest to the UDM to retrieve the identifier of the latest AUSF that authenticated the UE and the SUPI of the UE. The AAnF may provide the UE ID and the SNN.
[0078] In step 622, the UDM 606 may send a Nudm_UEAuth_ResultStatus response message to the AANF 608. The UDM may retrieve information on the identifier of the AUSF instance that authenticated the UE and the SUPI of the UE based on the UE ID and the SNN. The UDM may send a Nudm_UEAuth_ResultStatus response that includes the AUSF instance identifier of the last AUSF that reported a successful primary authentication to the UDM and the UE SUPI.
[0079] In step 624, the AANF 608 may send an AKMA key request including the SUPI to the AUSF 604. The AAnF may send a key request to the AUSF by providing the UE SUPI. The AANF may identify a specific AUSF based on the AUSF ID included in the Nudm_UEAuth_ResultStatus response.
[0080] In step 626, the AUSF 604 may generate the KAKMA. The AUSF may retrieve the KAUSF according to the SUPI and generate the KAKMA according to the KAUSF.
[0081] In step 628, the AUSF 604 may send an AKMA key response including the KAKMA to the AANF 608.
[0082] In step 630, the AANF 608 may derive a new RAND, generate and store a new KAKMA ID together with the KAKMA, derive the KAF based on the KAKMA, and set the KAF timeout period. The AAnF may generate a new RAND and further generate a new KAKMA ID based on the new RAND. The new KAKMA ID may include a combination of MCC, MNC, a routing indicator, the AAnF ID, and the new RAND. The MCC, MNC, and the routing indicator may be the same as the corresponding parts of the old KAKMA ID. The AAnF ID may be the identity of the current AAnF. The AAnF may store the KAKMA and the KAKMA identifier together with the new KAKMA ID. The AAnF may derive the KAF based on the KAKMA. The AAnF may set the KAF timeout period. The AAnF may also derive the KAF based on the KAKMA and the new RAND generated by the AAnF.
[0083] In step 632, the AANF 608 may send a KAF key response to the AF 610, where the KAF key response includes any one of the new RAND, the KAKMA ID, the KAF, and / or the KAF timeout period. The AAnF may send key response information to the AF. The key response information may include the AAnF ID, the new RAND, the new KAKMA ID, the KAF, and the key timeout period. The AAnF ID may include the identity of the AAnF, where the AAnF ID may be a domain name (e.g., AAnF_server_domain_name).
[0084] In step 634, the AF 610 may send an application session establishment response to the UE 602, where the application session establishment response includes any one of the new RAND, the new KAKMA ID, and / or the KAF timeout period. The AF may receive and store the AAnF ID, the KAF, and the key timeout period. In addition, the AF may send application session establishment response information to the UE. The application session establishment response information may include the new KAKMA ID and the KAF key timeout period.
[0085] In step 636, the UE 602 may update the old KAKMA ID with the new KAKMA ID, and derive the KAF based on the KAKMA or from the new RAND and the KAKMA. The UE may update the old KAKMA ID with the received new KAKMA ID. The UE may store the KAKMA and the new KAKMA ID and may delete the old KAKMA ID. The UE may derive the KAF based on the KAKMA. The UE may also derive the KAF based on the KAKMA and the new RAND received from the AAnF.
[0086] The Service Network Name (SNN) may include an SNN service code and an SNN network identifier separated by a colon. The SNN network identifier may identify the serving PLMN or the serving SNPN.
[0087] The MCC and MNC in the SNN-PLMN-ID may be the MCC and MNC of the serving PLMN. If the MNC of the serving PLMN has two digits, a zero may be added at the beginning. The MCC and MNC in the SNN-SNPN-ID may be the MCC and MNC of the serving SNPN. If the MNC of the serving SNPN has two digits, a zero may be added at the beginning. The SNN-NID may include a hexadecimal digit NID. The following table illustrates the ABNF syntax of the SNN.
[0088] SNN = SNN service code ":" SNN network identifier
[0089] SNN service code = %x35.47; "5G"
[0090] SNN network identifier = SNN-PLMN-ID / SNN-SNPN-ID
[0091] SNN-PLMN-ID = SNN-mnc-string SNN-mnc-digits "." SNN-mcc-string SNN-mcc-digits "." SNN-3gppnetwork-string "." SNN-org-string; Applicable when operating in non-SNPN access mode.
[0092] SNN-SNPN-ID = SNN-mnc-string SNN-mnc-digits "." SNN-mcc-string SNN-mcc-digits "." SNN-3gppnetwork-string "." SNN-org-string ":" SNN-NID; Applicable when operating in SNPN access mode.
[0093] SNN-mnc-digits = DIGIT DIGIT DIGIT; MNC of the PLMN ID
[0094] SNN-mcc-digits = DIGIT DIGIT DIGIT; MCC of the PLMN ID
[0095] SNN-mnc-string = %x6d.6e.63; lowercase "mnc"
[0096] SNN-mcc-string = %x6d.63.63; lowercase "mcc"
[0097] SNN-3gppnetwork-string = %x33.67.70.70.6e.65.74.77.6f.72.6b; lowercase "3gppnetwork"
[0098] SNN-org-string = %x6f.72.67; lowercase "org"
[0099] SNN-NID = 11SNN-hexadecimal-digit; NID in hexadecimal digits
[0100] SNN-hexadecimal-digit = DIGIT / %x41 / %x42 / %x43 / %x44 / %x45 / %x46
[0101] Table 1
[0102] The SNN service code can allow the separation of the ANID and the SNN, as both the SNN and the ANID can be carried in the AT_KDF_INPUT attribute.
[0103] In the first example, in the case of a PLMN, if the PLMN ID contains MCC = 234 and MNC = 15, the SNN can be 5G:mnc015.mcc234.3gppnetwork.org.
[0104] The parameters as described herein can be the SNN or the SNN network identifier. The Service Network Name (SNN) can be sent from the UE to the AF together with the KAKMAID and the UE ID. Then, the SNN and the UE ID can be sent to the AAnF and the UDM. The UDM can use both the SNN and the UE ID to retrieve the identifier of the AUSF instance holding the KAKMA. In the case of dual registration, the SNN can be used to complete the AUSF selection in the UDM. The parameter can be the SNN or the SNN network identifier.
[0105] Figure 7 Is an example method 700 for AUSF selection in the case of AKMA dual registration. The method can include: receiving, by a first network function, a request to retrieve the identifier of a second network function that has authenticated a terminal from a third function (block 702). The request can include a parameter.
[0106] The method may further include: sending, by a first network function, a response to a third network function, the response including an identifier of a second network function (block 704), where the second network function has authenticated a terminal identified based on the parameter.
[0107] In some embodiments, the first network function includes a Unified Data Management (UDM) function.
[0108] In some embodiments, the second network function includes an Authentication Server Function (AUSF).
[0109] In some embodiments, the third network function includes an Authentication and Key Management Application (AKMA) Anchor Function (AAnF).
[0110] In some embodiments, the response includes a Subscriber Permanent Identifier (SUPI).
[0111] In some embodiments, the parameter includes a serving network name.
[0112] In some embodiments, the request includes an identifier of the terminal.
[0113] In some embodiments, the parameter includes a serving network name network identifier.
[0114] In some embodiments, the method includes: identifying, by the first network function, a record in a database, the record in the database corresponding to the second network function that has authenticated a terminal based on the parameter; and retrieving, by the first network function, an identifier of the second network function that has authenticated the terminal, and retrieving the SUPI included in the record in the database.
[0115] In some embodiments, the third network function is configured to: send a key request message to the second network function, the second network function being identified based on the identifier of the second network function that has authenticated the terminal, the key request message including the SUPI.
[0116] In some embodiments, the second network function is configured to receive an AKMA key identifier, a terminal identifier, and a parameter from a fourth network function.
[0117] In some embodiments, the fourth network function is an AKMA Application Function (AF).
[0118] In some embodiments, the fourth network function is configured to receive an AKMA key identifier, a terminal identifier, and a parameter from the terminal.
[0119] In another exemplary embodiment, a method for communication includes: sending, by a first network function, a request to retrieve an identifier of a second network function that has authenticated a terminal from a third network function, the request including a parameter; and receiving, by the first network function, a response from the third network function, the response including the identifier of the second network function that has authenticated the terminal identified based on the parameter.
[0120] In some embodiments, the first network function includes an Authentication and Key Management Application (AKMA) Anchor Function (AAnF).
[0121] In some embodiments, the second network function includes an Authentication Server Function (AUSF).
[0122] In some embodiments, the third network function includes a Unified Data Management (UDM) function.
[0123] In some embodiments, the response includes a Subscriber Permanent Identifier (SUPI).
[0124] In some embodiments, the parameter includes a serving network name.
[0125] In some embodiments, the request includes an identifier of the terminal.
[0126] In some embodiments, the parameter includes a serving network name network identifier.
[0127] In some embodiments, the third network function is configured to: identify a record in a database (the record in the database corresponding to the second network function that has authenticated the terminal based on the parameter); and retrieve the identifier of the second network function that has authenticated the terminal, and retrieve the SUPI included in the record of the database.
[0128] In some embodiments, the method includes: sending a key request message to the second network function, the second network function being identified based on the identifier of the second network function that has authenticated the terminal, the key request message including the SUPI.
[0129] In some embodiments, the method includes: receiving, by the first network function, an AKMA key identifier, a terminal identifier, and a parameter from a fourth network function.
[0130] In some embodiments, the fourth network function includes an AKMA Application Function.
[0131] In some embodiments, the fourth network function is configured to receive an AKMA key identifier, a terminal identifier, and a parameter from the terminal.
[0132] Example Wireless System
[0133] Figure 8 FIG. 2 illustrates an example of a wireless communication system in which techniques according to one or more embodiments of the present technology may be applied. The wireless communication system 800 may include one or more base stations (BSs) 805a, 805b, one or more wireless devices 810a, 810b, 810c, 810d, and a core network 825. The base stations 805a, 805b may provide wireless services to the wireless devices 810a, 810b, 810c, and 810d in one or more wireless sectors. In some embodiments, the base stations 805a, 805b include directional antennas that generate two or more directional beams to provide wireless coverage in different sectors.
[0134] The core network 825 may communicate with one or more base stations 805a, 805b. The core network 825 provides connectivity to other wireless communication systems and wired communication systems. The core network may include one or more service subscription databases to store information related to the subscribed wireless devices 810a, 810b, 810c, and 810d. The first base station 805a may provide wireless services based on a first radio access technology, while the second base station 805b may provide wireless services based on a second radio access technology. The base stations 805a and 805b may be quasi-co-located or may be installed separately on-site depending on the deployment scenario. The wireless devices 810a, 810b, 810c, and 810d may support multiple different radio access technologies.
[0135] In some embodiments, the wireless communication system may include multiple networks using different wireless technologies. Dual-mode or multi-mode wireless devices include two or more wireless technologies that can be used to connect to different wireless networks.
[0136] Figure 9 FIG. 12 is a block diagram representation of a part of a hardware platform. A hardware platform 905, such as a network device or a base station or a wireless device (or UE), may include processor electronics 910, such as a microprocessor, that implements one or more of the wireless technologies presented in the present application. The hardware platform 905 may include transceiver electronics 915 for transmitting and / or receiving wired / wireless signals through one or more communication interfaces such as an antenna 920 or a wired interface. The hardware platform 905 may implement other communication interfaces using protocols defined for transmitting and receiving data. The hardware platform 905 may include one or more memories (not explicitly shown) configured to store information such as data and / or instructions. In some embodiments, the processor electronics 910 may include at least a part of the transceiver electronics 915. In some embodiments, at least some of the disclosed technologies, modules, or functions are implemented using the hardware platform 905.
[0137] Conclusion
[0138] In view of the foregoing, it should be understood that, for purposes of illustration, specific embodiments of the presently disclosed technology have been described herein, but various modifications may be made without departing from the scope of the present invention. Accordingly, the presently disclosed technology is not limited except as by the limitations of the appended claims.
[0139] The disclosed and other embodiments, modules, and functional operations described in this application can be implemented in digital electronic circuitry, or in computer software, firmware, or hardware (including the structures disclosed in this application and their equivalent structures), or in a combination of one or more of them. The disclosed and other embodiments can be implemented as one or more computer program products, i.e., one or more modules of computer program instructions encoded on a computer-readable medium for execution by, or to control the operation of, a data processing apparatus. The computer-readable medium can be a machine-readable storage device, a machine-readable storage substrate, a memory device, a composition of matter affecting a machine-readable propagated signal, or a combination of one or more of them. The term "data processing apparatus" encompasses all apparatus, devices, and machines for processing data, including, for example, a programmable processor, a computer, or multiple processors or computers. In addition to hardware, the apparatus may also include code for creating an execution environment for the computer program being discussed, e.g., code constituting processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them. The propagated signal is an artificially generated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, which is generated to encode information for transmission to a suitable receiver device.
[0140] A computer program (also referred to as a program, software, software application, script, or code) can be written in any form of programming language (including a compiled or interpreted language), and can be deployed in any form (including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment). A computer program does not necessarily correspond to a file in a file system. The program can be stored as part of a file that stores other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program being discussed, or in multiple cooperating files (e.g., files storing one or more modules, subroutines, or portions of code). A computer program can be deployed to execute on one computer, or on multiple computers located at one site or distributed across multiple sites and interconnected by a communication network.
[0141] The processes and logical flows described in this application can be executed by one or more programmable processors that run one or more computer programs to perform functions by computing on input data and generating output. The processes and logical flows can also be executed by special-purpose logic circuitry, such as an FPGA (Field Programmable Gate Array) or ASIC (Application Specific Integrated Circuit), and the apparatus can also be implemented as special-purpose logic circuitry.
[0142] Processors suitable for executing computer programs include, by way of example, both general and special purpose microprocessors, and any one or more processors of any kind of digital computer. Generally, a processor will receive instructions and data from a read only memory or a random access memory or both. The basic elements of a computer are a processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include, or be operatively coupled to, one or more mass storage devices (such as magnetic disks, magneto-optical disks, or optical disks) for storing data, to receive data from or transfer data to the mass storage device, or both. However, a computer need not have such devices. Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media and memory devices, including by way of example semiconductor memory devices, such as EPROM, EEPROM, and flash memory devices; magnetic disks, such as internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special-purpose logic circuitry.
[0143] Although this patent application contains many details, these details should not be construed as limitations on the scope of any invention or of what can be claimed, but rather as descriptions of features specific to particular embodiments of particular inventions. Certain features described in this patent application in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment can also be implemented separately in multiple embodiments or in any suitable sub-combination. Moreover, although the features may have been described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be deleted from the combination, and the claimed combination can be directed to a sub-combination or variation of a sub-combination.
[0144] Similarly, although the operations are depicted in the drawings in a particular order, this should not be understood as requiring that the operations be performed in the particular order shown or in a sequential order, or that all illustrated operations be performed to achieve the desired result. Additionally, the separation of various system components in the embodiments described in this patent application should not be understood as requiring such separation in all embodiments.
[0145] Only a few embodiments and examples are described, and other embodiments, enhancements, and variations can be made based on what is described and illustrated in this patent application.
Claims
1. A method for data communication, comprising: receiving, by a first network function, a request to retrieve an identifier of a second network function that has authenticated a terminal from a third network function, the request including a serving network name (SNN), the SNN (i) being obtained from the terminal in an application session request originating from the terminal, and (ii) identifying the serving network to which the terminal is currently registered; and sending, by the first network function, a response to the third network function, the response including the identifier of the second network function that has authenticated the terminal identified based on the SNN.
2. The method according to claim 1, wherein, the first network function includes a unified data management (UDM) function.
3. The method according to any one of claims 1 and 2, wherein, the second network function includes an authentication server function (AUSF).
4. The method according to any one of claims 1 and 2, wherein, the third network function includes an authentication and key management application (AKMA) anchor function (AAnF).
5. The method according to claim 1, wherein, the response includes a subscriber permanent identifier (SUPI).
6. The method according to claim 1, wherein, the request includes an identifier of the terminal.
7. The method according to claim 5, further comprising: identifying, by the first network function, a record in a database, the record in the database corresponding to the second network function that has authenticated the terminal based on the SNN; and retrieving, by the first network function, the identifier of the second network function that has authenticated the terminal, and retrieving the SUPI included in the record in the database.
8. The method according to claim 5, wherein, the third network function is configured to: send a key request message to the second network function, the second network function being identified based on the identifier of the second network function that has authenticated the terminal, the key request message including the SUPI.
9. The method according to claim 1, wherein, the second network function is configured to receive an AKMA key identifier, an identifier of the terminal, and the SNN from a fourth network function.
10. The method according to claim 9, wherein, the fourth network function is an AKMA application function (AF).
11. The method according to any one of claims 9 and 10, wherein, the fourth network function is configured to receive the AKMA key identifier, the identifier of the terminal, and the SNN from the terminal.
12. A method for data communication, comprising: sending, by a first network function, a request to retrieve an identifier of a second network function that has authenticated a terminal from a third network function, the request including a serving network name (SNN), the SNN (i) being obtained from the terminal in an application session request originating from the terminal, and (ii) identifying the serving network to which the terminal is currently registered; and The response is received by the first network function from the third network function, the response including an identifier of the second network function that has authenticated the terminal based on the SNN.
13. The method according to claim 12, wherein, the first network function includes an Authentication and Key Management Application (AKMA) Anchor Function (AAnF).
14. The method according to any one of claims 12 to 13, wherein, the second network function includes an Authentication Server Function (AUSF).
15. The method according to any one of claims 12 to 13, wherein, the third network function includes a Unified Data Management (UDM) function.
16. The method according to claim 12, wherein, the response includes a Subscription Permanent Identifier (SUPI).
17. The method according to claim 12, wherein, the request includes an identifier of the terminal.
18. The method according to claim 16, wherein, the third network function is configured to: identify a record in a database, the record in the database corresponding to the second network function that has authenticated the terminal based on the SNN; and retrieve the identifier of the second network function that has authenticated the terminal, and retrieve the SUPI included in the record of the database.
19. The method according to claim 16, further comprising: sending, by the first network function, a key request message to a second network function identified based on the identifier of the second network function that has authenticated the terminal, the key request message including the SUPI.
20. The method according to claim 12, further comprising: receiving, by the first network function, an AKMA key identifier, an identifier of the terminal, and the SNN from a fourth network function.
21. The method according to claim 20, wherein, the fourth network function includes an AKMA Application Function.
22. The method according to any one of claims 20 and 21, wherein, the fourth network function is configured to receive the AKMA key identifier, the identifier of the terminal, and the SNN from the terminal.
23. An apparatus for communication, the apparatus including a processor configured to execute the method according to any one of claims 1 to 22.
24. A non-transitory computer-readable medium having code stored thereon, which when executed by a processor causes the processor to implement the method according to any one of claims 1 to 22.