Authentication and key management for roaming using applications

By introducing the V-AAnF function, an AKMA security context is provided for data transmission between the UE and AF, which solves the problem that legal eavesdropping cannot be performed in the VPLMN in the existing specifications, and realizes the security protection of data traffic.

CN118020330BActive Publication Date: 2025-11-07LENOVO (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280064595.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-29
Filing Date
2022-10-31
Publication Date
2025-11-07
Estimated Expiration
2042-10-31

AI Technical Summary

Technical Problem

The existing 3GPP TS 33.535 specification lacks roaming features, which makes it impossible to perform lawful interception (LI) in the visited public land mobile network (VPLMN) in a wireless network, and thus cannot effectively protect the data traffic security between the UE and the application function (AF).

Method used

The AKMA Anchor Function (V-AAnF) is introduced to provide AKMA security context when establishing a secure tunnel between the UE and AF, and to receive and relay key materials through V-AAnF to support legitimate eavesdropping.

Benefits of technology

This implementation enables legitimate monitoring of data traffic between the UE and AF in the VPLMN, ensuring data security and resolving the issue that LI cannot be executed in roaming scenarios in existing specifications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118020330B_ABST
    Figure CN118020330B_ABST
Patent Text Reader

Abstract

Devices, methods, and systems are disclosed for enabling roaming using authentication and key management for applications. A device (800) includes a processor (805) that determines a serving network of a user equipment ("UE") device, the serving network comprising a visited public land mobile network ("VPLMN") that is different from a home PLMN ("HPLMN") associated with the UE. The processor (805) selects a network function within the serving network for providing an authentication and key management ("AKMA") security context for an application function ("AF") based on a name of the serving network. The device (800) includes a transceiver (825) that sends the security context to the network function.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross Reference to Related Applications

[0002] This application claims priority to U.S. Patent Application No. 17 / 515,238, entitled “ENABLING ROAMING WITH AUTHENTICATION AND KEY MANAGEMENT FOR APPLICATIONS,” by Andreas Kunz et al., filed October 29, 2021, the entirety of which is incorporated by reference herein. TECHNICAL FIELD

[0003] The subject matter disclosed herein relates generally to wireless communications, and more particularly to enabling roaming with authentication and key management for applications. BACKGROUND

[0004] In a wireless network, data traffic between a UE not co-located in the same network and an application function (“AF”) is secured using authentication and key management for applications (“AKMA”) features. As a result, lawful interception cannot be performed. SUMMARY

[0005] A procedure is disclosed for enabling roaming with authentication and key management for applications. The procedure can be implemented by a device, system, method, and / or computer program product.

[0006] In one embodiment, a first device includes a processor that determines a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) that is different from a home PLMN (“HPLMN”) associated with the UE. In one embodiment, the processor selects a network function within the serving network for providing an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network. In one embodiment, the first device includes a transceiver that sends the security context to the network function.

[0007] In one embodiment, a first method includes determining a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE. In one embodiment, the first method includes selecting a network function within the serving network for providing an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network. In one embodiment, the first method includes sending the security context to the network function.

[0008] In one embodiment, a second apparatus includes a transceiver that receives a key request at a network function of a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE, the key registration request for providing an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network for establishing a connection between the UE and the AF. In one embodiment, the transceiver sends a key response to a network function of the HPLMN.

[0009] In one embodiment, a second method includes receiving a key request at a network function of a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE, the key registration request for providing an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network for establishing a connection between the UE and the AF. In one embodiment, the second method includes sending a key response to a network function of the HPLMN. BRIEF DESCRIPTION OF DRAWINGS

[0010] More specific descriptions of the embodiments briefly described above will be rendered by reference to specific embodiments thereof that are illustrated in the appended drawings. Understanding that these drawings depict only some embodiments and are not therefore to be considered to be limiting of its scope, the embodiments will be described and explained with additional specificity and detail through the use of the accompanying drawings in which:

[0011] Figure 1 is a schematic block diagram illustrating one embodiment of a wireless communication system for roaming using authentication and key management for applications;

[0012] Figure 2 depicts a process flow for key provisioning to a V-AAnF at an application session establishment request;

[0013] Figure 3 Process flow depicting key provisioning for V-AAnF at AKMA key generation;

[0014] Figure 4 Process flow depicting key provisioning for V-AAnF after AF provisioning;

[0015] Figure 5 Process flow depicting provisioning of service network name;

[0016] Figure 6 Process flow depicting provisioning of service network name and V-AAnF selection;

[0017] Figure 7 is a block diagram illustrating one embodiment of a user equipment device that can be used to implement roaming using application authentication and key management;

[0018] Figure 8 is a block diagram illustrating one embodiment of a network device that can be used to implement roaming using application authentication and key management;

[0019] Figure 9 is a flow diagram illustrating one embodiment of a method for implementing roaming using application authentication and key management; and

[0020] Figure 10 is a flow diagram illustrating one embodiment of another method for implementing roaming using application authentication and key management. DETAILED DESCRIPTION

[0021] As will be appreciated by those skilled in the art, aspects of the embodiments can be embodied as a system, device, method or program product. Accordingly, aspects of the embodiments can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.) or an embodiment combining software and hardware aspects that can all generally be referred to herein as a "circuit," "module" or "system."

[0022] For example, disclosed embodiments can be implemented as hardware circuitry, including custom very-large-scale integration ("VLSI") circuits or gate arrays, off-the-shelf semiconductors such as logic chips, transistors, or other discrete components. Disclosed embodiments can also be implemented in programmable hardware devices such as field programmable gate arrays, programmable array logic, programmable logic devices or the like. As another example, disclosed embodiments can include one or more physical or logical blocks of executable code, which can be organized as an object, procedure or function.

[0023] Furthermore, embodiments can take the form of a program product embodied in one or more computer-readable storage devices having stored thereon computer-readable code (hereinafter referred to as code). The storage devices can be tangible, non-transitory, and / or non-transmission. The storage devices can not embody signals. In a certain embodiment, the storage devices only employ signals for accessing code.

[0024] Any combination of one or more computer-readable media can be utilized. The computer-readable media can be computer-readable storage media. The computer-readable storage media can be storage devices. Storage devices can be, for example, but not limited to, electronic, magnetic, optical, electromagnetic, infrared, holographic, micromechanical, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing.

[0025] More specific examples (a non-exhaustive list) of the storage device would include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory ("RAM"), a read-only memory ("ROM"), an erasable programmable read-only memory ("EPROM" or Flash memory), a portable compact disc read-only memory ("CD-ROM"), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of this document, a computer-readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device.

[0026] Code for carrying out operations for embodiments can be any number of lines and can be written in any combination of one or more programming languages, including an object- oriented programming language (e.g., Python, Ruby, Java, Smalltalk, C++, or the like), and conventional procedural programming languages (e.g., "C" programming language or the like), and / or machine languages (e.g., assembly languages). The code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network ("LAN"), wireless LAN ("WLAN"), or a wide area network ("WAN"), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider ("ISP")). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, application specific circuitry, or field programmable gate array ("FPGA") or system on a chip ("SOC") circuitry can execute the code. The code can also be stored in any other non-transitory, tangible, computer-readable storage medium, including a storage device in a server or other computing system.

[0027] Furthermore, the described features, structures, or characteristics of the embodiments can be combined in any suitable manner. In the following description, numerous specific details are provided, such as examples of programming, software modules, user selections, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., to provide a thorough understanding of the embodiments. One skilled in the relevant art will recognize, however, that the embodiments can be practiced without one or more of the specific details, or with other methods, components, materials, and so forth. In other instances, well-known structures, materials, or operations are not shown or described in detail in order to avoid obscuring aspects of the embodiments.

[0028] Reference throughout this specification to "an embodiment", "one embodiment", or similar language means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Thus, appearances of the phrases "in one embodiment", "in an embodiment", and similar language throughout this specification may, but do not necessarily, all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise explicitly stated. The terms "including", "comprising", "having" and variations thereof mean "including but not limited to", unless expressly specified otherwise. Enumerated lists of items do not imply any or all items are mutually exclusive, unless expressly specified otherwise. The terms "a", "an" and "the" also mean "one or more", unless expressly specified otherwise.

[0029] As used herein, a list with the conjunction "and / or" includes any single item in the list or a combination of items in the list. For example, a list of A, B and / or C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B and C. As used herein, a list using the terminology "one or more of' includes any single item in the list or a combination of items in the list. For example, one or more of A, B and C includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C, or a combination of A, B and C. As used herein, a list using the terminology "one of' includes one and only one of any single item in the list. For example, "one of A, B and C" includes only A, only B or only C, and excludes combinations of A, B and C. As used herein, "a member selected from the group consisting of A, B and C" includes one and only one of A, B or C, and excludes combinations of A, B and C. As used herein, "a member selected from the group consisting of A, B and C and combinations thereof includes only A, only B, only C, a combination of A and B, a combination of B and C, a combination of A and C or a combination of A, B and C.

[0030] The computer program product can have the code stored in a computer readable storage medium (or media) having a plurality of program-as instructions executable by a processor for implementing the functions / acts specified in the illustrative embodiments. Accordingly, various embodiments provide a computer program product, comprising a computer-readable medium having stored thereon, a computer program (that can include machine executable code) configured to be executed by a processor so as to perform the functions / acts specified in the illustrative embodiments.

[0031] The code can also be stored in a storage device that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the storage device produce an article of manufacture including instructions which implement the function / act specified in the flowchart diagrams and / or block diagrams.

[0032] The code can also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the code which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart diagrams and / or block diagrams.

[0033] The flow diagrams and / or block diagrams in the drawings are used to describe architectures, functionality, and operations of various embodiments. In this regard, each block in the flow diagrams and / or block diagrams can represent a module, segment, or portion of code which comprises one or more executable instructions for implementing the specified logical functions ("instructions"). It should also be noted that in some alternative implementations, the functions noted in the box can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. Other steps and methods can be conceived that are equivalent in function, logic, or effect to those illustrated, with the noted exceptions.

[0034] It should be borne in mind, however, that these flow diagrams and / or block diagrams and their associated data structures are merely means for teaching one skilled in the art about the methods and / or apparatuses described herein. They should not be interpreted in a limiting sense.

[0035] While various arrow types and line types can be employed in the flowchart diagrams and / or block diagrams, they are employed for purposes of demonstrating the illustrative embodiments. One having ordinary skill in the art will appreciate that some of the steps or methods can take place concurrently, be executed in a different order than depicted in the examples, or may, in fact, be performed in reverse order, depending on the functionality involved. Accordingly, embodiments are not limited to a particular order or arrangement of steps, methods, or algorithms.

[0036] In each figure, the description of elements can refer to elements of a previous figure. In all figures, like numbers refer to like elements throughout. Alternative embodiments of like elements can share like numbering. In each figure, the description of elements can refer to elements of a previous figure. In all figures, like numbers refer to like elements throughout. Alternative embodiments of like elements can share like numbering. In each figure, the description of elements can refer to elements of a previous figure. In all figures, like numbers refer to like elements throughout. Alternative embodiments of like elements can share like numbering.

[0037] Generally, the present disclosure describes systems, methods, and devices for enabling roaming using authentication and key management for applications. In certain embodiments, the methods can be performed using computer code embodied on a computer-readable medium. In certain embodiments, a device or system can include a computer-readable medium containing computer-readable code, which, when executed by a processor, causes the device or system to perform at least a portion of the solutions described below.

[0038] Current specification 3GPP TS 33.535 (Release 17) on Authentication and Key Management (“AKMA”) for Applications Based on 3GPP Credentials in 5G System (“5GS”) lacks the feature of roaming. Clause 4.4.0, “Overview,” covers the following note— “Aspects of roaming are not considered in this document.” Furthermore, the problem is raised and described in the Lawful Interception (“LI”) specification group SA3-LI in document S3i200477:

[0039] “Like GBA (TS 33.220) for 3G / 4G, AKMA derives security keys from the USIM application by creating an encrypted tunnel between the ME and a point outside the VPLMN (e.g., a point in the HPLMN or at an external OTT service provider), which in most cases can be used for encryption across the VPLMN. In both cases, without further technical means, it prevents LI from occurring in the VPLMN as required. There is a LI requirement to provide law enforcement means with decrypted or decrypted traffic for encryption that has been involved at establishment time for the MNO. This requirement applies to mechanisms like AKMA, where the MNO is involved in establishing and distributing key material for encryption. Furthermore, when roaming, LI needs to be able to perform independently in each of the involved jurisdictions. In particular, activation of LI in the VPLMN needs to be performed without explicit support from the HPLMN (otherwise it would reveal that the inbound roamer is a target of LI in the VPLMN).

[0040] Due to the nature of AKMA in current standard specifications (e.g., 3GPP TS 33.535), in one embodiment, the UE always establishes a secure tunnel to the Application Function (“AF”), regardless of where it is located, and the Visited Public Land Mobile Network (“VPLMN”) has no opportunity to perform LI on the traffic.

[0041] In one embodiment, the subject matter disclosed herein relates to a UE that provides a service network name (“SN”) to an application function (“AF”) in an application session establishment request in order to route a key request to a VPLMN. In one embodiment, the AF discovers a network exposure function (“NEF”) in the VPLMN based on the SN and sends an AKMA K AF request to a visited AKMA anchor function (“V-AAnF”) via the NEF. In one embodiment, the V-AAnF detects a home public land mobile network (“HPLMN”) based on the realm of the A-KID and selects an AAnF and sends an AKMA K AF request to the AAnF in the HPLMN. In one embodiment, the AAnF in the HPLMN validates the request and generates a K AF , K AF expiry time (KAFexptime) and potentially other parameters to the V-AAnF.

[0042] In one embodiment, the subject matter disclosed herein includes an authentication server function (“AUSF”) and a UE that use the SN as the realm of the A-KID. In one embodiment, the AUSF selects a V-AAnF or an AMF based on the SN of the UE and provides an AKMA security context to the V-AAnF or AMF in the serving network. In one embodiment, the AF in the serving network sends an AKMA K AF request to a NEF in the serving network based on the realm of the A-KID.

[0043] In one embodiment, the subject matter disclosed herein includes an AAnF that queries a service network name from an AUSF / UDM or the AAnF retrieves a service network name after primary authentication with K AKMA . Alternatively, the AAnF retrieves a service network name from the AUSF using the AKMA security context. In one embodiment, the AAnF selects a V-AAnF based on the service network name. In one embodiment, the AAnF provides the AKMA security context to the V-AAnF.

[0044] Figure 1A wireless communication system 100 for implementing roaming using authentication and key management for applications is depicted in accordance with embodiments of the present disclosure. In one embodiment, the wireless communication system 100 includes at least one remote unit 105, a Fifth Generation-Radio Access Network ("5G-RAN") 115, and a mobile core network 140. The 5G-RAN 115 and the mobile core network 140 form a mobile communication network. The 5G-RAN 115 can be composed of a Third Generation Partnership Project ("3GPP") access network 120 containing at least one cellular base unit 121 and / or a non-3GPP access network 130 containing at least one access point 131. The remote units 105 communicate with the 3GPP access network 120 using 3GPP communication links 123 and / or the non-3GPP access network 130 using non-3GPP communication links 133. Although a specific number of remote units 105, 3GPP access networks 120, cellular base units 121, 3GPP communication links 123, non-3GPP access networks 130, access points 131, non-3GPP communication links 133, and mobile core networks 140 are depicted in the Figure 1 wireless communication system 100, those skilled in the art will recognize that any number of remote units 105, 3GPP access networks 120, cellular base units 121, 3GPP communication links 123, non-3GPP access networks 130, access points 131, non-3GPP communication links 133, and mobile core networks 140 can be included in the wireless communication system 100.

[0045] In one implementation, the RAN 120 is compatible with a 5G system specified in 3GPP specifications. For example, the RAN 120 can be a Next Generation-RAN ("NG-RAN") implementing NR radio access technology ("RAT") and / or Long Term Evolution ("LTE") RAT. In another example, the RAN 120 can include a non-3GPP RAT (e.g., an Institute of Electrical and Electronics Engineers ("IEEE") 802.11 family of standards compliant WLAN). In another implementation, the RAN 120 is compatible with an LTE system specified in 3GPP specifications. However, more generally, the wireless communication system 100 can implement some other open or proprietary communication network, such as Worldwide Interoperability for Microwave Access ("WiMAX") or IEEE 802.16 family standards, among others. The present disclosure is not intended to be limited to the implementation of any particular wireless communication system architecture or protocol.

[0046] ​In one embodiment, the remote units 105 can include computing devices, such as desktop, laptop, personal digital assistant (“PDA”), tablet, smart phone, smart television (e.g., television connected to the Internet), smart appliance (e.g., appliance connected to the Internet), set-top box, game console, security system (including security camera), vehicle

[0047] The remote units 105 can communicate directly with one or more of the cellular base units 121 in the 3GPP access network 120 via UL and DL communication signals. Also, the UL and DL communication signals can be carried over the 3GPP communication links 123. Similarly, the remote units 105 can communicate with one or more of the access points 131 in the non-3GPP access network 130 via UL and DL communication signals carried over the non-3GPP communication links 133. Here, the access networks 120 and 130 are intermediate networks that provide the remote units 105 with access to the mobile core network 140.

[0048] In some embodiments, the remote units 105 communicate with remote hosts, such as in data network 150 or in data network 160, via network connections with the mobile core network 140. For example, an application 107 (e.g., a web browser, a

[0049] To establish a PDU session (or packet data network (“PDN”) connection), a remote unit 105 must register with the mobile core network 140 (also referred to as “attaching to the mobile core network” in the context of fourth generation (“4G”) systems). Note that a remote unit 105 can establish one or more PDU sessions (or other data connections) with the mobile core network 140. As such, a remote unit 105 can have at least one PDU session for communicating with a packet data network 150. Additionally - or alternatively - a remote unit 105 can have at least one PDU session for communicating with a packet data network 160. A remote unit 105 can establish additional PDU sessions for communicating with other data networks and / or other communication peers.

[0050] In the context of a 5G system (“5GS”), the term “PDU session” refers to a data connection that provides end-to-end (“E2E”) user plane (“UP”) connectivity between a remote unit 105 and a specific data network (“DN”) through a UPF 131. A PDU session supports one or more quality of service (“QoS”) flows. In certain embodiments, there can be a one-to-one mapping between QoS flows and QoS profiles, such that all packets belonging to a particular QoS flow have the same 5G QoS Identifier (“5QI”).

[0051] In the context of 4G / LTE systems, such as an evolved packet system (“EPS”), a PDN connection (also referred to as an EPS session) provides E2E UP connectivity between a remote unit and a PDN. A PDN connectivity procedure establishes an EPS bearer, i.e., a tunnel between a remote unit 105 and a packet gateway (“P-GW”) (not shown) in the mobile core network 130. In certain embodiments, there is a one-to-one mapping between EPS bearers and QoS profiles, such that all packets belonging to a particular EPS bearer have the same QoS class identifier (“QCI”).

[0052] As described in greater detail below, a remote unit 105 can use a first data connection (e.g., a PDU session) established with a first mobile core network 130 to establish a second data connection (e.g., part of a second PDU session) with a second mobile core network 140. When establishing a data connection (e.g., a PDU session) with the second mobile core network 140, the remote unit 105 uses the first data connection to register with the second mobile core network 140.

[0053] Cell site units 121 can be distributed throughout a geographic region. In certain embodiments, cell site units 121 can also be referred to as access terminals, base, base station, Node-B (“NB”), evolved Node B (abbreviated as eNodeB or “eNB,” also known as Evolved Universal Terrestrial Radio Access Network (“E-UTRAN”) Node B), 5G / NR Node B (“gNB”), home Node-B, home eNodeB, relay node, device, or by any other terminology used in the art. The cell site units 121 are generally part of a radio access network (“RAN”), such as the 3GPP access network 120, which can include one or more controllers communicably coupled to one or more corresponding cell site units 121. These and other elements of radio access networks are not illustrated but are well known to those of ordinary skill in the art. The cell site units 121 connect to the mobile core network 140 via the 3GPP access network 120.

[0054] A cell site unit 121 can serve a number of remote units 105 (e.g., cells or cell sectors) within a serving area via 3GPP wireless communication links 123. A cell site unit 121 can communicate directly with one or more of the remote units 105 via communication signals. Typically, a cell site unit 121 transmits DL communication signals at a time, frequency, and / or space domain to serve the remote units 105. Also, the DL communication signals can be carried over the 3GPP communication links 123. The 3GPP communication links 123 can be any suitable carrier in a licensed or unlicensed radio frequency spectrum. The 3GPP communication links 123 facilitate communication between one or more of the remote units 105 and / or one or more of the cell site units 121. Note that during NR operation on unlicensed spectrum (referred to as “NR-U”), the base site units 121 and the remote units 105 communicate over unlicensed (i.e., shared) radio frequency spectrum.

[0055] Non-3GPP access networks 130 can be distributed throughout a geographic region. Each non-3GPP access network 130 can serve a number of remote units 105 in a serving area. An access point 131 in a non-3GPP access network 130 can communicate directly with one or more remote units 105 by receiving UL communication signals and transmitting DL communication signals to serve the remote units 105 in a time, frequency, and / or space domain. Both the DL and UL communication signals are carried over the non-3GPP communication links 133. The 3GPP communication links 123 and the non-3GPP communication links 133 can employ different frequencies and / or different communication protocols. In various embodiments, the access points 131 can communicate using unlicensed radio frequency spectrum. The mobile core network 140 can provide service to the remote units 105 via the non-3GPP access networks 130, as described in greater detail herein.

[0056] In some embodiments, the non-3GPP access network 130 connects to the mobile core network 140 via an interworking entity 135. The interworking entity 135 provides interworking between the non-3GPP access network 130 and the mobile core network 140. The interworking entity 135 supports connectivity via “N2” and “N3” interfaces. As depicted, both the 3GPP access network 120 and the interworking entity 135 communicate with an access and mobility management function (“AMF”) 143 using the “N2” interface. The 3GPP access network 120 and the interworking entity 135 also communicate with a UPF 141 using the “N3” interface. Although depicted as being outside of the mobile core network 140, in other embodiments, the interworking entity 135 can be part of the core network. Although depicted as being outside of the non-3GPP RAN 130, in other embodiments, the interworking entity 135 can be part of the non-3GPP RAN 130.

[0057] In certain embodiments, the non-3GPP access network 130 can be controlled by the operator of the mobile core network 140 and can have direct access to the mobile core network 140. Such non-3GPP AN deployments are referred to as “trusted non-3GPP access networks.” When a non-3GPP access network 130 is operated by a 3GPP operator or a trusted partner, it is considered “trusted” and supports certain security features, such as strong air interface encryption. Conversely, a non-3GPP AN deployment that is not controlled by the operator (or a trusted partner) of the mobile core network 140, does not have direct access to the mobile core network 140, or does not support certain security features is referred to as an “untrusted” non-3GPP access network. An interworking entity 135 deployed in a trusted non-3GPP access network 130 can be referred to herein as a trusted network gateway function (“TNGF”). An interworking entity 135 deployed in an untrusted non-3GPP access network 130 can be referred to herein as a non-3GPP interworking function (“N3IWF”). Although depicted as being part of the non-3GPP access network 130, in some embodiments, the N3IWF can be part of the mobile core network 140 or can be located in the data network 150.

[0058] In one embodiment, the mobile core network 140 is a 5G core (“5GC”) or an evolved packet core (“EPC”), which can be coupled to data networks 150, such as the Internet and private data networks, among other data networks. A remote unit 105 can have a subscription or other account with the mobile core network 140. Each mobile core network 140 belongs to a single public land mobile network (“PLMN”). The present disclosure is not intended to be limited to the implementation of any particular wireless communication system architecture or protocol.

[0059] The mobile core network 140 includes several network functions (“NFs”). As depicted, the mobile core network 140 includes at least one UPF 141. The mobile core network 140 also includes a number of control plane functions including, but not limited to, an AMF 143 that serves the 5G-RAN 115, a Session Management Function (“SMF”) 145, a Policy Control Function (“PCF”) 147, an Authentication Server Function (“AUSF”) 148, a Unified Data Management (“UDM”), and a Unified Data Repository Function (“UDR”).

[0060] In the 5G architecture, the UPF 141 is responsible for packet routing and forwarding, packet inspection, QoS handling, and external PDU session for interconnecting Data Networks (“DNs”). The AMF 143 is responsible for termination of Non-Access Stratum (“NAS”) signaling, NAS ciphering and integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. The SMF 145 is responsible for session management (i.e., session establishment, modification, release), remote unit (i.e., UE) IP address allocation and management, DL data notification, and traffic steering configuration to route traffic for UPF.

[0061] The PCF 147 is responsible for a unified policy framework, providing policy rules to control plane (“CP”) functions, accessing subscription information for policy decisions in the UDR. The AUSF 148 acts as an authentication server.

[0062] The UDM is responsible for generating Authentication and Key Agreement (“AKA”) credentials, user identity handling, access authorization, subscription management. The UDR is a repository of subscriber information and can be used to serve several network functions. For example, the UDR can store subscription data, policy-related data, subscriber-related data that is allowed to be exposed to third party applications, etc. In some embodiments, the UDM and UDR are co-located, depicted as the combined entity “UDM / UDR” 149.

[0063] In various embodiments, the mobile core network 140 can also include a Network Exposure Function (“NEF”) (which is responsible for making network data and resources available to customers and network partners, e.g., via one or more APIs), a Network Repository Function (“NRF”) (which provides NF service registration and discovery, enabling NFs to identify appropriate services in each other and communicate with each other over application programming interfaces (“APIs”)), or other NFs defined for the 5GC. In certain embodiments, the mobile core network 140 can include an Authentication, Authorization, and Accounting (“AAA”) server.

[0064] In various embodiments, mobile core network 140 supports different types of mobile data connections and different types of network slices, where each mobile data connection utilizes a particular network slice. Here, a“network slice” refers to a portion of the mobile core network 140 that is optimized for a certain traffic type or communication service. A network instance can be identified by a single-network slice selection assistance information (“S-NSSAI”), while a set of network slices for which a remote unit 105 is authorized to use is identified by a network slice selection assistance information (“NSSAI”). In certain embodiments, the various network slices can include separate instances of network functions, e.g., SMF and UPF 141. In some embodiments, different network slices can share some common network functions, e.g., AMF 143. To facilitate explanation, Figure 1 Different network slices are not shown in FIG. 1, but are assumed to be supported.

[0065] Although Figure 1 particular number and type of network functions are depicted in FIG. 1, one of skill in the art will recognize that any number and type of network functions can be included in the mobile core network 140. Moreover, where the mobile core network 140 comprises an EPC, the depicted network functions can be replaced with appropriate EPC entities, e.g., a mobility management entity (“MME”), a serving gateway (“S-GW”), a P-GW, a home subscriber server (“HSS”), etc.

[0066] While Figure 1 components of a 5G RAN and a 5G core network, the described embodiments for access authentication over non-3GPP access are applicable to other types of communication networks and RATs, including IEEE 802.11 variants, GSM, GPRS, UMTS, LTE variants, CDMA 2000, Bluetooth, ZigBee, Sigfox, etc. For example, in 4G / LTE variants that involve an EPC, the AMF 143 can be mapped to a MME, the SMF is mapped to a control plane portion of a P-GW and / or to a MME, the UPF 141 can be mapped to an S-GW and a user plane portion of a P-GW, the UDM / UDR 149 can be mapped as a HSS, etc.

[0067] As depicted, remote units 105 (e.g., UEs) can connect to a mobile core network (e.g., to a 5G mobile communication network) via two types of access: (1) via a 3GPP access network 120 and (2) via a non-3GPP access network 130. The first type of access (e.g., 3GPP access network 120) uses a 3GPP-defined type of wireless communication (e.g., NG-RAN), and the second type of access (e.g., non-3GPP access network 130) uses a non-3GPP-defined type of wireless communication (e.g., WLAN). A 5G-RAN 115 refers to any type of 5G access network capable of providing access to a mobile core network 140, including both 3GPP access networks 120 and non-3GPP access networks 130.

[0068] As background, generally, the AKMA functionality is based on the Generic Bootstrapping Architecture (“GBA”) (see 3GPP TS 33.220), which was designed for 3GPP networks several generations before 5G. AKMA was designed to meet new protocol requirements posed by the introduction of the Service-Based Architecture (“SBA”).

[0069] The GBA defines roaming where the Network Application Function (“NAF”) is located in the VPLMN. In one embodiment, the NAF is the function with which the UE establishes a secure connection, and because it is located in the VPLMN, LI is possible.

[0070] Generally, the GBA architecture only considers the Application Function (AF / NAF) in the VPLMN as the function that hosts the encryption keys. In this case, the LI requirement would not be a problem, but the AF can be considered somewhere else in a different network, not limited to the VPLMN. In one embodiment, the AF can be located in the Home Public Land Mobile Network (“HPLMN”), but depending on the service and application, it can also be a different network, which does not solve the LI problem. Also, in one embodiment, performing LI in the UPF of the VPLMN does not solve the problem because the traffic is still tunneled between the UE and the AF, and the UPF does not have a security context.

[0071] Accordingly, as described herein, the AKMA security context is provided to the serving network at the time of AKMA key generation or at the time of session establishment from the UE. In view of this, a new function, the Visited-AKMA Anchor Function (“V-AAnF”), is introduced to receive the security context and further relay it to the AF. For LI reasons, the key material can be retrieved from the V-AAnF in order to decrypt the connection between the UE and the AF.

[0072] Figure 2A process flow 200 depicting key provisioning to a V-AAnF upon application session establishment request. In one embodiment, the process 200 describes using a V-AAnF as a proxy in a VPLMN to receive AKMA security context from a HPLMN AAnF. The V-AAnF can provision the AKMA security context to the relevant LI network function upon request.

[0073] In one embodiment, after primary authentication (see step 1, block 202) and before communication between the UE 207 and the AKMA AF 215 can begin, the UE 207 and the AKMA AF 215 need to know whether to use AKMA.

[0074] At step 2, in one embodiment, the UE 207 should derive K AUSF An AKMA anchor key (K AKMA ) and an AKMA key identifier A-KID. In one embodiment, when the UE 207 initiates communication with the AKMA AF 215 (see messaging 204), it should include the derived A-KID in the application session establishment request message. In one embodiment, the UE 207 can derive K AF In one embodiment, the UE 207 includes the serving network name (“SN”) of the current VPLMN in the request.

[0075] At step 3, in one embodiment, when the AF 215 is going to request AKMA application keys for the UE 207 from the AAnF 217, e.g., when the UE 207 initiates an application session establishment request, the AF 215 discovers the VPLMN 201 of the UE 207 based on the SN and sends a request (see messaging 206) via the NEF 209 serving API towards the V-AAnF 213. In one embodiment, the request should include the A-KID and the AF ID. In one embodiment, the AF ID consists of the fully qualified domain name (“FQDN”) of the AF 215 and a Ua* security protocol identifier. In one embodiment, the latter parameter identifies the security protocol that the AF 215 will use with the UE 207. In one embodiment, if the NEF 209 is not needed, the AF 215 can send the request message directly to the V-AAnF 213.

[0076] At step 4, in one embodiment, if the AF 215 is authorized by the NEF 209 to request K AF , the NEF 209 discovers and selects the V-AAnF 213 and sends K AFThe request is forwarded (see messaging 208) to the selected V-AAnF 213. In one embodiment, the V-AAnF 213 detects (see block 210) the HPLMN 205 based on the realm of the A-KID and selects the AAnF 217 within the HPLMN 205.

[0077] At step 6, in one embodiment, the V-AAnF 213 sends (see messaging 212) an AKMA K AF Request to the AAnF 217 in the HPLMN 205.

[0078] At step 7, in one embodiment, the AAnF 217 validates the request and generates K AF and sends (see messaging 214) a response to the V-AAnF 213 with K AF , K AF Expiry time (KAFexptime) and potentially other parameters.

[0079] At step 8, in one embodiment, the V-AAnF 213 forwards (see messaging 216) the response to the NEF 209.

[0080] At step 9, in one embodiment, the NEF 209 forwards (see messaging 218) the response to the AF 215.

[0081] At step 10, in one embodiment, the AF 215 sends (see messaging 220) an application session setup response to the UE 207.

[0082] Figure 3 A procedure flow 300 is depicted for key provisioning to a V-AAnF at AKMA key generation.

[0083] At step 1, in one embodiment, during a primary authentication procedure (see block 302), the AUSF 311 interacts (see messaging 304) with the UDM 313 in order to extract authentication information, such as subscription credentials (e.g., AKA authentication vector) and authentication method, using the Nudm_UEAuthentication_Get request service operation.

[0084] At step 2, in one embodiment, in the response message (see messaging 306), the UDM 313 can also indicate to the AUSF 311 whether an AKMA anchor key needs to be generated for the UE 305. If AKMA Ind is included, in one embodiment, the UDM 313 should also include the RID of the UE 305.

[0085] At step 3, in one embodiment, if the AUSF 311 receives an AKMA indication from the UDM 313, the AUSF 311 shall store K AUSF and from K AUSF generates (see block 308) AKMA anchor key (K AKMA ) and A-KID after the successful completion of the primary authentication procedure. In one embodiment, the AUSF 311 detects (see block 310) that the UE 305 is in a different serving network and uses the SN as the realm of the A-KID.

[0086] In one embodiment, the UE 305 generates (see block 312) AKMA anchor key (K AUSF ) and A-KID (see block 314) from K AKMA before initiating communication with the AKMA application function. The UE 305 uses the SN as the realm of the A-KID, respectively.

[0087] In a first option (Option A 316), in one embodiment, after generating the AKMA key material, the AUSF selects (see block 318) the V-AAnF 309 based on the SN of the UE 305 and sends the generated A-KID and K AKMA together with the subscription permanent identifier (“SUPI”) of the UE 305 (see messaging 320) to the V-AAnF 309 using the Naanf AKMA KeyRegistration request service operation. In one embodiment, the V-AAnF 309 stores the latest information sent by the AUSF 311 and sends a response (see messaging 322) to the AUSF 311 using the Naanf AKMA AnchorKey Register response service operation.

[0088] In a second option (Option B 324), in one embodiment, after generating the AKMA key material, the AUSF 311 selects the AMF 307 based on the SN of the UE 305 and sends the generated A-KID and K AKMAThe SUPI of the UE 305 is sent (see messaging 326) to the AMF 307. In one embodiment, the AMF 307 selects the V-AAnF 309 and forwards (see messaging 328) the request in a Naanf_AKMA_KeyRegistration request service operation. In one embodiment, the V-AAnF 309 stores the latest information sent by the AUSF 311. The V-AAnF 309 sends (see messaging 330) a response to the AMF 307, which forwards (see messaging 332) the response to the AUSF 311 using a Naanf_AKMA_AnchorKey_Register response service operation via the AMF 307.

[0089] In one embodiment, the A-KID identifies the K AKMA key for the UE 305. In other embodiments, the A-KID should be in a Network Access Identifier (“NAI”) format, e.g., username@realm. The username portion can contain the RID and an AKMA temporary UE identifier (“A-TID”), and the realm portion can contain a visited network identifier (e.g., SN). In one embodiment, the A-TID can be derived from the K AUSF AUSF 311 can use the RID received from the UDM 313 to derive the A-KID.

[0090] In one embodiment, if the UE sends an application session establishment request to the AF, the AF routes the request to a NEF or AAnF in the serving network (e.g., VPLMN) based on the SN of the A-KID. In one embodiment, the procedure is valid if the UE remains in the HPLMN or roams in the VPLMN.

[0091] Figure 4 Procedure flow 400 depicts key provisioning to a V-AAnF after provisioning by an AF.

[0092] At step 1, in one embodiment, after primary authentication (see block 402) and before communication between the UE 407 and the AKMA AF 415 can begin, the UE 407 and the AKMA AF 415 need to know whether to use AKMA.

[0093] At step 2, in one embodiment, the UE 407 generates an AKMA anchor key (K AUSF AKMA anchor key (K AKMA) and A-KID. When the UE 407 initiates communication with the AKMA AF 415 (see messaging 404), in one embodiment it can include the derived A-KID in the application session establishment request message. In one embodiment, the UE 407 can derive K AF . The UE 407 can include in the request the serving network name (“SN”) of the current VPLMN 401.

[0094] At step 3, in one embodiment, when the AF 415 is going to request AKMA application keys for the UE 407 from the AAnF 417, e.g., when the UE 407 initiates an application session establishment request, the AF 415 sends (see messaging 406) a request to the AAnF 417 via the NEF service API (not shown). The request can include the A-KID and the AF ID as well as the serving network name (SN) if available. In one embodiment, the AF ID consists of the FQDN of the AF and a Ua* security protocol identifier. In one embodiment, the latter parameter identifies the security protocol to be used by the AF 415 with the UE 407. If the NEF is not needed, the AF 415 can send the request message directly to the AAnF 417.

[0095] At step 4, in one embodiment, the AAnF validates the request, generates K AF , and sends (see messaging 408) a response to the AF 415 with K AF , K AF , K AKMA , the KAF exptime, and potentially other parameters.

[0096] At step 5, in one embodiment, the AF 415 sends (see messaging 410) an application session establishment response to the UE 407.

[0097] At step 6, in one embodiment, if the UE 407 included the serving network name in step 1, the AAnF 417 detects (see block 412) that the UE 407 is not located in the HPLMN 405 and is located in a different network. Alternatively, in one embodiment, the AUSF 419 provides the serving network name along with K AKMA , as shown in step 4 in Figure 5 . In this case, the AAnF 417 can skip steps 7 and 8.

[0098] At step 7, in one embodiment, the AAnF 417 sends (see messaging 414) a service network name request to the AUSF 419 and includes the SUPI of the UE 407. Alternatively, the AAnF 417 can directly contact the UDM regarding the service network name. If the service network name is no longer stored for the particular SUPI, the AUSF 419 can contact the UDM.

[0099] At step 8, in one embodiment, the AUSF 419 or UDM provides (see messaging 416) the service network name back to the AAnF 417.

[0100] At step 9, in one embodiment, the AAnF 417 uses the service network name to select (see block 418) the V-AAnF 413 in the service network.

[0101] At step 10, in one embodiment, the AAnF 417 sends (see messaging 420) a key provision request to the V-AAnF 413 with the K AF , K AF Expiry time (KAFexptime), SUPI, A-KID, and potentially other parameters. In one embodiment, the V-AAnF 413 stores the information for potential requests for lawful interception.

[0102] At step 11, in one embodiment, the V-AAnF 413 acknowledges the request and sends (see messaging 422) a key provision response back to the AAnF 417.

[0103] Figure 5 A procedure flow 500 is depicted for providing a service network name. In one embodiment, the AUSF 509 detects (see block 502) that the UE 505 is in a different PLMN 501 based on the service network name used in a previous primary authentication for K SEAF key derivation. In one embodiment, the AUSF 509 provides the service network name with other security parameters to the AAnF 507 in step 4 (see messaging 504). The AAnF 507 can then select the AAnF 507 in the service network when a later key request from an AF.

[0104] Figure 6 A procedure flow 600 is depicted for providing a service network name and V-AAnF selection.

[0105] In one embodiment, at step 1, during the primary authentication procedure (see block 602), the AUSF 619 interacts with the UDM to extract authentication information, e.g., subscription credentials (e.g., AKA authentication vector) and authentication method, using the Nudm_UEAuthentication_Get request service operation.

[0106] In one embodiment, at step 2, if the AUSF 619 receives an AKMA indication from the UDM, the AUSF 619 shall store the K AUSF and generate the AKMA anchor key (K AUSF ) and A-KID (see block 606) from K AKMA after the primary authentication procedure is successfully completed. In one embodiment, the UE 607 generates the AKMA anchor key (K AUSF ) and A-KID from K AKMA before initiating communication with the AKMA application function.

[0107] In one embodiment, at step 3, after generating the AKMA key material, the AUSF 619 selects the AAnF 617 and sends the generated A-KID and K AKMA together with the SUPI of the UE 607 and the service network name to the AAnF 617 using the Naanf_AKMA_KeyRegistration request service operation (see messaging 612).

[0108] At step 4, in one embodiment, the AAnF 617 stores the latest information sent by the AUSF 619 and sends (see messaging 614) the Naanf_AKMA_AnchorKey_Register response to the AUSF 619.

[0109] At step 5, in one embodiment, the UE 607 generates the AKMA anchor key (K AUSF ) and A-KID from K AKMA before initiating communication with the AKMA AF 613. In one embodiment, when the UE 607 initiates communication with the AKMA AF 613 (see messaging 616), it includes the derived A-KID in the application session establishment request message. In one embodiment, the UE 607 derives K AF before or after sending the message.

[0110] In one embodiment, at step 6, when the AF 613 is going to request AKMA application keys for the UE 607 from the AAnF 617, e.g., when the UE 607 initiates an application session establishment request, the AF 613 sends (see messaging 618) a request to the AAnF 617 via the NEF 615 serving API. The request can include the A-KID and the AF_ID. In one embodiment, the AF_ID consists of the FQDN of the AF 613 and a Ua* security protocol identifier. In one embodiment, the latter parameter identifies the security protocol that the AF 613 will use with the UE 607. If the NEF 615 is not needed, the AF 613 can send the request message directly to the AAnF 617; otherwise, the NEF 615 sends (see messaging 620) the request to the AAnF 617.

[0111] At step 7, in one embodiment, the AAnF 617 detects (see block 622) where the UE 607 is roaming based on the SN name, and:

[0112] If the VPLMN 601 does not have AKMA LI enhancements, but does have LI policies, the AAnF 617 can not provide K AF and indicate NULL encryption;

[0113] If the VPLMN 601 has AKMA LI enhancements, the AAnF 617 will provide K AF and K AF The expiration time is provided to the network function storing the AKMA LI context, e.g., the V-AAnF 611 in the VPLMN 601, along with the SUPI of the UE 607.

[0114] The VPLMN 601 AKMA capabilities and policies, as well as network functions, e.g., V-AAnF addresses, can be configured in the AAnF 617 and can be based on a service level agreement (“SLA”).

[0115] At step 8, in one embodiment, the AAnF 617 validates the request and generates K AF and sends a response to the AF 613 with K AF , K AF , the expiration time (KAFexptime), and potentially other parameters. The AAnF 617 sends the response directly to the AF 613 or via the NEF 615 (see messaging 624 and 626).

[0116] In one embodiment, at step 9, the AF 613 sends (see messaging 628) an application session establishment response to the UE 607.

[0117] At step 10, in one embodiment, the AAnF 617 sends (see messaging 630) a Key Provisioning Request to the V-AAnF 611 with the K AF , K AF Expiry Time (KAFexptime), SUPI, A-KID, and potentially other parameters. In one embodiment, the V-AAnF 611 stores the information for potential requests for lawful interception.

[0118] At step 11, in one embodiment, the V-AAnF 611 acknowledges the request and sends (see messaging 632) a Key Provisioning Response to the AAnF 617.

[0119] Figure 7 A user equipment device 700 that can be used for roaming using application authentication and key management is depicted in accordance with the embodiments of the present disclosure. In various embodiments, the user equipment device 700 is used to implement one or more of the above-described solutions. The user equipment device 700 can be one embodiment of the remote units 105 and / or the UEs described above. Furthermore, the user equipment device 700 can include a processor 705, a memory 710, an input device 715, an output device 720, and a transceiver 725.

[0120] In some embodiments, the input device 715 and the output device 720 are combined into a single device, such as a touch screen. In certain embodiments, the user equipment device 700 can not include any input device 715 and / or output device 720. In various embodiments, the user equipment device 700 can include one or more of: the processor 705, the memory 710, and the transceiver 725, and can not include the input device 715 and / or the output device 720.

[0121] As depicted, the transceiver 725 includes at least one transmitter 730 and at least one receiver 735. In some embodiments, the transceiver 725 communicates with one or more cells (or wireless coverage areas) supported by one or more base unit 121. In various embodiments, the transceiver 725 is operable over unlicensed spectrum. Further, the transceiver 725 can include multiple UE panels supporting one or more beams. Further, the transceiver 725 can support at least one network interface 740 and / or application interface 745. The application interface 745 can support one or more APIs. The network interface 740 can support 3GPP reference points, such as Uu, N1, PC5, etc. Other network interfaces 740 can be supported as understood by one of ordinary skill in the art.

[0122] In one embodiment, the processor 705 can include any known controller capable of executing computer-readable instructions and / or capable of performing logical operations. For example, the processor 705 can be a microcontroller, a microprocessor, a central processing unit ("CPU"), a graphics processing unit ("GPU"), an auxiliary processing unit, a field programmable gate array ("FPGA"), or similar programmable controller. In some embodiments, the processor 705 executes instructions stored in the memory 710 to perform methods and routines described herein. The processor 705 is communicatively coupled to the memory 710, the input device 715, the output device 720, and the transceiver 725. In some embodiments, the processor 705 includes a application processor (also known as "main processor") that manages application-domain and operating system ("OS") functions and a baseband processor (also known as "baseband radio processor") that manages radio functions.

[0123] In one embodiment, the memory 710 is a computer readable storage medium. In some embodiments, the memory 710 includes volatile computer storage media. For example, the memory 710 can include a RAM, including dynamic RAM ("DRAM"), synchronous dynamic RAM ("SDRAM"), and / or static RAM ("SRAM"). In some embodiments, the memory 710 includes non-volatile computer storage media. For example, the memory 710 can include a hard disk drive, a flash memory, or any other suitable non-volatile computer storage device. In some embodiments, the memory 710 includes both volatile and non-volatile computer storage media.

[0124] In some embodiments, the memory 710 stores data related to authentication and key management for use of applications in relation to roaming. For example, the memory 710 can store various parameters, panel / beam configurations, resource allocations, policies, etc. as described above. In certain embodiments, the memory 710 also stores program code and related data, such as an operating system or other controller algorithms operating on the user equipment device 700.

[0125] In one embodiment, the input device 715 can include any known computer input device, including a touch panel, buttons, a keyboard, a stylus, a microphone, etc. In some embodiments, for example, the input device 715 can be integrated into a touch screen or similar touch-sensitive display with the output device 720. In some embodiments, the input device 715 includes a touch screen such that text can be input using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, the input device 715 includes two or more different devices, such as a keyboard and a touch panel.

[0126] In one embodiment, output device 720 is designed to output visual, audible, and / or tactile signals. In some embodiments, output device 720 includes an electronically controllable display or display device capable of outputting visual data to a user. For example, output device 720 can include, but is not limited to, an LCD display, a LED display, an OLED display, a projector, or similar display device capable of outputting images, text, etc. to a user. As another non-limiting example, output device 720 can include a wearable display separate from, but communicatively coupled to, the rest of user equipment apparatus 700, such as a smartwatch, smartglasses, a heads-up display, etc. Further, output device 720 can be a component of a smart phone, a personal digital assistant, a television, a table computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, etc.

[0127] In certain embodiments, output device 720 includes one or more speakers for producing sound. For example, output device 720 can produce an audible alert or notification (e.g., a beep or chime). In some embodiments, output device 720 includes one or more haptic devices for producing vibrations, motion, or other haptic feedback. In some embodiments, all or portions of output device 720 can be integrated with input device 715. For example, input device 715 and output device 720 can form a touchscreen or similar touch-sensitive display. In other embodiments, output device 720 can be located near input device 715.

[0128] Transceiver 725 communicates with one or more network functions of a mobile communication network via one or more access networks. Transceiver 725 operates under the control of processor 705 to transmit messages, data, and other signals, and also to receive messages, data, and other signals. For example, processor 705 can selectively activate transceiver 725 (or portions thereof) at particular times in order to send and receive messages.

[0129] Transceiver 725 includes at least transmitter 730 and at least receiver 735. One or more transmitters 730 can be used to provide UL communication signals to base units 121, such as the UL transmissions described herein. Similarly, one or more receivers 735 can be used to receive DL communication signals from base units 121, as described herein. Although only one transmitter 730 and one receiver 735 are illustrated, user equipment apparatus 700 can have any suitable number of transmitters 730 and receivers 735. Further, transmitter 730 and receiver 735 can be any suitable type of transmitters and receivers. In one embodiment, transceiver 725 includes a first transmitter / receiver pair for communicating with a mobile communication network over licensed radio spectrum and a second transmitter / receiver pair for communicating with a mobile communication network over unlicensed radio spectrum.

[0130] In certain embodiments, the first transmitter / receiver pair for communicating with a mobile communication network over licensed radio spectrum and the second transmitter / receiver pair for communicating with a mobile communication network over unlicensed radio spectrum can be combined into a single transceiver unit, such as a single chip that performs functions used in connection with both licensed and unlicensed radio spectrum. In some embodiments, the first transmitter / receiver pair and the second transmitter / receiver pair can share one or more hardware components. For example, certain transceivers 725, transmitters 730, and receivers 735 can be implemented as physically separate components that access shared hardware and / or software resources, such as, for example, network interface 740.

[0131] In various embodiments, one or more transmitters 730 and / or one or more receivers 735 can be implemented and / or integrated into a single hardware component, such as a multi-transceiver chip, a system-on-a-chip, an ASIC, or other type of hardware component. In certain embodiments, one or more transmitters 730 and / or one or more receivers 735 can be implemented and / or integrated into a multi-chip module. In some embodiments, other components, such as network interface 740 or other hardware components / circuits, can be integrated with any number of transmitters 730 and / or receivers 735 into a single chip. In such embodiments, transmitters 730 and receivers 735 can be logically configured as a transceiver 725 that uses one or more common control signals, or modular transmitters 730 and receivers 735 implemented in the same hardware chip or multi-chip module.

[0132] Figure 8 A network device 800 that can be used for authentication and key management for roaming using applications is depicted in accordance with embodiments of the present disclosure. In one embodiment, the network device 800 can be one implementation of a RAN node, such as the base unit 121, RAN node 210, or gNB described above. Additionally, the base network device 800 can include a processor 805, a memory 810, an input device 815, an output device 820, and a transceiver 825.

[0133] In some embodiments, the input device 815 and the output device 820 are combined into a single device, such as a touch screen. In certain embodiments, the network device 800 can not include any input device 815 and / or output device 820. In various embodiments, the network device 800 can include one or more of the processor 805, the memory 810, and the transceiver 825, and can not include the input device 815 and / or the output device 820.

[0134] As depicted, the transceiver 825 includes at least one transmitter 830 and at least one receiver 835. Here, the transceiver 825 communicates with one or more remote units 105. Additionally, the transceiver 825 can support one or more network interfaces 840 and / or application interfaces 845. The application interfaces 845 can support one or more APIs. The network interfaces 840 can support 3GPP reference points, such as Uu, Nl, N2, and N3. Other network interfaces 840 can be supported, as understood by one of ordinary skill in the art.

[0135] In one embodiment, the processor 805 can include any known controller capable of executing computer-readable instructions and / or capable of performing logical operations. For example, the processor 805 can be a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processor, a FPGA, or similar programmable controller. In some embodiments, the processor 805 executes instructions stored in the memory 810 to perform methods and routines described herein. The processor 805 is communicatively coupled to the memory 810, the input device 815, the output device 820, and the transceiver 825. In certain embodiments, the processor 805 can include a application processor (also known as “main processor”) that manages application-domain and operating system (“OS”) functions, and a baseband processor (also known as “baseband radio processor”) that manages radio functions.

[0136] In various embodiments, the network device 800 is a RAN node (e.g., gNB) including the processor 805 and the transceiver 825. In one embodiment, the processor 805 determines a serving network for a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE. In one embodiment, the processor 805 selects a network function within the serving network for providing an authentication and key management (“AKMA”) security context for an application function (“AF”) based on a name of the serving network. In one embodiment, the transceiver 825 transmits the security context to the network function.

[0137] In one embodiment, the processor 805 determines the serving network for the UE by detecting that the UE is in the serving network. In one embodiment, the processor 805 generates an AKMA key information K AKMA and an AKMA key identifier A-KID. In one embodiment, the transceiver 825 transmits a registration request message to the selected network function based on the serving network name, the registration request message including the AKMA security context including the K AKMA, and a subscription permanent identifier (“SUPI”) of the UE. In one embodiment, transceiver 825 receives, from the selected network function, a registration response message for establishing a connection between the UE and the AF of the serving network.

[0138] In one embodiment, the selected network function comprises one of an access and mobility management function (“AMF”) and a visited AKMA anchor function (“V-AAnF”). In one embodiment, processor 805 determines the serving network of the UE by at least one of querying an authentication server function (“AUSF”) of the HPLMN for the serving network name, retrieving the serving network name during primary authentication with the UE, and receiving the serving network name from the AUSF along with the AKMA key information K AKMA .

[0139] In one embodiment, the serving network name is received from the AUSF in response to a serving network name request comprising a subscription permanent identifier (“SUPI”) of the UE.

[0140] In one embodiment, transceiver 825 sends, to the selected network function within the serving network, a key provisioning request comprising the AKMA security context containing key information for AKMA AF K AF , an expiration time for the K AF , a subscription permanent identifier (“SUPI”) of the UE, and an AKMA key identifier A-KID. In one embodiment, transceiver 825 receives, from the selected network function, a key provisioning response message.

[0141] In one embodiment, transceiver 825 receives, from an AF at a network function of the HPLMN associated with the UE, a key request for provisioning the AKMA security context for the AF for establishing a connection between the UE and the AF of the serving network. In one embodiment, processor 805 detects that the serving network comprising the VPLMN different from the HPLMN associated with the UE does not use a network function enhancement within the serving network for provisioning the AKMA security context. In one embodiment, transceiver 825 sends, to the AF, a key response comprising an indication of NULL encryption and a subscription permanent identifier (“SUPI”) of the UE.

[0142] In one embodiment, transceiver 825 receives, from the serving network, the AKMA AF K AFAKMA key information request. In one embodiment, the processor 805 validates the AKMA key information request. In one embodiment, in response to validating the AKMA key information request, the processor 805 generates the AKMA AF K AF , and the transceiver sends, to the serving network, an AKMA key information response including the AKMA AF K AF and an expiration time of the K AF .

[0143] In one embodiment, the transceiver 825 receives, at a network function of a serving network of a user equipment (“UE”) device, a key request, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE, the key registration request for an authentication and key management (“AKMA”) security context for an application function (“AF”) providing an application based on a name of the serving network to establish a connection between the UE and the AF. In one embodiment, the transceiver 825 sends, to a network function of the HPLMN, a key response.

[0144] In one embodiment, the processor 805 stores, at the network function of the serving network, security context information. In one embodiment, the network function of the serving network comprises one of an access and mobility management function (“AMF”) and a visited AKMA anchor function (“V-AAnF”).

[0145] In one embodiment, the processor 805 detects, based on an AKMA key identifier A-KID, that the key request is from an AAnF in the HPLMN. In one embodiment, the transceiver 825 sends, to the AAnF in the HPLMN, the key request, and receives, from the AAnF of the HPLMN, a key response including the AKMA AF K AF and an expiration time of the K AF .

[0146] In one embodiment, the memory 810 is a computer readable storage medium. In some embodiments, the memory 810 includes volatile computer storage media. For example, the memory 810 can include a RAM, including dynamic RAM (“DRAM”), synchronous dynamic RAM (“SDRAM”), and / or static RAM (“SRAM”). In some embodiments, the memory 810 includes non-volatile computer storage media. For example, the memory 810 can include a hard disk drive, a flash memory, or any other suitable non-volatile computer storage device. In some embodiments, the memory 810 includes both volatile and non-volatile computer storage media.

[0147] In some embodiments, the memory 810 stores data related to authentication and key management for roaming using applications. For example, the memory 810 can store parameters, configurations, resource allocations, policies, and the like as described above. In certain embodiments, the memory 810 also stores program code and related data, such as an operating system or other controller algorithms operating on the network device 800.

[0148] In one embodiment, the input device 815 can include any known computer input device including a touch panel, buttons, a keyboard, a stylus, a microphone, or the like. In some embodiments, for example, the input device 815 can be integrated into a touch screen or similar touch-sensitive display with the output device 820. In some embodiments, the input device 815 includes a touch screen such that text can be input using a virtual keyboard displayed on the touch screen and / or by handwriting on the touch screen. In some embodiments, the input device 815 includes two or more different devices, such as a keyboard and a touch panel.

[0149] In one embodiment, the output device 820 is designed to output visual, audible, and / or tactile signals. In some embodiments, the output device 820 includes an electronically controllable display or display device capable of outputting visual data to a user. For example, the output device 820 can include, but is not limited to, an LCD display, a LED display, an OLED display, a projector, or similar display device capable of outputting images, text, etc. to a user. As another non-limiting example, the output device 820 can include a wearable display separate from, but communicatively coupled to, the rest of the network device 800, such as a smart watch, smart glasses, a heads-up display, etc. Further, the output device 820 can be a component of a smart phone, a personal digital assistant, a television, a table computer, a notebook (laptop) computer, a personal computer, a vehicle dashboard, etc.

[0150] In certain embodiments, the output device 820 includes one or more speakers for producing sound. For example, the output device 820 can produce an audible alert or notification (e.g., a beep or chime). In some embodiments, the output device 820 includes one or more tactile devices for producing vibrations, motion, or other tactile feedback. In some embodiments, all or portions of the output device 820 can be integrated with the input device 815. For example, the input device 815 and output device 820 can form a touch screen or similar touch-sensitive display. In other embodiments, the output device 820 can be located near the input device 815.

[0151] The transceiver 825 includes at least transmitter 830 and at least one receiver 835. The one or more transmitters 830 can be used to communicate with UEs, as described herein. Similarly, the one or more receivers 835 can be used to communicate with network functions in a non-public network (“NPN”), a PLMN, and / or a RAN, as described herein. Although only one transmitter 830 and one receiver 835 are illustrated, the network device 800 can have any suitable number of transmitters 830 and receivers 835. Further, the transmitter(s) 830 and the receiver(s) 835 can be any suitable type of transmitters and receivers.

[0152] Figure 9 FIG. 9 is a flow diagram of a method 900 for implementing roaming using authentication and key management for applications. The method 900 can be performed by a UE, such as the remote unit 105, the UE, and / or the user equipment device 700 and / or a network entity, such as a base station node, gNB, and / or the network equipment device 800, as described herein. In some embodiments, the method 900 can be performed by a processor executing program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.

[0153] In one embodiment, the method 900 includes determining 905 a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) that is different from a home PLMN (“HPLMN”) associated with the UE. In one embodiment, the method 900 includes selecting 910 a network function within the serving network for providing an authentication and key management (“AKMA”) security context for an application function (“AF”) based on a name of the serving network. In one embodiment, the method 900 includes sending 915 the security context to the network function, and the method 900 ends.

[0154] Figure 10 FIG. 10 is a flow diagram of a method 1000 for implementing roaming using authentication and key management for applications. The method 1000 can be performed by a UE, such as the remote unit 105, the UE, and / or the user equipment device 700 and / or a network entity, such as a base station node, gNB, and / or the network equipment device 800, as described herein. In some embodiments, the method 1000 can be performed by a processor executing program code, such as a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.

[0155] In one embodiment, the method 1000 includes receiving 1005, at a network function of a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE, a key request for provisioning an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network to establish a connection between the UE and the AF. In one embodiment, the method 1000 includes sending 1010, to a network function of the HPLMN, a key response, and the method 1100 ends.

[0156] A first device for roaming using authentication and key management for applications is disclosed. The first device can include a UE as described herein, e.g., the remote unit 105, the UE, and / or the user equipment device 700 and / or a network entity such as a base station node, gNB, and / or the network equipment device 800. In some embodiments, the first device can include a processor executing program code, e.g., a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, or the like.

[0157] In one embodiment, the first device includes a processor that determines a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE. In one embodiment, the processor selects a network function within the serving network for provisioning an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network. In one embodiment, the first device includes a transceiver that sends the security context to the network function.

[0158] In one embodiment, the processor determines the serving network of the UE by detecting that the UE is in a serving network. In one embodiment, the processor generates an AKMA key information K AKMA and an AKMA key identifier A-KID. In one embodiment, the transceiver sends, to the selected network function based on the serving network name, a registration request message comprising the AKMA security context including the K AKMA , the A-KID, and a subscription permanent identifier (“SUPI”) of the UE. In one embodiment, the transceiver receives, from the selected network function, a registration response message for establishing a connection between the UE and the AF of the serving network.

[0159] In one embodiment, the selected network function comprises one of an Access and Mobility Management Function (“AMF”) and a Visited AKMA Anchor Function (“V-AAnF”). In one embodiment, the processor determines the serving network for the UE by at least one of querying an Authentication Server Function (“AUSF”) of the HPLMN for the serving network name, retrieving the serving network name during primary authentication with the UE, and receiving the serving network name from the AUSF along with the AKMA key information K AKMA .

[0160] In one embodiment, the serving network name is received from the AUSF in response to a serving network name request comprising a Subscription Permanent Identifier (“SUPI”) of the UE.

[0161] In one embodiment, the transceiver sends a key provisioning request to the selected network function within the serving network, the key provisioning request comprising the AKMA security context including AKMA AF K AF key information, an expiration time of the K AF , a Subscription Permanent Identifier (“SUPI”) of the UE, and an AKMA key identifier A-KID. In one embodiment, the transceiver receives a key provisioning response message from the selected network function.

[0162] In one embodiment, the transceiver receives a key request from an AF at a network function of the HPLMN associated with the UE, the key registration request for provisioning the AF with the AKMA security context for establishing a connection between the UE and the AF of the serving network. In one embodiment, the processor detects that the serving network comprising the VPLMN different from the HPLMN associated with the UE does not use a network function enhancement within the serving network for provisioning the AKMA security context. In one embodiment, the transceiver sends a key response to the AF, the key response comprising an indication of NULL encryption and a Subscription Permanent Identifier (“SUPI”) of the UE.

[0163] In one embodiment, the transceiver receives an AKMA key information request for the AKMA AF K AF from the serving network. In one embodiment, the processor validates the AKMA key information request. In one embodiment, in response to validating the AKMA key information request, the processor generates the AKMA AF K AF , and the transceiver sends the AKMA AF K AFand the K AF AKMA key information response.

[0164] A first method for enabling roaming using authentication and key management for applications is disclosed. The first method can be performed by a UE, such as the remote units 105, the UE 115, and / or the user equipment apparatus 700 and / or a network entity, such as a base station node, gNB, and / or the network equipment apparatus 800, as described herein. In some embodiments, the first method can be performed by a processor, such as a microcontroller, a microprocessor, a CPU, a GPU, an auxiliary processing unit, a FPGA, or the like, executing program code.

[0165] In one embodiment, the first method includes determining a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) that is different from a home PLMN (“HPLMN”) associated with the UE. In one embodiment, the first method includes selecting a network function within the serving network for providing an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network. In one embodiment, the first method includes sending the security context to the network function.

[0166] In one embodiment, the first method includes determining the serving network of the UE by detecting that the UE is in a serving network. In one embodiment, the first method includes generating an AKMA key information K AKMA and an AKMA key identifier A-KID. In one embodiment, the first method includes sending a registration request message to the selected network function based on the serving network name, the registration request message comprising the AKMA security context including the K AKMA , the A-KID, and a subscription permanent identifier (“SUPI”) of the UE. In one embodiment, the first method includes receiving a registration response message from the selected network function for establishing a connection between the UE and the AF of the serving network.

[0167] In one embodiment, the selected network function comprises one of an access and mobility management function (“AMF”) and a visited AKMA anchor function (“V-AAnF”). In one embodiment, the first method includes determining the serving network of the UE by at least one of querying an authentication server function (“AUSF”) of the HPLMN for the serving network name, retrieving the serving network name during primary authentication with the UE, and receiving the serving network name and the AKMA key information K AKMA from the AUSF.

[0168] In one embodiment, the service network name is received from the AUSF in response to a service network name request, the service network name request including a subscription permanent identifier (“SUPI”) of the UE.

[0169] In one embodiment, the first method includes sending a key provisioning request to the selected network function within the service network, the key provisioning request including the AKMA security context including AKMA AF K AF key information, an expiration time of the K AF , a subscription permanent identifier (“SUPI”) of the UE, and an AKMA key identifier A-KID. In one embodiment, the first method includes receiving a key provisioning response message from the selected network function.

[0170] In one embodiment, the first method includes receiving a key request at a network function of the HPLMN associated with the UE from an AF, the key registration request for providing the AKMA security context to the AF for establishing a connection between the UE and the AF of the service network. In one embodiment, the first method includes detecting that the service network including the VPLMN different from the HPLMN associated with the UE does not use a network function enhancement within the service network for providing the AKMA security context. In one embodiment, the first method includes sending a key response to the AF, the key response including an indication of NULL encryption and a subscription permanent identifier (“SUPI”) of the UE.

[0171] In one embodiment, the first method includes receiving an AKMA key information request for the AKMA AF K AF from the service network. In one embodiment, the first method includes verifying the AKMA key information request. In one embodiment, in response to verifying the AKMA key information request, the first method includes generating the AKMA AF K AF , and sending an AKMA key information response to the service network including the AKMA AF K AF and an expiration time of the K AF .

[0172] A second device that discloses roaming using authentication and key management for applications is disclosed. The second device can include a UE as described herein, e.g., a remote unit 105, a UE, and / or user equipment apparatus 700 and / or a network entity, e.g., a base station node, gNB, and / or network equipment apparatus 800. In some embodiments, the second device can include a processor executing program code, e.g., a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.

[0173] In one embodiment, the second device includes a transceiver that receives, at a network function of a serving network of a user equipment (“UE”) device, a key request, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE, the key registration request for providing an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network to establish a connection between the UE and the AF. In one embodiment, the transceiver sends a key response to a network function of the HPLMN.

[0174] In one embodiment, the second device includes a processor that stores security context information at the network function of the serving network. In one embodiment, the network function of the serving network comprises one of an access and mobility management function (“AMF”) and a visited AKMA anchor function (“V-AAnF”).

[0175] In one embodiment, the second device includes a processor that detects, based on an AKMA key identifier A-KID, that the key request is from an AAnF in the HPLMN. In one embodiment, the transceiver sends the key request to the AAnF in the HPLMN and receives a key response from the AAnF of the HPLMN comprising AKMA AF K AF AF information and an expiration time of the K

[0176] A second method that discloses roaming using authentication and key management for applications is disclosed. The second method can be performed by a UE as described herein, e.g., a remote unit 105, a UE, and / or user equipment apparatus 700 and / or a network entity, e.g., a base station node, gNB, and / or network equipment apparatus 800. In some embodiments, the second method can be performed by a processor executing program code, e.g., a microcontroller, microprocessor, CPU, GPU, auxiliary processing unit, FPGA, etc.

[0177] ​In one embodiment, the second method includes receiving, at a network function of a serving network of a user equipment (“UE”) device, a key request, the serving network comprising a visited public land mobile network (“VPLMN”) different from a home PLMN (“HPLMN”) associated with the UE, the key registration request for provisioning an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name of the serving network to provide authentication of an application and a AKMA security context for establishing a connection between the UE and the AF. In one embodiment, the second method includes sending a key response to a network function of the HPLMN.

[0178] In one embodiment, the second method includes storing, at the network function of the serving network, security context information. In one embodiment, the network function of the serving network comprises one of an access and mobility management function (“AMF”) and a visited AKMA anchor function (“V-AAnF”).

[0179] In one embodiment, the second method includes detecting, based on an AKMA key identifier A-KID, that the key request is from an AAnF in the HPLMN. In one embodiment, the second method includes sending the key request to the AAnF in the HPLMN and receiving a key response from the AAnF of the HPLMN comprising AKMA AF K AF AF information and an expiration time of the K

[0180] Embodiments can be practiced in other specific forms. The described embodiments are to be considered in all respects only as illustrative and not restrictive. The scope of the application is, therefore, indicated by the appended claims rather than by the description. All changes coming within the meaning and equivalency range of the claims are to be embraced within their scope.​

Claims

1. A method for a network device, comprising: receiving a name of a serving network of a user equipment (UE) from an authentication server function (AUSF) in a home public land mobile network (HPLMN), the name of the serving network being received as part of an applied authentication and key management (AKMA) key registration request; determining, based on the name of the serving network, that the UE is roaming in a visited PLMN (VPLMN) different from the HPLMN associated with the UE; selecting, based on the received name of the serving network, a network function within the serving network for providing an AKMA security context to an application function (AF), wherein at least one AKMA capability and an address of the network function of the VPLMN are configured based on at least one service level agreement (SLA) associated with the HPLMN; and sending the AKMA security context to the network function.

2. The method of claim 1, further comprising: Generating AKMA key information K AKMA and an AKMA key identifier A-KID; sending a registration request message to the selected network function based on the name of the service network, the registration request message including the AKMA security context containing the K AKMA , the A-KID, and a subscription permanent identifier (SUPI) of the UE; and receiving, from the selected network function, a registration response message for establishing a connection between the UE and the AF of the serving network.

3. The method of claim 2, wherein the selected network function comprises one of an access and mobility management function (AMF) and a visited AKMA anchor function (V-AAnF).

4. The method of claim 1, wherein determining the serving network of the UE comprises at least one of: querying an authentication server function (AUSF) of the HPLMN for the name of the serving network; retrieving the name of the serving network during primary authentication with the UE; and receiving, from the AUSF, the name of the service network and the AKMA key information K AKMA .

5. The method of claim 4, wherein the receiving the name of the serving network from the AUSF is in response to a serving network name request, the serving network name request comprising a subscription permanent identifier (SUPI) of the UE.

6. The method of claim 4, further comprising: sending a key provisioning request to the selected network function within the service network, the key provisioning request including the AKMA security context containing AKMA AF key information K AF , an expiration time of the K AF , a subscription permanent identifier SUPI of the UE, and an AKMA key identifier A-KID; and receiving, from the selected network function, a key provisioning response message.

7. The method of claim 4, further comprising: receiving, at a network function of the HPLMN associated with the UE, a key request from an AF, the key registration request for providing the AKMA security context to the AF for establishing a connection between the UE and the AF of the serving network; detecting that the serving network does not use a network function enhancement within the serving network for providing the AKMA security context, the serving network comprising the VPLMN different from the HPLMN associated with the UE; and sending, to the AF, a key response, the key response comprising an indication of NULL encryption and a subscription permanent identifier (SUPI) of the UE.

8. The method of claim 1, further comprising: verifying the AKMA key information request; and receiving, from the service network, an AKMA key information request for the K AF of the UE; 9. A network device, comprising: a processor; and In response to verifying the AKMA key information request, generating the K AF , and sending, to the service network, an AKMA key information response including the K AF , the K AF , and an expiration time of the K AF . a memory coupled to the processor, the memory comprising instructions executable by the processor to cause the network device to: ​ ​ ​ receive, from an authentication server function (AUSF) in a home public land mobile network (HPLMN), a name of a serving network of a user equipment (UE), the name of the serving network received as part of an applied authentication and key management for applications (AKMA) key registration request; determine, based on the name of the serving network, that the UE is roaming in a visited PLMN (VPLMN) different from the HPLMN associated with the UE; and select, based on the received name of the serving network, a network function within the serving network for providing an AKMA security context for an application function (AF), wherein at least one AKMA capability and an address of the network function of the VPLMN are configured based on at least one service level agreement (SLA) associated with the HPLMN; and send, to the network function, the AKMA security context.

10. The network device of claim 9, wherein the instructions are executable by the processor to cause the device to: receive, from the selected network function, a registration response message for establishing a connection between the UE and the AF of the serving network. Generating AKMA key information K AKMA and an AKMA key identifier A-KID; sending a registration request message to the selected network function based on the name of the service network, the registration request message including the AKMA security context containing the K AKMA , the A-KID, and a subscription permanent identifier (SUPI) of the UE; and 11. The network device of claim 10, wherein the selected network function comprises one of an access and mobility management function (AMF) and a visited AKMA anchor function (V-AAnF).

12. The network device of claim 9, wherein the instructions are executable by the processor to cause the device to determine the serving network of the UE by at least one of: querying an authentication server function (AUSF) of the HPLMN for the name of the serving network; retrieving the name of the serving network during primary authentication with the UE.

13. The network device of claim 12, wherein the receiving the name of the serving network from the AUSF is in response to a serving network name request, the serving network name request comprising a subscription permanent identifier (SUPI) of the UE. receiving, from the AUSF, the name of the service network and the AKMA key information K AKMA .

14. The network device of claim 13, wherein the instructions are executable by the processor to cause the network device to: receive, from an AF at a network function of the HPLMN associated with the UE, a key request, the key registration request for providing the AKMA security context for the AF for establishing a connection between the UE and the AF of the serving network; detect that the serving network does not use a network function enhancement within the serving network for providing the AKMA security context, the serving network comprising the VPLMN different from the HPLMN associated with the UE; and send, to the AF, a key response, the key response comprising an indication of NULL encryption and a subscription permanent identifier (SUPI) of the UE.

15. A network device comprising: a processor; and a memory coupled to the processor comprising instructions executable by the processor to cause the network device to: receive, from an authentication server function (AUSF) in a home public land mobile network (HPLMN), a name of a serving network of a user equipment (UE), the name of the serving network received as part of an applied authentication and key management for applications (AKMA) key registration request; determine, based on the name of the serving network, that the UE is roaming in a visited PLMN (VPLMN) different from the HPLMN associated with the UE; and select, based on the received name of the serving network, a network function within the serving network for providing an AKMA security context for an application function (AF), wherein at least one AKMA capability and an address of the network function of the VPLMN are configured based on at least one service level agreement (SLA) associated with the HPLMN; and send, to the network function, the AKMA security context. receiving, at a network function of a serving network of a user equipment, UE, the serving network comprising a visited public land mobile network, VPLMN, different from a home PLMN, HPLMN, associated with the UE, a key registration request for providing an authentication and key management, AKMA, security context for an application function, AF, based on a name of the serving network for an application to establish a connection between the UE and the AF; storing, at the network function of the VPLMN, the AKMA security context for a request associated with lawful interception, wherein at least one AKMA capability and an address of the network function of the VPLMN are configured based on at least one service level agreement, SLA, associated with the HPLMN; and sending, to a network function of the HPLMN, a key response.

16. The network device of claim 15, wherein the network function of the serving network comprises one of an access and mobility management function, AMF, and a visited AKMA anchor function, V-AAnF.

17. The network device of claim 15, wherein the instructions are executable by the processor to cause the network device to: detect, based on an AKMA key identifier, A-KID, that the key registration request is from an AKMA anchor function, AAnF, in the HPLMN; send, to the AAnF in the HPLMN, a second key registration request; and ​ receiving, from the AAnF in the HPLMN, a key response including AKMA AF key information K AF and an expiration time of the K AF .