Security in distributed NAS termination architecture

By introducing a hierarchy of anchor keys, NAS parent keys and child keys into the distributed NAS termination architecture, combined with the secure key management function (SKMF), the problem of difficulty in ensuring the security of multiple NAS connections in the distributed NAS termination architecture is solved, and higher NAS connection security and integrity are achieved.

CN120077689APending Publication Date: 2025-05-30NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280100975.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-08-10
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In a distributed NAS termination architecture, prior art is difficult to effectively protect the security of multiple NAS connections, especially if the NAS connection is terminated across multiple different network functions (NFs).

Method used

By introducing a hierarchy of anchor keys, NAS parent keys and NAS child keys, combined with the Secure Key Management Function (SKMF), secure key management and distribution of NAS connections are realized. The specific steps include generating the anchor key, derive the NAS parent key and child key, and establishing and maintaining the security context of the NAS connection based on these keys.

Benefits of technology

This solution improves the security of NAS connections in distributed NAS termination architecture, reduces the attack surface through key separation and management, and enhances the integrity and confidentiality of NAS connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120077689A_ABST
    Figure CN120077689A_ABST
Patent Text Reader

Abstract

Various embodiments provide a method and apparatus for security in a distributed NAS termination architecture. In an embodiment, a method performed by a terminal device comprises: generating an anchor key; receiving an anchor key identifier for the anchor key; deriving a set of non-access stratum (NAS) parent keys based on the anchor key, the subscription identifier, and NAS indicators indicating different NAS processes; and obtaining an NAS parent key identifier for each NAS parent key in the set of NAS parent keys.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure generally relate to wireless communication, and more particularly, to methods and apparatuses for security in a distributed NAS termination architecture. Background Art

[0002] In a 5G system architecture, as defined in 3GPP TS23.501, the non-access stratum (NAS) connection for a user equipment (UE) is always terminated at a single network function (NF) in the serving network, such as an access and mobility management function (AMF), as Figure 1 shown. The integrity and confidentiality of the NAS connection are protected by a security procedure executed between the UE and the NF, which establishes a NAS security context that is maintained by both the UE and the NF during the life cycle of the NAS connection. Among other parameters, this NAS security context also includes security keys and algorithms for protecting the NAS connection.

[0003] On the other hand, in a distributed NAS termination architecture, a UE may have multiple NAS connections that are terminated at multiple different NFs in the serving network. That is, the NAS connections are distributed among different NFs depending on the NAS procedures supported by the NAS connections, as Figure 2 shown. As an example, a UE may have two NAS connections terminated at two different NFs, one NAS connection carrying NAS mobility management procedures and terminated at NF1, and another NAS connection carrying NAS session management procedures and terminated at NF2. Summary of the Invention

[0004] This Summary of the Invention is provided to introduce a simplified concept of subnet configuration and procedures for enabling subnet operations, particularly with respect to subnet identification. This Summary of the Invention is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0005] According to a first aspect of the present disclosure, a terminal device is provided. The terminal device includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the terminal device to at least: generate an anchor key; receive an anchor key identifier for the anchor key; derive a non-access stratum NAS parent key set based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures; and obtain a NAS parent key identifier for each NAS parent key in the NAS parent key set.

[0006] According to a second aspect of the present disclosure, a network entity is provided, which is configured to implement a Security Key Management Function (SKMF). The network entity includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network entity to at least: generate an anchor key for a terminal device; derive an anchor key identifier for the anchor key and send the anchor key identifier to the terminal device; derive a set of NAS parent keys based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures; and derive a NAS parent key identifier for each NAS parent key in the set of NAS parent keys based on the corresponding NAS indicator.

[0007] According to a third aspect of the present disclosure, a core network entity is provided, which is configured to implement core network functions. The core network entity includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the network entity to at least: receive from a terminal device a request to establish a NAS connection carrying a NAS procedure between the terminal device and the core network entity; and obtain a NAS key for the NAS connection, where the NAS key is a NAS parent key or a NAS child key associated with a NAS indicator indicating a NAS procedure.

[0008] According to a fourth aspect of the present disclosure, a method performed by a terminal device is provided. The method includes: generating an anchor key; receiving an anchor key identifier for the anchor key; deriving a set of non-access stratum (NAS) parent keys based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures; and obtaining a NAS parent key identifier for each NAS parent key in the set of NAS parent keys.

[0009] According to a fifth aspect of the present disclosure, a method performed by a network entity configured to implement a Security Key Management Function (SKMF) is provided. The method includes: generating an anchor key for a terminal device; deriving an anchor key identifier for the anchor key and sending the anchor key identifier to the terminal device; deriving a set of non-access stratum (NAS) parent keys based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures; and deriving a NAS parent key identifier for each NAS parent key in the set of NAS parent keys based on the corresponding NAS indicator.

[0010] According to a sixth aspect of the present disclosure, a method performed by a core network entity configured to implement core network functions is provided. The method includes: receiving from a terminal device a request to establish a NAS connection carrying a NAS procedure between the terminal device and the core network entity; and obtaining a NAS key for the NAS connection, where the NAS key is a NAS parent key or a NAS child key associated with a NAS indicator indicating a NAS procedure.

[0011] According to a seventh aspect of the present disclosure, a terminal device is provided. The terminal device includes components for performing the steps of any of the methods according to the fourth aspect.

[0012] According to an eighth aspect of the present disclosure, a network entity is provided, which is configured to implement a Security Key Management Function (SKMF). The network entity includes components for performing the steps of any of the methods according to the fifth aspect.

[0013] According to a ninth aspect of the present disclosure, a core network entity is provided, which is configured to implement core network functions. The core network entity includes components for performing the steps of any of the methods according to the sixth aspect.

[0014] According to a tenth aspect of the present disclosure, a computer-readable storage medium is provided, on which instructions are stored, and when the instructions are executed by at least one processor, the at least one processor is caused to execute any of the methods according to the fourth or fifth or sixth aspect.

[0015] According to an eleventh aspect of the present disclosure, a computer program product is provided, which includes instructions, and when the instructions are executed by at least one processor, the at least one processor is caused to execute any of the methods according to the fourth or fifth or sixth aspect.

[0016] It should be understood that the Summary section is not intended to identify key or essential features of the embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Through the following description, other features of the present disclosure will become readily understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Some example embodiments will now be described with reference to the drawings, in which:

[0018] Figure 1 An example of a single NAS termination in a 5G system architecture is shown;

[0019] Figure 2 An example of a distributed NAS termination architecture is shown;

[0020] Figure 3 An example of a key hierarchy for a distributed NAS termination architecture according to some embodiments of the present disclosure is shown;

[0021] Figure 4 Another example of a key hierarchy for a distributed NAS termination architecture according to some embodiments of the present disclosure is shown;

[0022] Figure 5Shows yet another example of a key hierarchy for a distributed NAS termination architecture according to some embodiments of the present disclosure;

[0023] Figure 6 Shows yet another example of a key hierarchy for a distributed NAS termination architecture according to some embodiments of the present disclosure;

[0024] Figure 7 Is an exemplary call flow for protecting multiple NAS connections according to some embodiments of the present disclosure;

[0025] Figure 8 Shows a security architecture for a distributed NAS termination architecture according to some embodiments of the present disclosure;

[0026] Figure 9 Shows a security framework for a distributed NAS termination architecture according to some embodiments of the present disclosure;

[0027] Figure 10 Is another exemplary call flow for protecting multiple NAS connections according to some embodiments of the present disclosure;

[0028] Figure 11 Is a flowchart depicting a method for security in a distributed NAS termination architecture according to some embodiments of the present disclosure;

[0029] Figure 12 Is a flowchart depicting a method for security in a distributed NAS termination architecture according to some embodiments of the present disclosure;

[0030] Figure 13 Is a flowchart depicting a method for security in a distributed NAS termination architecture according to some embodiments of the present disclosure; and

[0031] Figure 14 Shows a simplified block diagram of a device according to some embodiments of the present disclosure. Detailed Description

[0032] Some example embodiments will be described more fully hereinafter with reference to the accompanying drawings, in which some, but not all embodiments are shown. In fact, the example embodiments may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will satisfy applicable legal requirements. Like reference numerals refer to like elements throughout.

[0033] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0034] References to "one embodiment", "an embodiment", "example embodiment", etc. in this disclosure indicate that the embodiment may include a particular feature, structure, or characteristic, but not necessarily every embodiment includes the particular feature, structure, or characteristic. Additionally, these phrases do not necessarily refer to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an example embodiment, it should be considered within the knowledge of those skilled in the art to combine such feature, structure, or characteristic with other embodiments, whether or not explicitly described.

[0035] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the example embodiment. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0036] The terms used herein are for the purpose of describing particular embodiments only and are not intended to limit the example embodiments. As used herein, unless the context clearly dictates otherwise, the singular forms "a", "an", and "the" are also intended to include the plural forms. It will also be understood that the terms "comprises", "comprising", "has", "having", "includes", and / or "including", when used herein, specify the presence of the stated features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0037] As used in this application, the term "circuitry" may refer to one or more or all of the following:

[0038] (a) Only hardware circuit implementations (such as, only implementations in analog and / or digital circuitry) and

[0039] (b) Combinations of hardware circuits and software, such as (where applicable):

[0040] (i) Combinations of (multiple) analog and / or digital hardware circuits and software / firmware and

[0041] (ii) Any portions of (multiple) hardware processors with software (including (multiple) digital signal processors), software, and (multiple) memories, which work together to enable a device (such as a mobile phone or a server) to perform various functions) and

[0042] (c) One or more hardware circuits and / or one or more processors, such as one or more microprocessors or portions of one or more microprocessors, which require software (e.g., firmware) to operate, but the software may not be present when the operation does not require software.

[0043] This definition of "circuitry" applies to all uses of the term in this application, including in any claims. As a further example, as used in this application, the term "circuitry" also encompasses implementations that are only hardware circuits or processors (or multiple processors) or portions of hardware circuits or processors and their (or their) attendant software and / or firmware. The term "circuitry" also encompasses, for example, if applicable to a particular claim element, a baseband integrated circuit or a processor integrated circuit for a mobile device or a similar integrated circuit in a server, a cellular network device, or other computing or network device.

[0044] As used herein, the term "communication network" refers to a network that follows any suitable communication standard, such as Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), New Radio (NR), etc. In addition, the communication between a terminal device and a network device in a communication network can be performed according to any suitable generation of communication protocol, including but not limited to the first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, 5G, future sixth generation (6G) communication protocols, and / or any other protocol currently known or to be developed in the future. Embodiments of the present disclosure can be applied to various communication systems. Given the rapid development of communication, of course, there will also be future types of communication technologies and systems in which the present disclosure can be embodied. This should not be construed as limiting the scope of the present disclosure to only the above systems.

[0045] As used herein, the term "terminal device" refers to any terminal device that can access a communication network and receive services therefrom. By way of example and not limitation, the terminal device can also refer to a user equipment (UE), which can be a combination of a Universal Integrated Circuit Card (UICC) / Subscriber Identity Module (SIM) card and a mobile device (ME), or other suitable devices. In the following description, the terms "terminal device", "user equipment", and "UE" can be used interchangeably.

[0046] As used herein, the term "network entity" refers to any entity used to support network functions in a communication network. The network entity can be implemented in a physical network node or in a virtual network node that performs functions through logical resources in more than one physical network node.

[0047] As described above, the 5G system architecture defines in 3GPP specifications (e.g., TS 23.501 / 23.502 / 24.501 / 33.501) how security is implemented for a single NAS connection between a UE and a single NF. However, no solution is defined to implement security for multiple NAS connections in a distributed NAS termination architecture.

[0048] Accordingly, various embodiments of the present disclosure describe a framework for securing NAS connections in a distributed NAS termination architecture. Specifically, the framework provides a mechanism for the derivation and distribution of shared keys and associated key identifiers, which are used to secure the NAS connections established between a UE and a terminating NF.

[0049] First, a key hierarchy for a distributed NAS termination architecture is described. To assist in the description, an analogy to a subset of the current 5G architecture key hierarchy is provided, where the terms "anchor key" and "NAS parent key" are analogous to Kseaf and Kamf, respectively. However, there are multiple NAS parent keys, and Kamf can be considered one of the NAS parent keys. The NAS parent keys provide key separation for NAS connections carrying different NAS procedures (such as NAS mobility management procedures, NAS session management procedures, NAS UE policy management procedures, etc.).

[0050] Figure 3 An example of a key hierarchy for a distributed NAS termination architecture (Option 1) according to some embodiments of the present disclosure is shown, which includes a common anchor key and a common NAS parent key. Referring Figure 3 , a single anchor key Ka is established through an Authentication and Key Agreement (AKA) process, and this anchor key Ka is common to all NAS connections. This anchor key Ka is equivalent to the Kseaf key in the current 5G architecture key hierarchy. A single NAS parent key Kp is derived from the common anchor key Ka that is common to all NAS connections. Regardless of the number of NAS connections, this method requires running a single AKA process.

[0051] Option 1 is closely aligned with the current 5G architecture key hierarchy. However, when it is applied to a distributed NAS termination architecture, it has many drawbacks: a) Since the same NAS parent key Kp is used between different NAS connections, it may increase the attack surface and weaken NAS security, especially in the case of having multiple NAS termination points; and b) The same NAS parent key Kp needs to be distributed to multiple NFs, which increases the attack surface and weakens NAS security compared to 5G.

[0052] Figure 4Shows another example of a key hierarchy for a distributed NAS termination architecture (Option 2) according to some embodiments of the present disclosure, which includes a common anchor key Ka and multiple NAS parent keys Kp1, Kp2... Kpn. Refer to Figure 4 , the anchor key Ka is established through the AKA process, and this anchor key Ka is common to all NAS connections. This anchor key Ka is equivalent to the Kseaf key in the current 5G architecture key hierarchy. Multiple NAS parent keys Kp1, Kp2... Kpn are derived from this common anchor key Ka for each NAS connection. Regardless of the number of NAS connections, this method requires running a single AKA process.

[0053] Figure 5 Shows yet another example of a key hierarchy for a distributed NAS termination architecture (Option 3) according to some embodiments of the present disclosure, which includes multiple anchor keys and multiple NAS parent keys. Refer to Figure 5 , multiple anchor keys Ka1, Ka2,... Kan are established through the AKA process, with each NAS connection having one anchor key. These anchor keys Ka1, Ka2,... Kan are equivalent to multiple unique Kseaf keys derived from the Kausf key in the current 5G architecture key hierarchy. One NAS parent key is derived from each anchor key for each NAS connection. As Figure 5 shown, the NAS parent key Kp1 is derived from the anchor key Ka1, the NAS parent key Kp2 is derived from the anchor key Ka2, and the NAS parent key Kpn is derived from the anchor key Kan. This method requires running an AKA process for each NAS connection.

[0054] Options 2 and 3 propose using multiple NAS parent keys to provide a unique shared key for each NAS connection, so compared with Option 1 which has a common NAS parent key for all NAS connections, they provide better NAS security.

[0055] Option 3 may be considered to provide the strongest security because each NAS connection has its own anchor key and NAS parent key derived from the AKA run. However, Option 3 requires running the AKA process and signaling with the home network each time a new NAS connection is established, which may hinder the performance of the NAS process. In addition, it will also have an impact on the home network NFs (such as the authentication function (AUSF), unified data management (UDM), unified data repository (UDR)) and the UE (such as the universal integrated circuit card (UICC), mobile device (ME)) to derive, store, and manage multiple anchor keys.

[0056] Option 2 also supports multiple NAS parent keys, but due to the common anchor key, it only requires a single AKA procedure for multiple NAS connections and has no impact on the home network NFs (such as AUSF, UDM, UDR). Therefore, Option 2 is considered the best key hierarchy for a distributed NAS termination architecture and will be described in detail later. Additionally, the following description will be in the context of Option 2 and will also apply to Option 3.

[0057] Figure 6 Another example of a key hierarchy for a distributed NAS termination architecture according to some embodiments of the present disclosure is shown, where in addition to the common anchor key Ka and multiple NAS parent keys (such as Kp1, Kp2), NAS sub-keys are also proposed. While the NAS parent keys provide key separation for NAS connections carrying different NAS procedures, the NAS sub-keys provide key separation for NAS connections carrying the same NAS procedure (such as the NAS session management procedure). A UE may have two NAS protocol data unit (PDU) sessions and thus have two NAS connections belonging to different network slices, each slice having different security requirements. As Figure 6 shown, the NAS sub-keys Kc2-1 and Kc2-2 are derived from the NAS parent key Kp2 for the two NAS connections. The NAS sub-keys provide key separation between these two NAS connections. Note that the NAS sub-keys are mainly applied to the NAS session management procedure, but their use is not excluded for other NAS procedures.

[0058] Figure 7 is an exemplary call flow for protecting multiple NAS connections according to some embodiments of the present disclosure, which depicts a scenario where the UE registers in the network and subsequently establishes two different NAS connections, one connection carrying the NAS session management procedure and the other connection carrying the NAS UE policy management procedure. In this example, the call flow involves the UE, two core NFs (NF1 and NF2), and a security key management function (SKMF) similar to the security anchor function (SEAF) in 5G.

[0059] At step 1, the main AKA procedure is executed, which establishes an anchor key and a set of NAS parent keys in both the UE and the SKMF.

[0060] At step 2, the UE requests to establish NAS connection #1 by sending a NAS connection request #1 message (such as an initial NAS session management (SM) request), and the NAS connection request #1 message is routed to NF1. Since NF1 does not have a valid security context for NAS connection #1, it requests a key from the SKMF, for example, by sending a key request.

[0061] At step 3, based on the information provided in the key request from NF1, the SKMF can select the NAS parent key specific to the NAS SM procedure that has been derived, or alternatively derive a NAS child key from the selected NAS parent key, and return the NAS parent key or the NAS child key to NF1, e.g., in a key response.

[0062] At step 4, NF1 further derives the NAS integrity and encryption keys that will be used together with the selected NAS integrity and encryption algorithms to protect NAS connection #1 using the received key. NF1 sends a NAS security mode command message to the UE.

[0063] At step 5, based on the NAS security mode command message received from NF1, the UE can select the NAS parent key specific to the NAS SM procedure that has been derived, or alternatively derive a NAS child key from the selected NAS parent key, and further derive the NAS integrity and encryption keys as derived at NF1 using the NAS parent key or the NAS child key. The UE fills the complete NAS connection request #1 message into a NAS security mode complete message, protects the NAS security mode complete message using the NAS integrity and encryption keys, and sends the encrypted and integrity-protected NAS security mode complete message to NF1.

[0064] At step 6, NF1 performs a security check on the received NAS security mode complete message using its NAS integrity and encryption keys, extracts the complete NAS connection request #1 message, processes it and returns a NAS connection response #1 to the UE. At this point, a security context is established between the UE and NF1 for NAS connection #1 using the derived NAS integrity and encryption keys and the selected NAS integrity and encryption algorithms.

[0065] At step 7, the UE requests the establishment of NAS connection #2 by sending a NAS connection request #2 message (e.g., an initial NAS UE policy request), and the NAS connection request #2 message is routed to NF2. Since NF2 does not have a valid security context for this NAS connection, it requests a key from the SKMF by sending a key request to the SKMF.

[0066] At step 8, based on the information provided in the key request from NF2, the SKMF can select the derived NAS parent key specific to the NAS UE policy management procedure, or alternatively derive a NAS child key from the selected NAS parent key, and return the NAS parent key or the NAS child key to NF2.

[0067] At step 9, NF2 further derives NAS integrity and encryption keys to be used together with the selected NAS integrity and encryption algorithms using the received key to protect NAS connection #2. NF2 sends a NAS security mode command message to the UE.

[0068] At step 10, based on the NAS security mode command message received from NF2, the UE can select the derived NAS parent key specific to the NAS UE policy management process, or alternatively derive a NAS child key from the selected NAS parent key, and further derive the NAS integrity and encryption keys as derived at NF2 using the NAS parent key or NAS child key. The UE fills the complete NAS connection request #2 message into the NAS security mode complete message, protects the NAS security mode complete message using the NAS integrity and encryption keys, and sends the encrypted and integrity-protected NAS security mode complete message to NF2.

[0069] At step 11, NF2 performs a security check on the received NAS security mode complete message using its NAS integrity and encryption keys, extracts the complete NAS connection request #2 message, processes it and returns a NAS connection response #2 to the UE. At this time, a security context is established between the UE and NF2 for NAS connection #2 using the derived NAS integrity and encryption keys and the selected NAS integrity and encryption algorithms.

[0070] Subsequent NAS message exchanges related to NAS connection #1 and NAS connection #2 are protected by their respective security contexts, which remain after an idle connection mode transition, so there is no need to re-run the NAS security mode command process.

[0071] Embodiments of the present disclosure will provide the following novel aspects:

[0072] · NAS parent keys, NAS parent key identifiers (KI) and how they are derived and used;

[0073] · NAS child keys, NAS child key identifiers and how they are derived, distributed and used;

[0074] · HASH concept

[0075] · Enhancement of the NAS security mode command (SMC) process to support new parameters

[0076] · Enhancement of the SEAF function to support NAS parent / child key derivation and distribution as an independent NF, i.e., SKMF;

[0077] ·Enhancement of UE functions to support NAS parent / child key derivation, enhancement of the NAS SMC process, consideration of new temporary identifiers (such as MM-GUTI (Mobility Management - Globally Unique Temporary Identifier) or its shortened version MM-S-TMSI (Mobility Management - Short - Temporary Mobile Subscriber Identity), SM-GUTI (Session Management - Globally Unique Temporary Identifier) / SM-S-TMSI, etc.) handling for multiple NAS terminations;

[0078] ·Enhancement of the key hierarchy in the network and UE;

[0079] ·Enhancement of NF to support NAS termination and support enhanced SMC process, HASH parameter setting / generation, key request process, UE capability request process;

[0080] ·Interfaces and processes (request / response, subscription / notification) based on a new key management service for NF - to - NF communication (such as NF - NF and NF - SKMF communication). Services include key derivation request, new key derivation notification (AKA run), authentication request, and UE registration request;

[0081] ·Enhancement of the primary authentication process to include NAS parent key derivation and optional NAS parent key identifier derivation;

[0082] ·Newly defined initial NAS messages and minimum mandatory information elements.

[0083] Some aspects described in this document can utilize and extend the following functions and processes in 3GPP specifications, such as:

[0084] ·NAS security mode command process defined in 3GPP TS 33.501;

[0085] ·Key hierarchy defined in 3GPP TS 33.501;

[0086] ·NAS container used in N2 handover in 3GPP TS 33.501.

[0087] ·Authentication process defined in 3GPP TS 33.501

[0088] It should also be noted that the specification numbers for 6G systems and security are unknown at the time of this disclosure.

[0089] Figure 8 A security architecture for a distributed NAS termination architecture according to some embodiments of the present disclosure is shown. As Figure 8 shown, the security architecture involves the UE, multiple core NFs, and SKMF.

[0090] On the network side, the SKMF in the serving network supports the derivation and management of anchor / NAS parent / NAS child keys and key identifiers (KI). The SKMF is proposed to incorporate and extend the currently defined SEAF functionality to additionally support a standardized set of services that will enable the (multiple) core NFs to obtain NAS parent / child keys and key identifiers, as well as subscribe to and receive notifications when new security keys are derived, such as when a new anchor / NAS parent key is derived as a result of a successful master AKA run.

[0091] In terms of deployment, the SKMF can be:

[0092] Option 1: Deployed as a stand-alone SKMF in a centralized location and expose its services via the service-based interface (SBI) and services. As a stand-alone deployment, it offers flexibility in terms of deployment location, security, performance, and scalability;

[0093] Option 2: Co-located with the core NF that processes the NAS mobility management procedures. This option may bring optimization in terms of signaling load.

[0094] Defining the key management service set and exposing these services via the SBI provides the greatest flexibility and supports deployment options.

[0095] In some embodiments, the core NF may terminate the (multiple) NAS connections and store and manage the NAS security context for each NAS connection, which includes the anchor key identifier, NAS parent key identifier, NAS child key, NAS child key identifier, NAS algorithm, NAS integrity and encryption keys, and NAS count. The core NF may also support a HASH derivation function that is responsible for defining the input parameters and the derivation of the HASH value, which is provided to the UE and the SKMF to derive the NAS child key. The core NF may also support the NAS security mode command procedure and NAS container handling (during N2 handover).

[0096] In addition, in some embodiments, the core NF that terminates the NAS mobility management procedure has only a single NAS connection per access type at any point in time per UE. These core NFs are also responsible for the derivation and distribution of access stratum (AS) key material, as currently defined in 3GPP TS33.501, such as KgNB, NCC, NH, KN3IWF.

[0097] In some embodiments, a UE may have only a single NAS connection for NAS mobility management procedures at any point in time per access type, and may concurrently have zero, one, or more NAS connections for non-NAS mobility management procedures. In other words, NAS connections for non-NAS mobility management procedures may exist only when a NAS connection for NAS mobility management procedures has been established.

[0098] UE functionality may be extended to support NAS parent / child key and key identifier derivation and management, as well as extensions to the AKA procedure and NAS SMC / NAS container related procedures.

[0099] Some concepts mentioned in the embodiments of the present disclosure will be explained below.

[0100] 1. NAS Indicator

[0101] When a NAS connection is terminated across different types of core NFs depending on the NAS procedure carried by the NAS connection, it is assumed that the UE provides a NAS indicator (with a standardized value) to indicate the carried NAS procedure. For example, a NAS connection carrying a NAS mobility management procedure will be terminated at a core NF that supports the NAS mobility management procedure, and a NAS connection carrying a NAS session management procedure will be terminated at a core NF that supports the NAS session management procedure.

[0102] In some embodiments, the NAS indicator may be defined and standardized, and its value will indicate the supported NAS procedure. For example:

[0103] NAS indicator value "MM" = NAS mobility management procedure;

[0104] NAS indicator value "SM" = NAS session management procedure;

[0105] NAS indicator value "SMS" = NAS short message service (SMS) management procedure;

[0106] NAS indicator value "UEP" = NAS UE policy management procedure, etc.

[0107] In some embodiments, all values of the NAS indicator are inherently known to the UE and the network.

[0108] In some embodiments, the NAS indicator may be carried in a NAS message to identify the NAS procedure and may be used to make decisions regarding NF selection and security key derivation. The NAS indicator is also provided and visible to lower layers (e.g., radio resource control (RRC)) to enable access nodes to make decisions regarding NF discovery and selection.

[0109] In some embodiments, the NAS indicator may also be included in the NF profile to support, for example, the discovery and selection of the correct NF from the Network Repository Function (NRF).

[0110] 2. Security Key Hierarchy, Derivation, and Distribution

[0111] Figure 9 A security framework for a distributed NAS termination architecture according to some embodiments of the present disclosure is shown. For this security framework, the following concepts are introduced:

[0112] · Anchor key and anchor key identifier;

[0113] · NAS parent key and NAS parent key identifier;

[0114] · NAS child key and NAS child key identifier;

[0115] · HASH value.

[0116] 2.1 Anchor key and anchor key identifier

[0117] The anchor key and anchor key identifier can provide an anchor point for building the security for the distributed NAS termination architecture. The anchor key and anchor key identifier are similar to Kseaf and ngKSI correspondingly used in 5G, with the same AKA process but with some extensions / enhancements.

[0118] 2.2 NAS parent key and NAS parent key identifier

[0119] The NAS parent key can be independently derived by the UE and the SKMF from the anchor key, the Subscription Permanent Identifier (SUPI), and the NAS indicator. The NAS parent key identifier is associated with the NAS parent key and can be independently derived by the UE and the SKMF.

[0120] The purpose of the NAS parent key is to provide a shared key that is unique for NAS connections carrying the same type of NAS procedures. For example, a NAS connection carrying NAS mobility management procedures may have a different NAS parent key from a NAS connection carrying NAS session management procedures, etc.

[0121] In some embodiments, a new NAS parent key can also be horizontally derived by the UE and the SKMF by using the current NAS parent key and the NAS count value as inputs, for example, during an N2 handover. In this case, the new NAS parent key is identified by the existing NAS parent key identifier of the old NAS parent key.

[0122] In some embodiments, the value of the NAS parent key identifier may be the same as the NAS indicator value used to derive the NAS parent key. Since all NAS indicator values are standardized and thus known to both the UE and the SKMF, this ensures that both the UE and the SKMF can derive the same NAS parent key identifier for the NAS parent keys they derive accordingly.

[0123] An alternative way to generate the NAS parent key identifier is that the SKMF can assign a unique value to each NAS parent key identifier and provide this value and the associated NAS indicator to the UE during the AKA procedure. This method can allow the serving network to control the NAS parent key identifier value and remove the requirement to derive the NAS parent key identifier from the UE.

[0124] 2.3 NAS child keys and NAS child key identifiers

[0125] In some embodiments, the NAS child keys can be independently derived by the UE and the SKMF from the NAS parent key and the HASH value.

[0126] The purpose of the NAS child keys is to provide shared keys that are unique for NAS connections carrying the same type of NAS procedures. This is needed when a single type of NAS connection can be terminated in multiple core NF instances. For example, a NAS connection carrying NAS session management procedures may have two NAS PDU sessions, one session terminated at the core NF instance of the SM handling slice 1 and the other session terminated at the core NF instance of the SM handling slice 2. NAS child keys that are unique for both slice 1 and slice 2 can be derived.

[0127] In some embodiments, the NAS child key identifier associated with a particular NAS child key can be derived in the SKMF and subsequently provided to the UE in the NAS container during the NAS SMC procedure or during an N2 handover.

[0128] To enable the UE to derive the NAS child key, the following information is provided by the network to the UE:

[0129] · The anchor key identifier, used to check whether it is associated with the current and valid AKA run;

[0130] · The anchor key identifier and the NAS parent key identifier, used to identify the NAS parent key;

[0131] · The HASH value to be used with the NAS parent key to derive the NAS child key;

[0132] · The NAS child key identifier assigned to the derived NAS child key.

[0133] In some embodiments, the new NAS sub - key can also be derived horizontally by the UE and the SKMF, for example, during an N2 handover, by using the current NAS sub - key and the NAS count value as inputs. In this case, the new NAS sub - key can be identified by the existing NAS sub - key identifier of the old NAS sub - key.

[0134] To identify a specific key, one or more key identifiers may be required. For example, to identify an anchor key, only the anchor key identifier is needed. To identify a NAS parent key, the anchor key identifier and the NAS parent key identifier are required. And, to identify a NAS sub - key, the anchor key identifier, the NAS parent key identifier, and the NAS sub - key identifier are required.

[0135] 2.4 HASH Value

[0136] The purpose of the HASH value is to provide separation of NAS sub - keys. The HASH value is a value derived by the core NF from a specific set of input parameters, and the core NF can be configured to select from this specific set of input parameters and provide them to the UE and the SKMF. Each core NF may use the same or different sets of input parameters to derive the HASH value. The UE and the SKMF do not know how the HASH value is derived, which provides flexibility for the (multiple) mechanisms used to derive the HASH value.

[0137] In some embodiments, such input parameters can be single - network slice selection assistance information (S - NSSAI), PDU session ID, NF set ID, etc. The parameters used to generate the HASH value can be configured by the network and can thus be specific to the serving network operator. The HASH value can be transmitted to the UE as part of the enhanced NAS security mode command procedure so that the UE can derive the NAS sub - key.

[0138] Depending on how the HASH value is derived, the NAS sub - key can be used to protect either a single NAS connection or multiple NAS connections of the same NAS procedure group. For example, if the HASH value is derived based on the UE's PDU session ID, the NAS sub - key derived from that HASH value is only applicable to the NAS connection carrying that PDU session ID. On the other hand, if the HASH value is derived based on the S - NSSAI, the NAS sub - key derived from that HASH value will be common among the NAS connections associated with that S - NSSAI. In the latter case, even though the NAS sub - key returned from the SKMF to each core NF will be the same, the NAS sub - key identifier for the NAS sub - key will be unique among different NFs. The reason is that even though the NAS sub - key is initially the same when assigned by the SKMF, each NF can independently perform the horizontal key derivation of its NAS sub - key, which will result in a new NAS sub - key being derived, thus unique among each other, and in order for the UE to distinguish these NAS sub - keys, they need to have unique NAS sub - key identifiers.

[0139] If the HASH value is derived from a combination of the PDU session ID and the S - NSSAI, then the NAS sub - key derived from that HASH value will be dedicated to a specific NAS connection associated with that PDU session within that S - NSSAI. The HASH value and NAS sub - key / identifier concept provides a powerful, flexible, and scalable mechanism to dynamically derive security keys based on security requirements.

[0140] In order for the UE to obtain services from the network, the UE must first register with the network so that the UE and the network authenticate each other, and if successful, the UE will be authorized to use the services provided by the network based on its subscription. As part of the registration process, the UE performs the AKA process, which causes the UE and the network to derive an anchor key. Subsequently, the NAS parent key is also independently derived in the UE and the SKMF from the anchor key, the SUPI, and the NAS indicator(s).

[0141] The mechanism for establishing a security context for NAS connections between the UE and the network generally follows a common procedure. First, the core NF that receives the initial NAS message will create a HASH value and send a request to the SKMF to derive the NAS sub-key. If successful, the SKMF will return the derived NAS sub-key and the NAS sub-key identifier to the core NF. The core NF will use the same HASH value and the received NAS sub-key to generate security parameters, which will be used during the NAS security mode command procedure for the UE. The receipt of the NAS security mode command procedure triggers the UE to derive the NAS sub-key and assign the NAS identifier received from the core NF to it. If successful, both the UE and the core NF will have the same NAS sub-key and NAS sub-key identifier, which are used in combination with the agreed NAS integrity and encryption algorithms to integrity protect and encrypt the NAS connection between the UE and the core NF.

[0142] Figure 10 Another exemplary call flow for protecting multiple NAS connections according to some embodiments of the present disclosure describes a scenario in which the UE registers with the network and establishes a NAS connection for the NAS mobility management process, and then requests another NAS connection for the NAS session management process. This call flow explains how these NAS connections are protected.

[0143] At step 1, the UE initiates a registration request to the selected network and sends an initial NAS message (e.g., NAS MM registration request) in plain text (i.e., not security protected), with the minimum mandatory information elements (e.g., Subscription Concealed Identifier (SUCI) / Temporary ID, UE security capabilities, anchor key identifier, NAS indicator) to enable the network to process the request. The UE also provides the NAS indicator and the derived temporary identifier (MM-GUTI) to the lower layer (e.g., RRC) to enable the (R)AN to make a decision on the discovery and selection of the appropriate core NF for this NAS process. In this example, NF#1 is selected. The value of the NAS indicator will indicate the NAS mobility management process.

[0144] At step 2, NF#1 determines that UE authentication is required based on the received NAS registration request because, for example, the anchor key identifier indicates the absence of a valid anchor key, or the SUCI is received, or the temporary identifier is invalid or not found. Then, NF#1 sends an authentication request to the SKMF, which includes the SUCI, the serving network ID, and the NAS indicator.

[0145] At step 3, the SKMF triggers the primary AKA process with the UE, which, if successful, results in the following:

[0146] · The UE and the SKMF independently derive and store the anchor key;

[0147] · The SKMF derives and stores an anchor key identifier that identifies the anchor key and provides it to the UE, and the UE stores the anchor key identifier.

[0148] · The UE and the SKMF will independently use the anchor key and the standardized NAS indication value to derive the NAS parent key for key separation and store them.

[0149] · The UE and the SKMF will independently use the anchor key identifier and the standardized NAS indicator value to derive the NAS parent key identifier(s) for identifier separation and store them.

[0150] · After the NAS parent key and the NAS parent identifier are derived and stored, the anchor key is deleted from the UE and the SKMF, while the anchor key identifier is retained in the UE and the SKMF.

[0151] Note: The AKA process needs to be enhanced to accommodate the derivation of the NAS parent key and the NAS parent key identifier.

[0152] At step 4, the SKMF returns an authentication response to NF#1, which contains the anchor key identifier and the NAS parent key identifier associated with the NAS indicator provided in the authentication request.

[0153] At step 5, NF#1 sends a key request for this NAS connection to the SKMF, which contains the received anchor key identifier, the NAS parent key identifier, and optionally includes a HASH value. NF#1 can use the pre-configured information and the information provided by the UE to determine which parameters (such as S-NSSAI-x, NF SET-ID, etc.) are used as inputs to generate the HASH value.

[0154] In some scenarios, the NAS sub-key is beneficial for the MM process (e.g., mobility from one MM function to another, parallel dual-registered MM functions). However, in other scenarios, the NAS sub-key can be considered optional. In this call flow, for illustrative purposes, it is assumed that the NAS sub-key is required, but it is not mandatory for the MM process with distributed NAS termination.

[0155] At step 6, the SKMF uses the anchor key identifier to check whether it is associated with the current and valid AKA run, and uses the anchor key identifier and the NAS parent key identifier to identify the NAS parent key. If the HASH value is received, the SKMF can use it and the NAS parent key to derive the NAS child key and the NAS child key identifier. Then, if the HASH value is received, the SKMF can return the derived NAS child key, NAS child key identifier, and NAS parent key identifier to NF#1. If the HASH value is not received, the SKMF can return the identified NAS parent key to NF#1.

[0156] In some embodiments, the signaling between NF#1 and the SKMF can be optimized. Here, NF#1 refers to any NF that processes NAS mobility management procedures.

[0157] In some embodiments, the key request and response messages between NF#1 and the SKMF can be removed. The authentication request message can implicitly trigger the SKMF to return certain keys and associated key identifiers to NF#1 in the authentication response, which will optimize the signaling load by removing explicit key request / response messages.

[0158] This can be implemented as follows:

[0159] · The SKMF implicitly determines the NAS indicator associated with the authentication request because it is always associated with the NAS mobility management procedure, which will have its own standardized NAS indicator value, i.e., there is no need to include the NAS indicator in the authentication request;

[0160] · The SKMF uses the NAS indicator to derive the NAS parent key from the anchor key and the SUPI;

[0161] · The SKMF derives the NAS parent key identifier as usual, e.g., using the NAS indicator value;

[0162] · If no HASH value is provided, the SKMF returns the NAS parent key and the NAS parent key identifier to NF#1 in the authentication response;

[0163] · If the NAS child key is needed, the authentication request can include a HASH value that will allow the SKMF to derive and return the NAS child key and the NAS child key identifier to NF#1.

[0164] In some embodiments, NF#1 and the SMKF can be co-located. NF#1 and the SKMF can be deployed to be co-located as a single NF, which means the interaction between them is within the NF.

[0165] In some embodiments, if the SKMF is deployed as a stand-alone NF, the AKA procedure it performs on the UE may be executed indirectly via NF#1 or may directly bypass NF#1.

[0166] At step 7, based on the UE security capabilities received in step 1, NF#1 selects the highest-priority NAS integrity and encryption algorithms supported by the UE from the configured and prioritized list of supported NAS integrity and encryption algorithms. NF#1 uses the selected NAS integrity and encryption algorithm identifiers and the NAS sub-key or NAS parent key received from the SKMF to derive the NAS integrity key and the NAS encryption key.

[0167] NF#1 creates and sends a NAS security mode command message to the UE and starts the NAS downlink (DL) count for this NAS connection, which is initialized to zero. The NAS security mode command message may include the anchor key identifier, the NAS parent key identifier, the NAS sub-key identifier, the HASH value, the UE security capabilities, the selected NAS integrity and encryption algorithms, a flag requesting that the complete initial NAS message (e.g., NAS registration request) be returned in the NAS security mode complete message. The NAS security mode command message is integrity-protected by the NAS integrity key.

[0168] In addition, NF#1 may store the following information in its NAS security context for this NAS connection: the anchor key identifier, the NAS parent key identifier, the NAS sub-key identifier, the NAS sub-key, the HASH value, the UE security capabilities, the selected NAS integrity and encryption algorithms, the NAS integrity and encryption keys, and the NAS UL / DL count.

[0169] At step 8, from the received NAS security mode command message, the UE may use the anchor key identifier to check whether it is associated with the current and valid AKA run and use the anchor key identifier and the NAS parent key identifier to identify the NAS parent key. If the HASH value and the NAS sub-key identifier are received, the UE may use the HASH value and the NAS parent key to derive the NAS sub-key and assign the received NAS sub-key identifier to the derived NAS sub-key. Then, the UE may use the NAS parent key or the NAS sub-key and the selected NAS integrity and encryption algorithm identifiers to derive the NAS integrity and encryption keys. In addition, the UE may use the NAS integrity key and the NAS integrity algorithm to check the integrity of the received NAS security mode command message. Additionally, the UE may check the UE security capabilities to ensure that no protocol downgrading attack has occurred.

[0170] If all the checks pass, the UE can generate a NAS security mode complete message, which includes a complete registration request (triggered by the flag received in the NAS security mode command message). Then, the UE can encrypt and integrity protect the NAS security mode complete message using the selected NAS integrity and encryption algorithms and the NAS integrity and encryption keys. The UE can also prepare a NAS uplink (UL) counter initialized to zero for this NAS connection. Then, the UE sends the NAS security mode complete message to NF#1.

[0171] In addition, the UE can store the following information in its NAS security context for this NAS connection: anchor key identifier, NAS parent key identifier, NAS child key identifier, NAS child key, HASH value, UE security capabilities, selected NAS integrity and encryption algorithms, NAS integrity and encryption keys, and NAS UL / DL count.

[0172] At step 9, NF#1 performs an integrity check and decrypts the received NAS security mode complete message using the selected NAS integrity and encryption algorithms and the NAS integrity and encryption keys. If successful, the newly received complete initial NAS message (e.g., NAS registration request) is processed, and a NAS registration response is returned to the UE, which contains a UE temporary context identifier (MM-GUTI) for this NAS connection.

[0173] The MM-GUTI (or its abbreviated version MM-S-TMSI) identifier uniquely identifies the MM context of the UE within the NF and the NF itself. The UE MM context contains information such as the NAS security context for the UE's MM NAS connection. Note that the MM part of the MM-GUTI / MM-S-TMSI indicates that the context is related to the mobility management process (of which registration is a part). The UE context for the NAS session management (SM) process can be identified by the SM-GUTI / SM-S-TMSI.

[0174] For subsequent NAS mobility management processes related to this NAS connection, the NAS messages will contain the MM-GUTI / MM-S-TMSI temporary identifier to enable the identification of the serving NF and the UE context stored within that NF.

[0175] All subsequent NAS messages between the UE and NF#1 for this NAS connection are integrity protected and encrypted using the common security parameters / keys stored in the NAS security context in the UE and NF#1.

[0176] At step 10, after successful network registration, the UE can initiate a new NAS connection, for example, initiate the establishment of a PDU session using the NAS session management procedure. Similar to step 1, the initial NAS message is sent in plain text, with the minimum mandatory information elements to enable the network to process the request, and the (R)AN will use the NAS indicator provided by the UE to the lower layer, MM-GUTI / MM-S-TMSI, and S-NSSAI-y parameters to assist in selecting the appropriate core NF to handle the selection of the NAS session management procedure. In this case, the NAS indicator will indicate that the request is for the NAS session management procedure, and the (R)AN will select the core NF that supports those procedures. In this example, the core NF is NF#n. The mechanism by which the (R)AN can select the appropriate core NF may include: using the NAS indicator as a lookup key in a locally configured NF table, or querying the Network Repository Function (NRF).

[0177] In an embodiment, the initial NAS message for the NAS session management procedure may include: MM-GUTI, an anchor key identifier, a NAS parent key identifier associated with the NAS indicator for the NAS session management procedure, and the NAS indicator.

[0178] At step 11, NF#n can use the received MM-GUTI / MM-S-TMSI to confirm that the UE has been successfully registered to the network by sending a request identified from the MM-GUTI / MM-S-TMSI parameters to NF#1. The MM-GUTI / MM-S-TMSI can be provided to NF#1 to identify the UE context that NF#1 has stored for the UE.

[0179] At step 12, if it is confirmed that the UE has been successfully registered, NF#1 can return a success response to NF#n, which also includes the UE security capabilities.

[0180] At step 13, NF#n sends a key request for this NAS connection to the SKMF, which request contains the received anchor key identifier, NAS parent key identifier, and optionally includes a HASH value. In one embodiment, NF#n can use pre-configured information and information provided by the UE to determine which parameters (such as S-NSSAI-y, NF SET-ID, etc.) are used as inputs to generate the HASH value.

[0181] At step 14, the SKMF checks whether it is associated with the current and valid AKA run using the anchor key identifier, and uses the anchor key identifier and the NAS parent key identifier to identify the NAS parent key. If the HASH value is received, the SKMF can use it and the NAS parent key to derive the NAS child key and the NAS child key identifier. Then, if the HASH value is received, the SKMF can return the derived NAS child key, NAS child key identifier, and NAS parent key identifier to NF#n. If the HASH value is not received, the SKMF can return the identified NAS parent key to NF#n.

[0182] At step 15, NF#n can select the highest-priority NAS integrity and encryption algorithms supported by the UE from the configured, prioritized list of supported NAS integrity and encryption algorithms based on the received UE security capabilities. NF#n uses the selected NAS integrity and encryption algorithm identifiers and the NAS child key or NAS parent key received from the SKMF to derive the NAS integrity key and the NAS encryption key.

[0183] Then, NF#n can create and send a NAS security mode command message to the UE and start the NAS DL count for this NAS connection, which is initialized to zero. The NAS security mode command message can include the anchor key identifier, NAS parent key identifier, NAS child key identifier, HASH value, UE security capabilities, selected NAS integrity and encryption algorithms, a flag requesting that the complete initial NAS message (e.g., NAS PDU session request) be sent in the NAS security mode complete message. The NAS security mode command message is integrity protected by the NAS integrity key.

[0184] In addition, NF#n can store the following information in its NAS security context for this NAS connection: anchor key identifier, NAS parent key identifier, NAS child key identifier, NAS child key, HASH value, UE security capabilities, selected NAS integrity and encryption algorithms, NAS integrity and encryption keys, and NAS UL / DL count.

[0185] At step 16, from the received NAS security mode command message, the UE can use the anchor key identifier to check whether it is associated with the current and valid AKA run, and use the anchor key identifier and the NAS parent key identifier to identify the NAS parent key. If the HASH value and the NAS child key identifier are received, the UE can use the HASH value and the NAS parent key to derive the NAS child key and assign the received NAS child key identifier to the derived NAS child key. Then, the UE can use the NAS parent key or the NAS child key and the selected NAS integrity and encryption algorithm identifiers to derive the NAS integrity and encryption keys. In addition, the UE can use the NAS integrity key and the NAS integrity algorithm to check the integrity of the received NAS security mode command message. Additionally, the UE can check the UE security capabilities to ensure that no protocol downgrade attack has occurred.

[0186] If all the checks pass, the UE can generate a NAS security mode complete message, which includes the complete initial NAS message (e.g., NAS PDU session request), and the complete initial NAS message is triggered by the flags received in the NAS security mode command message. Then, the UE can encrypt and integrity protect the NAS security mode complete message using the selected NAS integrity and encryption algorithms and the NAS integrity and encryption keys. The UE can also prepare a NAS uplink (UL) counter initialized to zero for this NAS connection. Then, the UE sends the NAS security mode complete message to NF#n.

[0187] In addition, the UE can store the following information in its NAS security context for this NAS connection: the anchor key identifier, the NAS parent key identifier, the NAS child key identifier, the NAS child key, the HASH value, the UE security capabilities, the selected NAS integrity and encryption algorithms, the NAS integrity and encryption keys, and the NAS UL / DL count.

[0188] At step 17, NF#n performs integrity checking and decryption on the received NAS security mode complete message using the selected NAS integrity and encryption algorithms and the NAS integrity and encryption keys. If successful, the newly received complete initial NAS message (e.g., NAS PDU session request) is processed, and a NAS PDU session response is returned to the UE, which contains the UE temporary context identifier (SM-GUTI) for this NAS connection.

[0189] The SM-GUTI (or its abbreviated version SM-S-TMSI) identifier uniquely identifies the UE's SM context according to the NF where the UE is located and the UE SM context within that NF. The UE SM context contains information such as the NAS security context for the UE's SM NAS connection. Note that the SM part of the SM-GUTI / SM-S-TMSI indicates that the context is related to the NAS session management process.

[0190] For subsequent NAS PDU session management processes on this NAS connection, the NAS message will contain the SM-GUTI / SM-S-TMSI temporary identifier to enable the identification of the serving NF and the UE context stored within that NF.

[0191] All subsequent NAS messages for this NAS connection between the UE and NF#n are integrity protected and encrypted using the common security parameters / keys stored in the NAS security context in the UE and NF#n.

[0192] Note that NAS sub-keys and NAS sub-key identifiers, as well as HASH values, are mainly needed in cases where key separation is required between NAS connections that need to handle the same NAS process (e.g., two or more NAS connections handling NAS SM processes). In cases where such key separation is not required, such as for a single NAS connection for NAS MM processes, NAS parent keys and NAS parent key identifiers can be used. If there are two NAS connections handling the same NAS process, NAS parent keys and NAS parent key identifiers cannot be used, and NAS sub-keys and NAS sub-key identifiers must be used.

[0193] When NAS sub-keys and NAS sub-key identifiers are not used, i.e., NAS parent keys and NAS parent key identifiers are used to protect the NAS connection, HASH values, NAS sub-keys, and NAS sub-key identifiers are not derived / distributed in the UE and the network. The decision on whether NAS sub-keys and NAS sub-key identifiers are derived depends on the configuration of the core NF terminating the NAS connection. If the core NF is configured to provide the HASH value to the SKMF / UE for key derivation, NAS sub-keys and NAS sub-key identifiers are derived and used; otherwise, no NAS sub-keys and NAS sub-key identifiers are derived, and NAS parent keys and NAS parent key identifiers are used.

[0194] More details of an example embodiment according to the present disclosure will be described with reference to Figures 11 to 13 be described.

[0195] Figure 11It is a flowchart showing method 1100 for security in a distributed NAS termination architecture according to some embodiments of the present disclosure. Method 1100 can be executed by a terminal device (such as a UE) for handling the security of multiple NAS connections in a distributed NAS termination architecture.

[0196] As Figure 11 shown, at block 1110, the terminal device generates an anchor key with a network entity (hereinafter referred to as the SKMF entity, which can be used interchangeably with SKMF herein) configured to implement a security key management function (SKMF). In some embodiments, the terminal device and the SKMF entity can perform a primary AKA process to generate the anchor key.

[0197] At block 1120, the terminal device receives an anchor key identifier for the anchor key from the SKMF entity. As described above, the anchor key identifier can be used to identify the anchor key.

[0198] At block 1130, the terminal device derives a set of NAS parent keys based on the anchor key, the subscription identifier, and a NAS indicator indicating different NAS procedures. In some embodiments, the subscription identifier can be the SUPI. As described above, the NAS indicator can have different values for indicating different NAS procedures. Thus, the terminal device can obtain multiple NAS parent keys based on the anchor key, the subscription identifier (such as the SUPI), and the different values of the NAS indicator.

[0199] Then at block 1140, for each NAS parent key in the set of NAS parent keys, the terminal device obtains a NAS parent key identifier. In some embodiments, the terminal device can derive the NAS parent key identifier for the NAS parent key based on the NAS indicator from which the NAS parent key is derived. In some embodiments, the NAS parent key identifier associated with the NAS parent key can be received from the SKMF entity, so the terminal device does not need to derive the NAS parent key identifier.

[0200] In some embodiments, the NAS parent key identifier associated with the NAS parent key can have the same value as the NAS indicator based on which the NAS parent key is derived. In some embodiments, the NAS parent key identifier can be assigned a unique value by the SKMF entity.

[0201] Thus, the NAS parent key can be identified by a combination of the anchor key identifier and the NAS parent key identifier.

[0202] Additionally, in some embodiments, the terminal device can store the anchor key identifier, the NAS parent key, and the associated NAS parent key identifier. Further, the anchor key can be removed from the terminal device.

[0203] In addition, in some embodiments, the terminal device may request to establish a first NAS connection carrying a first NAS procedure between the terminal device and a first core network entity configured to implement core network functions. As used herein, the terms "core network entity" and "core network function" may be used interchangeably. In some embodiments, the terminal device may send a first NAS connection request to the first core network entity implementing core network functions. In some embodiments, the first NAS connection request may include information such as an anchor key identifier and a NAS indicator indicating the first NAS procedure. In one embodiment, the first NAS connection request may be an initial NAS message, such as a NAS mobility management registration request, and the first NAS procedure may be a NAS mobility management procedure, so the first core network entity may be an NF supporting the mobility management procedure.

[0204] Then, the terminal device may determine a NAS key for the first NAS connection based on security-related information associated with the first NAS procedure from the first core network entity. In some embodiments, the security-related information may be received in a NAS security mode command message. In some embodiments, the security-related information may include an anchor key identifier, a NAS parent key identifier, UE security capabilities, selected NAS integrity and encryption algorithms, and a flag requesting that the complete initial NAS message be sent. In this case, the terminal device may identify the NAS parent key based on the anchor key identifier and the NAS parent key identifier, and since no HASH value is provided, the NAS key is determined to be the identified NAS parent key. In some embodiments, the security-related information may further include a HASH value and a NAS sub-key identifier. In this case, after the terminal device identifies the NAS parent key, it may derive the NAS sub-key based on the identified NAS parent key and the HASH value, and assign the received NAS sub-key identifier to the NAS sub-key. Then the NAS sub-key is determined to be the NAS key for the first NAS connection. The NAS sub-key may be identified by a combination of the anchor key identifier, the NAS parent key identifier, and the NAS sub-key identifier.

[0205] Further, in some embodiments, the terminal device may derive NAS integrity and encryption keys based on the NAS key and the selected NAS integrity and encryption algorithms, and generate a NAS security mode complete message including the complete initial NAS message. Then, the terminal device may encrypt and integrity protect the NAS security mode complete message and send it to the first core network entity. Additionally, in some embodiments, the terminal device may store the NAS security context for the first NAS connection. The NAS security context may include an anchor key identifier, a NAS parent key identifier, a NAS child key identifier, a NAS child key, a HASH value, the security capabilities of the terminal device, the selected NAS integrity and encryption algorithms, the NAS integrity and encryption keys, and the NAS count. Further, the terminal device may receive a temporary context identifier for the first NAS connection from the first core network entity. The temporary context identifier may be used to identify the NAS security context of the terminal device within the first core network entity, as well as the first core network entity itself.

[0206] Alternatively, in some embodiments, the terminal device may (re)generate an anchor key after requesting the establishment of the first NAS connection from the first core network entity.

[0207] In addition, in some embodiments, the terminal device may request the establishment of a second NAS connection carrying a second NAS procedure between the terminal device and the second core network entity. In some embodiments, the terminal device may send a second NAS connection request to the second core network entity. In some embodiments, the second NAS connection request may include information such as an anchor key identifier and a NAS indicator indicating the second NAS procedure. In one embodiment, the second NAS connection request may also be an initial NAS message, such as a NAS PDU session request, and the second NAS procedure may be a NAS session management procedure, and the second core network entity may be an NF supporting the session management procedure.

[0208] Then, the terminal device can determine the NAS key for the second NAS connection based on the security-related information associated with the second NAS procedure received from the second core network entity. In some embodiments, the security-related information can be included in the NAS security mode command message. In some embodiments, the security-related information associated with the second NAS procedure message can include an anchor key identifier, a NAS parent key identifier, UE security capabilities, selected NAS integrity and encryption algorithms, and a flag requesting that the complete initial NAS message be sent. In this case, the terminal device can identify the NAS parent key based on the anchor key identifier and the NAS parent key identifier, and since no HASH value is provided, the NAS key is determined to be the identified NAS parent key. In some embodiments, the security-related information associated with the second NAS procedure can further include a HASH value and a NAS child key identifier. In this case, after the terminal device identifies the NAS parent key, it can derive the NAS child key based on the identified NAS parent key and the HASH value, and assign the received NAS child key identifier to the NAS child key. Then the NAS child key is determined as the NAS key for the second NAS connection.

[0209] Further, in some embodiments, the terminal device can derive NAS integrity and encryption keys based on the NAS key and the selected NAS integrity and encryption algorithms, and generate a NAS security mode complete message including the complete initial NAS message. Then, the terminal device can encrypt and integrity-protect the NAS security mode complete message and send it to the second core network entity. Further, in some embodiments, the terminal device can store the NAS security context for the second NAS connection. Further, the terminal device can receive a temporary context identifier for the second NAS connection from the first core network entity.

[0210] Although only two NAS connections carrying different NAS procedures are given as examples to explain method 1100, those skilled in the art will understand that method 1100 can be applied to more than two NAS connections.

[0211] In addition, in some embodiments, the first NAS procedure and the second NAS procedure are the same NAS procedure or different NAS procedures, and the first core network function is different from the second core network function. It should be noted that if the first NAS procedure is a NAS mobility management procedure, then the second NAS procedure can only be a non-NAS mobility management procedure. The first NAS procedure and the second NAS procedure can be the same non-NAS mobility management procedure.

[0212] Figure 12It is a flowchart showing method 1200 for security in a distributed NAS termination architecture according to some embodiments of the present disclosure. Method 1200 can be executed by an SKMF entity.

[0213] As Figure 12 shown, at block 1210, the SKMF entity can generate an anchor key with a terminal device (e.g., a UE in a distributed NAS termination architecture). In some embodiments, the SKMF entity and the terminal device can perform a primary AKA process to generate the anchor key.

[0214] At block 1220, the SKMF entity can derive an anchor key identifier for the anchor key and send the anchor key identifier to the terminal device. Then at block 1230, the SKMF entity can derive a set of NAS parent keys based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures. In some embodiments, the subscription identifier can be a SUPI. As described above, the NAS indicator can have different values for indicating different NAS procedures. Thus, the SKMF entity can obtain multiple NAS parent keys based on the anchor key, the subscription identifier (e.g., SUPI), and different values of the NAS indicator.

[0215] At block 1240, the SKMF entity can derive a NAS parent key identifier for each NAS parent key in the set of NAS parent keys based on the corresponding NAS indicator. Thus, a NAS parent key can be identified by a combination of the anchor key identifier and the NAS parent key identifier. In some embodiments, the NAS parent key identifier associated with a NAS parent key can have the same value as the NAS indicator based on which the NAS parent key is derived.

[0216] Alternatively or additionally, in some embodiments, the SKMF entity can send the NAS parent key identifier to the terminal device such that the terminal device does not have to derive the NAS parent key identifier itself. Alternatively, in some embodiments, the SKMF entity can assign a unique value to the NAS parent key identifier and send the NAS parent key identifier with that value, as well as the associated NAS indicator, to the terminal device.

[0217] In addition, in some embodiments, the SKM entity can store the anchor key identifier, the NAS parent keys, and the associated NAS parent key identifiers. Further, the anchor key can be removed from the SKMF entity.

[0218] Additionally, in some embodiments, the SKMF entity may receive a first request for a NAS key for a first NAS connection from a first core network entity, where the first NAS connection carries a first NAS procedure. Then, the SKMF entity may determine the NAS key for the first NAS connection based on the first request and send the NAS key for the first NAS connection to the first core network entity.

[0219] In some embodiments, the first request may include an anchor key identifier and a NAS parent key identifier. In this case, the SKMF entity may determine the NAS key by identifying the NAS parent key based on the anchor key identifier and the NAS parent key identifier received in the first request, and since no HASH value is provided, the NAS key is determined to be the identified NAS parent key. Then, the SKMF entity may send the identified NAS parent key to the first core network entity.

[0220] Alternatively, in some embodiments, the first request may further include a HASH value in addition to the anchor key identifier and the NAS parent key identifier. In this case, the SKMF entity may determine the NAS key as follows: identify the NAS parent key based on the anchor key identifier and the NAS parent key identifier, derive a NAS child key based on the identified NAS parent key and the HASH value, derive a NAS child key identifier for the NAS child key, and determine the NAS key as the derived NAS child key. Then, the SKMF entity may send the NAS child key, the NAS child key identifier, and the NAS parent key identifier to the first core network entity.

[0221] In some embodiments, the first request may be a key request, and the NAS key and related information (if any) may be included in a key response to be sent to the first core network entity.

[0222] Alternatively, in some embodiments, the generation of the anchor key by the SKMF entity may be triggered upon receipt of an authentication request from the first core network entity. The authentication request may be based on a request from a terminal device for establishing a first NAS connection carrying a first NAS procedure between the terminal device and the first core network entity, and may include a NAS indicator indicating the first NAS procedure and other information. In this case, the SKMF entity may derive a NAS parent key associated with the first NAS procedure based on the anchor key, subscription identifier (e.g., SUPI), and NAS indicator included in the authentication request, and derive a NAS parent key identifier for the NAS parent key. Then, the SKMF entity may send the anchor key identifier and the NAS parent key identifier to the first core network entity in an authentication response.

[0223] Alternatively or additionally, in some embodiments, the SKMF entity may determine a NAS key for a first NAS connection based on an authentication request. In some embodiments, the authentication request may further include a HASH value. In such a case, the SKMF entity may also derive a NAS child key based on the derived NAS parent key and the HASH value, derive a NAS child key identifier for the NAS child key, and determine the NAS key for the first NAS connection as the NAS child key. Then, the SKMF entity may send the derived NAS child key, the NAS child key identifier, and the NAS parent key identifier to the first core network entity. In some embodiments, the authentication request does not include a HASH value. In such a case, the SKMF entity may determine the NAS key as the derived NAS parent key associated with the first NAS procedure, and send the NAS parent key and the NAS parent key identifier to the first core network entity.

[0224] Additionally, in some embodiments, the first core network entity may be configured to handle NAS mobility management procedures, and the network entity and the first core network entity may be co-located.

[0225] Additionally, in some embodiments, the SKMF entity may receive a second request for a NAS key for a second NAS connection from a second core network entity, where the second NAS connection carries a second NAS procedure. Then, the SKMF entity may determine the NAS key for the second NAS connection based on the second request, and send the NAS key for the second NAS connection to the second core network entity. The SKMF entity may process the second request in the same manner as the first request, and thus the description of the processing of the second request is omitted here.

[0226] Although only two NAS connections carrying different NAS procedures are given as examples to explain method 1200, those skilled in the art will understand that method 1200 may be applicable to more than two NAS connections.

[0227] Figure 13 is a flowchart showing a method 1300 for security in a distributed NAS termination architecture according to some embodiments of the present disclosure. Method 1300 may be executed by a core network entity configured to implement core network functions, such as an NF supporting a mobility management procedure, or a session management procedure, or a policy management procedure, etc.

[0228] As Figure 13As shown, at block 1310, the core network entity may receive a request from the terminal device to establish a NAS connection carrying a NAS procedure between the terminal device and the core network entity. The terminal device may be a UE in a distributed NAS termination architecture. In some embodiments, the request may be an initial NAS message, such as a NAS MM registration request or a NAS PDU session request, and thus the NAS procedure may be a NAS mobility management procedure or a NAS session management procedure.

[0229] At block 1320, the core network entity may obtain a NAS key for the NAS connection from a network entity configured to implement SKMF (such as the SKMF entity as described above). The NAS key may be a NAS parent key or a NAS child key associated with a NAS indicator indicating the NAS procedure.

[0230] In some embodiments, the core network entity may determine whether authentication for the terminal device is required based on the request for the establishment of the NAS connection. In some embodiments, the request may include a SUCI or a temporary context ID (such as MM-GUTI / MM-S-TMSI), UE security capabilities, an anchor key identifier, and a NAS indicator indicating the NAS procedure. If the anchor key identifier indicates the absence of a valid anchor key, or the SUCI is included in the request, or the temporary context ID is invalid or not found, then authentication may be determined to be required. Otherwise, it is determined that authentication is not required.

[0231] If it is determined that authentication is required, the core network entity may send an authentication request to the SKMF entity. The authentication request may include a NAS indicator indicating the NAS procedure and other information. Then, the core network entity may receive an anchor key identifier and a NAS parent key identifier associated with the NAS indicator, such as in the authentication response. The core network entity may trigger sending a request for the NAS key to the SKMF entity, where the request includes the received anchor key identifier and NAS parent key identifier. In some embodiments, the request may be a key request. When the request does not include a HASH value, the core network entity may receive the NAS parent key identified by the anchor key identifier and NAS parent key identifier as the NAS key. When the request also includes a HASH value, the core network entity may receive a NAS child key based on the anchor key identifier, NAS parent key identifier, and HASH value as the NAS key, a NAS child key identifier for the NAS child key, and the NAS parent key identifier.

[0232] Alternatively, in some embodiments, when it is determined that authentication is required, the core network entity may trigger sending an authentication request to the SKMF entity, and the authentication request may include a NAS indicator indicating the NAS procedure, and optionally include a HASH value, and other information. In the case where the authentication request does not include a HASH value, the core network entity may receive the NAS parent key identified by the anchor key identifier and the NAS parent key identifier from the SKMF entity as the NAS key. In the case where the authentication request further includes a HASH value, the core network entity may receive the NAS child key associated with the NAS indicator as the NAS key, the NAS child key identifier for the NAS child key, and the NAS parent key identifier associated with the NAS parent key, and the NAS child key is derived based on the NAS parent key.

[0233] Additionally, in some embodiments, if it is determined that authentication is not required, the core network entity may verify whether the terminal device has been successfully registered. In some embodiments, the core network entity may send a request to another core network entity identified by the received MM-GUTI / MM-S-TMSI for verification. If the terminal device is verified as having been successfully registered, the core network entity may receive a success response from the other core network entity. Then, the core network entity may send a request for the NAS key, such as a key request, to the SKMF entity. The request may include the anchor key identifier and the NAS parent key identifier and optionally include a HASH value. In the case where the request does not include a HASH value, the core network entity may receive the NAS parent key identified by the anchor key identifier and the NAS parent key identifier from the SKMF entity as the NAS key. In the case where the request further includes a HASH value, the core network entity may receive the NAS child key based on the anchor key identifier, the NAS parent key identifier, and the HASH value from the SKMF entity as the NAS key, the NAS child key identifier for the NAS child key, and the NAS parent key identifier.

[0234] Additionally, in some embodiments, the core network entity may generate a HASH value based on at least one of the following: PDU session ID; S-NSSAI; and network function set identifier.

[0235] Additionally, the core network entity may be configured to handle NAS mobility management procedures, and the core network entity and the SKMF entity may be co-located.

[0236] The above various embodiments of the present disclosure can ensure that NAS connections terminated at different core NFs are secure, resilient, and the risks caused by any potential attacks are minimized. Additionally, the solutions of these embodiments are optimal and performance-efficient.

[0237] Some additional aspects / embodiments of the present disclosure will be presented below.

[0238] 1. Handling of access stratum (AS) keys.

[0239] The UE may have multiple concurrent NAS connections terminating in the serving network. Each NAS connection may be associated with a NAS indicator, and depending on the value of the NAS indicator, the same NAS indicator may be used for more than one NAS connection. For example, in the case where the UE has multiple NAS PDU sessions across different S-NSSAIs, for example, the NAS indicator used for NAS session management procedures may be used for multiple concurrent NAS connections. However, for the UE, at any given time, the NAS indicator used for NAS mobility management procedures can only be used for a single NAS connection per access type (3GPP access or non-3GPP access). That is, for example, for 3GPP access, there cannot be multiple active NAS connections simultaneously using the NAS indicator for NAS mobility management procedures.

[0240] In some embodiments, the NAS master key associated with the NAS connection used for NAS mobility management procedures may be used as an input for the UE and the core NF to derive the AS key. The NAS sub key associated with the NAS connection used for non-NAS mobility management procedures cannot be used to derive the AS key.

[0241] In some embodiments, the core NF terminating the NAS connection used for NAS mobility management procedures may use its NAS master key to derive and distribute the AS key (such as K gNB , NH, K N3IWF ) in the same way as defined in TS33.501, where the AMF uses the Kamf key and other parameters (such as NAS count, NCC) as inputs to derive and distribute the AS key. The UE may use the NAS master key associated with the NAS mobility management procedure to derive the AS key in the same way as defined in TS 33.501, where the UE uses the Kamf key and other parameters (such as NAS count, NCC) as inputs to derive the AS key (such as K gNB , NH, K N3IWF ).

[0242] The derivation of a new NAS sub key / master key associated with the NAS mobility management procedure may also trigger the derivation of a new AS key.

[0243] 2. NAS connections via 3GPP access and non-3GPP access

[0244] Utilizing and based on TS 33.501, section 6.4.2.2, when the UE has two NAS connections that support the same NAS procedure, where one NAS connection is via 3GPP access and the other NAS connection is via non-3GPP access, and both terminate at the core NF in the same PLMN, the UE and the core NF will maintain NAS count and NAS connection identifiers (3GPP / non-3GPP) for each NAS connection as part of their respective NAS security contexts. Other NAS security context parameters will be shared between the two NAS connections, such as NAS integrity and encryption keys, and NAS integrity and encryption algorithms. When the UE has two NAS connections that support the same NAS procedure, where one NAS connection is via 3GPP access and the other NAS connection is via non-3GPP access, and both terminate at core NFs in different PLMNs, the UE and the core NF will maintain a complete set of security parameters for each NAS connection, including NAS count, NAS connection identifiers (3GPP / non-3GPP), NAS integrity and encryption keys, and NAS integrity and encryption algorithms, as part of their respective NAS security contexts.

[0245] 3. Initial NAS messages, and idle to connected mode transition handling

[0246] The handling of initial NAS messages according to 3GPP TS 33.501, section 6.4.6 and the handling of idle to connected mode transition according to 3GPP 33.501, section 6.8.1.2.1 are both utilized and extended.

[0247] In the case where the UE has a valid NAS security context, the UE provides in the initial NAS message a minimum mandatory information unit (e.g., SUCI / Temporary ID / MM-S-TMSI / SM-S-TMSI, UE security capabilities, anchor key identifier, NAS parent key identifier, NAS child key identifier, NAS indicator in plaintext, and the complete NAS message encrypted using its NAS security context and the integrity of the entire initial NAS message protected.

[0248] If the core NF has the same NAS security context, it will perform an integrity check on the initial NAS message, decrypt the received complete NAS message, process it, and protect the response using the NAS security context. If the core NF does not have or cannot obtain a valid NAS security context, it may request to trigger the AKA procedure to derive a new anchor key, etc. If the core NF is handling a NAS mobility management process, it sends an authentication request to the SKMF. If the core NF is handling a non-NAS mobility management process, then it sends a request to the NF handling the NAS mobility management process, which in turn will trigger the AKA procedure to the SKMF.

[0249] If the AKA runs successfully, the core NF handling the NAS mobility management procedure will trigger a NAS security mode command to the UE to establish a NAS security context for the NAS connection, as referenced previously Figure 7 and Figure 10 described.

[0250] 4. N2 Handover

[0251] In an N2 handover, the target NF may choose NAS integrity and ciphering algorithms different from those used by the source NF, and the source NF may provide the target NF with a new NAS child key or parent key (depending on which one is used), so these changes need to be reflected in the UE's NAS security context.

[0252] During an N2 handover, the principles defined in section 6.9.2.3.3 of 3GPP TS 33.501 can be exploited and extended. Triggered by the reception of a handover request message, the source NF may provide the target NF with an anchor key identifier, a NAS parent key identifier, a NAS child key identifier, UE security capabilities, a NAS DL count, a NAS child / parent key, and an indication of whether the NAS child / parent key has been derived horizontally. The NAS security context of a NAS connection protected by a NAS parent key has a NAS parent key and a NAS parent key identifier, but no NAS child key and NAS child key identifier. The NAS security context of a NAS connection protected by a NAS child key has a NAS parent key, a NAS parent key identifier, a NAS child key, and a NAS child key identifier.

[0253] The decision on whether to perform horizontal key derivation for the NAS parent key or NAS child key can be determined by the presence or absence of the NAS child key identifier. If the NAS child key identifier is present, horizontal key derivation of the NAS child key occurs, and if the NAS child key identifier is missing, horizontal key derivation of the NAS parent key occurs.

[0254] Similarly, the target NF can decide whether to use the NAS parent key or NAS child key to derive the NAS integrity and ciphering keys based on the presence or absence of the NAS child key. If the NAS child key is present, it is used to derive the NAS integrity and ciphering keys, otherwise the NAS parent key is used.

[0255] Based on the local policy configuration, the source NF can determine whether horizontal key derivation is to be performed. The source NF can perform the horizontal derivation of the NAS sub / parent key using the currently active NAS sub / parent key and the NASDL count as inputs, thereby deriving a new NAS sub / parent key. The source NF can send these inputs to the SKMF in a request for horizontal key derivation, and the SKMF returns the newly horizontally derived NAS sub / parent key.

[0256] Based on the UE security capabilities indicating the supported NAS integrity and encryption algorithms, the target NF can select the highest prioritized NAS integrity and encryption algorithms from among those it supports, and use these NAS integrity and encryption algorithm identifiers as inputs, together with the NAS sub / parent key, to derive the NAS integrity and encryption keys. The target NF can store the anchor key identifier, NAS parent key identifier, NAS sub key identifier, NAS sub / parent key, NAS integrity and encryption keys, UE security capabilities, NASDL count, and NAS integrity and encryption algorithms in its NAS security context.

[0257] The target NF can create a NAS container with security parameters, which is integrity protected using the NAS integrity key and provided to the UE via the (R)AN. The purpose of the NAS container can be considered similar to that of the NAS security mode command. The NAS container can contain the anchor key identifier, NAS parent key identifier, NAS sub key identifier, UE security capabilities, NASDL count, the selected NAS integrity and encryption algorithms, and an indication of whether the NAS sub / parent key has been horizontally derived.

[0258] From its locally stored NAS security context, the UE can use the anchor key identifier to check whether it is associated with the current and valid AKA run, use the anchor key identifier and NAS parent key identifier to identify the NAS parent key, and use the anchor key identifier, NAS parent key identifier, and NAS sub key identifier to identify the NAS sub key. If horizontal key derivation is indicated, the UE can use the locally identified NAS sub / parent key and the received NASDL count to horizontally derive a new NAS sub / parent key associated with the existing NAS sub / parent key identifier.

[0259] The NAS integrity and encryption algorithm identifiers and the new NAS sub / parent key can be used as inputs to derive the NAS integrity and encryption keys. The NAS integrity key can be used to check the integrity of the received NAS container, and the received UE security capabilities can be checked to ensure that no protocol downgrade attack has occurred.

[0260] If the NAS integrity check passes, the UE's NAS security context can be updated with a new NAS child / parent key, new NAS integrity and encryption keys, and the NAS count. Note that according to TS 33.501, section 6.9.2.3.3, if the NAS child / parent key is derived horizontally, the NAS count is set to zero; otherwise, the received NAS count is used.

[0261] The above process mainly relates to the mobility management function relocation scenario, but this can be extended and applied to any NF that can be relocated as part of the UE mobility.

[0262] 5. Xn Handover

[0263] The NF that anchors the NAS mobility management connection can be responsible for providing key material to the target RAN, as defined in 3GPP TS 33.501, section 6.9.2.3.2, where Kamf corresponds to the NAS child / parent key.

[0264] 6. Idle Mode Mobility Registration Update

[0265] When the target NF receives a NAS mobility registration update, it can use a temporary identifier (e.g., MM-GUTI / MM-S-TMSI) to identify the source NF that stores the UE context (which includes the UE NAS security context). If the source NF finds a valid UE context, it can provide the SUPI to the target NF and can provide the NAS security context information it stores.

[0266] During the NAS mobility registration update, the principles defined in 3GPP TS 33.501, section 6.9.3 can be exploited and extended.

[0267] According to the local policy configuration, the source NF can decide whether horizontal key derivation is performed. The source NF can use the current active NAS child / parent key and the NAS UL count of the received NAS registration request (mobility update) as inputs to perform horizontal derivation of the NAS child / parent key to derive a new NAS child / parent key. The source NF can send these inputs to the SKMF in a request for horizontal key derivation, and the SKMF returns the newly horizontally derived NAS child / parent key.

[0268] The source NF can provide the UE NAS security context information to the target NF, which includes the anchor key identifier, NAS parent key identifier, NAS child key identifier, UE security capabilities, NAS UL count, NAS child / parent key, and an indication of whether the NAS child / parent key has been derived horizontally.

[0269] Based on the UE security capabilities indicating the supported NAS integrity and encryption algorithms, the target NF can select the highest prioritized NAS integrity and encryption algorithms from among those it supports and use these NAS integrity and encryption algorithm identifiers as inputs, together with the NAS sub / parent keys, to derive the NAS integrity and encryption keys.

[0270] The target NF can store the anchor key identifier, NAS parent key identifier, NAS child key identifier, NAS sub / parent key, NAS integrity and encryption keys, UE security capabilities, NAS UL count, and NAS integrity and encryption algorithms in its NAS security context.

[0271] According to the local policy configuration, the target NF can decide whether to use the NAS sub / parent key derived horizontally from the source NF. If not, the target NF can trigger a re-authentication process, which can derive a new anchor key, anchor key identifier, NAS parent key identifier, NAS child key identifier, NAS sub / parent key, and establish a new NAS security context with the UE.

[0272] If the NAS security context information from the source NF is used, the target NF can create and send a NAS security mode command message to the UE, which is integrity protected by the NAS integrity key and includes the anchor key identifier, NAS parent key identifier, NAS child key identifier, UE security capabilities, the selected NAS integrity and encryption algorithms, and an indication of whether the NAS sub / parent key has been derived horizontally.

[0273] From its locally stored NAS security context, the UE can use the anchor key identifier to check whether it is associated with the current and valid AKA run, use the anchor key identifier and NAS parent key identifier to identify the NAS parent key, and use the anchor key identifier, NAS parent key identifier, and NAS child key identifier to identify the NAS child key. If horizontal key derivation is indicated, the UE can use the locally identified NAS sub / parent key and the NAS UL count of the NAS registration request to horizontally derive a new NAS sub / parent key.

[0274] The NAS integrity and encryption algorithm identifiers and the new NAS sub / parent key can be used as inputs to derive the NAS integrity and encryption keys. The NAS integrity key can be used to check the integrity of the received NAS security mode command, and the received UE security capabilities can be used to ensure that no protocol downgrade attack has occurred.

[0275] If the NAS integrity check passes, the UE can update its NAS security context with the new NAS sub / parent keys, new NAS integrity and encryption keys, NAS integrity and encryption algorithms, and NAS count, and return NAS security mode complete to the target NF.

[0276] Now refer to Figure 14 , Figure 14 FIG. shows a simplified block diagram of apparatus 1400, which may be embodied as a terminal device, or a network entity configured to implement the SKMF, or a core network entity configured to implement the core NF. Apparatus 1400 may include at least one processor 1401, such as a data processor (DP) and at least one memory (MEM) 1402 coupled to the at least one processor 1401. Apparatus 1400 may also include a transmitting unit and a receiving unit 1403 coupled to one or more processors 1401.

[0277] Processor 1401 may be of any type suitable for the local technical environment and, as a non-limiting example, may include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture.

[0278] (Multiple) MEM 1402 may be of any type suitable for the local technical environment and, as a non-limiting example, may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory.

[0279] MEM 1402 stores a program (PROG) 1404. PROG 1404 may include instructions that, when executed on the associated processor 1401, enable apparatus 1400 to operate in accordance with embodiments of the present disclosure, such as performing one of the methods 1100, 1200, and 1300 as shown in Figure 11 , Figure 12 and Figure 13 FIGS. The combination of at least one processor 1401 and at least one MEM 1402 may form a processing circuitry or component 1405 suitable for implementing various embodiments of the present disclosure.

[0280] Various embodiments of the present disclosure may be implemented by a computer program, software, firmware, hardware, or a combination thereof executable by one or more processors 1401.

[0281] Generally, the various exemplary embodiments of the present disclosure can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software, which can be executed by a controller, a microprocessor, or other computing devices, although the invention is not limited thereto. Although the various aspects of the exemplary embodiments of the present disclosure can be shown and described in block diagrams, flowcharts, or using some other graphical representation, it should be fully understood that, by way of non-limiting example, the blocks, devices, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuits or logic, general-purpose hardware or controllers, or other computing devices, or some combination thereof.

[0282] Accordingly, it should be understood that at least some aspects of the exemplary embodiments of the present disclosure can be practiced in various components, such as integrated circuit chips and modules. Thus, it should be understood that the exemplary embodiments of the present disclosure can be implemented in a device embodied as an integrated circuit, where the integrated circuit can include circuitry (and possibly firmware) for embodying at least one or more of a data processor, a digital signal processor, a baseband circuitry, and a radio frequency circuitry, which can be configured to operate in accordance with the exemplary embodiments of the present disclosure.

[0283] It should be understood that at least some aspects of the exemplary embodiments of the present disclosure can be embodied in computer-executable instructions, such as in one or more program modules, and executed by one or more computers or other devices. Generally, program modules include routines, programs, objects, components, data structures, etc., which perform specific tasks or implement specific abstract data types when executed by a processor in a computer or other device. The computer-executable instructions can be stored on a computer-readable medium, such as a non-transitory computer-readable medium, such as a hard disk, an optical disk, a removable storage medium, a solid-state memory, a RAM, etc. As will be understood by those skilled in the art, the functions of the program modules can be combined or distributed as needed in various embodiments. Additionally, the functions can be embodied in whole or in part in firmware or hardware equivalents, such as integrated circuits, field-programmable gate arrays (FPGAs), etc.

[0284] Moreover, although the operations are depicted in a particular order, they should not be construed as requiring that the operations be performed in the particular order shown or in a sequential order, or that all of the illustrated operations be performed, to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Also, although several specific implementation details are included in the foregoing discussion, these details should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination.

[0285] The present disclosure includes any novel feature or combination of features disclosed herein, whether explicitly disclosed or any generalization thereof. When read in conjunction with the accompanying drawings, various modifications and changes to the foregoing exemplary embodiments of the present disclosure will become apparent to those skilled in the relevant art in view of the above description. However, any and all modifications will still fall within the scope of the non-limiting and exemplary embodiments of the present disclosure.

Claims

1. A terminal device, comprising: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the terminal device to at least: generate an anchor key; receive an anchor key identifier for the anchor key; derive a non-access stratum (NAS) parent key set based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures; and for each NAS parent key in the NAS parent key set, obtain a NAS parent key identifier.

2. The terminal device according to claim 1, wherein, in order to obtain a NAS parent key identifier for each NAS parent key in the NAS parent key set, the terminal device is caused to: for each NAS parent key in the NAS parent key set, derive the NAS parent key identifier based on the corresponding NAS indicator.

3. The terminal device according to claim 1, wherein, in order to obtain a NAS parent key identifier for each NAS parent key in the NAS parent key set, the terminal device is caused to: receive the NAS parent key identifier associated with the NAS parent key.

4. The terminal device according to any one of claims 1 to 3, wherein the terminal device is further caused to: store the anchor key identifier, the NAS parent key set, and the corresponding NAS parent key identifiers.

5. The terminal device according to any one of claims 1 to 4, wherein the NAS parent key identifier associated with a NAS parent key has the same value as the NAS indicator as follows: the NAS parent key is derived based on the NAS indicator.

6. The terminal device according to any one of claims 1 to 5, wherein the terminal device is further caused to: request to establish a first NAS connection carrying a first NAS procedure between the terminal device and a first core network entity; and determine a NAS key for the first NAS connection based on security-related information associated with the first NAS procedure from the first core network entity.

7. The terminal device according to claim 6, wherein, in order to request to establish the first NAS connection carrying the first NAS procedure between the terminal device and the first core network entity, the terminal device is caused to: send a first NAS connection request to the first core network entity, the first NAS connection request comprising: the anchor key identifier and the NAS indicator indicating the first NAS procedure.

8. The terminal device according to claim 6 or 7, wherein, in order to determine the NAS key for the first NAS connection, the terminal device is caused to: identify the NAS parent key based on the NAS parent key identifier and the anchor key identifier included in the security-related information associated with the first NAS procedure; when the security-related information does not include a HASH value, determine the NAS key as the identified NAS parent key; when the security-related information includes a HASH value, Derive an NAS child key based on the identified NAS parent key and the HASH value; Assign the NAS child key identifier included in the security-related information associated with the first NAS procedure to the derived NAS child key; And Determine the NAS key as the derived NAS child key.

9. The terminal device according to any one of claims 6 to 8, wherein the generation of the anchor key is performed after the request for establishing the first NAS connection.

10. The terminal device according to any one of claims 6 to 9, wherein the terminal device is further caused to: Derive a new NAS key for the first NAS connection based on the current NAS key for the first NAS connection and the NAS count during handover or NAS registration update.

11. The terminal device according to any one of claims 6 to 10, wherein the terminal device is further caused to: Request to establish a second NAS connection carrying a second NAS procedure between the terminal device and a second core network entity; and Determine the NAS key for the second NAS connection based on the security-related information associated with the second NAS procedure from the second core network entity.

12. The terminal device according to claim 11, wherein in order to request to establish the second NAS connection carrying the second NAS procedure between the terminal device and the second core network entity, the terminal device is caused to: Send a second NAS connection request to the second core network entity, the second NAS connection request Comprises: The anchor key identifier and the NAS indicator indicating the second NAS procedure.

13. The terminal device according to claim 11 or 12, wherein in order to determine the NAS key for the second NAS connection, the terminal device is caused to: Identify the NAS parent key based on the NAS parent key identifier and the anchor key identifier included in the security-related information associated with the second NAS procedure; When the security-related information associated with the second NAS procedure does not include a HASH value, determine the NAS key as the identified NAS parent key; When the security-related information associated with the second NAS procedure includes a HASH value, Derive an NAS child key based on the identified NAS parent key and the HASH value; Assign the NAS child key identifier included in the security-related information associated with the second NAS procedure to the derived NAS child key; And Determine the NAS key as the derived NAS child key.

14. The terminal device according to any one of claims 11 to 13, wherein the terminal device is further caused to: Derive a new NAS key for the second NAS connection based on the current NAS key for the second NAS connection and the NAS count during handover or NAS registration update.

15. The terminal device according to any one of claims 11 to 14, wherein the first NAS procedure and the second NAS procedure are the same NAS procedure or different NAS procedures.

16. The terminal device according to any one of claims 6 to 15, wherein the terminal device is further caused to: Derive an access stratum AS key at least in part based on the NAS key for the NAS connection for: the NAS connection carrying an NAS mobility management procedure.

17. A method performed by a terminal device, the method comprising: Generating an anchor key; Receiving an anchor key identifier for the anchor key; Deriving a non-access stratum NAS parent key set based on the anchor key, a subscription identifier, and an NAS indicator indicating different NAS procedures; and For each NAS parent key in the NAS parent key set, obtaining an NAS parent key identifier.

18. The method according to claim 17, wherein obtaining an NAS parent key identifier for each NAS parent key in the NAS parent key set comprises: For each NAS parent key in the NAS parent key set, deriving the NAS parent key identifier based on the corresponding NAS indicator.

19. The method according to claim 17, wherein obtaining an NAS parent key identifier for each NAS parent key in the NAS parent key set comprises: Receiving the NAS parent key identifier associated with the NAS parent key.

20. The method according to any one of claims 17 to 19, wherein the method further comprises: Storing the anchor key identifier, the NAS parent key set, and the corresponding NAS parent key identifier.

21. The method according to any one of claims 17 to 20, wherein the NAS parent key identifier associated with the NAS parent key has the same value as the NAS indicator for: the NAS parent key is derived based on the NAS indicator.

22. The method according to any one of claims 17 to 21, wherein the method further comprises: Requesting to establish a first NAS connection carrying a first NAS procedure between the terminal device and a first core network entity; and Determining an NAS key for the first NAS connection based on security-related information associated with the first NAS procedure from the first core network entity.

23. The method according to claim 22, wherein requesting to establish a first NAS connection carrying a first NAS procedure between the terminal device and a first core network entity comprises: Sending a first NAS connection request to the first core network entity, the first NAS connection request including: the anchor key identifier and the NAS indicator indicating the first NAS procedure.

24. The method according to claim 22 or 23, wherein determining an NAS key for the first NAS connection comprises: Identify the NAS parent key based on the NAS parent key identifier and the anchor key identifier included in the security-related information associated with the first NAS procedure; When the security-related information does not include a HASH value, determine the NAS key as the identified NAS parent key; When the security-related information includes a HASH value, Derive a NAS child key based on the identified NAS parent key and the HASH value; Assign the NAS child key identifier included in the security-related information associated with the first NAS procedure to the derived NAS child key; And Determine the NAS key as the derived NAS child key.

25. The method according to any one of claims 22 to 24, wherein the generation of the anchor key is performed after the request for establishing the first NAS connection.

26. The method according to any one of claims 22 to 25, wherein the method further comprises: Derive a new NAS key for the first NAS connection based on the current NAS key for the first NAS connection and the NAS count during handover or NAS registration update.

27. The method according to any one of claims 22 to 26, wherein the method further comprises: Request to establish a second NAS connection carrying a second NAS procedure between the terminal device and a second core network entity; And Determine the NAS key for the second NAS connection based on the security-related information associated with the second NAS procedure from the second core network entity.

28. The method according to claim 27, wherein requesting to establish a second NAS connection carrying a second NAS procedure between the terminal device and a second core network entity comprises: Send a second NAS connection request to the second core network entity, the second NAS connection request including: the anchor key identifier and the NAS indicator indicating the second NAS procedure.

29. The method according to claim 27 or 28, wherein determining the NAS key for the second NAS connection comprises: Identify the NAS parent key based on the NAS parent key identifier and the anchor key identifier included in the security-related information associated with the second NAS procedure; When the security-related information associated with the second NAS procedure does not include a HASH value, determine the NAS key as the identified NAS parent key; When the security-related information associated with the second NAS procedure includes a HASH value, Derive a NAS child key based on the identified NAS parent key and the HASH value; Assign the NAS child key identifier included in the security-related information associated with the second NAS procedure to the derived NAS child key; And Determine the NAS key as the derived NAS child key.

30. The method according to any one of claims 27 to 29, wherein the method further comprises: Derive a new NAS key for the second NAS connection based on the current NAS key for the second NAS connection and the NAS count during handover or NAS registration update.

31. The method according to any one of claims 27 to 30, wherein the first NAS procedure and the second NAS procedure are the same NAS procedure or different NAS procedures.

32. The method according to any one of claims 22 to 31, wherein the method further comprises: Derive an access stratum AS key at least partially based on the NAS key for the NAS connection that carries a NAS mobility management procedure.

33. A network entity configured to implement a security key management function, comprising: At least one processor; and At least one memory storing instructions that, when executed on the at least one processor, cause the network entity to: Generate an anchor key with a terminal device; Derive an anchor key identifier for the anchor key and send the anchor key identifier to the terminal device; Derive a non-access stratum NAS parent key set based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures; and For each NAS parent key in the NAS parent key set, derive a NAS parent key identifier based on the corresponding NAS indicator.

34. The network entity according to claim 33, wherein the network entity is further caused to: Store the anchor key identifier, the NAS parent key set, and the corresponding NAS parent key identifiers.

35. The network entity according to claim 33 or 34, wherein the network entity is further caused to: Send the NAS parent key identifier associated with the NAS parent key to the terminal device.

36. The network entity according to any one of claims 33 to 35, wherein the NAS parent key identifier associated with the NAS parent key has the same value as the NAS indicator based on which the NAS parent key is derived.

37. The network entity according to any one of claims 33 to 36, wherein the network entity is further caused to: Receive a first request from a first core network entity for a NAS key for a first NAS connection that carries a first NAS procedure; Determine the NAS key for the first NAS connection based on the first request; and Send the NAS key for the first NAS connection to the first core network entity.

38. The network entity according to claim 37, wherein in order to determine the NAS key for the first NAS connection, the network entity is caused to: Identify the NAS parent key based on the anchor key identifier and the NAS parent key identifier included in the first request; When the first request does not include a HASH value, determine the NAS key as the identified NAS parent key; When the first request includes a HASH value, Derive an NAS child key based on the identified NAS parent key and the HASH value; Derive an NAS child key identifier for the NAS child key; And Determine the NAS key as the derived NAS child key; And Wherein, in order to send the NAS key for the first NAS connection to the first core network entity, the network entity is caused to: When the NAS key is determined as the identified NAS parent key, send the identified NAS parent key to the first core network entity; And When the NAS key is determined as the derived NAS child key, send the NAS child key, the NAS child key identifier, and the NAS parent key identifier to the first core network entity.

39. The network entity according to any one of claims 33 to 36, wherein the generation of the anchor key is triggered after receiving an authentication request from a first core network entity, wherein the authentication request is based on a request from the terminal device for establishing a first NAS connection carrying a first NAS procedure between the terminal device and the first core network entity, and Comprises: The NAS indicator indicating the first NAS procedure.

40. The network entity according to claim 39, wherein the network entity is further caused to: Derive the NAS parent key associated with the first NAS procedure based on the anchor key and the NAS indicator included in the authentication request; Derive the NAS parent key identifier for the derived NAS parent key based on the NAS indicator; When the authentication request does not include a HASH value, Determine the NAS key for the first NAS connection as the derived NAS parent key; And Send the derived NAS parent key and the NAS parent key identifier to the first core network entity; When the authentication request includes a HASH value, Derive an NAS child key based on the derived NAS parent key and the HASH value; Derive the NAS child key identifier for the NAS child key; Determine the NAS key for the first NAS connection as the derived NAS child key; And Send the derived NAS child key, the NAS child key identifier, and the NAS parent key identifier to the first core network entity.

41. The network entity according to any one of claims 37, 38, and 40, wherein the network entity is further caused to: Derive a new NAS key for the first NAS connection based on the current NAS key for the first NAS connection and the NAS count during handover or NAS registration update; and Send the new NAS key to the first core network entity.

42. The network entity according to any one of claims 37 to 41, wherein the network entity is further caused to: Receive a second request for the NAS key for a second NAS connection carrying a second NAS procedure from a second core network entity; Determine the NAS key for the second NAS connection based on the second request; and Send the NAS key for the second NAS connection to the second core network entity.

43. The network entity according to claim 42, wherein in order to determine the NAS key for the second NAS connection, the network entity is further caused to: Identify the NAS parent key based on the anchor key identifier and the NAS parent key identifier included in the second request; When the second request does not include a HASH value, determine the NAS key as the identified NAS parent key; When the second request includes a HASH value, Derive a NAS child key based on the identified NAS parent key and the HASH value; Derive a NAS child key identifier for the NAS child key; and Determine the NAS key as the derived NAS child key; and wherein in order to send the NAS key for the second NAS connection to the second core network entity, the network entity is further caused to: Based on the NAS key being determined as the identified NAS parent key, send the identified NAS parent key to the second core network entity; and Based on the NAS key being determined as the derived NAS child key, send the NAS child key, the NAS child key identifier, and the NAS parent key identifier to the second core network entity.

44. The network entity according to claim 42 or 43, wherein the network entity is further caused to: Derive a new NAS key for the second NAS connection based on the current NAS key for the second NAS connection and the NAS count during handover or NAS registration update; and Send the new NAS key to the second core network entity.

45. The network entity according to any one of claims 37 to 44, wherein the first core network entity is configured to handle NAS mobility management procedures, and the network entity and the first core network entity are co-located.

46. A method performed by a network entity for a security key management function, the method comprising: Generate an anchor key with a terminal device; Derive an anchor key identifier for the anchor key and send the anchor key identifier to the terminal device; Derive a set of non-access stratum NAS parent keys based on the anchor key, a subscription identifier, and a NAS indicator indicating different NAS procedures; and Derive a NAS parent key identifier for each NAS parent key in the set of NAS parent keys based on the corresponding NAS indicator.

47. The method according to claim 46, wherein the method further comprises: Store the anchor key identifier, the set of NAS parent keys, and the corresponding NAS parent key identifiers.

48. The method according to claim 46 or 47, wherein the method further comprises: Send the NAS parent key identifier associated with the NAS parent key to the terminal device.

49. The method according to any one of claims 46 to 48, wherein the NAS parent key identifier associated with the NAS parent key has the same value as the NAS indicator as follows: the NAS parent key is derived based on the NAS indicator.

50. The method according to any one of claims 46 to 49, wherein the method further comprises: receiving, from a first core network entity, a first request for a NAS key for a first NAS connection, the first NAS connection carrying a first NAS procedure; determining, based on the first request, the NAS key for the first NAS connection; and sending the NAS key for the first NAS connection to the first core network entity.

51. The method according to claim 50, wherein determining the NAS key for the first NAS connection comprises: identifying the NAS parent key based on the anchor key identifier and the NAS parent key identifier included in the first request; when the first request does not include a HASH value, determining the NAS key as the identified NAS parent key; when the first request includes a HASH value, deriving a NAS child key based on the identified NAS parent key and the HASH value; deriving a NAS child key identifier for the NAS child key; and determining the NAS key as the derived NAS child key; and wherein sending the NAS key for the first NAS connection to the first core network entity comprises: when the NAS key is determined as the identified NAS parent key, sending the identified NAS parent key to the first core network entity; and when the NAS key is determined as the derived NAS child key, sending the NAS child key, the NAS child key identifier, and the NAS parent key identifier to the first core network entity.

52. The method according to any one of claims 46 to 49, wherein the generation of the anchor key is triggered after receiving an authentication request from a first core network entity, wherein the authentication request is based on a request from the terminal device for establishing a first NAS connection carrying a first NAS procedure between the terminal device and the first core network entity, and comprises: the NAS indicator indicating the first NAS procedure.

53. The method according to claim 52, wherein the method further comprises: deriving the NAS parent key associated with the first NAS procedure based on the anchor key and the NAS indicator included in the authentication request; deriving the NAS parent key identifier for the derived NAS parent key based on the NAS indicator; when the authentication request does not include a HASH value, determining the NAS key for the first NAS connection as the derived NAS parent key; and sending the derived NAS parent key and the NAS parent key identifier to the first core network entity; When the authentication request includes a HASH value, derive a NAS child key based on the derived NAS parent key and the HASH value; derive a NAS child key identifier for the NAS child key; determine the NAS key for the first NAS connection as the derived NAS child key; and send the derived NAS child key, the NAS child key identifier, and the NAS parent key identifier to the first core network entity.

54. The method according to any one of claims 50, 51, and 53, wherein the method further comprises: derive a new NAS key for the first NAS connection based on the current NAS key for the first NAS connection and the NAS count during handover or NAS registration update; and send the new NAS key to the first core network entity.

55. The method according to any one of claims 50 to 54, wherein the method further comprises: receive a second request from a second core network entity for a NAS key for a second NAS connection for carrying a second NAS procedure; determine the NAS key for the second NAS connection based on the second request; and send the NAS key for the second NAS connection to the second core network entity.

56. The method according to claim 55, wherein determining the NAS key for the second NAS connection comprises: identify the NAS parent key based on the anchor key identifier and the NAS parent key identifier included in the second request; when the second request does not include a HASH value, determine the NAS key as the identified NAS parent key; when the second request includes a HASH value, derive a NAS child key based on the identified NAS parent key and the HASH value; derive a NAS child key identifier for the NAS child key; and determine the NAS key as the derived NAS child key; and wherein sending the NAS key for the second NAS connection to the second core network entity comprises: send the identified NAS parent key to the second core network entity based on the NAS key being determined as the identified NAS parent key; and send the NAS child key, the NAS child key identifier, and the NAS parent key identifier to the second core network entity based on the NAS key being determined as the derived NAS child key.

57. The network entity method according to claim 55 or 56, wherein the method further comprises: derive a new NAS key for the second NAS connection based on the current NAS key for the second NAS connection and the NAS count during handover or NAS registration update; and send the new NAS key to the second core network entity.

58. A core network entity configured to implement core network functions, comprising: at least one processor; and At least one memory storing instructions which, when executed by the at least one processor, cause the core network entity to at least: Receive, from a terminal device, a request for establishing a NAS connection carrying a NAS procedure between the terminal device and the core network entity; And Obtain a NAS key for the NAS connection, where the NAS key is a NAS parent key or a NAS child key associated with a NAS indicator indicating the NAS procedure.

59. The core network entity according to claim 58, wherein, in order to obtain a NAS key for the NAS connection, the core network entity is caused to: Determine whether authentication of the terminal device is required based on the request for establishing the NAS connection ; And Based on the determination that the authentication is required, Trigger the sending of an authentication request, where the authentication request includes: the NAS indicator indicating the NAS procedure; Receive an anchor key identifier and a NAS parent key identifier associated with the NAS indicator; Send a request for the NAS key, where the request includes: the anchor key identifier and the NAS parent key identifier; When the request does not include a HASH value, receive the NAS parent key identified by the anchor key identifier and the NAS parent key identifier as the NAS key; and When the request further includes a HASH value, receive the NAS child key based on the anchor key identifier, the NAS parent key identifier, and the HASH value as the NAS key, a NAS child key identifier for the NAS child key, and the NAS parent key identifier.

60. The core network entity according to claim 59, wherein, in order to obtain a NAS key for the NAS connection, the core network entity is further caused to: Based on the determination that the authentication is required, Trigger the sending of an authentication request, where the authentication request Includes: The NAS indicator indicating the NAS procedure; When the authentication request does not include a HASH value, receive the NAS parent key associated with the NAS indicator as the NAS key; And When the authentication request further includes a HASH value, receive the NAS child key associated with the NAS indicator as the NAS key, a NAS child key identifier for the NAS child key, and the NAS parent key identifier associated with the following NAS parent key: the NAS child key is derived based on the NAS parent key.

61. The core network entity according to claim 59 or 60, wherein, in order to obtain a NAS key for the NAS connection, the core network entity is further caused to: Based on the determination that the authentication is not required, Verify whether the terminal device is successfully registered; When the terminal device is verified as successfully registered, send a request for the NAS key, where the request includes: an anchor key identifier and a NAS parent key identifier; When the request does not include a HASH value, receiving the NAS parent key identified by the anchor key identifier and the NAS parent key identifier as the NAS key; and When the request further includes a HASH value, receiving the NAS child key based on the anchor key identifier, the NAS parent key identifier, and the HASH value as the NAS key, the NAS child key identifier for the NAS child key, and the NAS parent key identifier.

62. The core network entity according to any one of claims 58 to 61, wherein the core network entity is further caused to: Generate a HASH value based on at least one of the following: a protocol data unit (PDU) session identifier (ID); a single network slice selection assistance information (S-NSSAI); or a network function set identifier.

63. The core network entity according to any one of claims 58 to 62, wherein the core network entity is further caused to: derive an access stratum (AS) key at least partially based on the NAS key for the NAS connection for: the NAS connection carrying an NAS mobility management procedure.

64. The core network entity according to any one of claims 58 to 63, wherein the core network entity is a source network entity in a handover or an NAS registration update, and wherein the core network entity is further caused to: Derive a new NAS key for the NAS connection based on the current NAS key for the NAS connection and an NAS count; and Provide the new NAS key to a target network entity in the handover or the NAS registration update.

65. A method performed by a core network entity configured to implement core network functions, comprising: Receiving, from a terminal device, a request to establish an NAS connection carrying an NAS procedure between the terminal device and the core network entity; and Obtaining an NAS key for the NAS connection, wherein the NAS key is an NAS parent key or an NAS child key associated with an NAS indicator indicating the NAS procedure.

66. The method according to claim 65, wherein obtaining the NAS key for the NAS connection comprises: Based on the request to establish the NAS connection, determining whether authentication of the terminal device is required; and Based on the determination that authentication is required, Triggering the sending of an authentication request, wherein the authentication request includes: the NAS indicator indicating the NAS procedure; Receiving an anchor key identifier and an NAS parent key identifier associated with the NAS indicator; Sending a request for the NAS key, wherein the request includes: the anchor key identifier and the NAS parent key identifier; When the request does not include a HASH value, receiving the NAS parent key identified by the anchor key identifier and the NAS parent key identifier as the NAS key; and When the request further includes a HASH value, receive the NAS sub - key based on the anchor key identifier, the NAS parent key identifier, and the HASH value as the NAS key, the NAS sub - key identifier for the NAS sub - key, and the NAS parent key identifier.

67. The method according to claim 66, wherein obtaining the NAS key for the NAS connection further includes: Based on the determination that the authentication is required, Trigger the sending of an authentication request, wherein the authentication request includes: the NAS indicator indicating the NAS procedure; When the authentication request does not include a HASH value, receive the NAS parent key associated with the NAS indicator as the NAS key; and When the authentication request further includes a HASH value, receive the NAS sub - key associated with the NAS indicator as the NAS key, the NAS sub - key identifier for the NAS sub - key, and the NAS parent key identifier associated with the following NAS parent key: the NAS sub - key is derived based on the NAS parent key.

68. The method according to claim 66 or 67, wherein obtaining the NAS key for the NAS connection further includes: Based on the determination that the authentication is not required, Verify whether the terminal device is successfully registered; When the terminal device is verified as successfully registered, send a request for the NAS key, wherein the request includes: an anchor key identifier and a NAS parent key identifier; When the request does not include a HASH value, receive the NAS parent key identified by the anchor key identifier and the NAS parent key identifier as the NAS key; and When the request further includes a HASH value, receive the NAS sub - key based on the anchor key identifier, the NAS parent key identifier, and the HASH value as the NAS key, the NAS sub - key identifier for the NAS sub - key, and the NAS parent key identifier.

69. The method according to any one of claims 65 to 68, wherein the method further includes: Generate a HASH value based on at least one of the following: a protocol data unit (PDU) session identifier (ID); A single network slice selection assistance information (S - NSSAI); Or a network function set identifier.

70. The method according to any one of claims 65 to 69, wherein the core network entity is a source network entity in a handover or a NAS registration update, and wherein the method further includes: Derive a new NAS key for the NAS connection based on the current NAS key for the NAS connection and the NAS count; And Provide the new NAS key to the target network entity in the handover or the NAS registration update.