Multi-access edge computing (MEC)-key id derivation in authentication between ue and edge server
Patent Information
- Application Number
- CN202180006359.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-10
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2041-05-10
Smart Images

Figure CN117204002B_ABST
Abstract
Description
Technical Field
[0001] This application relates to wireless communication systems in general, including the export of key IDs in authentication. Background Technology
[0002] Wireless mobile communication technologies use various standards and protocols to transmit data between base stations and wireless communication devices. Wireless communication system standards and protocols can include, for example, 3GPP Long Term Evolution (LTE) (such as 4G), 3GPP New Radio (NR) (such as 5G), and the IEEE 802.11 standard for Wireless Local Area Networks (WLANs) (often referred to within industry organizations as...). ).
[0003] As envisioned by 3GPP, different wireless communication system standards and protocols can use various radio access networks (RANs) to enable RAN base stations (which are sometimes also called RAN nodes, network nodes, or simply nodes) to communicate with wireless communication equipment called user equipment (UEs). 3GPP RANs may include, for example, Global System for Mobile Communications (GSM), Enhanced Data Rate GSM Evolution (EDGE) RAN (GERAN), Universal Terrestrial Radio Access Network (UTRAN), Evolved Universal Terrestrial Radio Access Network (E-UTRAN), and / or Next Generation Radio Access Network (NG-RAN).
[0004] Each RAN can use one or more Radio Access Technologies (RATs) for communication between the base station and the UE. For example, GERAN implements the GSM and / or EDGE RAT, UTRAN implements the Universal Mobile Telecommunications System (UMTS) RAT or other 3GPP RATs, E-UTRAN implements the LTE RAT (sometimes simply referred to as LTE), and NG-RAN implements the NR RAT (sometimes also referred to herein as the 5G RAT, 5G NR RAT, or simply NR). In some deployments, E-UTRAN may also implement the NR RAT. In some deployments, NG-RAN may also implement the LTE RAT.
[0005] The base stations used by a RAN can correspond to that RAN. An example of an E-UTRAN base station is an Evolved Universal Terrestrial Radio Access Network (E-UTRAN) Node B (also commonly referred to as Evolved Node B, Enhanced Node B, eNodeB, or eNB). An example of an NG-RAN base station is a Next Generation Node B (sometimes also called gNodeB or gNB).
[0006] The RAN provides communication services to external entities through its connection with the core network (CN). For example, E-UTRAN can utilize the evolved packet core network (EPC), while NG-RAN can utilize the 5G core network (5GC). Attached Figure Description
[0007] To facilitate identification of any particular element or action being discussed, one or more of the most significant digits in the reference numerals refer to the drawing number in which the element was first introduced.
[0008] Figure 1 An exemplary architecture of a wireless communication system according to an embodiment disclosed herein is shown.
[0009] Figure 2 An exemplary service-based architecture according to certain implementation schemes is shown.
[0010] Figure 3 This is a message flow diagram illustrating the main authentication procedure (5G AKA).
[0011] Figure 4 This is a block diagram illustrating the key hierarchy structure in 5G.
[0012] Figure 5 This is a block diagram illustrating the architecture used to enable edge applications.
[0013] Figure 6 This is a message sequence diagram illustrating the call flow.
[0014] Figure 7 It shows K 边缘 The table containing the data in the ID.
[0015] Figure 8 It is a flowchart based on an implementation plan.
[0016] Figure 9 A system for performing signaling between a wireless device and a network device according to an embodiment disclosed herein is shown. Detailed Implementation
[0017] Various embodiments are described with respect to the UE. However, references to the UE are provided for illustrative purposes only. Exemplary embodiments may be used with any electronic component capable of establishing a connection to a network and configured with hardware, software, and / or firmware for exchanging information and data with the network. Therefore, the UE described herein is used to represent any suitable electronic component.
[0018] Figure 1An exemplary architecture of a wireless communication system 100 according to an embodiment disclosed herein is shown. The description provided below is for an exemplary wireless communication system 100 operating in conjunction with LTE system standards and / or 5G or NR system standards provided by 3GPP technical specifications.
[0019] like Figure 1 As shown, the wireless communication system 100 includes UE 102 and UE 104 (however, any number of UEs may be used). In this example, UE 102 and UE 104 are shown as smartphones (e.g., handheld touchscreen mobile computing devices capable of connecting to one or more cellular networks), but may also include any mobile or non-mobile computing device configured for wireless communication.
[0020] UE 102 and UE 104 can be configured to communicate with RAN 106. In this implementation, RAN 106 can be NG-RAN, E-UTRAN, etc. UE 102 and UE 104 utilize connections (or channels) with RAN 106 (shown as connection 108 and connection 110, respectively), where each connection (or channel) includes a physical communication interface. RAN 106 may include one or more base stations, such as base station 112 and base station 114, that implement connection 108 and connection 110.
[0021] In this example, Connection 108 and Connection 110 are air interfaces that implement this communication coupling and are compatible with the RAT used by RAN106, such as, for example, LTE and / or NR.
[0022] In some implementations, UE 102 and UE 104 may also exchange communication data directly via sidelink interface 116. UE 104 is shown configured to access an access point (shown as AP 118) via connection 120. For example, connection 120 may include a local wireless connection, such as any connection conforming to the IEEE 802.11 protocol, where AP 118 may include... Router. In this example, AP 118 may connect to another network (e.g., the Internet) without using CN 124.
[0023] In the implementation, UE 102 and UE 104 may be configured to communicate with each other or with base station 112 and / or base station 114 on a multi-carrier communication channel using orthogonal frequency division multiplexing (OFDM) communication signals, based on various communication technologies, such as, but not limited to, orthogonal frequency division multiple access (OFDMA) communication technology (e.g., for downlink communication) or single-carrier frequency division multiple access (SC-FDMA) communication technology (e.g., for uplink and ProSe or sidelink communication), although the scope of the implementation is not limited in this respect. The OFDM signal may include multiple orthogonal subcarriers.
[0024] In some implementations, all or part of base station 112 or base station 114 may be implemented as one or more software entities running on a server computer as part of a virtual network. Furthermore, or in other implementations, base station 112 or base station 114 may be configured to communicate with each other via interface 122. In implementations where the wireless communication system 100 is an LTE system (e.g., when CN 124 is an EPC), interface 122 may be an X2 interface. This X2 interface may be defined between two or more base stations (e.g., two or more eNBs, etc.) connected to the EPC and / or between two eNBs connected to the EPC. In implementations where the wireless communication system 100 is an NR system (e.g., when CN 124 is a 5GC), interface 122 may be an Xn interface. This Xn interface may be defined between two or more base stations connected to the 5GC (e.g., two or more gNBs, etc.), between base station 112 (e.g., a gNB) connected to the 5GC and an eNB, and / or between two eNBs connected to the 5GC (e.g., CN 124).
[0025] The diagram illustrates RAN 106 communicatively coupled to CN 124. CN 124 may include one or more network elements 126 configured to provide various data and telecommunications services to customers / subscribers (e.g., users of UE 102 and UE 104) connected to CN 124 via RAN 106. Components of CN 124 may be implemented in a single physical device or in separate physical devices, including components for reading and executing instructions from machine-readable or computer-readable media (e.g., non-transitory machine-readable storage media).
[0026] In this implementation, CN 124 can be an EPC, and RAN 106 can be connected to CN 124 via S1 interface 128. In this implementation, S1 interface 128 can be divided into two parts: an S1 user plane (S1-U) interface, which carries traffic data between base station 112 or 114 and the serving gateway (S-GW); and an S1-MME interface, which is the signaling interface between base station 112 or 114 and the mobility management entity (MME).
[0027] In this implementation, CN 124 can be a 5GC, and RAN 106 can be connected to CN 124 via NG interface 128. In this implementation, NG interface 128 can be divided into two parts: an NG user plane (NG-U) interface, which carries traffic data between base station 112 or 114 and the User Plane Function (UPF); and an S1 control plane (NG-C) interface, which is the signaling interface between base station 112 or 114 and the Access and Mobility Management Function (AMF).
[0028] Generally, application server 130 can be a component (e.g., packet-switched data service) providing resources for applications that use Internet Protocol (IP) bearers with CN 124. Application server 130 can also be configured to support one or more communication services (e.g., VoIP sessions, group communication sessions, etc.) for UE 102 and UE 104 via CN 124. Application server 130 can communicate with CN 124 via IP communication interface 132.
[0029] The Authentication and Key Agreement (AKA) procedure involves mutual authentication between the UE and the network to obtain encryption keys that protect user plane and control plane data. Each generation of 3G, 4G, and 5G defines several authentication methods to allow authorized users to access the network and deny unauthorized users access. The 3GPP standard defines Evolved Packet System-AKA (EPS-AKA) for 4G LTE systems. Similarly, for 5G systems, three authentication methods are defined: 5G-AKA; Extensible Authentication Protocol-AKA (EAP-AKA); and Extensible Authentication Protocol-Transport Layer Security (EAP-TLS).
[0030] Figure 2 A service-based architecture 200 in a 5G system according to one implementation is illustrated. 3GPP has proposed a service-based architecture 200 for core networks with new network entities and services to support a unified authentication framework. This framework uses three authentication methods: 5G-AKA, EAP-AKA', and EAP-TLS, making the 5G-AKA procedure applicable to both open and access network-agnostic environments. The framework allows multiple security contexts to be established through a single authentication execution, thereby allowing UEs to migrate from 3GPP access networks to non-3GPP networks without having to re-authenticate.
[0031] As described in 3GPP TS 23.501, the service-based architecture 200 includes network functions such as NSSF 208, NEF 210, NRF 214, PCF 212, UDM 226, AUSF 218, AMF 220, and SMF 222 to communicate with UE 216, (R)AN 206, UPF 202, and DN 204. NF and NF services can communicate directly (referred to as direct communication) or indirectly via SCP 224 (referred to as indirect communication). Figure 2 It also shows the corresponding service-based interfaces including Nutm, Naf, Nudm, Npcf, Nsmf, Nnrf, Namf, Nnef, Nnssf, and Nausf, as well as reference points N1, N2, N3, N4, and N6. The following describes the... Figure 2 Some exemplary functions provided by NF are shown in the figure.
[0032] NSSF 208 supports functions such as: selecting the set of network slice instances serving the UE; determining the allowed NSSAIs and, if necessary, the mapping to subscribed S-NSSAIs; determining the configured NSSAIs and, if necessary, the mapping to subscribed S-NSSAIs; and / or determining the set of AMFs to be used to serve the UE, or, based on the configuration, possibly by querying the NRF to determine a list of candidate AMFs.
[0033] Network Exposure Functions (NEFs) (e.g., NEF 210) support the exposure of capabilities and events. NF capabilities and events can be securely exposed by NEF 210 (e.g., for third parties, application functions, and / or edge computing). NEF 210 can use a standardized interface (Nudr) to the UDR to store / retrieve information as structured data. NEF 210 can also securely provide information from external applications to the 3GPP network and can provide application functions to securely provide information to the 3GPP network (e.g., anticipated UE behavior, 5GLAN group information, and service-specific information), where NEF 210 can authenticate and authorize and help restrict application functions. NEF 210 can provide internal-external information translation by translating information exchanged with AFs and information exchanged with internal network functions. For example, NEF 210 translates between AF service identifiers and internal 5G core information (such as DNN and S-NSSAI). NEF 210 can handle the masking of network and user-sensitive information to external AFs according to network policies. The NEF 210 can receive information from other network functions (based on the exposure capabilities of other network functions) and store the received information as structured data using a standardized interface to the UDR. The stored information can then be accessed by the NEF 210 and re-exposed to other network functions and application functions for purposes such as analysis. For external exposure of services related to a specific UE, the NEF 210 can reside in the HPLMN. Depending on the operator agreement, the NEF 210 in the HPLMN can have an interface with the NF in the VPLMN. When the UE is able to switch between EPC and 5GC, SCEF+NEF can be used for service exposure.
[0034] NRF 214 supports service discovery by receiving NF discovery requests from NF instances or SCPs and providing information about discovered NF instances to the NF instances or SCPs. NRF 214 also supports P-CSCF discovery (a special case of SMF discovery AF), maintaining NF profiles of available NF instances and their supported services, and / or notifying subscribed NF service consumers or SCPs of newly registered / updated / deregistered NF instances along with their NF services. In the context of network slicing, multiple NRFs can be deployed at different levels depending on the network implementation, such as PLMN level (NRFs configured with information about the entire PLMN), shared slice level (NRFs configured with information about the network slice set), and / or slice-specific level (NRFs configured with information about the S-NSSAI). In the context of roaming, multiple NRFs can be deployed in different networks, where the NRF in the visited PLMN (referred to as vNRF) is configured with information about the visited PLMN, and the NRF in the home PLMN (referred to as hNRF) is configured with information about the home PLMN, referenced by the vNRF via the N27 interface.
[0035] PCF 212 supports a unified policy framework for managing network behavior. PCF 212 provides policy rules for control plane functions to enforce them. PCF 212 accesses subscription information related to policy decisions in the Unified Data Repository (UDR). PCF 212 can access the UDR located in the same PLMN as PCF.
[0036] UDM 226 supports the generation of AKA authentication credentials, user identification processing (e.g., storage and management of Subscription Permanent Identifier (SUPI) for each subscriber in a 5G system), dehiding of Privacy-Preserving Subscription Hidden Identifier (SUCI), access authorization based on subscription data (e.g., roaming restrictions), UE service NF registration management (e.g., storing AMF for UE storage services, storing SMF for UE PDU sessions), service / session continuity (e.g., maintaining SMF / DNN allocation for ongoing sessions), MT-SMS delivery, lawful interception functionality (especially in outbound roaming scenarios where the UDM is the only contact point of the LI), subscription management, SMS management, 5GLAN group management processing, and / or external parameter configuration (expected UE behavior parameters or network configuration parameters). To provide these functions, UDM 226 uses subscription data (including authentication data) that can be stored in a UDR. In this case, the UDM implements application logic and may not require internal user data storage, and several different UDMs can provide services to the same user in different transactions. UDM 226 may reside in the HPLMN of its subscribers and can access information from UDRs located in the same PLMN. UDM 226 may resemble an HSS / HLR entity and host data management-related functions such as the Authentication Credentials Storehouse and Processing Function (ARPF), which in some implementations selects an authentication method based on subscriber identity and configured policies, and calculates authentication data and keys for the Authentication Server Function (AUSF).
[0037] The Subscription Identifier Decryption Function (SIDF) decrypts the SUCI to obtain its long-term identity, known as the SUPI, such as the IMSI. In 5G, the subscriber's long-term identity is transmitted in encrypted form via the radio interface. More specifically, public-key-based encryption is used to protect the SUPI. Therefore, only the SIDF has access to the private key associated with the public key assigned to the UE to encrypt its SUPI.
[0038] AF 228 interacts with the core network to provide services such as: application-driven traffic routing; access to NEF 210; interaction with policy frameworks used for policy control; and / or interaction between IMS and 5GC. Based on operator deployment, application functions trusted by the operator can be allowed to interact directly with relevant network functions. Application functions that the operator does not allow direct access to network functions can interact with relevant network functions via an external exposure framework through NEF 210.
[0039] AUSF 218 supports authentication for 3GPP access and untrusted non-3GPP access. AUSF 218 also provides support for network slicing-specific authentication and authorization. It performs authentication within the home network and with the UE. It makes decisions regarding UE authentication and can use a backend to calculate authentication data and keys when using '5G-AKA' or 'EAP-AKA'.
[0040] The AMF 220 supports the termination of the RAN CP interface (N2), the termination of the NAS (N1) for NAS encryption and integrity protection, registration management, connection management, reachability management, mobility management, lawful interception (for AMF events and interfaces to the LI system), transmission of SM messages between the UE and SMF, transparent proxy for routing SM messages, access authentication, access authorization, transmission of SMS messages between the UE and SMSF, Secure Anchoring Function (SEAF), location service management for regulated services, transmission of location service messages between the UE and LMF and between the RAN and LMF, EPS bearer ID allocation for interoperability with EPS, UE mobility event notification, control plane CIoT 5GS optimization, user plane CIoT 5GS optimization, configuration of external parameters (expected UE behavior parameters or network configuration parameters), and / or network slice-specific authentication and authorization. Some or all of the AMF functions can be supported in a single instance of the AMF220. Regardless of the number of network functions, in some implementations, only one NAS interface instance per access network between the UE and the CN terminates with one of the network functions that implements at least NAS security and mobility management. The AMF 220 may also include policy-related functions. The AMF 220 receives connection and session-related information from the user equipment (UE) (N1 / N2) to handle connection and mobility management tasks.
[0041] SEAF resides within the serving network (closely related to AMF) and acts as a "middleman" during the authentication process between the UE and its home network. It can reject authentication from the UE, but it relies on the UE's home network to accept authentication.
[0042] Non-3GPP Interoperability Function (N3IWF) is an entity that acts as a VPN server to allow UEs to access the 5G core via an IPsec tunnel through an untrusted non-3GPP network. Multiple security contexts can exist that can be established with a single authentication execution, allowing UEs to migrate from a 3GPP access network to a non-3GPP network without having to re-authenticate.
[0043] In addition to the functions described above, the AMF 220 may also include the following functions supporting non-3GPP access networks: support for the N2 interface with N3IWF / TNGF, on which some information (e.g., 3GPP cell identifier) and procedures (e.g., handover related) defined on 3GPP access may not be applicable, and non-3GPP access-specific information that is not applicable to 3GPP access can be applied; support for NAS signaling by the UE via N3IWF / TNGF, where some procedures supported by NAS signaling on 3GPP access may not be applicable to untrusted non-3GPP (e.g., paging) access; support for authentication of UEs connected via N3IWF / TNGF; management of mobility, authentication, and separate security context states for UEs connected via non-3GPP access or simultaneously via 3GPP access or non-3GPP access; support for effective coordination of RM management contexts on both 3GPP and non-3GPP access; and / or support for dedicated CM management contexts for UEs connecting via non-3GPP access. Support for all of the above functions may not be required in network slicing instances.
[0044] SMF 222 supports session management (e.g., session establishment, modification, and publication, including tunnel maintenance between UPF and AN nodes), UE IP address allocation and management (including optional authorization) (where UE IP addresses can be received from the UPF or from an external data network), DHCPv4 (server and client) and DHCPv6 (server and client) functions, the ability to respond to Address Resolution Protocol (ARP) requests and / or IPv6 neighbor request requests with local cached information based on Ethernet PDUs (e.g., the SMF responds to ARP and / or IPv6 neighbor request requests by providing the MAC address corresponding to the IP address sent in the request), selection and control of user plane functions (including controlling the UPF to proxy ARP or IPv6 neighbor discovery or forwarding all ARP / IPv6 neighbor request traffic to the SMF for Ethernet PDU sessions), traffic-directing configuration at the UPF to route traffic to the appropriate destination, and 5G VN group management (e.g., maintaining the topology of the involved PSA UPF, in the PSA...). Establish and publish N19 tunnels between UPFs, configure traffic forwarding at the UPF to apply local handover, and / or N6-based or N19-based forwarding, terminate the interface for policy control functions, lawful interception (for SM events and interfaces to the LI system), charge for data collection and support the charging interface, control and coordinate charging data collection at the UPF, terminate the SM portion of NAS messages, downlink data notification, initiator of AN-specific SM information sent to the AN via the AMF through N2, determination of the SSC mode of the session, control plane CIoT 5GS optimization, header compression, act as an I-SMF in the deployment of insertable / removable / repositionable I-SMFs, configure external parameters (expected UE behavior parameters or network configuration parameters), P-CSCF discovery for IMS services, roaming functions (e.g., handling local implementation to apply QoS). SLA (VPLMN), charging data collection and charging interface (VPLMN) and / or lawful interception (in the VPLMN for SM events and interfaces to the LI system), interaction with external DN to transmit signaling for PDU session authentication / authorization for external DN and / or instructing UPF and NG-RAN to perform redundant transmissions on the N3 / N9 interface. Some or all of the SMF functions may be supported in a single instance of the SMF. However, in some implementations, not all functions need to be supported in instances of network slices. In addition to functionality, SMF 222 may include policy-related functions.
[0045] SCP 224 includes one or more of the following functions: indirect communication; delegated discovery; message forwarding and routing to the destination NF / NF service; communication security (e.g., authorization for NF service consumers to access NF service manufacturer APIs), load balancing, monitoring, overload control, etc.; and / or optionally interacting with a UDR to resolve UDM group ID / UDR group ID / AUSF group ID / PCF group ID / CHF group ID / HSS group ID based on UE identity (e.g., SUPI or IMPI / IMPU). Some or all of the SCP functions may be supported in a single instance of the SCP. In some implementations, SCP 224 may be deployed in a distributed manner and / or more than one SCP may exist in the communication path between NF services. SCPs may be deployed at the PLMN level, shared slice level, and slice-specific level. Carrier deployments may be left to ensure that the SCP can communicate with the relevant NRF.
[0046] UE 216 may include devices with radio communication capabilities. For example, UE 216 may include a smartphone (e.g., a handheld touchscreen mobile computing device that can connect to one or more cellular networks). UE 216 may also include any mobile or non-mobile computing device, such as a personal data assistant (PDA), pager, laptop computer, desktop computer, wireless handheld device, or any computing device that includes a wireless communication interface. UE is also referred to as a client, mobile phone, mobile device, mobile terminal, user terminal, mobile unit, mobile station, mobile user, subscriber, user, remote station, access agent, user agent, receiver, radio equipment, reconfigurable radio equipment, or reconfigurable mobile device. UE 216 may include an IoT UE, which may include a network access layer designed to utilize low-power IoT applications with short-lived UE connections. The IoT UE may exchange data with an MTC server or device via a PLMN, other UEs using ProSe or D2D communication, a sensor network, or an IoT network using technologies such as M2M, MTC, or mMTC. M2M or MTC data exchange may be machine-initiated data exchange. An IoT network describes interconnected IoT UEs, which may include uniquely identifiable embedded computing devices (within the Internet infrastructure). IoT UEs may execute background applications (e.g., keeping track of activity messages, status updates, etc.) to facilitate connectivity within the IoT network.
[0047] UE 216 can be configured to connect or communicatively couple with (R)AN 206 via radio interface 230. This radio interface can be a physical communication interface or layer configured to operate using cellular communication protocols such as GSM, CDMA network protocols, keyless to reach (PTT), cellular PTT (POC), UMTS, 3GPP LTE, 5G, NR, etc. For example, UE 216 and (R)AN 206 can use a Uu interface (e.g., an LTE-Uu interface) to exchange control plane data via a protocol stack including PHY, MAC, RLC, PDCP, and RRC layers. DL transmissions can be made from (R)AN 206 to UE 216, and UL transmissions can be made from UE 216 to (R)AN 206. UE 216 can also use a sidelink to communicate directly with another UE (not shown) for D2D, P2P, and / or ProSe communication. For example, the ProSe interface may include one or more logical channels, including but not limited to the Physical Side Link Control Channel (PSCCH), Physical Side Link Shared Channel (PSSCH), Physical Side Link Discovery Channel (PSDCH), and Physical Side Link Broadcast Channel (PSBCH).
[0048] (R)AN 206 may include one or more access nodes, which may be referred to as a base station (BS), node B, evolved Node B (eNB), next-generation Node B (gNB), RAN node, controller, transport receiving point (TRP), etc., and may include ground stations (e.g., terrestrial access points) or satellite stations that provide coverage within a geographic area (e.g., a cell). (R)AN 206 may include one or more RAN nodes for providing coverage of macro cells, pico cells, femto cells, or other types of cells. Macro cells may cover a relatively large geographic area (e.g., with a radius of several kilometers) and may allow UEs to have unrestricted access with a service subscription. Pico cells may cover a relatively small geographic area and may allow UEs to have unrestricted access with a service subscription. Femto cells may cover a relatively small geographic area (e.g., a home) and may allow restricted access for UEs associated with a femto cell (e.g., a UE in a closed subscriber group (CSG), a UE of a user in a home, etc.).
[0049] Although not shown, multiple RAN nodes (such as (R)AN 206) may be used, with Xn interfaces defined between two or more nodes. In some specific implementations, the Xn interface may include an Xn user plane (Xn-U) interface and an Xn control plane (Xn-C) interface. Xn-U provides non-guaranteed delivery of user plane PDUs and supports / provides data forwarding and flow control functions. Xn-C provides management and error handling functions for managing the functionality of the Xn-C interface; mobility support for UE 216 in connected modes (e.g., CM-CONNECTED) includes functions for managing UE mobility in connected modes between one or more (R)AN nodes. This mobility support may include context transfer from the old (source) serving (R)AN node to the new (destination) serving (R)AN node; and control of user plane tunnels between the old (source) serving (R)AN node and the new (destination) serving (R)AN node.
[0050] UPF 202 can serve as an anchor point for mobility within and between RATs, an external PDU session point interconnected with DN 204, and a branch point supporting multi-homed PDU sessions. UPF 202 can also perform packet routing and forwarding, packet inspection, enforce policy rules in the user plane portion, legally intercept packets (UP collection), traffic usage reporting, perform QoS processing on the user plane (e.g., packet filtering, gating, UL / DL rate enforcement), perform uplink traffic authentication (e.g., SDF to QoS flow mapping), transport-level packet marking in uplink and downlink, and downlink packet buffering and downlink data notification triggering. UPF 202 may include an uplink classifier to support traffic routing to the data network. DN 204 may represent various network operator services, Internet access, or third-party services. DN 204 may include, for example, an application server.
[0051] Figure 3 The main authentication procedure for 5G-AKA is shown. There are two phases in '5G AKA / EAP-AKA': the initiation procedure and the authentication procedure.
[0052] During the initiation procedure, the UE sends an identifier to the SEAF in the VPLMN. The SEAF sends an authentication request to the AUSF in the HPLMMN. The AUSF provides an authorization request to the UDM / ARPF / SIDF.
[0053] The authentication process requires authentication vector generation, where AV includes RAND, authentication token (AUTN), expected response (XRES*), and K. AUSF K can be based on policies regarding the home operator using such keys. AUSF Securely stored in AUSF. AUSF according to KAUSF Export K SEAF (Anchor key) and send a challenge message to SEAF. Upon receiving RAND and AUTN, the Universal User Identity Module (USIM) calculates the response RES and returns RES, CK, and IK to the UE. The Mobile Equipment (ME) calculates RES* based on RES and sends it back. SEAF calculates HRES* based on RES* and compares HRES* with HXRES*. If successful, it forwards RES* to AUSF. AUSF compares the received RES* with the stored XRES*; if successful, authentication is successful and AUSF instructs SEAF.
[0054] UE generates K itself AUSF If the UE is a true UE, then it can generate the correct K. AUSF This is consistent with the K generated by the network (UDM / ARPF). AUSF Same. Regarding K AUSF The detailed information generated is provided in Clause 6.1.3.2.0 of 3GPP TS 33.501, whereby the UE generates K after receiving the necessary parameters from the network. AUSF .
[0055] Figure 4 The key hierarchy structure in 5G is shown. K AUSF It is universal between the UE and AUSF in the home network and forms the basis for subsequent key hierarchy structures. K AUSF It was not delivered, but was generated separately by the UE and the network. Since the UE and the network have the same root key, they generate the same K. AUSF Calculate K AUSF The required parameters are delivered from the network to the UE.
[0056] Figure 5 Architecture 500 for enabling edge applications is shown, as described in 3GPP TS 23.558. The Edge Data Network (EDN), i.e., EDN 502, is the local data network. The Edge Application Server (EAS), i.e., EAS 504, and the Edge Enabler Server (EES) 506 are contained within EDN 502. The Edge Configuration Server (ECS), i.e., ECS 508, provides configuration related to EES 506, including details of EDN 502 hosting EES 506. UE 510 includes an application client 512 and an Edge Enabler Client (EEC), i.e., EEC 514. EAS 504, EES 506, and ECS 508 can interact with the 3GPP core network 516.
[0057] ECS 508 provides the support functions required for EEC 514 to connect to EES 506. ECS 508's functions include allocating edge configuration information to EEC 514. This edge configuration information includes: information for EEC 514 to connect to EES 506, such as service area information applicable to Local Area Data Networks (LADN); and information for establishing a connection with EES 506, such as Uniform Resource Identifiers (URIs).
[0058] EEC 514 provides the support functions required by application clients. The functions of EEC 514 include: retrieving and configuring configuration information to enable the exchange of application data traffic with EAS 504; and discovering EAS 504 as provided in EDN 502.
[0059] The EEC ID is a globally unique value that identifies an EEC. One or more EECs can reside in the UE.
[0060] SA6 3GPP TS 23.558 also outlines the following specifications: The application layer architecture supports the use of 3GPP credentials, application-specific credentials, or both, for communication between the UE and functional entities providing edge computing services, depending on the deployment requirements. The application layer architecture supports mutual authentication and authorization checks between clients and servers, or between servers and interacting servers. Such procedures are not yet present in the SA6 specification. This disclosure proposes an authentication and authorization method between EEC 514 and ECS 508.
[0061] The certification and authorization between EEC and ECS are proposed in 3GPP TR 33.839. Figure 6 The SA3 call flow authentication and authorization 600 between EEC 602 and ECS 604 is illustrated. Those skilled in the art will understand that similar functionality can be performed between EEC 602 and EES, but for the sake of brevity, only ECS 604 (not EES) is described below.
[0062] Initially, UE 606 performs primary authentication 608 using the network. Then, K is shared between UE 606 and AUSF610 in the home network. AUSF .
[0063] UE 606 uses K AUSF Generate 612 voucher K with SUPI 边缘 (K edge ) and K 边缘 ID, and K 边缘 and K 边缘 The ID is stored securely. The following discussion focuses on K. 边缘 and K 边缘 ID generation.
[0064] AUSF 610 uses K AUSF Generate 614 voucher K with SUPI 边缘 and K 边缘 ID, and K 边缘 and K 边缘 The ID is stored securely.
[0065] EEC 602 obtains 616K 边缘 and K 边缘 Therefore, UE 606 provides a secure interface to transmit the K ID. 边缘 and K 边缘 ID.
[0066] EEC 602 uses K 边缘 Calculate 618MAC using EEC ID EEC Using input K 边缘 Calculate MEC using SHA256 of EEC ID EEC .
[0067] UE 606 sends a 620 application registration request (EEC ID, MAC address) to ECS 604. EEC K 边缘 (ID). Whether the message is sent using NAS or the user plane is optional.
[0068] ECS 604 sends 622 authentication verification (EEC ID, MAC address) to NEF 624. EEC K 边缘 (ID) is used for verification.
[0069] NEF 624 sends 626 authentication verification (EEC ID, MAC address) to UDM 628. EEC K 边缘 ID) for MAC EEC verify.
[0070] AUSF 610 uses K 边缘 ID search 630K 边缘 And using K 边缘 Verify MAC with EEC ID EEC .
[0071] If AUSF 610 authentication is successful, AUSF 610 will send an authentication verification response (success) to NEF 624 via 632; otherwise, AUSF 610 will send an authentication verification response (failure) to NEF 624.
[0072] NEF 624 sends a 634 authentication verification response (success / failure) from UDM 628 to ECS 604.
[0073] Based on the verification results, ECS 604 decides whether to accept or reject the authentication request and sends an authentication request 636 to EEC602 in UE 606 to accept / reject the authentication request.
[0074] K 边缘 It was generated using the Key Derivation Function (KDF) defined in Appendix B of 3GPP TS 33.220 (V17.0.0), and Appendix B is incorporated herein by reference. Based on K... AUSF Export K 边缘 When using this parameter, the following parameters should be used to form the input string S of the KDF: FC = xxxx, which is assigned by the 3GPP specification (B 2.2 in Appendix B of TS 33.220); P0 = <supi> ;L0= <supi>The length of the input key, i.e., the key should be K. AUSF K 边缘 The ID is generated by AUSF and uniquely identifies a K. 边缘 The new MEC number needs to be reassigned by 3GPP, and TS 33.220 B2.2 should be modified accordingly.
[0075] Figure 7 It shows K 边缘 Table 700 shows examples of information in the ID. However, it is important to note initially that K... 边缘 The ID is independent of any specific authentication method; K is used in many authentication solutions within SA3. 边缘 ID. In other words, K 边缘 The ID can be used for other authentication methods. In some implementations, K 边缘 The ID deployment is as follows: (1) K 边缘 An ID can uniquely identify a K. 边缘 The UE can support multiple edge services, therefore it can have multiple K... 边缘 and K 边缘 (2) In the authentication process, the ECS can coordinate with the AUSF to authenticate whether the UE has passed the primary authentication, and then the ECS can utilize K 边缘 ID routing to the correct AUSF. There may be other methods to find the correct AUSF, using K. 边缘 ID is one of them, and this method does not require adding other IEs in the UE's registration request to the ECS. (3) Using only K 边缘 ID, attackers cannot deduce or calculate K. 边缘 .
[0076] Figure 7 K is shown 边缘 An ID may include a route, a service identifier, and a unique component. Each component is explained below. (The " / " in the diagram represents "or," meaning that some or all of the following elements may be used in various implementations.)
[0077] Routing section 702 is designed to identify the correct AUSF or NEF. Routing section 702 is based on one or more of the SUPI, the Common Public Subscription Identifier (GPSI), and the Public Land Mobile Network (PLMN) ID.
[0078] Service Identifier Section 704 is intended for the identification of edge services. Service Identifier Section 704 is based on one or more of the EEC ID, EASID, and EAS Provider Identifier.
[0079] The uniqueness section 706 is designed to ensure that when the routing section and the service identifier section are the same, K 边缘 IDs will not conflict. Random numbers can be generated by a pseudo-random number generator (PRNG).
[0080] In other implementation schemes, Figure 7 The order of the three parts shown can be different. K 边缘 The length of the ID does not need to be strictly limited, as it is a function of the length of the variable EEC ID / EAS ID / EAS provider ID.
[0081] Figure 8 This illustrates a routine 800 performed by a UE configured to communicate in a 5G network, performing authentication and authorization between the UE's EEC and ECS. In block 802, routine 800 utilizes the 5G network to perform primary authentication to obtain K. AUSF In box 804, routine 800 uses K. AUSF And SUPI to generate K 边缘 and K 边缘 In box 806, routine 800 provides the K to the EEC. 边缘 and K 边缘 ID, so that it can use K 边缘 Calculate MAC with EEC ID EEC In box 808, routine 800 sends an application registration request to the ECS. This application registration request includes the EEC ID and MAC address. EEC and K 边缘 ID.
[0082] Routine 800 may optionally include sending a Non-Access Stratum (NAS) or User Plane message that includes an application registration request.
[0083] Routine 800 may optionally include accepting or rejecting authentication requests received from the ECS.
[0084] Example 800 may optionally include generating K from a key derivation function (KDF). 边缘 The input string S of KDF includes FC, P0 and L0 parameters, where the FC parameter is predetermined (e.g., assigned according to the 3GPP specification in Appendix B), the P0 parameter is equal to SUPI, and L0 is equal to the length of SUPI.
[0085] Example 800 may optionally include a unique identifier for a K. 边缘 K 边缘 ID.
[0086] Routine 800 may optionally include a K with a routing section for locating AUSF or NEF. 边缘 ID. Example 800 may optionally include a routing portion based on one or more of the SUPI, GPSI, and PLMN IDs.
[0087] Routine 800 may optionally include a K with a service identifier portion for identifying edge services. 边缘 ID. Example 800 may optionally include a service identifier portion based on one or more of the EEC ID, EAS ID, and EAS provider identifier.
[0088] Routine 800 may optionally include K 边缘 ID, which has a unique part to ensure K 边缘 ID will not be associated with another K 边缘 ID conflict. In one implementation, K 边缘 The ID is a pseudo-random number.
[0089] Figure 9 A system 900 for executing signaling 934 between a wireless device 902 and a network device 918 according to an embodiment disclosed herein is shown. System 900 may be part of a wireless communication system as described herein. Wireless device 902 may be, for example, a UE (User Equipment) of a wireless communication system. Network device 918 may be, for example, a base station (e.g., an eNB or gNB) of a wireless communication system.
[0090] Wireless device 902 may include one or more processors 904. Processor 904 may execute instructions to perform various operations of wireless device 902 as described herein. Processor 904 may include one or more baseband processors implemented using, for example, a central processing unit (CPU), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a controller, a field-programmable gate array (FPGA) device, another hardware device, a firmware device, or any combination thereof configured to perform the operations described herein.
[0091] Wireless device 902 may include memory 906. Memory 906 may be a non-transitory computer-readable storage medium that stores instructions 908, which may include, for example, instructions executed by processor 904. Instructions 908 may also be referred to as program code or computer program. Memory 906 may also store data used by processor 904 and results calculated by processor.
[0092] Wireless device 902 may include one or more transceivers 910, which may include radio frequency (RF) transmitter and / or receiver circuitry that uses antenna 912 of wireless device 902 to facilitate the transmission or receipt of signaling (e.g., signaling 934) between wireless device 902 and other devices (e.g., network device 918) in accordance with a corresponding RAT.
[0093] Wireless device 902 may include one or more antennas 912 (e.g., one, two, four, or more). In embodiments with multiple antennas 912, wireless device 902 can fully utilize the spatial diversity of these multiple antennas 912 to transmit and / or receive multiple different data streams on the same time-frequency resource. This practice may be referred to, for example, as a multiple-input multiple-output (MIMO) approach (referring to multiple antennas used separately on the transmitting and receiving sides to implement this aspect). MIMO transmissions performed by wireless device 902 can be achieved according to precoding (or digital beamforming) applied to wireless device 902, which multiplexes data streams among antennas 912 based on known or assumed channel characteristics, such that each data stream is received with appropriate signal strength relative to the other streams at a desired location in the spatial domain (e.g., the location of the receiver associated with that data stream). Some implementations may use a single-user MIMO (SU-MIMO) method (where the entire data stream is directed to a single receiver) and / or a multi-user MIMO (MU-MIMO) method (where individual data streams may be directed to individual (different) receivers at different locations in the airspace).
[0094] In some implementations with multiple antennas, the wireless device 902 may implement analog beamforming technology, whereby the phase of the signal transmitted by the antenna 912 is relatively adjusted, making the (joint) transmission of the antenna 912 directional (this is sometimes referred to as beam control).
[0095] Wireless device 902 may include one or more interfaces 914. Interfaces 914 can be used to provide input to or from wireless device 902. For example, wireless device 902 as a UE may include interfaces 914, such as a microphone, speaker, touchscreen, buttons, etc., to allow users of the UE to input to and / or output to the UE. Other interfaces of such UEs may consist of transmitters, receivers, and other circuitry (e.g., in addition to the transceiver 910 / antenna 912 already described), allowing the UE to communicate with other devices and according to known protocols (e.g., ...). (etc.) to perform the operation.
[0096] Wireless device 902 may include authentication / authorization module 916. Authentication / authorization module 916 may be implemented via hardware, software, or a combination thereof. For example, authentication / authorization module 916 may be implemented as a processor, circuitry, and / or instructions 908 stored in memory 906 and executed by processor 904. In some examples, authentication / authorization module 916 may be integrated within processor 904 and / or transceiver 910. For example, authentication / authorization module 916 may be implemented via a combination of software components (e.g., executed by a DSP or general-purpose processor) and hardware components (e.g., logic gates and circuitry) within processor 904 or transceiver 910.
[0097] The authentication / authorization module 916 can be used in various aspects of this disclosure, for example, Figures 2 to 8 This applies to various aspects. For example, the authentication / authorization module 916 is configured to execute KDF or routine 800.
[0098] Network device 918 may include one or more processors 920. Processor 920 may execute instructions to perform various operations of network device 918 as described herein. Processor 904 may include one or more baseband processors, which are implemented using, for example, a CPU, DSP, ASIC, controller, FPGA device, another hardware device, firmware device, or any combination thereof configured to perform the operations described herein.
[0099] Network device 918 may include memory 922. Memory 922 may be a non-transitory computer-readable storage medium that stores instructions 924, which may include, for example, instructions executed by processor 920. Instructions 924 may also be referred to as program code or computer program. Memory 922 may also store data used by processor 920 and results calculated by processor.
[0100] Network device 918 may include one or more transceivers 926, which may include RF transmitter and / or receiver circuitry that uses the antenna 928 of network device 918 to facilitate the transmission or receipt of signaling (e.g., signaling 934) between network device 918 and other devices (e.g., wireless device 902) in accordance with a corresponding RAT.
[0101] Network device 918 may include one or more antennas 928 (e.g., one, two, four or more). In embodiments with multiple antennas 928, network device 918 may perform MIMO, digital beamforming, analog beamforming, beam control, etc., as described above.
[0102] Network device 918 may include one or more interfaces 930. Interface 930 may be used to provide input to or output to network device 918. For example, network device 918 as a base station may include interface 930 consisting of transmitters, receivers and other circuitry (e.g., in addition to the transceiver 926 / antenna 928 described), enabling the base station to communicate with other equipment in the core network and / or enabling the base station to communicate with external networks, computers, databases, etc., for the purpose of operating, managing and maintaining the base station or other equipment operablely connected to it.
[0103] Network device 918 may include authentication / authorization module 932. Authentication / authorization module 932 may be implemented via hardware, software, or a combination thereof. For example, authentication / authorization module 932 may be implemented as a processor, circuitry, and / or instructions 924 stored in memory 922 and executed by processor 920. In some examples, authentication / authorization module 932 may be integrated within processor 920 and / or transceiver 926. For example, authentication / authorization module 932 may be implemented via a combination of software components (e.g., executed by a DSP or general-purpose processor) and hardware components (e.g., logic gates and circuitry) within processor 920 or transceiver 926.
[0104] The authentication / authorization module 932 can be used in various aspects of this disclosure, for example, Figures 2 to 8 All aspects. For example, the authentication / authorization module 932 is configured to perform... Figure 2 and Figure 6 The aspects of SEAF, AUSF, UDM, or NEF shown.
[0105] The following examples relate to other implementation schemes.
[0106] Example 1 may include an apparatus comprising means for performing one or more elements of a method or process described or associated with any of the methods or processes described herein.
[0107] Embodiment 2 may include one or more non-transitory computer-readable media, the one or more non-transitory computer-readable media including instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements of the method or any other method or process described herein, as described in any of the foregoing embodiments or related to them.
[0108] Example 3 may include an apparatus comprising logic components, modules, or circuitry for performing one or more elements of the methods described or associated with any of the above embodiments or any other methods or processes described herein.
[0109] Example 4 may include any method, technique, or process, or part or component thereof, that is described in or related to any of the above examples.
[0110] Embodiment 5 may include an apparatus comprising one or more processors and one or more computer-readable media, the one or more computer-readable media including instructions that, when executed by the one or more processors, cause the one or more processors to perform any of the methods, techniques, or processes or portions thereof described or associated with any of the above embodiments.
[0111] Example 6 may include any of the signals or parts or components described or associated with any of the above examples.
[0112] Embodiment 7 may include datagrams, packets, frames, segments, protocol data units (PDUs) or messages or parts or components thereof as described in or related to any of the above embodiments, or otherwise described in this disclosure.
[0113] Embodiment 8 may include a data-encoded signal or part or component thereof described or associated with any of the above embodiments, or otherwise described in this disclosure.
[0114] Embodiment 9 may include signals or portions or components thereof encoded as datagrams, packets, frames, segments, PDUs or messages as described in any of the above embodiments or in connection with them, or otherwise described in this disclosure.
[0115] Example 10 may include an electromagnetic signal carrying computer-readable instructions, wherein execution of the computer-readable instructions by one or more processors will cause the one or more processors to perform any of the methods, techniques, or processes or portions thereof described in or related to any of the above examples.
[0116] Example 11 may include a computer program comprising instructions, wherein execution of the program by a processing element will cause the processing element to perform any of the methods, techniques, or processes or portions thereof described in or associated with any of the above embodiments.
[0117] Example 12 may include signals in a wireless network as shown and described herein.
[0118] Example 13 may include methods for communicating in a wireless network as shown and described herein.
[0119] Example 14 may include a system for providing wireless communication as shown and described herein.
[0120] Example 15 may include a device for providing wireless communication as shown and described herein.
[0121] Unless otherwise expressly stated, any of the above embodiments may be combined with any other embodiment (or combination of embodiments). The foregoing description of one or more specific embodiments provides illustration and description, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise forms disclosed. In view of the teachings above, modifications and variations are possible, or modifications and variations may be obtained from the practice of various embodiments.
[0122] Implementations and specific embodiments of the systems and methods described herein may include various operations embodied in machine-executable instructions to be executed by a computer system. The computer system may include one or more general-purpose or special-purpose computers (or other electronic devices). The computer system may include hardware components, including specific logical components for performing the operations, or may include a combination of hardware, software, and / or firmware.
[0123] It should be recognized that the systems described herein include descriptions of specific implementations. These implementations may be combined into a single system, partially integrated into other systems, divided into multiple systems, or otherwise partitioned or combined. Furthermore, it is conceivable to use parameters, attributes, aspects, etc., of one implementation in another implementation. For clarity, these parameters, attributes, aspects, etc., are described only in one or more implementations, and it should be recognized that unless specifically stated herein, these parameters, attributes, aspects, etc., may be combined with or substituted for parameters, attributes, aspects, etc., of another implementation.
[0124] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.
[0125] For one or more embodiments, at least one of the components shown in one or more of the foregoing figures may be configured to perform one or more of the operations, techniques, processes, and / or methods described herein. For example, the baseband circuitry described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples below. As another example, the circuitry associated with the UE, base station, network element, etc., described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples shown below.
[0126] Although the foregoing has been described in considerable detail for clarity, it will be apparent that certain changes and modifications can be made without departing from the principles of the invention. It should be noted that many alternative ways exist to implement both the processes and apparatus described herein. Therefore, embodiments of the invention should be considered illustrative rather than restrictive, and this specification is not limited to the details given herein, but can be modified within the scope of the appended claims and their equivalents.< / supi> < / supi>
Claims
1. A method for authentication and authorization between an edge enabler client (EEC) and an edge configuration server (ECS) of a user equipment (UE) configured to communicate in a 5G network, the method comprising: Performing primary authentication using the 5G network to obtain K AUSF ; Using the K AUSF And subscribe to the permanent identifier SUPI to generate K 边缘 and K 边缘 Identifier ID, wherein K 边缘 The ID includes a service identifier portion used to identify edge services; Provide the K to the EEC 边缘 and the K 边缘 ID, so that it uses the K 边缘 Calculate MAC with EEC ID EEC ; as well as Send an application registration request to the ECS, the application registration request including the EEC ID and the MAC address. EEC and the K 边缘 ID.
2. The method of claim 1, wherein the sending includes sending a Non-Access Stratum (NAS) message.
3. The method of claim 1, wherein the sending includes sending a user plane message.
4. The method according to claim 1, further comprising receiving an authentication request acceptance or rejection from the ECS.
5. The method according to claim 1, further comprising generating the K based on the key derivation function KDF. 边缘 The input string S of the KDF includes FC parameters, P0 parameters and L0 parameters. The FC parameters are allocated according to the 3GPP specification, the P0 parameters are equal to the SUPI, and the L0 parameters are equal to the length of the SUPI.
6. The method according to claim 1, wherein K 边缘 ID uniquely identifies a K 边缘 .
7. The method according to claim 1, wherein K 边缘 The ID includes the routing portion used to locate the Authentication Server Function (AUSF) or the Network Exposure Function (NEF).
8. The method of claim 7, wherein the routing portion is based on one or more of the SUPI, the General Public Subscription Identifier (GPSI), and the Public Land Mobile Network (PLMN) ID.
9. The method of claim 1, wherein the service identifier portion is based on one or more of the EEC ID, the Edge Application Server (EAS) ID, and the EAS provider identifier.
10. The method of claim 1, wherein K 边缘 The ID includes a unique component to ensure that the K 边缘 ID will not be associated with another K 边缘 ID conflict.
11. The method of claim 10, wherein the unique portion is a pseudo-random number.
12. A non-transitory computer-readable storage medium for a user equipment (UE) configured to communicate in a 5G network and perform authentication and authorization between an edge enabler client (EEC) and an edge configuration server (ECS) of the UE, the computer-readable storage medium comprising instructions that, when executed by the UE, cause the UE to: Performing primary authentication using the 5G network to obtain K AUSF ; Using the K AUSF And subscribe to the permanent identifier SUPI to generate K 边缘 and K 边缘 Identifier ID, wherein K 边缘 The ID includes a service identifier portion used to identify edge services; Provide the K to the EEC 边缘 and the K 边缘 ID, so that it uses the K 边缘 Calculate MAC with EEC ID EEC ; as well as Send an application registration request to the ECS, the application registration request including the EEC ID and the MAC address. EEC and the K 边缘 ID.
13. The computer-readable storage medium of claim 12, wherein the instructions further configure the UE to send a non-access stratum (NAS) message including the application registration request.
14. The computer-readable storage medium of claim 12, wherein the instructions further configure the UE to send a user plane message including the application registration request.
15. The computer-readable storage medium of claim 12, wherein the instructions further configure the UE to receive an authentication request acceptance or rejection from the ECS.
16. The computer-readable storage medium of claim 12, wherein the instructions further configure the UE to generate the K according to the key derivation function KDF. 边缘 The input string S of the KDF includes FC parameters, P0 parameters and L0 parameters. The FC parameters are allocated according to the 3GPP specification, the P0 parameters are equal to the SUPI, and the L0 parameters are equal to the length of the SUPI.
17. The computer-readable storage medium of claim 12, wherein the K 边缘 ID uniquely identifies a K 边缘 .
18. The computer-readable storage medium of claim 12, wherein the K 边缘 The ID includes the routing portion used to locate the Authentication Server Function (AUSF) or the Network Exposure Function (NEF).
19. The computer-readable storage medium of claim 18, wherein the routing portion is based on one or more of the SUPI, the General Public Subscription Identifier (GPSI), and the Public Land Mobile Network (PLMN) ID.
20. The computer-readable storage medium of claim 12, wherein the service identifier portion is based on one or more of the EEC ID, the Edge Application Server (EAS) ID, and the EAS provider identifier.
21. The computer-readable storage medium of claim 12, wherein the K 边缘 The ID includes a unique component to ensure that the K 边缘 ID will not be associated with another K 边缘 ID conflict.
22. The computer-readable storage medium of claim 21, wherein the unique portion is a pseudo-random number.