Wireless method and device thereof

Through the wireless communication method between the anchor function and the authentication server function, the service network names of different access types are stored and managed, which solves the problem of multiple registration of user equipment in multiple registration scenarios, ensuring correct key material transmission and supervision service support.

CN120359791APending Publication Date: 2025-07-22ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380083060.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-13
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In a multiple registration scenario, when a user device performs multiple registrations in a service network of a different public land mobile network, it may only use one access network to connect to the target application function, resulting in some multiple registration problems in the application authentication and key management roaming scenario.

Method used

Through the wireless communication method between the anchor function and the authentication server function, service network names of different access types are stored and managed, and key information is transmitted based on the current network, ensuring that the key material can be correctly transmitted regardless of which network initiated service by the user equipment.

Benefits of technology

It solves the multiple registration problem in the AKMA roaming scenario, ensuring that no matter which network initiates the service by the user equipment, the key material can be correctly transmitted, and the supervision service is supported.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120359791A_ABST
    Figure CN120359791A_ABST
Patent Text Reader

Abstract

A wireless communication method for use in an anchor function is disclosed. The method includes receiving a first key registration request for a wireless terminal from an authentication server function, where the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network, where the first access type is one of a plurality of access types; the first serving network name is stored as a current network of the wireless terminal corresponding to the first access type.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This document generally relates to wireless communication, and in particular to fifth-generation (5G) communication. th Generation, 5G) communication.

[0002] According to the prior art, in a multi-registration scenario, a user equipment (UE) can perform multi-registration in serving networks of different public land mobile networks (PLMNs). Although the UE can be connected to two different access networks, the UE may only utilize one access network to connect to a target application function (AF), resulting in certain multi-registration problems in the authentication and key management for applications (AKMA) roaming scenario.

[0003] This document relates to methods, systems, and devices for multi-registration, and in particular to methods, systems, and devices for multi-registration in AKMA roaming.

[0004] This disclosure relates to a wireless communication method used in an anchor function. The method includes:

[0005] Receiving, from an authentication server function, a first key registration request for a wireless terminal, where the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network, and the first access type is one of a plurality of access types; and

[0006] Storing the first service network name as the current network of the wireless terminal corresponding to the first access type.

[0007] Various embodiments may preferably implement the following features:

[0008] Preferably, the plurality of access types include a trusted access type and an untrusted access type.

[0009] Preferably, the wireless communication method further includes:

[0010] Receiving, from an application function, a key acquisition request for the wireless terminal, and

[0011] Transmitting, based on the current networks corresponding to the plurality of access types, key information of the wireless terminal to a plurality of network functions.

[0012] Preferably, the wireless communication method further includes:

[0013] Receive a key acquisition request for a wireless terminal from an application function, and

[0014] Transmit the key information of the wireless terminal to a first network function of a current network corresponding to a first access type.

[0015] Preferably, the wireless communication method further includes:

[0016] Receive a second key registration request for the wireless terminal from an authentication server function, where the second key registration request includes a second service network name of a second access network and a second access type associated with the second access network, where the second access type is one of a plurality of access types and is different from the first access type, and

[0017] Store the second service network name as the current network of the wireless terminal corresponding to the second access type.

[0018] Preferably, the wireless communication method further includes:

[0019] Receive a key acquisition request for a wireless terminal from an application function, and

[0020] Transmit the key information of the wireless terminal to a first network function of a current network corresponding to a first access type, and

[0021] Transmit the key information of the wireless terminal to a second network function of a current network corresponding to a second access type.

[0022] Preferably, the wireless communication method further includes:

[0023] Receive a third key registration request for the wireless terminal from an authentication server function, where the third key registration request includes a third service network name of a third access network and a first access type associated with the third access network, and

[0024] Store the third service network name as the current network of the wireless terminal corresponding to the first access type.

[0025] Preferably, the wireless communication method further includes:

[0026] Receive a key acquisition request for a wireless terminal from an application function, and

[0027] Transmit the key information of the wireless terminal to a third network function of a current network corresponding to a first access type, and

[0028] Transmit the key information of the wireless terminal to a second network function of a current network corresponding to a second access type.

[0029] Preferably, the first key registration request further includes a first anchor key and a first key identifier, and the method further includes:

[0030] Storing the first anchor key as the current anchor key of the wireless terminal, and

[0031] Storing the first anchor key identifier as the current anchor key identifier of the wireless terminal.

[0032] Preferably, the wireless communication method further includes:

[0033] Receiving a fourth key registration request for the wireless terminal from an authentication server function, where the fourth key registration request includes a second anchor key and a second key identifier,

[0034] Storing the second anchor key as the current anchor key of the wireless terminal, and

[0035] Storing the second anchor key identifier as the current anchor key identifier of the wireless terminal.

[0036] Preferably, the fourth key registration request is associated with a fourth access network, and the fourth access network has a fourth access type that is the same as or different from the first access type.

[0037] The present disclosure relates to a wireless communication method used in an authentication server function. The method includes: transmitting a first key registration request for a wireless terminal to an anchor function, where the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network, and the first access type is one of a plurality of access types.

[0038] Various embodiments may preferably implement the following features:

[0039] Preferably, the plurality of access types includes a trusted access type and an untrusted access type.

[0040] Preferably, the wireless communication method further includes: transmitting a second key registration request for the wireless terminal to the anchor function, where the second key registration request includes a second service network name of a second access network and a second access type associated with the second access network, and the second access type is one of the plurality of access types and is different from the first access type.

[0041] Preferably, the wireless communication method further includes: transmitting a third key registration request for the wireless terminal to the anchor function, where the third key registration request includes a third service network name of a third access network and the first access type associated with the third access network.

[0042] Preferably, the first key registration request further includes a first anchor key and a first key identifier.

[0043] Preferably, the wireless communication method further includes:

[0044] A fourth key registration request for the wireless terminal is transmitted to the anchor function, wherein the fourth key registration request includes the second anchor key and the second key identifier.

[0045] Preferably, the fourth key registration request is associated with a fourth visited network having a fourth access type which is the same as or different from the first access type.

[0046] The present disclosure relates to a wireless device for anchor point function. The wireless device comprises:

[0047] a communication unit configured to receive a first key registration request for the wireless terminal from the authentication server function, wherein the first key registration request includes a first serving network name of a first access network and a first access type associated with the first access network, wherein the first access type is one of a plurality of access types, and

[0048] The processor is configured to store the first service network name as a current network of the wireless terminal corresponding to the first access type.

[0049] Various embodiments may preferably achieve the following features:

[0050] Preferably, the processor is further configured to execute any of the aforementioned wireless communication methods.

[0051] The present disclosure relates to a wireless device for authenticating server functions. The wireless device comprises:

[0052] A communication unit is configured to transmit a first key registration request for the wireless terminal to the anchor function, wherein the first key registration request includes a first serving network name of a first access network and a first access type associated with the first access network, wherein the first access type is one of a plurality of access types.

[0053] Various embodiments may preferably achieve the following features:

[0054] Preferably, the wireless device further comprises a processor configured to execute any of the aforementioned wireless communication methods.

[0055] The present disclosure relates to a computer program product, including a computer-readable program medium code stored thereon, and when the code is executed by a processor, the processor implements the wireless communication method described in any of the aforementioned methods.

[0056] Exemplary embodiments disclosed herein are intended to provide certain features which will become apparent by incorporating the accompanying drawings and referring to the following description. According to various embodiments, exemplary systems, methods, devices, and computer program products are disclosed herein. However, it should be understood that these embodiments are presented by way of example and not limitation, and various modifications to the disclosed embodiments will be apparent to those of ordinary skill in the art who have read this disclosure, and such modifications are still within the scope of this disclosure.

[0057] Accordingly, this disclosure is not limited to the exemplary embodiments and applications described and illustrated herein. In addition, the particular order and / or hierarchy of steps in the methods disclosed herein are merely exemplary methods. Based on design preferences, the particular order or hierarchy of steps of the disclosed method or process can be rearranged while remaining within the scope of this disclosure. Thus, those of ordinary skill in the art will understand that the methods and techniques disclosed herein present various steps or acts in an exemplary order, and this disclosure is not limited to the particular order or hierarchy presented unless otherwise expressly stated.

[0058] The invention is defined by the independent claims. Preferred embodiments are defined in the dependent claims. In the following description, although many features may be designated as optional, it should be recognized that all features included in the independent claims should not be construed as optional.

[0059] The above and other aspects and their implementations are described in more detail in the drawings, the description, and the claims.

[0060] Figure 1 A schematic diagram of a network according to an embodiment of the present disclosure is shown.

[0061] Figures 2A to 2C A schematic diagram of a process according to an embodiment of the present disclosure is shown.

[0062] Figure 3 An example of a schematic diagram of a wireless terminal according to an embodiment of the present disclosure is shown.

[0063] Figure 4 An example of a schematic diagram of a wireless network node according to an embodiment of the present disclosure is shown.

[0064] Figure 5 A flowchart of a method according to an embodiment of the present disclosure is shown.

[0065] Figure 6 A flowchart of a method according to an embodiment of the present disclosure is shown.

[0066] Figure 1Shows a service-based architecture (SBA) of a 5G System (5GS) for roaming UE access to application functions. Figure 1 The 5GS shown includes the following network functions (NFs):

[0067] The Access and Mobility Management function (AMF) includes functions such as UE mobility management, reachability management, connection management, etc.

[0068] The Security Anchor Function (SEAF) in the serving network stores an anchor key called KSEAF provided by the AUSF of the home network. KSEAF is derived from the key material generated by the primary authentication and key negotiation process.

[0069] The Authentication Server Function (AUSF) supports authentication for 3rd Generation Partnership Project (3GPP) access and untrusted non-3GPP access. In the AKMA architecture, the AUSF provides the Subscription Permanent Identifier (SUPI) of the UE and the AKMA key material (e.g., AKMA key ID (A-KID) and / or AKMA Anchor Key (K AKMA )) to the AAnF. The AUSF also performs AAnF selection.

[0070] The AKMA Anchor Function (AAnF) stores the AKMA key material (e.g., K AKMA and / or SUPI) of the UE for AKMA services, where the AKMA key material is received from the AUSF after the UE successfully completes 5G primary authentication. The AAnF also generates the AKMA key material to be used between the UE and the Application Function (AF) and maintains the UE AKMA context. The AAnF transmits the SUPI of the UE to the AF located inside the network operator's network or sends the SUPI to the Network Exposure Function (NEF) according to a request from the SUPI.

[0071] Unified Data Management (UDM) stores the subscription profiles of UEs. In the AKMA architecture, UDM stores the AKMA subscription data of users.

[0072] As discussed in the background section, although a UE can be connected to two different access networks, the UE can use only one access network to connect to the target AF. In this case, some multiple registration problems in the AKMA roaming scenario may occur.

[0073] For example, the UE first registers with the visited Public Land Mobile Network 1 (VPLMN1) through 3GPP access (e.g., trusted access), and the AAnF stores the SN-name of VPLMN1. When the UE initiates an AKMA service in VPLMN1, the AAnF can transmit the AKMA key information to the NF in VPLMN1.

[0074] If the UE simultaneously registers with the visited Public Land Mobile Network 2 (VPLMN2) through non-3GPP access (e.g., untrusted access), the AAnF overwrites the SN-name of VPLMN1 and stores the SN-name of VPLMN2. In this case, regardless of whether the UE initiates an AKMA service through VPLMN1 or VPLMN2, the AAnF always transmits the AKMA key information to the NF in VPLMN2. If a supervision service is configured in VPLMN1, the supervision service cannot be realized.

[0075] Similarly, when the UE roams from VPLMN1 to another visited Public Land Mobile Network 3 (VPLMN3) through 3GPP access, if the primary authentication is triggered, the AAnF overwrites the SN-name of VPLMN2 and stores the SN-name of VPLMN3. In this case, regardless of whether the UE initiates an AKMA service through VPLMN2 or VPLMN3, the AAnF always transmits the AKMA key information to the NF in VPLMN3. If a supervision service is set up in VPLMN2, the supervision service cannot be implemented.

[0076] In the present disclosure, a method for multiple registration problems in the AKMA roaming scenario is disclosed.

[0077] In one embodiment, the AAnF stores the parameter "Access Type" to indicate whether the access is via 3GPP / non-3GPP access. For each access type, the AAnF stores the latest corresponding SN-name information. Note that the access type may not be limited to 3GPP access (e.g., trusted access) or non-3GPP access (untrusted access), and may include other types of access.

[0078] In one embodiment, regardless of which VPLMN the UE initiates the AKMA service through, the AAnF transmits the AKMA key material to the VPLMN based on the latest SN-name information for each access type. If there is only the latest SN-name information for a single access type, the AAnF transmits the AKMA key material to the VPLMN with that SN-name. If there is the latest SN-name information for multiple access types (e.g., 3GPP access and non-3GPP access), the AAnF transmits the AKMA key material to multiple VPLMNs according to the latest SN-name information.

[0079] Figures 2A to 2C A schematic diagram of a process according to an embodiment of the present disclosure is shown. Figures 2A to 2C The process shown includes the following steps:

[0080] Figure 2A Steps 1-8 in: The UE registers with VPLMN1 through the 3GPP access type.

[0081] Step 1: The UE is authenticated through the 3GPP access type in VPLMN1.

[0082] Step 2: After generating the AKMA key material, the AUSF selects the AAnF, uses the Naanf_AKMA_KeyRegistration request service operation, and sends the generated A-KID1, K AKMA , the SN-name of VPLMN1, and the corresponding access type (i.e., the 3GPP access type) together with the UE's SUPI to the AAnF.

[0083] Step 3: The AAnF stores the latest information sent by the AUSF. Note that the stored information includes the SN-name of VPLMN1 and the corresponding access type.

[0084] Step 4: The AAnF sends a response to the AUSF using the Naanf_AKMA_AnchorKey_Register response service operation.

[0085] Step 5: Before initiating communication with the AKMA Application Function (AF), the UE generates the A-KID1 and K received from K AUSF When / if the UE initiates an AKMA service in VPLMN1 to communicate with the AKMA AF, the UE includes the derived A-KID1 in the application session establishment request message. The UE may derive K before or after sending the message AKMA .. AF

[0086] Step 6: If the AF does not have an active context associated with A-KID1, the AF selects the AAnF and sends a Naanf_AKMA_ApplicationKey_Get request to the AAnF, with A-KID1, to request the UE's K AF . The AF may also include its identity (i.e., AF_ID) in the request

[0087] Step 7: If the AAnF does not have K AF , the AAnF derives K from K AKMA . In one embodiment, if the AAnF needs to provide regulatory information to VPLMN1, the AAnF needs to push the AKMA key material to the NF of VPLMN1 based on the SN-name of VPLMN1. For example, the NF in VPLMN1 to which the AKMA key material is pushed can be the AMF, AAnF or other new NF in VPLMN1 AF .

[0088] Step 8: The AAnF sends a Naanf_AKMA_ApplicationKey_Get response to the AF, with SUPI, K AF and K AF expiry time

[0089] Figure 2B Steps 9 - 16 in: If the UE wishes to register with VPLMN2 simultaneously via a non-3GPP access type, steps 9 - 16 are executed

[0090] Step 9: The UE is authenticated via a non-3GPP access type in VPLMN2

[0091] Step 10: After generating the AKMA key material, the AUSF uses the Naanf_AKMA_KeyRegistration request service operation to send the generated A-KID1, new K AKMA , the SN-name of VPLMN2 and the corresponding access type (i.e., 3GPP access type) together with the UE's SUPI to the AAnF​

[0092] Step 11: AAnF rewrites K AKMA as the newly received K AKMA , rewrites A-KID1 as A-KID2, and stores the SN-name and the corresponding access type of VPLMN2.

[0093] Specifically, AAnF checks whether it has SN-name information corresponding to the received access type and SUPI. If there is no existing SN-name information corresponding to this access type and SUPI, AAnF stores the SN-name and the corresponding access type.

[0094] Step 12: AAnF sends a response to the AUSF using the Naanf_AKMA_AnchorKey_Register response service operation.

[0095] Step 13: Before initiating communication with the AKMA AF, the UE generates a new K AUSF and A-KID2 from K AKMA , and rewrites the K AKMA and A-KID1 generated in step 5. When / if the UE initiates an AKMA service via VPLMN1 or VPLMN2 to communicate with the AKMA AF, the UE includes the derived A-KID2 in the application session establishment request message. The UE may derive K AKMA from the new K AF before or after sending the message.

[0096] Step 14: If the AF does not have an active context associated with A-KID2, the AF sends a Naanf_AKMA_ApplicationKey_Get request to the AAnF, with A-KID2, to request the UE's K AF . The AF may also include its identity (i.e., AF_ID) in the request.

[0097] Step 15: If the AAnF does not have K AF , the AAnF derives K AKMA from K AF . Note that if the AAnF needs to provide regulatory information, the AAnF needs to push the AKMA key material to the NFs in VPLMN1 and VPLMN2 based on the already stored SN-name and the corresponding access type.

[0098] For example, the NF can be the AMF, AAnF, or other new NFs in VPLMN1 and / or VPLMN2.

[0099] Step 16: AAnF sends an Naanf_AKMA_ApplicationKey_Get response to AF, with SUPI, K AF and K AF expiry time.

[0100] Figure 2C Steps 17 - 24 in : If the UE roams from VPLMN1 to another VPLMN3 and registers via 3GPP access, steps 17 - 24 are executed.

[0101] Step 17: The UE is authenticated via the 3GPP access type in VPLMN3.

[0102] Step 18: After generating the AKMA key material, the AUSF uses the Naanf_AKMA_KeyRegistration request service operation to send the generated A - KID3, new K AKMA , the SN - name of VPLMN3, and the corresponding access type, together with the UE's SUPI, to AAnF.

[0103] Step 19: AAnF rewrites K AKMA as the newly received K AKMA , rewrites A - KID2 as A - KID3, and rewrites the stored SN - name and corresponding access type of VPLMN3 as the received SN - name and access type of VPLMN3.

[0104] Specifically, AAnF checks whether it has SN - name information corresponding to the received access type (i.e., 3GPP access type) and SUPI. Since there is existing SN - name information corresponding to the received access type, AAnF rewrites the SN - name as the received SN - name of VPLMN3.

[0105] Step 20: AAnF sends a response to the AUSF using the Naanf_AKMA_AnchorKey_Register response service operation.

[0106] Step 21: Before initiating communication with the AKMA application function, the UE generates a new K AUSF and A - KID3 from K AKMA and rewrites the K AKMAand A-KID2. When the UE initiates the AKMA service via VPLMN2 or VPLMN3 to communicate with the AKMA AF, the UE includes the derived A-KID3 in the application session establishment request message. The UE can derive K from the new K before or after sending the message AKMA to derive K AF .

[0107] Step 22: If the AF does not have an active context associated with A-KID3, the AF sends a Naanf_AKMA_ApplicationKey_Get request to the AAnF, with A-KID3, to request the UE's K AF . The AF can also include its identity (i.e., AF_ID) in the request.

[0108] Step 23: If the AAnF does not have K AF , the AAnF derives K from K AKMA to derive K AF . Note that if the AAnF needs to provide regulatory information, the AAnF needs to push the AKMA key material to the NFs in VPLMN2 and VPLMN3 based on the already stored SN-name and the corresponding access type.

[0109] Note that the NFs in VPLMN2 and / or VPLMN3 can be the AMF, AAnF, or other new NFs in VPLMN2 and / or VPLMN3.

[0110] Step 24: The AAnF sends a Naanf_AKMA_ApplicationKey_Get response to the AF, with SUPI, K AF and K AF expiration time.

[0111] Figure 3Schematic diagram of a wireless terminal 30 according to an embodiment of the present disclosure. The wireless terminal 30 may be a UE, a mobile phone, a laptop computer, a tablet computer, an e-book, or a portable computer system, and is not limited thereto. The wireless terminal 30 may include a processor 300 such as a microprocessor or an application specific integrated circuit (ASIC), a storage unit 310, and a communication unit 320. The storage unit 310 may be any data storage device that stores program code 312 accessed and executed by the processor 300. Embodiments of the storage unit 312 include, but are not limited to, a subscriber identity module (SIM), a read-only memory (ROM), a flash memory, a random-access memory (RAM), a hard disk, and an optical data storage device. The communication unit 320 may be a transceiver and is used to transmit and receive signals (e.g., messages or packets) according to the processing result of the processor 300. In one embodiment, the communication unit 320 transmits and receives signals via Figure 3 at least one antenna 322 shown.

[0112] In one embodiment, the storage unit 310 and the program code 312 may be omitted, and the processor 300 may include a storage unit having the stored program code.

[0113] The processor 300 may implement any one of the steps in the exemplary embodiments on the wireless terminal 30, for example, by executing the program code 312.

[0114] The communication unit 320 may be a transceiver. Alternatively or additionally, the communication unit 320 may combine a transmission unit and a reception unit configured to transmit signals to and receive signals from a wireless network node (e.g., a base station), respectively.

[0115] Figure 4Schematic diagram of a wireless network node 40 according to an embodiment of the present disclosure. The wireless network node 40 can be a satellite, a base station (BS), a network entity, a mobility management entity (MME), a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), a radio access network (RAN) node, a next generation RAN (NG-RAN) node, a 5G base station (gNodeB, gNB), an evolved node B (eNB), a gNB central unit (gNB-CU), a gNB distributed unit (gNB-DU), a data network, a core network, a radio network controller (RNC), and is not limited thereto. In addition, the wireless network node 40 can include (perform) at least one network function, such as an access and mobility management function (AMF), a session management function (SMF), a user location function (UPF), a policy control function (PCF), an application function (AF), etc. The wireless network node 40 can include a processor 400 such as a microprocessor or an ASIC, a storage unit 410, and a communication unit 420. The storage unit 410 can be any data storage device that stores program code 412 accessed and executed by the processor 400. Examples of the storage unit 412 include, but are not limited to, SIM, ROM, flash memory, RAM, hard disk, and optical data storage devices. The communication unit 420 can be a transceiver and is used to transmit and receive signals (e.g., messages or packets) according to the processing result of the processor 400. In one example, the communication unit 420 transmits and receives signals via Figure 4 at least one antenna 422 shown.

[0116] In one embodiment, the storage unit 410 and the program code 412 can be omitted. The processor 400 can include a storage unit with stored program code.

[0117] The processor 400 may implement any of the steps described in the exemplary embodiments on the wireless network node 40, for example, by executing program code 412.

[0118] The communication unit 420 may be a transceiver. Alternatively or additionally, the communication unit 420 may combine a transmission unit and a reception unit configured to transmit signals to and receive signals from a wireless terminal (e.g., a user equipment or another wireless network node), respectively.

[0119] Figure 5 A flowchart of a method according to an embodiment of the present disclosure is shown. Figure 5 The method shown may be used in an anchor function (e.g., an AAnF, a wireless device including the AAnF, or a wireless device performing at least part of the functions of the AAnF), and includes the following steps:

[0120] Step 501: Receive a first key registration request for a wireless terminal from an AUSF, where the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network.

[0121] Step 502: Store the first service network name as the current network of the wireless terminal corresponding to the first access type.

[0122] In Figure 5 the anchor function receives a first key registration request (e.g., a Naanf_AKMA_KeyRegistration request) for a wireless terminal (e.g., a UE) from an AUSF. The first key registration request includes a first service network name of a first access network (e.g., a VPLMN) and a first access type associated with the first access network. The first access type is one of a plurality of access types. The anchor function stores the first service network name as the current network of the wireless terminal corresponding to the first access type. That is, the anchor function records the most recent service network name for each access type of the wireless terminal. Note that the service network name may be replaced by any service network information associated with (e.g., distinguishable from) the access network.

[0123] In one embodiment, the anchor function is in a home network (e.g., an HPLMN).

[0124] In one embodiment, the plurality of access types includes a trusted access type (e.g., a 3GPP access type) and an untrusted access type (e.g., a non-3GPP access type).

[0125] In one embodiment, the anchor function bases the key information (e.g., K AKMAand A-KID) to multiple network functions. In one embodiment, the network function may be an AMF or an AUSF in the corresponding network. In other words, if the anchor function needs to transmit the key information of the wireless terminal, the anchor function transmits / pushes the key information to the NF in the access network corresponding to multiple access types based on the stored SN name.

[0126] In one embodiment, the anchor function transmits the key information of the wireless terminal in response to receiving a key acquisition request for the wireless terminal from the AF (in the home network).

[0127] In one embodiment, the anchor function receives a second key registration request for the wireless terminal from the AUSF. The second key registration request includes the second service network name of the second access network and the second access type associated with the second access network. In this embodiment, the second access type is one of the multiple access types and is different from the first access type. The anchor function stores the second service network name as the current network corresponding to the second access type of the wireless terminal. Note that since the second access type is different from the first access type, the anchor function does not rewrite the current network corresponding to the first access type with the second service network name (i.e., the second access network). In this case, if the anchor function needs to transmit the key information of the wireless terminal (e.g., if a key acquisition request for the wireless terminal is received from the AF), the anchor function transmits the key information of the wireless terminal to the first network function (i.e., the first access network) of the current network corresponding to the first access type and the second network function (i.e., the second access network) of the current network corresponding to the second access type.

[0128] In one embodiment, the anchor function receives a third key registration request for the wireless terminal from the AUSF. The third key registration request includes the third service network name of the third access network and the third access type associated with the second access network. In this embodiment, the third access type is equal to the first access type. The anchor function stores the third service network name as the current network corresponding to the first / third access type of the wireless terminal. Note that since the third access type and the first access type are the same, the anchor function overwrites the current network corresponding to the first access type with the third service network name (i.e., the third access network). In this case, if the anchor function needs to transmit the key information of the wireless terminal (e.g., if a key acquisition request for the wireless terminal is received from the AF), the anchor function transmits the key information of the wireless terminal to the third network function (i.e., the third access network) of the current network corresponding to the first / third access type and the second network function (i.e., the second access network) of the current network corresponding to the second access type.

[0129] In one embodiment, the first key registration request further includes a first anchor key (e.g., K AKMA) and a first key identifier (e.g., A-KID), and the anchor function stores the first anchor key as the current anchor key of the wireless terminal and stores the first anchor key identifier as the current anchor key identifier of the wireless terminal.

[0130] In one embodiment, the anchor function receives, from the AUSF, a fourth key registration request for the wireless terminal (e.g., a second key registration request or a third key registration request). The fourth key registration request includes a second anchor key (e.g., K AKMA ) and a second key identifier (e.g., A-KID). In this embodiment, the anchor function stores the second anchor key as the current anchor key of the wireless terminal and stores the second anchor key identifier as the current anchor key identifier of the wireless terminal. Note that the fourth key registration request is associated with a fourth access network (e.g., having a fourth SN name for the fourth access network), and the fourth access network has a fourth access type that is the same as or different from the first access type. That is, regardless of whether the latest / received key registration request is associated with the same or a different access type, the anchor function always rewrites the anchor key and the key identifier (i.e., key information) with the anchor key and the key identifier included in the latest / received key registration request.

[0131] Figure 6 A flowchart of a method according to an embodiment of the present disclosure is shown. Figure 6 The method shown in can be used in an AUSF (e.g., a wireless device including an AUSF or a wireless device that performs at least part of the functions of an AUSF), and includes the following steps:

[0132] Step 601: Transmit a first key registration request for the wireless terminal to the anchor function, where the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network.

[0133] In Figure 6 , the AUSF transmits a first key registration request for the wireless terminal (e.g., UE) to the anchor function (e.g., AAnF). The first key registration request includes a first service network name of a first access network and a first access type associated with the first access network. In one embodiment, the first access type is one of multiple access types.

[0134] In one embodiment, the multiple access types include a trusted access type (e.g., 3GPP access type) and an untrusted access type (e.g., non-3GPP access type).

[0135] In one embodiment, the AUSF also transmits a second key registration request for the wireless terminal to the anchor function. The second key registration request includes the second service network name of the second access network and the second access type associated with the second access network. In this embodiment, the second access type is one of multiple access types and is different from the first access type.

[0136] In one embodiment, the AUSF also transmits a third key registration request for the wireless terminal to the anchor function. The third key registration request includes the third service network name of the third access network and the third access type associated with the third access network. In this embodiment, the third access type is one of multiple access types and is the same as the first access type.

[0137] In one embodiment, the first key registration request further includes a first anchor key (e.g., K AKMA ) and a first key identifier (A-KID).

[0138] In one embodiment, the AUSF transmits a fourth key registration request for the wireless terminal to the anchor function. The fourth key registration request includes a second anchor key (e.g., K AKMA ) and a second key identifier (A-KID).

[0139] In one embodiment, the fourth key registration request is associated with a fourth access network that has a fourth access type that is different from or the same as the first access type.

[0140] Although various embodiments of the present disclosure have been described above, it should be understood that they are given by way of example only and not by way of limitation. Similarly, the various figures may depict example architectures or configurations provided to enable those of ordinary skill in the art to understand the exemplary features and functions of the present disclosure. However, those skilled in the art will understand that the present disclosure is not limited to the example architectures or configurations shown, but rather can be implemented using a variety of alternative architectures and configurations. Additionally, as will be understood by those of ordinary skill in the art, one or more features of one embodiment may be combined with one or more features of another embodiment described herein. Therefore, the breadth and scope of the present disclosure should not be limited by any of the above exemplary embodiments.

[0141] It should also be understood that any reference to elements using names such as "first", "second", etc. generally does not limit the number or order of those elements. Instead, these names are used herein as a convenient means of distinguishing between two or more elements or instances of an element. Thus, references to a first and a second element do not imply that only two elements can be employed, or that the first element must be located before the second element in some manner.

[0142] In addition, those of ordinary skill in the art will understand that any of a variety of different technologies can be used to represent information and signals. For example, the data, instructions, commands, information, signals, bits, and symbols that may be referenced in the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0143] Those skilled in the art will further understand that any of the various illustrative logical blocks, units, processors, devices, circuits, methods, and functions described in connection with the aspects disclosed herein can be implemented by electronic hardware (e.g., digital implementation, analog implementation, or a combination of both), firmware, various forms of programs or design code containing instructions (for convenience, referred to herein as "software" or "software units"), or any combination of these techniques.

[0144] To clearly illustrate this interchangeability of hardware, firmware, and software, the various illustrative components, blocks, units, circuits, and steps have been generally described above in terms of their functionality. Implementing this functionality as hardware, firmware, or software, or a combination of these techniques, depends on the particular application and the design constraints imposed on the overall system. Those skilled in the art can implement the described functionality in various ways for each particular application, but such implementation decisions do not depart from the scope of the present disclosure. According to various embodiments, a processor, device, component, circuit, structure, machine, unit, etc. can be configured to perform one or more of the functions described herein. The terms "configured to" or "configured for" used herein with respect to a particular operation or function refer to a processor, device, component, circuit, structure, machine, unit, etc. that is physically constructed, programmed, and / or set to perform the particular operation or function.

[0145] In addition, those skilled in the art will understand that the various illustrative logical blocks, units, devices, components, and circuits described herein can be implemented or executed within an integrated circuit (IC) including a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, or any combination thereof. The logical blocks, units, and circuits can further include antennas and / or transceivers to communicate with various components within a network or within a device. The general-purpose processor can be a microprocessor, but alternatively, the processor can be any conventional processor, controller, or state machine. The processor can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other suitable configuration to perform the functions described herein. If implemented in software, the functions can be stored as one or more instructions or code on a computer-readable medium. Thus, the steps of the methods or algorithms disclosed herein can be implemented as software stored on a computer-readable medium.

[0146] A computer-readable medium includes computer storage media and communication media, and the communication media includes any medium that can enable a computer program or code to be transferred from one place to another. The storage media can be any available media accessible by a computer. By way of example and not limitation, such computer-readable media can include RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage, or other magnetic storage devices, and any other medium that can be used to store the desired program code in the form of instructions or data structures and that can be accessed by a computer.

[0147] As used herein, the term "unit" refers to software, firmware, hardware, and any combination of these elements to perform the related functions described herein. Additionally, for purposes of discussion, the various units are described as discrete units; however, it will be apparent to those of ordinary skill in the art that two or more units can be combined to form a single unit that performs the related functions according to embodiments of the present disclosure.

[0148] Additionally, in embodiments of the present disclosure, memories or other storage and communication components may be employed. It should be understood that, for clarity, the above description has described embodiments of the present disclosure with reference to different functional units and processors. However, it will be apparent that any suitable functional distribution between different functional units, processing logic elements or domains may be used without departing from the present disclosure. For example, functions illustrated as being performed by separate processing logic elements or controllers may be performed by the same processing logic element or controller. Thus, the reference to specific functional units is only a reference to the appropriate devices for providing the described functions, rather than indicating a strict logical or physical structure or organization.

[0149] Various modifications to the implementations described in this disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other implementations without departing from the scope of the claims. Thus, the present disclosure is not intended to be limited to the implementations shown herein, but is to be accorded the widest scope consistent with the novel features and principles disclosed herein, as set forth in the following claims.

Claims

1. A wireless communication method used in an anchor function, wherein, The method includes: Receiving, from an authentication server function, a first key registration request for a wireless terminal, wherein the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network, wherein the first access type is one of a plurality of access types; and Storing the first service network name as the current network of the wireless terminal corresponding to the first access type.

2. The wireless communication method according to claim 1, wherein, The plurality of access types includes a trusted access type and an untrusted access type.

3. The wireless communication method according to claim 1 or 2, further comprising: Receiving, from an application function, a key acquisition request for the wireless terminal, and Transmitting, based on the current network corresponding to the plurality of access types, key information of the wireless terminal to a plurality of network functions.

4. The wireless communication method according to any one of claims 1 to 3, further comprising: Receiving, from an application function, a key acquisition request for the wireless terminal, and Transmitting the key information of the wireless terminal to a first network function of the current network corresponding to the first access type.

5. The wireless communication method according to any one of claims 1 to 4, further comprising: Receiving, from the authentication server function, a second key registration request for the wireless terminal, wherein the second key registration request includes a second service network name of a second access network and a second access type associated with the second access network, wherein the second access type is one of the plurality of access types and is different from the first access type, and Storing the second service network name as the current network of the wireless terminal corresponding to the second access type.

6. The wireless communication method according to claim 5, further comprising: Receiving, from an application function, a key acquisition request for the wireless terminal, and Transmitting the key information of the wireless terminal to a first network function of the current network corresponding to the first access type, and Transmitting the key information of the wireless terminal to a second network function of the current network corresponding to the second access type.

7. The wireless communication method according to any one of claims 1 to 6, further comprising: Receiving, from the authentication server function, a third key registration request for the wireless terminal, wherein the third key registration request includes a third service network name of a third access network and the first access type associated with the third access network, and storing the third service network name as the current network of the wireless terminal corresponding to the first access type.

8. The wireless communication method according to claim 7, further comprising: Receiving, from an application function, a key acquisition request for the wireless terminal, and Transmitting the key information of the wireless terminal to a third network function of the current network corresponding to the first access type, and Transmitting the key information of the wireless terminal to a second network function of the current network corresponding to the second access type.

9. The wireless communication method according to any one of claims 1 to 8, wherein, The first key registration request further includes a first anchor key and a first key identifier, and wherein the method further includes: Store the first anchor key as the current anchor key of the wireless terminal, and store the first anchor key identifier as the current anchor key identifier of the wireless terminal.

10. The wireless communication method according to claim 9, further comprising: Receiving, from the authentication server function, a fourth key registration request for the wireless terminal, wherein the fourth key registration request includes a second anchor key and a second key identifier, Storing the second anchor key as the current anchor key of the wireless terminal, and Storing the second anchor key identifier as the current anchor key identifier of the wireless terminal.

11. The wireless communication method according to claim 10, wherein, The fourth key registration request is associated with a fourth access network having a fourth access type the same as or different from the first access type.

12. A wireless communication method used in an authentication server function, the method comprising: Transmitting, to an anchor function, a first key registration request for a wireless terminal, wherein the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network, wherein the first access type is one of a plurality of access types.

13. The wireless communication method according to claim 12, wherein, The plurality of access types includes a trusted access type and an untrusted access type.

14. The wireless communication method according to claim 12 or 13, further comprising: Transmitting, to the anchor function, a second key registration request for the wireless terminal, wherein the second key registration request includes a second service network name of a second access network and a second access type associated with the second access network, wherein the second access type is one of the plurality of access types and is different from the first access type.

15. The wireless communication method according to any one of claims 12 to 14, further comprising: Transmitting, to the anchor function, a third key registration request for the wireless terminal, wherein the third key registration request includes a third service network name of a third access network and the first access type associated with the third access network.

16. The wireless communication method according to any one of claims 12 to 15, wherein, The first key registration request further includes a first anchor key and a first key identifier.

17. The wireless communication method according to any one of claims 12 to 16, further comprising: Transmitting, to the anchor function, a fourth key registration request for the wireless terminal, wherein the fourth key registration request includes a second anchor key and a second key identifier.

18. The wireless communication method according to claim 17, wherein, The fourth key registration request is associated with a fourth access network having a fourth access type the same as or different from the first access type.

19. A wireless device for an anchor function, wherein, The wireless device includes: A communication unit configured to receive, from an authentication server function, a first key registration request for a wireless terminal, wherein the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network, wherein the first access type is one of a plurality of access types, and A processor configured to store the first service network name as the current network of the wireless terminal corresponding to the first access type.

20. The wireless device according to claim 19, wherein, The processor is further configured to execute the wireless communication method according to any one of claims 2 to 11.

21. A wireless device for authenticating a server function, the wireless device comprising: a communication unit configured to transmit a first key registration request for a wireless terminal to an anchor function, wherein the first key registration request includes a first service network name of a first access network and a first access type associated with the first access network, wherein the first access type is one of a plurality of access types.

22. The wireless device according to claim 21, further comprising a processor configured to execute the wireless communication method according to any one of claims 13 to 18.

23. A computer program product comprising computer-readable program media code stored thereon, which when executed by a processor causes the processor to implement the wireless communication method according to any one of claims 1 to 18.