A key generation method, device, apparatus and readable storage medium
By generating session keys (KAS) for multiple service servers in the same trust domain using AF, the problem of wasted core network resources in edge computing is solved, and signaling resources are saved while service latency is met.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE COMM LTD RES INST
- Filing Date
- 2021-12-14
- Publication Date
- 2026-04-14
AI Technical Summary
In edge computing scenarios, existing technologies require each service server to execute the AKMA process to generate the final key, resulting in a waste of core network resources and signaling processes.
The application server (AF) generates session keys (KAS) for multiple service servers in the same trust domain. Using the group key (KAF) and preset parameters, the session key is generated through the key derivation function (KDF), thus avoiding duplicate requests from multiple service servers to the core network AKMA process.
It saves signaling resources, reduces the signaling interaction process in the core network, is suitable for latency-sensitive business scenarios, and meets the latency requirements of the business.
Smart Images

Figure CN116264688B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a key generation method, apparatus, device, and readable storage medium. Background Technology
[0002] The standard defines the architecture and process for Authentication and Key Management for Applications (AKMA). AKMA technology can be used for authentication and authorization between terminals and edge computing servers in edge computing scenarios, as well as for the security protection of business channels between terminals and edge computing servers.
[0003] In edge computing and other application scenarios, a single edge node may have multiple service servers belonging to the same trust domain or the same vertical industry user. In this case, the terminal and each service server execute an AKMA procedure, causing the core network (AAnF (AKMA anchor function)) to execute the AKMA procedure and generate the final key (K) for each service server. AF ).
[0004] It can be seen that in the existing technology, for each request from an Application Function (AF) to the AAnF, the AAnF must execute the AKMA process and generate the corresponding final key for the AF, which results in a waste of core network resources and signaling processes. Summary of the Invention
[0005] This application provides a key generation method, apparatus, device, and readable storage medium to save signaling resources.
[0006] In a first aspect, embodiments of this application provide a key generation method applied to AF, comprising:
[0007] When the Application Service (AS) and the terminal need to establish a service connection, it does so based on the group key K. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS .
[0008] Wherein, one or more ASs belong to the same trust domain.
[0009] The method further includes:
[0010] Send the corresponding session key K to one or more ASs AS .
[0011] Among them, according to the group key KAF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS Previously, the method also included:
[0012] Obtain the group key K AF .
[0013] Wherein, obtaining the group key K AF ,include:
[0014] The terminal receives a first request, the first request including an intermediate key K. AKMA Corresponding key identifier;
[0015] Based on the key identifier, obtain the group key K from AAnF. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0016] Wherein, obtaining the group key K AF ,include:
[0017] Receive a second request from AS, the second request including the intermediate key K AKMA Corresponding key identifier;
[0018] The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0019] Specifically, the group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF ,include:
[0020] Send a third request to the AAnF, the third request including the key identifier and the AF identifier AF_ID;
[0021] Receive the group key K sent by AAnF according to the third request. AF .
[0022] The preset parameters include the AS identifier AS_ID; the parameters are based on the group key K. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS ,include:
[0023] According to the group key K AF And the AS_ID of the one or more ASs, generate a corresponding session key K for the one or more ASs. AS .
[0024] The session key K is generated according to the following formula. AS :
[0025] K AS =KDF(K AF (AS_ID);
[0026] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0027] The AS_ID is sent to the AF by one or more ASs.
[0028] Secondly, embodiments of this application provide a key generation method applied to AS, including:
[0029] When a service connection needs to be established with the terminal, the session key K is obtained from the AF. AS ; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters.
[0030] Among them, obtaining the session key K from AF AS ,include:
[0031] Receive a fourth request sent by the terminal, the fourth request including the intermediate key K. AKMA Corresponding key identifier;
[0032] Based on the key identifier, a fifth request is sent to the AF, the fifth request including the key identifier and the AS_ID of the AS;
[0033] Receive the session key K sent by the AF AS .
[0034] Thirdly, embodiments of this application provide a key generation method, applied to a terminal, including:
[0035] When a business connection needs to be established with the AS, it is based on the group key K. AF Generate session key K using preset parameters. AS .
[0036] The method further includes: triggering the AS to obtain the session key K. AS .
[0037] Wherein, triggering the AS to obtain the session key K AS , including any one of the following:
[0038] Send a sixth request to AAnF, the sixth request including the intermediate key K AKMA The corresponding key identifier, the sixth request is used to trigger AAnF based on the group key K AF Based on preset parameters, a corresponding session key K is generated for the AS. AS ;
[0039] A seventh request is sent to the AS, the seventh request including the intermediate key K. AKMA The corresponding key identifier, the seventh request is used to trigger the AS to obtain the corresponding session key K from the AAnF. AS .
[0040] The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS :
[0041] K AS =KDF(K AF (AS_ID);
[0042] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0043] Fourthly, embodiments of this application provide a key generation apparatus for use in AF, comprising:
[0044] The first generation module is used to generate data based on the group key K when the AS and the terminal need to establish a service connection. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS .
[0045] Wherein, one or more ASs belong to the same trust domain.
[0046] The device further includes:
[0047] The first sending module is used to send the corresponding session key K to the one or more ASs. AS .
[0048] The device further includes:
[0049] The first acquisition module is used to acquire the group key K. AF .
[0050] The first acquisition module includes:
[0051] A first receiving submodule is configured to receive a first request from the terminal, the first request including an intermediate key K. AKMA Corresponding key identifier;
[0052] The first acquisition submodule is used to obtain the group key K from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0053] The first acquisition module includes:
[0054] The first receiving submodule is configured to receive a second request from AS, the second request including the intermediate key K. AKMA Corresponding key identifier;
[0055] The first acquisition submodule is used to obtain the group key K from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0056] The first acquisition submodule includes:
[0057] The first sending unit is configured to send a third request to the AAnF, the third request including the key identifier and the AF identifier AF_ID;
[0058] The first receiving unit is used for the group key K sent by AAnF according to the third request. AF .
[0059] The preset parameters include the AS identifier AS_ID; the first generation module is used to generate the group key K. AF And the AS_ID of the one or more ASs, generate a corresponding session key K for the one or more ASs. AS .
[0060] The first generation module is used to generate the session key K according to the following formula. AS :
[0061] K AS =KDF(K AF (AS_ID);
[0062] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0063] Fifthly, embodiments of this application provide a key generation apparatus applied to an AS, comprising:
[0064] The first acquisition module is used to obtain the session key K from the AF when a service connection needs to be established with the terminal. AS; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters.
[0065] The first acquisition module includes:
[0066] The first receiving submodule is configured to receive a fourth request sent by the terminal, the fourth request including an intermediate key K. AKMA Corresponding key identifier;
[0067] The first sending submodule is configured to send a fifth request to the AF according to the key identifier, the fifth request including the key identifier and the AS_ID of the AS;
[0068] The first acquisition submodule is used to receive the session key K sent by the AF. AS .
[0069] Sixthly, embodiments of this application provide a key generation apparatus, applied to a terminal, comprising:
[0070] The first generation module is used to generate data based on the group key K when a business connection with the AS needs to be established. AF Generate session key K using preset parameters. AS .
[0071] The device further includes:
[0072] The first triggering module is used to trigger the AS to obtain the session key K. AS .
[0073] The first triggering module is used to execute any one of the following:
[0074] Send a sixth request to AAnF, the sixth request including the intermediate key K AKMA The corresponding key identifier, the sixth request is used to trigger AAnF based on the group key K AF Based on preset parameters, a corresponding session key K is generated for the AS. AS ;
[0075] A seventh request is sent to the AS, the seventh request including the intermediate key K. AKMA The corresponding key identifier, the fifth request is used to trigger the AS to obtain the corresponding session key K from the AAnF. AS .
[0076] The preset parameters include the AS identifier AS_ID; the first generation module is used to generate the session key K according to the following formula. AS :
[0077] KAS =KDF(K AF (AS_ID);
[0078] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0079] In a seventh aspect, embodiments of this application provide a key generation apparatus for use in AF, comprising: a processor and a transceiver;
[0080] The processor is used to, when the AS and the terminal need to establish a service connection, determine the group key K. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS .
[0081] Wherein, one or more ASs belong to the same trust domain.
[0082] The transceiver is used to send the corresponding session key K to the one or more ASs. AS .
[0083] The processor is further configured to: obtain the group key K AF .
[0084] The processor is further configured to:
[0085] The terminal receives a first request, the first request including an intermediate key K. AKMA Corresponding key identifier;
[0086] The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0087] The processor is further configured to:
[0088] Receive a second request from AS, the second request including the intermediate key K AKMA Corresponding key identifier;
[0089] The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0090] The processor is further configured to:
[0091] Send a third request to the AAnF, the third request including the key identifier and the AF identifier AF_ID;
[0092] Receive the group key K sent by AAnF according to the third request. AF .
[0093] The preset parameters include the AS identifier AS_ID; the processor is further configured to:
[0094] According to the group key K AF And the AS_ID of the one or more ASs, generate a corresponding session key K for the one or more ASs. AS .
[0095] The processor is further configured to generate session key K according to the following formula. AS :
[0096] K AS =KDF(K AF (AS_ID);
[0097] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0098] Eighthly, embodiments of this application provide a key generation apparatus applied to an AS, comprising: a processor and a transceiver;
[0099] The processor is used to obtain the session key K from the AF when it is necessary to establish a service connection with the terminal. AS ; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters.
[0100] The processor is further configured to:
[0101] Receive a fourth request sent by the terminal, the fourth request including the intermediate key K. AKMA Corresponding key identifier;
[0102] Based on the key identifier, a fifth request is sent to the AF, the fifth request including the key identifier and the AS_ID of the AS;
[0103] Receive the session key K sent by the AF AS .
[0104] Ninthly, embodiments of this application provide a key generation apparatus for use in a terminal, comprising: a processor and a transceiver;
[0105] The processor is used to, when a service connection needs to be established with the AS, determine the group key K. AF Generate session key K using preset parameters. AS .
[0106] The processor is also used to trigger the AS to obtain the session key K. AS .
[0107] The processor is also configured to perform any one of the following:
[0108] Send a sixth request to AAnF, the sixth request including the intermediate key K AKMA The corresponding key identifier, the sixth request is used to trigger AAnF based on the group key K AF Based on preset parameters, a corresponding session key K is generated for the AS. AS ;
[0109] A fifth request is sent to the AS, the fifth request including the intermediate key K. AKMA The corresponding key identifier, the seventh request is used to trigger the AS to obtain the corresponding session key K from the AAnF. AS .
[0110] The preset parameters include the AS identifier AS_ID; the processor is further configured to generate the session key K according to the following formula. AS :
[0111] K AS =KDF(K AF (AS_ID);
[0112] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0113] In a tenth aspect, embodiments of this application also provide a communication device, including: a transceiver, a memory, a processor, and a program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps in the key generation method described above.
[0114] Eleventhly, embodiments of this application also provide a readable storage medium storing a program that, when executed by a processor, implements the steps in the key generation method described above.
[0115] In this embodiment of the application, the AF generates a session key K for one or more ASs. AS Therefore, the solution using the embodiments of this application avoids repeated requests from multiple ASs to the core network AKMA process, thereby saving signaling resources. Attached Figure Description
[0116] Figure 1 This is a schematic diagram of the AKMA key hierarchy system according to an embodiment of this application;
[0117] Figure 2 This is one of the flowcharts of the key generation method provided in the embodiments of this application;
[0118] Figure 3 This is the second flowchart of the key generation method provided in the embodiments of this application;
[0119] Figure 4 This is the third flowchart of the key generation method provided in the embodiments of this application;
[0120] Figure 5 This is the fourth flowchart of the key generation method provided in the embodiments of this application;
[0121] Figure 6 This is the fifth flowchart of the key generation method provided in the embodiments of this application;
[0122] Figure 7 This is one of the structural diagrams of the key generation device provided in the embodiments of this application;
[0123] Figure 8 This is a second structural diagram of the key generation device provided in the embodiments of this application;
[0124] Figure 9 This is the third structural diagram of the key generation device provided in the embodiments of this application;
[0125] Figure 10 This is the fourth structural diagram of the key generation device provided in the embodiments of this application;
[0126] Figure 11 This is the fifth structural diagram of the key generation device provided in the embodiments of this application;
[0127] Figure 12 This is the sixth structural diagram of the key generation device provided in the embodiments of this application. Detailed Implementation
[0128] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0129] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0130] The technologies described in this article are not limited to NR (New Radio) systems and Long Time Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in various wireless communication systems such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" are often used interchangeably. CDMA systems can implement radio technologies such as CDMA2000 and Universal Terrestrial Radio Access (UTRA). UTRA includes Wideband Code Division Multiple Access (WCDMA) and other CDMA variants. TDMA systems can implement radio technologies such as the Global System for Mobile Communication (GSM). OFDMA systems can implement radio technologies such as Ultra Mobile Broadband (UMB), Evolution-UTRA (E-UTRA), IEEE 802.21 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, and Flash-OFDM. UTRA and E-UTRA are parts of the Universal Mobile Telecommunications System (UMTS). LTE and more advanced versions of LTE (such as LTE-A) are newer versions of UMTS that use E-UTRA. UTRA, E-UTRA, UMTS, LTE, LTE-A, and GSM are described in documents from an organization called the 3rd Generation Partnership Project (3GPP). CDMA2000 and UMB are described in documents from an organization called 3rd Generation Partnership Project 2 (3GPP2).The techniques described herein can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. However, the following description describes NR systems for illustrative purposes, and NR terminology is used in most of the following description, although these techniques can also be applied to applications beyond NR systems.
[0131] The following description provides examples and is not intended to limit the scope, applicability, or configuration set forth in the claims. Changes may be made to the function and arrangement of the elements discussed without departing from the spirit and scope of this disclosure. Various procedures or components may be appropriately omitted, substituted, or added to the examples. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Furthermore, features described with reference to certain examples may be combined in other examples.
[0132] Figure 1 This diagram illustrates a key hierarchy using the intermediate key KAUSF in a 5G key architecture for subsequent key derivation. Here, ME represents Mobile Equipment, and HPLMN (Home Public Land Mobile Network) represents the home PLMN (Public Land Mobile Network). One AF can correspond to multiple ASs, which belong to the same trust domain or the same vertical industry user.
[0133] In this embodiment, the KAF is used as the root key or group key of a certain trust domain to perform key derivation for the related AS under that trust domain. The specific method is as follows:
[0134] K AS =KDF(K AF ,AS_ID), where KDF is the key derivation function, and AS_ID can be the FQDN (Fully Qualified Domain Name) of AS.
[0135] The specific implementation process of the embodiments of this application will be described in detail below with reference to different examples.
[0136] See Figure 2 , Figure 2 This is a flowchart of the key generation method provided in the embodiments of this application, applied to AF, such as... Figure 2 As shown, it includes the following steps:
[0137] Step 201: When the AS and the terminal need to establish a service connection, according to the group key K AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS.
[0138] The one or more ASs belong to the same trust domain. Different ASs can have different session keys K. AS .
[0139] Wherein, the group key K AF It can be stored in the AF itself, or it can be obtained from AAnF. Optionally, before step 201, the AF obtains the group key K. AF .
[0140] Specifically, the AF obtains the group key based on a request from the terminal, or it can obtain the group key based on a request from the AS. The group key can also be referred to as the root key.
[0141] Specifically, the AF can receive a first request from the terminal, the first request including an intermediate key K. AKMA The corresponding key identifier (A-KID) is used to obtain the group key K from AAnF. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0142] The first request could be, for example, an Application Session Establishment Request. If the AF determines, based on the key identifier, that it does not have an activation context associated with A-KID, then the AF can obtain the group key K from AAnF. AF If the AF determines that it has an activation context associated with A-KID based on the key identifier, then the AF can obtain the group key K from itself. AF .
[0143] Specifically, the AF can also receive a second request from the AS, the second request including the intermediate key K. AKMA The corresponding key identifier (A-KID) is used to obtain the group key K from AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0144] The second request could be, for example, a key request. If the AF determines, based on the key identifier, that it does not have an activation context associated with A-KID, then the AF can obtain the group key K from AAnF. AF If the AF determines that it has an activation context associated with A-KID based on the key identifier, then the AF can obtain the group key K from itself. AF .
[0145] AF obtains group key K from AAnF AF During the process, AF can send a third request to AAnF, the third request including the key identifier and AF identifier AF_ID, and receive the group key K sent by AAnF according to the third request. AF For example, AF can send a Naanf_AKMA_ApplicationKey_Get Requeset message to AAnF and obtain the group key K from AAnF. AF .
[0146] In this embodiment of the application, the preset parameter includes an AS identifier, AS_ID. The AS_ID can be sent to the AF by one or more ASs after receiving a service establishment request from the terminal, or it can be determined by the AF based on pre-stored information after receiving a key request from an AS.
[0147] Specifically, AF can generate the session key K according to the following formula. AS :
[0148] K AS =KDF(K AF (AS_ID);
[0149] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0150] The AS ID can be the FQDN of the AS.
[0151] Optionally, the AF may also send the corresponding session key K to one or more ASs. AS This allows the AS to establish a service connection with the terminal. Specifically, the AF can generate the session key K. AS It can then be sent directly to the AS, or the session key K can be sent upon request from the AS. AS Send to AS.
[0152] In this embodiment of the application, the AF generates a session key K for one or more ASs. AS Therefore, the solution using the embodiments of this application avoids repeated requests from multiple ASs to the core network AKMA process, thereby saving signaling resources.
[0153] See Figure 3 , Figure 3 This is a flowchart of the key generation method provided in the embodiments of this application, applied to AS, such as... Figure 3 As shown, it includes the following steps:
[0154] Step 301: When it is necessary to establish a service connection with the terminal, obtain the session key K from the AF. AS ; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters.
[0155] In practical applications, when an AS receives a service establishment request from a terminal, it can obtain the session key K from the AF. AS .
[0156] Specifically, the AS can receive a fourth request sent by the terminal, the fourth request including the intermediate key K. AKMA The corresponding key identifier is used, and a fifth request is sent to the AF based on the key identifier. The fifth request includes the key identifier and the AS_ID of the AS.
[0157] The fourth request may be, for example, a service establishment request, and the fifth request may be, for example, a key acquisition request.
[0158] In this embodiment of the application, the AF generates a session key K for one or more ASs. AS Therefore, the solution using the embodiments of this application avoids repeated requests from multiple ASs to the core network AKMA process, thereby saving signaling resources.
[0159] See Figure 4 , Figure 4 This is a flowchart of the key generation method provided in the embodiments of this application, applied to a terminal, such as... Figure 4 As shown, it includes the following steps:
[0160] Step 401: When it is necessary to establish a service connection with AS, based on the group key K AF Generate session key K using preset parameters. AS .
[0161] The preset parameters include the AS identifier AS_ID. The terminal can generate the session key K according to the following formula. AS :
[0162] K AS =KDF(K AF (AS_ID);
[0163] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0164] In the above embodiments, the terminal may also trigger the AS to obtain the session key K. ASThe terminal can directly trigger the AF to generate a session key for the AS, or it can trigger the AS to obtain a session key from the AF.
[0165] Specifically, the terminal can send a sixth request to AAnF, which includes a key identifier corresponding to the intermediate key KAKMA. This sixth request is used to trigger AAnF to use the group key K. AF Based on preset parameters, a corresponding session key K is generated for the AS. AS The sixth request could be, for example, an Application Session EstablishmentRequest.
[0166] Specifically, the terminal can send a seventh request to the AS, the seventh request including the intermediate key K. AKMA The corresponding key identifier, the seventh request is used to trigger the AS to obtain the corresponding session key K from the AAnF. AS The seventh request could be, for example, a service establishment request.
[0167] In this embodiment of the application, the AF generates a session key K for one or more ASs. AS Therefore, the solution using the embodiments of this application avoids repeated requests from multiple ASs to the core network AKMA process, thereby saving signaling resources.
[0168] In this embodiment of the application, K is used AF Used as the root key or group key of a certain trust domain, it is used for key derivation for the relevant AS under that trust domain. The specific method is as follows:
[0169] K AS =KDF(K AF ,AS_ID), where KDF is the key derivation function, and AS_ID can be the FQDN of AS.
[0170] In the following embodiments, it is assumed that the terminal and the core network have completed K AKMA Key creation.
[0171] See Figure 5 , Figure 5 This is a flowchart of a key generation method provided in an embodiment of this application. The method may include:
[0172] Step 501: When the UE (User Equipment) initiates communication with the AKMA AF (AF), the Application Session Establishment Request message includes A-KID. The UE can deduce KID before or after sending this message. AF .
[0173] Before interacting with the AKMA application server, the UE obtains data from K... AUSF Derivation of K AKMA And A-KID (key identifier).
[0174] Step 502: If there is no activation context associated with A-KID in AKMA AF, then AF sends a Naanf_AKMA_ApplicationKey_Get Requeset message to AAnF to request the UE's K AF The message carries A-KID and AF_ID. AF_ID includes the AF's FQDN and Ua* protocol identifier, where the Ua* protocol identifier identifies the security protocol used between the AF and the UE. If the AKMA AF has an activation context associated with A-KID, then the AKMA AF directly retrieves the K from the activation context. AF .
[0175] Step 503, AAnF obtains K AF .
[0176] AAnF can use AF_ID to check whether it can provide services to AF based on configured local policies or authorization information or policies provided by NRF (Network Repository Function). Simultaneously, AAnF can determine whether a user is authorized to use AKMA by verifying whether the corresponding KAKMA can be found through A-KID.
[0177] When AAnF can provide services to AF and determines that the user is authorized to use AKMA, the following process is executed; otherwise, AAnF refuses to execute the subsequent process and sends an error response.
[0178] If AAnF has no K AF If so, then AAnF is determined by K. AKMA Derivation of K AF Otherwise, the existing K can be used directly. AF .
[0179] Step 504: AAnF sends a Naanf_AKMA_ApplicationKey_Get Response message to AKMA AF, carrying the K key in the response message. AF And lifecycle. Alternatively, AAnF sends a Naanf_AKMA_ApplicationKey_Get Response message to the AKMA AF, and the response message indicates that the AKMA key request failed.
[0180] Step 505: AKMA AF sends an Application Session Establishment Response message to the UE.
[0181] If the information in step 504 indicates that the AKMA key request failed, the AF should reject the application session establishment request and include the error reason in the Application Session Establishment Response. Subsequently, the UE may initiate a new application session establishment request to the AF, carrying the latest A-KID.
[0182] Step 506) / 506' / / 506”: The UE sends a service establishment request to the edge computing service server (AS_1 / AS_2 / AS_N), carrying the A-KID.
[0183] Step 507) / 507' / 507”: The edge computing service server (AS_1 / AS_2 / AS_N) sends a key request to the AF, carrying A-KID and AS_ID.
[0184] Step 508) / 508' / / 508”, the AF deployed on the edge node generates the corresponding K according to the key derivation method described above. AS .
[0185] Step 509) / 509' / / 509”, the AF deployed on this edge node sends the corresponding K via a key response. AS Send to AS.
[0186] Step 510) / 510' / / 510”, AS responds to UE with a service establishment response, completing the establishment of a secure channel.
[0187] See Figure 6 , Figure 6 This is a flowchart of a key generation method provided in an embodiment of this application. The method may include:
[0188] Step 601: Before interacting with the AKMA application server, the UE accesses the K...AUSF Derivation of K AKMA And A-KID. When the UE communicates with the AS (taking AS1 as an example), the Application Session Establishment Request message includes the A-KID.
[0189] Step 602: If there is no K associated with A-KID in AKMA AS AS If so, AS sends a key request to AF. AS sends a key request to AF, carrying A-KID.
[0190] Step 603: If AF does not have a key K corresponding to A-KID AF If so, AF sends a Naanf_AKMA_ApplicationKey_Get Request message to AAnF, carrying A-KID and AF_ID.
[0191] Step 604, AAnF derivation of K AF And return it to AF.
[0192] Step 605: AAnF sends a Naanf_AKMA_ApplicationKey_Get Response message to AKMA AF, carrying the K key in the response message. AF and life cycle.
[0193] Step 606, AF according to K AF Derivation of K AS_1 .
[0194] Step 607, AF will K AS_1 Return to AS_1.
[0195] Step 608: AS replies to UE with a service establishment response, completing the establishment of a secure channel.
[0196] Steps 609-613: When the UE communicates with other ASs in the trusted domain, the other ASs directly request K from the AF. AF AF and perform the corresponding K AS This derivation allows for the establishment and protection of a secure channel between the UE and other ASs.
[0197] As can be seen from the above description, the scheme using the embodiments of this application, where AF is an AS in the same trust domain based on K... AF Derivation of K ASThis saves on the signaling interaction process in the core network and avoids repeated requests from the service server of the same edge computing node to the core network AKMA process. At the same time, for latency-sensitive service scenarios, the solution using the embodiment of this application saves interaction latency and makes it easier to meet service latency requirements.
[0198] This application also provides a key generation apparatus for use in AF. See also Figure 7 , Figure 7 This is a structural diagram of the key generation device provided in an embodiment of this application. Figure 7 As shown, the key generation device 700 includes:
[0199] The first acquisition module 701 is used to obtain the group key K when the AS and the terminal need to establish a service connection. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS .
[0200] Wherein, one or more ASs belong to the same trust domain.
[0201] Optionally, the apparatus may further include: a first transmitting module, configured to transmit a corresponding session key K to the one or more ASs. AS .
[0202] The device further includes: a first acquisition module, used to acquire the group key K. AF .
[0203] The first acquisition module includes:
[0204] A first receiving submodule is configured to receive a first request from the terminal, the first request including an intermediate key K. AKMA Corresponding key identifier;
[0205] The first acquisition submodule is used to obtain the group key K from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0206] The first acquisition module includes:
[0207] The first receiving submodule is configured to receive a second request from AS, the second request including the intermediate key K. AKMA Corresponding key identifier;
[0208] The first acquisition submodule is used to obtain the group key K from the application layer authentication and session key management anchor function AAnF based on the key identifier. AFAlternatively, the group key K can be obtained from the AF itself. AF .
[0209] The first acquisition submodule includes:
[0210] The first sending unit is configured to send a third request to the AAnF, the third request including the key identifier and the AF identifier AF_ID;
[0211] The first receiving unit is used for the group key K sent by AAnF according to the third request. AF .
[0212] The preset parameters include the AS identifier AS_ID; the first generation module is used to generate the group key K. AF And the AS_ID of the one or more ASs, generate a corresponding session key K for the one or more ASs. AS .
[0213] The first generation module is used to generate the session key K according to the following formula. AS :
[0214] K AS =KDF(K AF (AS_ID);
[0215] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0216] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0217] This application also provides a key generation apparatus for use in an AS. See also Figure 8 , Figure 8 This is a structural diagram of the key generation device provided in an embodiment of this application. Figure 8 As shown, the key generation device 800 includes:
[0218] The first acquisition module 801 is used to acquire the session key K from the AF when it is necessary to establish a service connection with the terminal. AS ; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters.
[0219] The first acquisition module includes:
[0220] The first receiving submodule is configured to receive a fourth request sent by the terminal, the fourth request including an intermediate key K.AKMA Corresponding key identifier;
[0221] The first sending submodule is configured to send a fifth request to the AF according to the key identifier, the fifth request including the key identifier and the AS_ID of the AS;
[0222] The first acquisition submodule is used to receive the session key K sent by the AF. AS .
[0223] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0224] This application also provides a key generation device for use in a terminal. See also... Figure 9 , Figure 9 This is a structural diagram of the key generation device provided in an embodiment of this application. Figure 9 As shown, the key generation device 900 includes:
[0225] The first generation module 901 is used to generate data based on the group key K when a service connection with the AS needs to be established. AF Generate session key K using preset parameters. AS .
[0226] The device may further include:
[0227] The first triggering module is used to trigger the AS to obtain the session key K. AS .
[0228] The first triggering module is used to execute any one of the following:
[0229] Send a sixth request to AAnF, the sixth request including the intermediate key K AKMA The corresponding key identifier, the sixth request is used to trigger AAnF based on the group key K AF Based on preset parameters, a corresponding session key K is generated for the AS. AS ;
[0230] A seventh request is sent to the AS, the seventh request including the intermediate key K. AKMA The corresponding key identifier, the fifth request is used to trigger the AS to obtain the corresponding session key K from the AAnF. AS .
[0231] The preset parameters include the AS identifier AS_ID; the first generation module is used to generate the session key K according to the following formula. AS :
[0232] K AS=KDF(K AF (AS_ID);
[0233] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0234] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0235] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0236] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0237] This application provides a key generation device applied to AF, such as... Figure 10 As shown, it includes: a processor 1001 and a transceiver 1002;
[0238] The processor 1001 is used to, when the AS and the terminal need to establish a service connection, determine the group key K. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS .
[0239] Wherein, one or more ASs belong to the same trust domain;
[0240] The transceiver 1002 is used to send the corresponding session key K to the one or more ASs. AS .
[0241] The processor 1001 is further configured to: obtain the group key K AF .
[0242] The processor 1001 is further configured to:
[0243] The terminal receives a first request, the first request including an intermediate key K. AKMA Corresponding key identifier;
[0244] The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0245] The processor 1001 is further configured to:
[0246] Receive a second request from AS, the second request including the intermediate key K AKMA Corresponding key identifier;
[0247] The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
[0248] The processor 1001 is further configured to:
[0249] Send a third request to the AAnF, the third request including the key identifier and the AF identifier AF_ID;
[0250] Receive the group key K sent by AAnF according to the third request. AF .
[0251] The preset parameters include the AS identifier AS_ID; the processor is further configured to:
[0252] According to the group key K AF And the AS_ID of the one or more ASs, generate a corresponding session key K for the one or more ASs. AS .
[0253] The processor 1001 is further configured to generate a session key K according to the following formula. AS :
[0254] K AS =KDF(KAF (AS_ID);
[0255] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0256] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0257] This application provides a key generation device applied to an AS, such as... Figure 11 As shown, it includes: a processor 1101 and a transceiver 1102;
[0258] The processor 1101 is used to obtain the session key K from the AF when it is necessary to establish a service connection with the terminal. AS ; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters.
[0259] The processor 1101 is further configured to:
[0260] Receive a fourth request sent by the terminal, the fourth request including the intermediate key K. AKMA Corresponding key identifier;
[0261] Based on the key identifier, a fifth request is sent to the AF, the fifth request including the key identifier and the AS_ID of the AS;
[0262] Receive the session key K sent by the AF AS .
[0263] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0264] This application provides a key generation device for use in a terminal, such as... Figure 12 As shown, it includes: a processor 1201 and a transceiver 1202;
[0265] The processor 1201 is used to, when a service connection needs to be established with the AS, determine the group key K. AF Generate session key K using preset parameters. AS .
[0266] The processor 1201 is also used to trigger the AS to obtain the session key K. AS .
[0267] The processor 1201 is further configured to perform any one of the following:
[0268] Send a sixth request to AAnF, the sixth request including the intermediate key K AKMA The corresponding key identifier, the sixth request is used to trigger AAnF based on the group key K AF Based on preset parameters, a corresponding session key K is generated for the AS. AS ;
[0269] A fifth request is sent to the AS, the fifth request including the intermediate key K. AKMA The corresponding key identifier, the seventh request is used to trigger the AS to obtain the corresponding session key K from the AAnF. AS .
[0270] The preset parameters include the AS identifier AS_ID; the processor is further configured to generate the session key K according to the following formula. AS :
[0271] K AS =KDF(K AF (AS_ID);
[0272] Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
[0273] The apparatus provided in this application embodiment can execute the above method embodiment, and its implementation principle and technical effect are similar, so it will not be described again here.
[0274] This application provides a communication device, including: a memory, a processor, and a program stored in the memory and executable on the processor; the processor is configured to read the program in the memory to implement the steps in the key generation method described above.
[0275] This application also provides a readable storage medium storing a program. When executed by a processor, this program implements the various processes of the above-described key generation method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here. The readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic storage (e.g., floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc.), optical storage (e.g., CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (e.g., ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs)).
[0276] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0277] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0278] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A key generation method, applied to application function AF, characterized in that, include: When the application server AS and the terminal need to establish a service connection, it is based on the group key K. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS ; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF The group key is represented by AS_ID, which represents the identifier of one or more ASs.
2. The method according to claim 1, characterized in that, The one or more ASs belong to the same trust domain.
3. The method according to claim 1, characterized in that, The method further includes: Send the corresponding session key K to one or more ASs AS .
4. The method according to claim 3, characterized in that, The AS_ID is sent to the AF by one or more ASs.
5. The method according to claim 1, characterized in that, According to the group key K AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS Previously, the method also included: Obtain the group key K AF .
6. The method according to claim 5, characterized in that, The acquisition of the group key K AF ,include: The terminal receives a first request, the first request including an intermediate key K. AKMA Corresponding key identifier; The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
7. The method according to claim 5, characterized in that, The acquisition of the group key K AF ,include: Receive a second request from AS, the second request including the intermediate key K AKMA Corresponding key identifier; The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF Alternatively, the group key K can be obtained from the AF itself. AF .
8. The method according to claim 6 or 7, characterized in that, The group key K is obtained from the application layer authentication and session key management anchor function AAnF based on the key identifier. AF ,include: Send a third request to the AAnF, the third request including the key identifier and the AF identifier AF_ID; Receive the group key K sent by AAnF according to the third request. AF .
9. A key generation method, applied to an application server AS, characterized in that, include: When a service connection needs to be established with the terminal, the session key K is obtained from the AF. AS Wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF The group key is represented by AS_ID, which represents the identifier of the AS.
10. The method according to claim 9, characterized in that, The session key K is obtained from AF. AS ,include: Receive a fourth request sent by the terminal, the fourth request including the intermediate key K. AKMA Corresponding key identifier; Based on the key identifier, a fifth request is sent to the AF, the fifth request including the key identifier and the AS_ID of the AS; Receive the session key K sent by the AF AS .
11. A key generation method, applied to a terminal, characterized in that, include: When a business connection needs to be established with the application server AS, it is based on the group key K. AF Generate session key K using preset parameters. AS ; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
12. The method according to claim 11, characterized in that, The method further includes: Trigger the AS to obtain session key K AS .
13. The method according to claim 12, characterized in that, The AS is triggered to obtain the session key K. AS , including any one of the following: Send a sixth request to AAnF, the sixth request including the intermediate key K AKMA The corresponding key identifier, the sixth request is used to trigger AAnF based on the group key K AF Based on preset parameters, a corresponding session key K is generated for the AS. AS ; A seventh request is sent to the AS, the seventh request including the intermediate key K. AKMA The corresponding key identifier, the seventh request is used to trigger the AS to obtain the corresponding session key K from the AAnF. AS .
14. A key generation device, applied to application function AF, characterized in that, include: The first generation module is used to generate data based on the group key K when the application server AS and the terminal need to establish a service connection. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS ; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF The group key is represented by AS_ID, which represents the identifier of one or more ASs.
15. A key generation device, applied to an application server AS, characterized in that, include: The first acquisition module is used to obtain the session key K from the application function AF when a service connection with the terminal needs to be established. AS ; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF The group key is represented by AS_ID, which represents the identifier of the AS.
16. A key generation device, applied to a terminal, characterized in that, include: The first generation module is used to establish a business connection with the application server AS when necessary, based on the group key K. AF Generate session key K using preset parameters. AS ; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
17. A key generation device, applied to application function AF, characterized in that, include: Processor and transceiver; The processor is used to, when the application server AS and the terminal need to establish a service connection, determine the group key K. AF Based on preset parameters, generate a corresponding session key K for one or more ASs. AS ; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF The group key is represented by AS_ID, which represents the identifier of one or more ASs.
18. A key generation device, applied to an application server AS, characterized in that, include: Processor and transceiver; The processor is used to obtain the session key K from the application function AF when it is necessary to establish a service connection with the terminal. AS ; wherein, the session key K AS The AF is based on the group key K AF Generated with preset parameters; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF The group key is represented by AS_ID, which represents the identifier of the AS.
19. A key generation device, applied to a terminal, characterized in that, include: Processor and transceiver; The processor is used to, when a business connection needs to be established with the application server AS, determine the group key K. AF Generate session key K using preset parameters. AS ; The preset parameters include the AS identifier AS_ID; the session key K is generated according to the following formula. AS : K AS =KDF(K AF ,AS_ID); Where KDF represents a preset key derivation function, K AF This represents the group key, and AS_ID represents the identifier of the AS.
20. A communication device, comprising: A memory, a processor, and a program stored in the memory and executable on the processor; characterized in that the processor is configured to read the program from the memory to implement the steps of the key generation method as described in any one of claims 1 to 13.
21. A readable storage medium for storing a program, characterized in that, When the program is executed by a processor, it implements the steps of the key generation method as described in any one of claims 1 to 13.
Citation Information
Patent Citations
Key generation method and equipment
CN113162758A
Key acquisition method and device
CN113543126A