Key management for applications
The method addresses the lack of cryptographic parameter delivery to VPLMN LIF in AKMA by enabling the HPLMN's AAnF to manage and distribute keys to the VPLMN's LIF, ensuring lawful interception of UE-AF communications.
Patent Information
- Application Number
- CN202380083169.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-10-10
- Filing Date
- 2023-10-03
- Publication Date
- 2025-07-15
AI Technical Summary
In the prior art, the 3GPP AKMA roaming solution fails to effectively meet the legal listening requirements, and HPLMN is unable to provide the VPLMN with the necessary password parameters to support service decryption between the UE and the AF.
Provided is a method to ensure that the LIF within the VPLMN can decrypt the UE's services by obtaining the address of the legal listening function (LIF) and providing the LIF with the cryptographic information, including the key material, to the LIF.
The network function in the HPLMN can provide the necessary password information to the LIF in the VPLMN, so that the LIF in the VPLMN can decrypt services to the UE and services from the UE, and meet the needs of legal listening.
Smart Images

Figure CN120323045A_ABST
Abstract
Description
Technical Field
[0001] Embodiments related to key management for applications are disclosed. Background Art
[0002] The 3rd Generation Partnership Project (3GPP) Technical Specification (TS) 33.535 V17.7.0 (“TS 35.535”) specifies security features and mechanisms such as Application Authentication and Key Management (AKMA) to support application authentication and key management based on 3GPP 5th Generation (5G) subscription credentials, thereby enabling secure establishment between a User Equipment (UE) and an Application Function (AF). The AF can be inside (e.g., core network) or outside the 5G system. 3GPP is also studying potential enhanced requirements to support AKMA when the UE is roaming (e.g., see 3GPP Technical Report (TR) 33.737 V0.2.0 (“TR 33.737”).
[0003] TR 33.737 describes certain “key issues”. As described in TR 33.737, the AKMA roaming scenario depends on the UE and AF locations, and there are different scenarios for AKMA roaming that need to be addressed, including:
[0004] Case 1: The UE is in a Visited Public Land Mobile Network (VPLMN) and accessing an AF (both internal AF and external AF) in the Home Public Land Mobile Network (HPLMN); and
[0005] Case 2: The UE is in a VPLMN and accessing an AF (both internal AF and external AF) in the VPLMN.
[0006] As further pointed out in TR 33.737, the AKMA roaming solution should comply with the Lawful Interception (LI) requirements. The requirements should provide the VPLMN with the means to decrypt the traffic or provide the means for law enforcement to decrypt the traffic (e.g., provide keys). The LI requirements for access keys are only for encryption and apply when the “Ua*” protocol is encrypted in the AKMA case. Summary of the Invention
[0007] There are certain challenges currently. For example, it is desirable that the AKMA roaming solution should comply with the LI requirements. Therefore, the Home PLMN (HPLMN) of the UE should support the means for the Visited PLMN (VPLMN) to decrypt the traffic between the UE and the AF, and this security is established based on the AKMA service provided by the HPLMN. However, according to the above architecture, the AKMA service signaling does not traverse on the VPLMN. Therefore, there is no provision on how the HPLMN provides the cryptographic parameters to the LI function within the VPLMN.
[0008] Thus, in one aspect, a method for providing cryptographic information to a Lawful Interception Function (LIF) is provided. The method includes: obtaining an address for the LIF. The method further includes: obtaining cryptographic information (e.g., a cryptographic key) that is used to secure communication between a User Equipment (UE) and an Application Function (AF). The method further includes: using the obtained address for the LIF to provide a report message containing the obtained cryptographic information to the LIF.
[0009] In another aspect, a computer program comprising instructions is provided, which when executed by a processing circuit of a device, cause the device to implement any of the methods disclosed herein. In one embodiment, a carrier containing the computer program is provided, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer-readable storage medium. In another aspect, a device configured to implement the methods disclosed herein is provided. The device may include a memory and a processing circuit coupled to the memory.
[0010] The advantages of the embodiments disclosed herein are that they enable network functions within the UE's Home Public Land Mobile Network (HPLMN) to provide necessary cryptographic information to the Lawful Interception (LI) function in the Visited Public Land Mobile Network (VPLMN) in which the UE is currently receiving service. This enables the LI function within the VPLMN to decrypt traffic destined for the UE and traffic from the UE. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The drawings incorporated herein and forming a part of this specification illustrate various embodiments.
[0012] Figure 1A An AKMA architecture represented according to reference points for an internal AF is shown.
[0013] Figure 1B An AKMA architecture represented according to reference points for an external AF is shown.
[0014] Figure 2 A roaming network model for AKMA when the AF is inside the HPLMN is shown.
[0015] Figure 3 A roaming network model for AKMA when the AF is external (e.g., located in a Data Network (DN)) is shown.
[0016] Figure 4 A roaming network model for AKMA when the AF is inside the VPLMN is shown.
[0017] Figure 5 is a signaling diagram according to some embodiments.
[0018] Figure 6 is a flowchart showing a process according to an embodiment.
[0019] Figure 7 is a block diagram of a network node according to an embodiment. DETAILED DESCRIPTION
[0020] Figure 1A shows the AKMA architecture represented according to reference points for internal AF, Figure 1B shows the AKMA architecture represented according to reference points for external AF. As Figure 1A and Figure 1B shown, the AKMA service requires a logical entity called the AKMA anchor function (AAnF) 102.
[0021] The AAnF 102 is an anchor function in the HPLMN of the UE 101. The AAnF stores the AKMA anchor key (K AKMA ) and the subscriber permanent identifier (SUPI), which are received from the authentication server function (AUSF) 106 after the UE successfully completes 5G primary authentication. The AAnF also generates key material to be used between the UE and the application function (AF) 104 and maintains the UE AKMA context. The AAnF sends the SUPI of the UE to the AF located within the operator's network or to the NEF 112 according to an AF request.
[0022] In 3GPP TS23.501 V17.6.0 (“TS23.501”), it is defined that the AF has possible additional functions, such as: i) the AF with the AKMA service, enabling the use of the A-KID to request the AKMA application key (K AF ) from the AAnF; ii) before providing K AF to the AF, the AF shall be authenticated and authorized by the operator network; and iii) the AF located within the operator's network implements AAnF selection.
[0023] In TS23.501, it is defined that the NEF has possible additional functions, such as: i) the NEF enables and authorizes the external AF to evaluate the AKMA service and forwards the request to the AAnF, and ii) the NEF implements AAnF selection.
[0024] In TS23.501, it is defined that the AUSF has possible additional functions, such as: i) the AUSF provides the SUPI and AKMA key material (A-KID, K AKMA ) of the UE to the AAnF, and ii) the AUSF implements AAnF selection.
[0025] TS 23.501 defines that the UDM 108 has an additional function of storing the AKMA subscription data of the subscriber.
[0026] Figure 2 Shows the roaming network model for AKMA when the AF is within the HPLMN; Figure 3 Shows the roaming network model for AKMA when the AF is external (e.g., located in a data network (DN)); Figure 4 Shows the roaming network model for AKMA when the AF is within the VPLMN. When the UE is roaming and attempts to access an internal HPLMN AF, the UE uses a home-routed protocol data unit (PDU) session, and the access is handled by the internal AF, as described in Section 6.2 of TS 33.535. When the UE is roaming and attempts to access an external AF of the HPLMN or VPLMN, the access is handled by the external AF, as described in Section 6.3 of TS 33.535. In other words, the external AF contacts the HPLMN AAnF via the HPLMN NEF. When the UE is roaming and attempts to access an internal AF of the VPLMN, the access is handled by the external AF, as described in Section 6.3 of TS 33.535. In other words, the VPLMN AF contacts the HPLMN AAnF via the HPLMN NEF.
[0027] In one embodiment, a lawful interception (LI) function 502 (referred to herein as the "AKMA LI regulatory control point (ALICP)" 502 (see Figure 5 )) is provided that is deployed in the serving VPLMN. The ALICP obtains cryptographic parameters and performs the necessary regulatory actions accordingly.
[0028] The ALICP can be an independent node in the PLMN, or can be combined with existing 5G core network functions (NFs) (such as the access and mobility management function (AMF) 110, the security anchor function (SEAF), the session management function (SMF), the user plane function (UPF), etc.), or can be part of these 5G NFs.
[0029] The traffic encryption between the UE and the AF is enabled by cryptographic parameters (e.g., encryption keys). The cryptographic parameters can include: i) security material specified in the AKMA service and known to the AKMA anchor function (AAnF), including keys K akma 、K af and the information used to derive K af and / or refresh K af (e.g., this information can include a counter) (for the sake of brevity, these are referred to as "cryptographic information 1"); and
[0030] ii) Security keys that are not specified in the AKMA service and are known to the AF, including: keys derived from K af or other parameters derived in the AF, information for key derivation (e.g., the selected encryption algorithm, cipher suite, inputs for encrypting keys, random numbers, counters, etc.) (for the sake of brevity, these are referred to as "cryptographic information 2").
[0031] In some embodiments, when the AAnF obtains cryptographic information 1 or cryptographic information 2 or an update of these parameters, the AAnF delivers the cryptographic information to the ALICP. The AAnF may obtain the ALICP address (for each VPLMN) in the following ways: 1) based on local configuration and VPLMN ID information (which is part of the UE roaming information retrieved from the UDM), and / or 2) directly from the UE roaming message containing the ALICP information (i.e., when the UE attaches to the 5GC, the AMF registers the address of the ALICP of the serving PLMN in the UE registration context stored in the UDM). In some embodiments, when the AAnF receives an AKMA root key registration, it retrieves the UE roaming information, vPLMN information, and / or ALICP information from the UDM and subscribes to the UDM to obtain potential further updates of this information. The AAnF may obtain cryptographic information 2 from the AF via the Network Exposure Function (NEF).
[0032] Figure 5 is a signaling diagram showing a process according to some embodiments.
[0033] The process begins with: the UE 101 sending a registration request message m502, which is received and processed by the AMF 110. If the registration request indicates that the UE is performing an initial registration, an authentication process is performed.
[0034] The process further includes: the AUSF sending a registration key message m506 to the AAnF, the message including the AKMA anchor key (K AKMA ), which is generated as defined in TS 33.535. The AAnF stores K AKMA .
[0035] After receiving message m506, AAnF sends an information request message m508 (e.g., UE roaming information request message) to the UDM. Message m508 contains the ID associated with the UE (UE ID, such as SUPI), and may also include an indication for retrieving ALICP information (e.g., the address for ALICP, which ALICP may include in the network function (NF) profile it registers with the Network Repository Function (NRF)). Message m508 configures the UDM such that when the information of the UE identified by the UE ID is updated, the UDM sends a notification message to AAnF, which may include the updated information.
[0036] The UDM sends a response message m509 (e.g., UE roaming information response message) to the AANF. Message m509 contains the UE ID of the UE, UE context information (e.g., the PLMN ID of the network serving the UE, the AMF address of the AMF serving the UE, the ALICP address (if available), access type, etc.). If the UE has not been registered in the UDM or is registered on more than one visited PLMN, there may be zero or multiple sets of such information in the response message m509. In the case where the registration request m502 is not for an initial registration, UE context information including the ALICP address may already exist in the UDM, e.g., from an earlier UE registration.
[0037] In one embodiment, the AMF obtains the address of the ALICP (e.g., by retrieving the NF profile (or a part thereof) of the ALICP from the NRF or retrieving the address of the ALICP from the local configuration of the AMF). The address may be an Internet Protocol address or a domain name (e.g., a Fully Qualified Domain Name (FQDN)). After obtaining the ALICP address, the AMF sends a registration message m510 to the UDM (e.g., the AMF invokes the Nudm_UECM_Registration procedure). This message contains the UE ID of the UE, the serving PLMN ID, and the ALICP address. The UE registration information is updated and stored in the UDM. This step may occur before AAnF sends message m508; in this scenario, the response message 509 should contain the ALICP address. The AMF also sends a registration acceptance message m504 to the UE to notify the UE that its registration request has been accepted.
[0038] Assuming that the registration information of the UE has been updated (e.g., the ALICP address has been added to the registration information of the UE), the UDM sends a notification message m511 (e.g., UE roaming information update) to the AAnF. This message m511 contains the UE ID of the UE and the ALICP address (this message may also include other UE context information (e.g., the PLMN ID of the visited network, the AMF address, access type, etc.)).
[0039] As Figure 5 shown, the UE can initiate communication with the AF by sending a session establishment request message m512 to the AF. After receiving the message m512, the AF requests an AF key from the AAnF (possibly via the NEF if the AF is not authorized to communicate directly with the AAnF). That is, the AF sends a key request message m514. In some embodiments, the key request message m514 is a Naanf_AKMA_ApplicationKey_Get request message or a Nnef_AKMA_ApplicationKey_Get request message, both defined in TS33.535.
[0040] After receiving the key request message m514, the AAnF generates an AF key (K af ), and as specified in TS 33.535, the AAnF sends a key response message m516 containing K af to the AF. The key response message can be a Naanf_AKMA_ApplicationKey_Get response message or a Nnef_AKMA_ApplicationKey_Get response, both defined in TS 33.535.
[0041] In one embodiment, the AAnF includes in the key response message m516 an indicator requesting the AF to report AF cipher information (i.e., cipher information 2).
[0042] After obtaining Kaf, the AF can generate cipher information 2 (e.g., security material derived from Kaf or other key material derived in the AF, and the information used for its key derivation includes the selected encryption algorithm, cipher suite, inputs for encrypting the following: keys, random numbers, counters, etc.). In addition, the AF can send a report message m517 containing cipher information 2 to the AAnF.
[0043] After sending the AF key to the AF, the AAnF can obtain the ALICP address and use the ALICP address to send a report message m518 to the ALICP, which contains the UE ID (e.g., SUPI) cipher information 1 and / or cipher information 2 in the report message m517 obtained from the AF.
[0044] The AF also sends a session establishment response message m520 to the UE. At this time, the communication between the UE and the AF is established and protected. This communication can be protected by cipher information 1 (e.g., Kaf) or cipher information 2 (e.g., key material derived from Kaf or other key material derived in the AF).
[0045] If the AF updates the cryptographic parameters for securing traffic to / from the UE, the AF may send another report message m522 (e.g., AF cryptographic information report) via the NEF to provide or update the cryptographic information 2 to the AAnF. This message contains the UEID and the cryptographic information 2.
[0046] When the cryptographic information 1 or the cryptographic information 2 is updated in the AAnF, the AAnF sends another report message m524 (e.g., AKMA cryptographic information update) to the ALICP. Message m524 contains the UE ID (e.g., SUPI), the cryptographic information 1 or the cryptographic information 2 or both.
[0047] In the above manner, the ALICP obtains the AKMA cryptographic information for the UE and accordingly performs the necessary regulatory operations (e.g., now the ALICP can decrypt the traffic sent by the UE to the AMF and the traffic sent by the AF to the UE).
[0048] In some embodiments, if the ALICP address is not reported by the AMF to the UDM and is not included in the UE roaming information, the AAnF obtains the ALICP address based on the local configuration and the PLMN ID identifying the network serving the UE.
[0049] In some embodiments, if the AKMA context is removed or stopped in the AAnF, the AAnF may send a message (e.g., AKMA cryptographic information removal) to the ALICP to remove all the AKMA cryptographic information for the UE.
[0050] Figure 6 is a flowchart showing a process 600 according to an embodiment. The process 600 may start at step s602.
[0051] Step s602 includes: obtaining the address for the lawful interception function (LIF) (also referred to as the ALICP).
[0052] Step s604 includes: obtaining the cryptographic information (e.g., cryptographic key) used to secure the communication between the UE and the AF.
[0053] Step s606 includes: using the obtained address for the LIF to provide the obtained cryptographic information to the LIF.
[0054] Figure 7 is a block diagram of a network node 700 according to some embodiments. The network node 700 may implement any of the network functions disclosed herein. As Figure 7As shown in the figure, the network node 700 may include: a processing circuit (PC) 702, which may include one or more processors (P) 755 (e.g., one or more general-purpose microprocessors and / or one or more other processors, such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), etc.), which may be co-located in a single housing or a single data center, or may be geographically distributed (i.e., the network node 700 may be a distributed computing device); at least one network interface 748 (e.g., a physical interface or an air interface), including a transmitter (Tx) 745 and a receiver (Rx) 747 for enabling the network node 700 to send data to and receive data from other nodes connected to the network 110 (e.g., an Internet Protocol (IP) network), and the network interface 748 is (physically or wirelessly) connected to the network 110 (e.g., the network interface 748 may be coupled to an antenna device, which includes one or more antennas for enabling the network node 700 to wirelessly send / receive data); and a storage unit (also referred to as a "data storage system") 708, which may include one or more non-volatile storage devices and / or one or more volatile storage devices. In embodiments where the PC 702 includes a programmable processor, a computer-readable storage medium (CRSM) 742 may be provided. The CRSM 742 may store a computer program (CP) 743 including computer-readable instructions (CRI) 744. The CRSM 742 may be a non-transitory computer-readable medium, such as a magnetic medium (e.g., a hard disk), an optical medium, a storage device (e.g., a random access memory, a flash memory), etc. In some embodiments, the CRI 744 of the computer program 743 is configured such that when executed by the PC 702, the CRI causes the network node 700 to implement the steps described herein (e.g., the steps described herein with reference to the flowcharts). In other embodiments, the network node 700 may be configured to implement the steps described herein without code. That is, for example, the PC 702 may consist only of one or more ASICs. Thus, the features of the embodiments described herein may be implemented in hardware and / or software.
[0055] Overview of various embodiments
[0056] A1. A method 600 (see Figure 6 ) includes: obtaining (s602) an address for a lawful interception function (LIF) (also referred to as an ALICP); obtaining (s604) cryptographic information (e.g., a cryptographic key) for securing communication between a user equipment UE 101 and an application function AF 104; and using (s606) the obtained address for the LIF to provide a report message (m518, m524) including the obtained cryptographic information to the LIF.
[0057] A2. The method according to embodiment A1, wherein the method is implemented by an anchor function AnF (e.g., an Application Authentication and Key Management (AMKA) anchor function (AAnF)).
[0058] A3. The method according to embodiment A1 or A2, wherein obtaining an address for the LIF includes: receiving messages (m509, m511) sent by a data manager 108 (e.g., 5G Unified Data Management (UDM)), and the messages sent by the data manager include an identifier associated with the UE (e.g., SUPI) and an address for the LIF.
[0059] A4. The method according to embodiment A1 or A2, wherein obtaining an address for the LIF includes: receiving messages (m509, m511) sent by a data manager 108 (e.g., 5G Unified Data Management (UDM)), wherein the messages sent by the data manager include a network identifier (e.g., PLMN ID) identifying the network serving the UE; and using the PLMN ID to determine the address.
[0060] A5. The method according to any one of embodiments A1 - A4, further comprising: receiving a key request message (m514) from the AF; and in response to the key request message, sending a key response message (m516) to the AF, wherein the key response message includes an AF key.
[0061] A6. The method according to embodiment A5, wherein the report message includes the AF key.
[0062] A7. The method according to embodiment A5, further comprising: after sending the key response message, receiving messages (m517, m522) sent by the AF, wherein the messages sent by the AF include a derived key derived by the AF using the AF key and / or parameters used by the AF to derive the derived key, and the report message includes the derived key and / or the parameters used by the AF to derive the derived key.
[0063] A8. The method according to any one of embodiments A5 - A7, further comprising: generating the AF key in response to receiving the key request message.
[0064] A9. The method according to any one of embodiments A1 - A8, wherein the UE has a home Public Land Mobile Network PLMN, the UE is currently being served by a visited PLMN, i.e., VPLMN, the LIF is within the VPLMN, and the method is implemented by a network function within the home PLMN of the UE.
[0065] B1. A computer program (743) comprising instructions (744) which, when executed by a processing circuit (702) of a network node, cause the network to implement a method according to any one of embodiments A1 - A9.
[0066] B2. A carrier containing the computer program according to embodiment B1, wherein the carrier is one of an electronic signal, an optical signal, a radio signal, and a computer - readable storage medium (742).
[0067] C1. A network node (700) configured to implement a process comprising: obtaining (s602) an address for a lawful interception function (LIF) (also referred to as ALICP); obtaining (s604) cryptographic information (e.g., a cryptographic key) for securing communication between a user equipment UE 101 and an application function AF104; and using (s606) the obtained address for the LIF to provide a report message (m518, m524) of the obtained cryptographic information to the LIF.
[0068] C2. The network node according to embodiment C2, wherein the network node is further configured to implement a process according to any one of embodiments A2 - A9.
[0069] Although various embodiments are described herein, it should be understood that they are presented by way of example and not limitation. Accordingly, the breadth and scope of the present disclosure should not be limited by any of the above - described exemplary embodiments. Additionally, unless otherwise stated herein or unless clearly contradicted by the context, any combination of the above elements in all possible variations is covered by the present disclosure.
[0070] As used herein, "sending" a message to or towards an intended recipient includes sending the message directly to the intended recipient or sending the message indirectly to the intended recipient (i.e., one or more other nodes are used to relay the message from the source node to the intended recipient). Similarly, as used herein, "receiving" a message from a sender includes receiving the message directly from the sender or receiving the message indirectly from the sender (i.e., one or more nodes are used to relay the message from the sender to the receiving node). Further, as used herein, "a" means "at least one" or "one or more".
[0071] Furthermore, although the processes shown above and in the figures are shown as a series of steps, this is done merely for illustration. Accordingly, it is contemplated that some steps may be added, some steps may be omitted, the order of the steps may be rearranged, and some steps may be implemented in parallel.
Claims
1. A method (600), comprising: obtaining (s602) an address for a lawful interception function LIF; obtaining (s604) cryptographic information for securing communication between a user equipment UE (101) and an application function AF (104); and using (s606) the obtained address for the LIF to provide a report message (m518, m524) including the obtained cryptographic information to the LIF.
2. The method according to claim 1, wherein, The method is implemented by an anchor function AnF.
3. The method according to claim 1 or 2, wherein Obtaining the address for the LIF includes: receiving messages (m509, m511) sent by a data manager (108), and the messages sent by the data manager include an identifier associated with the UE and the address for the LIF.
4. The method according to claim 1 or 2, wherein Obtaining the address for the LIF comprises: receiving messages (m509, m511) sent by a data manager (108), wherein the messages sent by the data manager include a network identifier identifying a network serving the UE; and using the network identifier to determine the address.
5. The method according to any one of claims 1-4, further comprising: receiving a key request message (m514) from the AF; and in response to the key request message, sending a key response message (m516) to the AF, wherein the key response message includes an AF key.
6. The method according to claim 5, wherein The report message includes the AF key.
7. The method according to claim 5, further comprising: after sending the key response message, receiving messages (m517, m522) sent by the AF, wherein the messages sent by the AF include an export key derived by the AF using the AF key and / or parameters used by the AF to derive the export key, wherein the report message includes the export key and / or the parameters used by the AF to derive the export key.
8. The method according to any one of claims 5-7 further comprises: Generating the AF key in response to receiving the key request message.
9. The method according to any one of claims 1 to 8, wherein the UE has a home public land mobile network PLMN, the UE is currently being served by a visited PLMN, i.e., VPLMN, the LIF is within the VPLMN, and the method is implemented by a network function within the home PLMN of the UE.
10. A computer program (743) comprising instructions (744) which, when executed by a processing circuit (702) of a network node, cause the network to implement the method according to any one of claims 1-9.
11. A carrier containing the computer program according to claim 10, wherein, The carrier is one of an electronic signal, an optical signal, a radio signal, and a computer-readable storage medium (742).
12. A network node (700) configured to implement a process comprising the following: obtaining (s602) an address for a lawful interception function LIF; obtaining (s604) cryptographic information for securing communication between a user equipment UE (101) and an application function AF (104); and Use the obtained address for the LIF to provide a report message (m518, m524) including the obtained password information to the LIF.
13. The network node according to claim 12, wherein, The network node is further configured to perform the process according to any one of claims 2-9.