Method for triggering main authentication by home network for AKMA key update
By triggering master authentication in the wireless communication system and generating a new key using AUSF and AMF, the problem of AKMA key update failure in existing technologies is solved, thereby improving system security and key management flexibility.
Patent Information
- Application Number
- CN202380095650.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-15
- Publication Date
- 2025-10-28
AI Technical Summary
The existing 3GPP technical specification TS 33.535 does not support the updating of AKMA anchor keys (KAKMA), which means that the same application key (KAF) cannot be updated after its lifecycle ends, affecting security.
The primary authentication process is triggered from the home network, and new KAUSF and KAKMA keys are generated using the Authentication Server Function (AUSF). The primary authentication process is then triggered via the Access and Mobility Management Function (AMF) to update the AKMA key.
It enables effective AKMA key updates when KAF and/or KAKMA keys are invalid, improving the security and key management flexibility of wireless communication systems.
Smart Images

Figure CN120858595A_ABST
Abstract
Description
Technical Field
[0001] This topic generally relates to wireless communications. In particular, this topic relates to methods, devices, and systems for enabling the refresh of Authentication and Key Management for Application (AKMA) keys by triggering master authentication from the home network. Background Technology
[0002] In 3GPP Technical Specification (TS) 33.535, AKMA application key (K AF Updates can only be made via the Ua* protocol; there is no way to update K. AF Other methods. If the Ua* protocol does not support K AF Key update, and AKMA anchor key (K AKMA If K remains unchanged, then the same K AF The key will be generated again. On the other hand, if K AKMA The key can be updated, so this problem may be solvable.
[0003] The AKMA function specified in TS 33.535 does not support K AKMA The update. In fact, even K... AF The key's lifetime has expired, in K AUSF It is also impossible to update the AKMA key during its lifecycle. According to this topic, the Authentication Server Function (AUSF) can generate a new key by triggering master authentication from the home network. AUSF Key and new K AKMA Key. Additionally, this topic provides the technology for selecting Access and Mobility Management Functions (AMF) to trigger master authentication. Summary of the Invention
[0004] This topic relates to a method, apparatus, and system for updating an AKMA key by triggering master authentication from the home network.
[0005] In some embodiments, a method for updating an authentication key in a wireless communication system by triggering master authentication includes sending an application session establishment request to an application function (AF) and receiving an application session establishment response from the AF. The application session establishment response includes an indication that the user equipment (UE) does not have an application authentication and key management (AKMA) subscription in the unified data management (UDM). The method also includes avoiding initiating further application session establishment requests based on this indication.
[0006] In some embodiments, a method for updating an authentication key in a wireless communication system by triggering master authentication includes: an application function (AF) subscribing to a policy control function (PCF) to receive a notification of a user equipment (UE) access type; receiving the access type notification from the PCF; receiving an application session establishment request from the UE; sending the access type to an application authentication and key management anchor function (AAnF); receiving a new authentication key from the AAnF; and sending an application session establishment response to the UE.
[0007] In some embodiments, a method for updating an authentication key in a wireless communication system by triggering master authentication includes receiving an authentication request from the Anchor Function (AAnF) by a Unified Data Management (UDM) including a User Equipment (UE) access type; checking whether the UE's Application Authentication and Key Management (AKMA) subscription exists; and sending an authentication response to the AAnF including a success or failure result.
[0008] In some embodiments, a method for updating an authentication key in a wireless communication system by triggering master authentication includes receiving a request for a new authentication key for a user equipment (UE) from an application function (AF) by an anchor function (AAnF). The request includes the UE access type. The method also includes forwarding the access type to unified data management (UDM).
[0009] In some other embodiments, the apparatus for wireless communication may include a memory storing instructions and processing circuitry communicating with the memory. When the processing circuitry executes the instructions, the processing circuitry is configured to perform the methods described above.
[0010] In some other embodiments, the device for wireless communication may include a memory storing instructions and processing circuitry communicating with the memory. When the processing circuitry executes the instructions, the processing circuitry is configured to perform the methods described above.
[0011] In some other embodiments, a computer-readable medium includes instructions that, when executed by a computer, cause the computer to perform the methods described above.
[0012] The above and other aspects and their embodiments are described in more detail in the accompanying drawings, description and claims. Attached Figure Description
[0013] Figure 1 An example wireless communication system including a wireless base station and user equipment is shown.
[0014] Figure 2 An example of a base station is shown.
[0015] Figure 3 An example of a user device is shown.
[0016] Figure 4 The example home network triggers a master authentication communication swimlane diagram.
[0017] Figure 5 The swimlane diagram for an example home network triggering master authentication communication is shown.
[0018] Figure 6 The swimlane diagram for an example home network triggering master authentication communication is shown. Detailed Implementation
[0019] The subject matter will now be described in detail below with reference to the accompanying drawings, which form part of this subject matter and illustrate specific examples of embodiments by way of illustration. However, it should be noted that the subject matter can be embodied in a variety of different forms, and therefore, the covered or claimed subject matter is intended to be construed as not being limited to any of the embodiments set forth below.
[0020] Throughout the specification and claims, terms may have implied or subtle nuanced meanings in the context that go beyond their expressly stated meanings. Similarly, the phrases “in one embodiment” or “in some embodiments” as used herein do not necessarily refer to the same embodiment, and the phrases “in another embodiment” or “in other embodiments” as used herein do not necessarily refer to different embodiments. For example, the claimed subject matter is intended to include all or part of exemplary embodiments or combinations of embodiments.
[0021] Generally, terms can be understood, at least in part, based on their usage in the context. For example, terms used herein, such as “and,” “or,” or “and / or,” can include a variety of meanings that can depend at least in part on the context in which they are used. Typically, “or,” if used to associate a list, such as A, B, or C, is intended to mean A, B, and C, here in the sense of inclusion, and A, B, or C, here in the sense of exclusivity. Furthermore, the terms “one or more” or “at least one,” as used herein, can be used, at least in part, to describe any feature, structure, or characteristic in a singular sense, or can be used to describe a combination of features, structures, or characteristics in a plural sense. Similarly, terms such as “a,” “an,” or “the” can also be understood to convey either a singular or a plural usage, at least in part, depending on the context. Moreover, the terms “based on” or “determined by” can be understood not necessarily to convey a set of exclusive factors, and instead may allow for the presence of additional factors that are not necessarily explicitly described, again at least in part, depending on the context.
[0022] Figure 1 A schematic diagram of an example wireless communication system 100 is shown, which includes a plurality of communication nodes (or nodes only) configured to communicate wirelessly with each other. Typically, the communication nodes include at least one user equipment 102 and at least one wireless access node 104. Figure 1 The example wireless communication system 100 is shown as including two user equipments 102, including a first user equipment 102 (1) and a second user equipment 102 (2), and a wireless access node 104. However, various other examples of wireless communication systems 100 including any of various combinations of one or more user equipments 102 and / or one or more wireless access nodes 104 are possible.
[0023] Generally, user equipment described herein, such as user equipment 102, may include a single electronic device or apparatus capable of wireless communication over a network, or multiple (e.g., network) electronic devices or apparatuses. User equipment may include, or be otherwise referred to as, a user terminal, user terminal equipment, or user equipment (UE). Furthermore, user equipment may be, or includes, mobile devices (such as mobile phones, smartphones, smartwatches, tablets, laptops, vehicles, or other means of transportation (human-, motor-, or engine-driven, as non-limiting examples, such as cars, airplanes, trains, ships, or bicycles)) or fixed or stationary devices (such as desktop computers or other computing devices that are not typically moved for extended periods, such as appliances, other relatively heavy devices including the Internet of Things (IoT), or computing devices used in commercial or industrial environments, as non-limiting examples). In various embodiments, user equipment 102 may include transceiver circuitry 106 coupled to antenna 108 to enable wireless communication with wireless access node 104. Transceiver circuitry 106 may also be coupled to processor 110, which may also be coupled to memory 112 or other storage devices. The memory 112 may store instructions or code that, when read and executed by the processor 110, cause the processor 110 to implement the various methods described herein.
[0024] Furthermore, generally, a wireless access node as described herein, such as wireless access node 104, may include a single electronic device or apparatus, or multiple (e.g., network) electronic devices or apparatuses, and may include one or more base stations or other wireless network access points capable of wirelessly communicating with one or more user equipments and / or one or more other wireless access nodes 104 via a network. For example, in various embodiments, wireless access node 104 may include a 4G LTE base station, a 5G NR base station, a 5G central unit base station, a 5G distributed unit base station, a next-generation node B (gNB), an enhanced node B (eNB), or other similar or next-generation (e.g., 6G) base station. Wireless access node 104 may include transceiver circuitry 114 coupled to an antenna 116, which may include an antenna tower 118 in various methods to enable wireless communication with user equipment 102 or another wireless access node 104. Transceiver circuitry 114 may also be coupled to one or more processors 120, which may also be coupled to memory 122 or other storage devices. The memory 122 may store instructions or code that, when read and executed by the processor 120, cause the processor 120 to implement one or more of the methods described herein.
[0025] In various embodiments, two communication nodes in the wireless communication system 100—such as user equipment 102 and wireless access node 104, two user equipment 102 without wireless access node 104, or two wireless access nodes 104 without user equipment 102—can be configured to wirelessly communicate with each other in or through a mobile network and / or wireless access network according to one or more standards and / or specifications. Generally, standards and / or specifications can define rules or procedures for communication nodes to wirelessly communicate. In various embodiments, these rules or procedures may include rules or procedures for communicating in the millimeter (mm) band and / or for communicating using multi-antenna schemes and beamforming capabilities. Furthermore, or alternatively, the standards and / or specifications are those that define radio access technologies and / or cellular technologies, such as fourth-generation (4G) Long Term Evolution (LTE), fifth-generation (5G) New Radio (NR), or New Radio License (NR-U), as non-limiting examples.
[0026] Furthermore, in the wireless communication system 100, communication nodes are configured to wirelessly transmit signals to each other. Typically, communication between two communication nodes in the wireless communication system 100 can be or includes both sending and receiving, and usually occurs simultaneously, depending on the perspective of the specific node in the communication. For example, for a given communication between a first node and a second node, where the first node is sending a signal to the second node and the second node is receiving a signal from the first node, the first node can be referred to as a source or transmitting node or device, and the second node can be referred to as a destination or receiving node or device, and the communication can be considered as the first node sending and the second node receiving. Of course, since communication nodes in the wireless communication system 100 can both send and receive signals, a single communication node can simultaneously be both a transmitting / source node and a receiving / destination node, or switch between being a source / transmitting node and a destination / receiving node.
[0027] Furthermore, specific signals can be characterized or defined as uplink (UL) signals, downlink (DL) signals, or sidelink (SL) signals. An uplink signal is a signal transmitted from user equipment 102 to radio access node 104. A downlink signal is a signal transmitted from radio access node 104 to user equipment 102. A sidelink signal is a signal transmitted from one user equipment 102 to another user equipment 102, or from one radio access node 104 to another radio access node 104. Moreover, for sidelink transmission, the first / source user equipment 102 directly transmits the sidelink signal to the second / destination user equipment 102 without forwarding the sidelink signal to radio access node 104.
[0028] Furthermore, the signals transmitted between communication nodes in the wireless communication system 100 can be characterized or defined as data signals or control signals. Generally, data signals are signals that include or carry data, such as multimedia data (e.g., voice and / or image data), and control signals are signals that carry control information that configures the communication nodes to communicate with each other in a specific way, or otherwise controls how the communication nodes transmit data signals to each other. Additionally, certain signals can be defined or characterized by combinations of data / control and uplink / downlink / sidelink, including uplink control signals, uplink data signals, downlink control signals, downlink data signals, sidelink control signals, and sidelink data signals.
[0029] For at least some specifications, such as 5G NR, data and control signals are transmitted and / or carried on physical channels. Typically, a physical channel corresponds to a set of time-frequency resources used for signal transmission. Different types of physical channels can be used to transmit different types of signals. For example, physical data channels (or data-only channels) are used to transmit data signals, and physical control channels (or control-only channels) are used to transmit control signals. Example types of physical data channels include, but are not limited to, the Physical Downlink Shared Channel (PDSCH) for transmitting downlink data signals, the Physical Uplink Shared Channel (PUSCH) for transmitting uplink data signals, and the Physical Side Link Shared Channel (PSSCH) for transmitting sidelink data signals. Similarly, example types of physical control channels include, but are not limited to, the Physical Downlink Control Channel (PDCCH) for transmitting downlink control signals, the Physical Uplink Control Channel (PUCCH) for transmitting uplink control signals, and the Physical Side Link Control Channel (PSCCH) for transmitting sidelink control signals. For simplicity, unless otherwise stated, a specific type of physical channel is used here to refer to signals transmitted on that specific type of physical channel and / or transmissions on that specific type of transmission. As an example, PDSCH refers to the Physical Downlink Shared Channel itself, downlink data signals transmitted on the PDSCH, or downlink data transmissions. Therefore, a communication node that transmits or receives a PDSCH means that the communication node is transmitting or receiving signals on the PDSCH.
[0030] Furthermore, for at least some specifications, such as 5G NR, and / or for at least some types of control signals, the control signals transmitted by the communication nodes may include control information that includes information necessary to enable the transmission of one or more data signals between the communication nodes and / or to schedule one or more data channels (or one or more transmissions on data channels). For example, such control information may include information necessary for the proper reception, decoding, and demodulation of data signals received on physical data channels during data transmission, and / or information necessary for notifying user equipment of uplink scheduling permission regarding resources and transmission formats for uplink data transmission. In some embodiments, the control information includes downlink control information (DCI) transmitted from radio access node 104 to user equipment 102 in the downlink direction. In other embodiments, the control information includes uplink control information (UCI) transmitted from user equipment 102 to radio access node 104 in the uplink direction, or sidelink control information (SCI) transmitted from one user equipment 102 (1) to another user equipment 102 (2) in the sidelink direction.
[0031] Furthermore, in the wireless communication system 100, the time slot format of multiple time slots or frames can be configured by the wireless access node 104 or specified by a protocol. In some examples, time slots can be indicated or specified as downlink time slots, flexible time slots, or uplink time slots. Additionally, in various embodiments, orthogonal frequency division multiplexing (OFDM) symbols can be indicated or specified as downlink symbols, flexible symbols, or uplink symbols.
[0032] Figure 2 An example of base station 200 is shown. Example base station 200 may include radio transmit / receive (Tx / Rx) circuitry 208 for transmitting / receiving communications with a UE and / or other base stations. Base station 200 may also include network interface circuitry 209 to enable the base station to communicate with other base stations and / or core networks, such as optical or wired interconnects, Ethernet, and / or other data transmission media / protocols. Base station 200 may optionally include input / output (I / O) interface 206 for communicating with operators, etc.
[0033] Base station 200 may also include system circuitry 204. System circuitry 204 may include one or more processors 221 and / or memory 222. Memory 222 may include operating system 224, instructions 226, and parameters 228. Instructions 226 may be configured to cause one or more processors 224 to perform the functions of the base station. Parameters 228 may include parameters that support the execution of instructions 226. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping allocation, and / or other parameters.
[0034] Figure 3An example of an electronic device implementing terminal device 300 (e.g., user equipment (UE)) is shown. UE 300 may be a mobile device, such as a smartphone or mobile communication module installed in a vehicle. UE 300 may include a communication interface 302, system circuitry 304, input / output interface (I / O) 306, display circuitry 308, and storage device 309. The display circuitry may include a user interface 310. System circuitry 304 may include any combination of hardware, software, firmware, or other logic / circuit. System circuitry 304 may be implemented, for example, with one or more system-on-chip (SoC), application-specific integrated circuit (ASIC), discrete analog and digital circuitry, and other circuitry. System circuitry 304 may be part of an implementation of any desired functionality in UE 300. In this regard, system circuitry 304 may include, for example, logic to facilitate the decoding and playback of music and video, such as MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user input; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections, such as for internet connections; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on user interface 310. User interface 310 and input / output (I / O) interface 306 may include a graphical user interface, a touch-sensitive display, haptic feedback or other haptic outputs, voice or facial recognition inputs, buttons, switches, speakers, and other user interface elements. Other examples of I / O interface 306 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headphone and microphone input / output jacks, universal serial bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors), and other types of inputs.
[0035] Communication interface 302 may include radio frequency (RF) transmit (Tx) and receive (Rx) circuitry 316 that processes the transmission and reception of signals via one or more antennas 314. Communication interface 302 may include one or more transceivers. The transceiver may be a wireless transceiver that includes modulation / demodulation circuitry, a digital-to-analog converter (DAC), a shaping table, an analog-to-digital converter (ADC), filters, waveform shapers, filters, preamplifiers, power amplifiers, and / or other logic for transmission and reception via one or more antennas or (for some devices) via a physical (e.g., wired) medium. The transmitted and received signals may conform to any of a variety of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM), frequency channels, bit rates, and encodings. As a specific example, communication interface 302 may include a transceiver supporting transmission and reception under 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS), High-Speed Packet Access (HSPA)+, 4G / LTE, and 5G standards. However, the techniques described below are applicable to other wireless communication technologies, whether they originate from the 3rd Generation Partnership Project (3GPP), the GSM Association, 3GPP2, IEEE, or other partners or standards bodies.
[0036] System circuitry 304 may include one or more processors 321 and memory 322. Memory 322 stores, for example, an operating system 324, instructions 326, and parameters 328. Processor 321 is configured to execute instructions 326 to implement the desired functions of UE 300. Parameters 328 can provide and specify configuration and operational options for instructions 326. Memory 322 may also store any BT, WiFi, 3G, 4G, 5G, or other data that UE 300 will send or has received via communication interface 302. In various embodiments, system power for UE 300 may be provided by power storage devices such as batteries or transformers.
[0037] Figure 4 A swimlane diagram illustrating an example home network-triggered master authentication communication between several entities is shown. Figure 4The entities shown include UE 300, Access and Mobility Management Function / Security Anchor Function (AMF / SEAF) 403, Authentication Server Function (AUSF) 405, and Unified Data Management (UDM) 407. UDM 407, AUSF 405, and AMF / SEAF 403 are network functions within the control plane function group of the 5G system architecture. UDM 407 can initiate primary authentication based on procedures initiated by UE 300 (e.g., UE registration in 5GC), procedures initiated to UE 300 (e.g., Roaming Guidance (SoR) / Update Parameters Update (UPU)), or other events from other network functions (NFs), also considering local policies. Alternatively or additionally, UDM 407 can be pre-configured with an operator authentication policy 409 to determine when to trigger the primary authentication procedure 411. UE 300 can register with the network. As part of the registration, Service AMF / SEAF 403 may register UE 300 with UDM 407 via Nudm_UECM_Registration in accordance with Clause 4.2.2.2.2 of TS 23.502. UDM 407 may create an implicit subscription for Service AMF / SEAF 403 so that UDM 407 may later notify AMF / SEAF 403 of a potential re-authentication.
[0038] A prerequisite for initiating home network-triggered policy authentication is that UDM 407 already has information about the AMF / SEAF 403 serving UE300. Otherwise, UDM 407 may not be able to access any AMF / SEAF 403 in subsequent steps.
[0039] UDM 407 can be determined independently based on events (e.g., whether SoR / UPU or AKMA Anchor Function (AAnF) requests it) or authentication policies, and can trigger home network master authentication 411, as described below. AAnF can determine to request master authentication from UDM 407 using the UDM service described in Clause 14 of TS 33.501 based on certain factors.
[0040] Based on the received events and the local operator authentication policy, when there is no ongoing primary authentication for UE 300, and if UDM 407 determines that primary authentication 411 is triggered, then UDM 407 can determine the service AMF / SEAF 403 of the target UE 300.
[0041] If different AMF / SEAF 403s are registered in UDM 407 for different accesses and support the procedures defined in the proposed clause 6.1X of TS 33.501, then UDM 407 may select one AMF / SEAF 403 to perform re-authentication.
[0042] UDM 407 may send a notification 413 to AMF / SEAF 403 containing the UE's 300 Subscription Permanent Identifier (SUPI). Upon receiving notification 413 from UDM 407, AMF / SEAF 403 may decide whether to perform the primary authentication procedure based on its own local authentication policy and the UE 300 state. For example, if the UE 300 is in handover, or if the UE 300 is already authenticating with AMF / SEAF 403 before receiving authentication notification 413 from UDM 407, a procedure similar to that in a network-triggered service request (i.e., TS23.502, Clause 4.2.3.3) may be reused. If AMF / SEAF 403 cannot perform primary authentication, it may send an authentication response message 415 to UDM 407 with an acknowledgment of failure; otherwise, the result may be set to success.
[0043] In the event of a failure to receive an authentication response message 415 from AMF / SEAF 403, UDM 407 can check if another AMF / SEAF 403 is available and can be accessed in an alternative manner. If available, UDM 407 can select another AMF / SEAF 403 and send an authentication notification 413. AMF / SEAF 403 can then initiate the master authentication procedure 417 as defined in Clause 6.2.1 of TS 33.501.
[0044] UDM 407 may perform other procedures (e.g., SoR / UPU) based on the result that causes UDM 407 to trigger authentication (or re-authentication) step 411.
[0045] Figure 5 It is shown in K AF In the event that the key may be invalid, a swimlane diagram of an example home network between several entities triggering master authentication communication is shown. Specifically, Figure 5 Also shown are the AAnF 503, Application Function (AF) 505, and Policy Control Function (PCF) 507 elements. Like UDM 407, AUSF 405, and AMF / SEAF 403, AF 505 is a network function within the control plane function group of the 5G system architecture.
[0046] AF 505 can subscribe to 509PCF 507 to be notified of the access types currently available to UE 300 and changes to those access types. The access type can be 3GPP or non-3GPP.
[0047] PCF 507 can forward the access type in notification 511 to AF 505. AF 505 can store the access type.
[0048] When UE 300 initiates communication with AKMAAF 505, UE 300 may send an Application Session Establishment Request (ASAP) message 513 to AF 505, which may include a derived AKMA Key Identifier (A-KID). If the UE 300 access type associated with the ASAP message 513 has changed compared to a previous session, PCF 507 may notify UE 300 of the current access type by forwarding the access type, as described in reference notification 511.
[0049] After receiving the application session establishment request message 513, AF 505 can check K. AF Key state 515. If K AF The timer has expired, or if AF 505 determines the current K. AF If the key is insecure, AF 505 can request a new key. AF Key.
[0050] AF 505 can select AAnF 503 based on the routing indicator (RID) in A-KID, and can send a Naanf_AKMA_NewApplicationKey_Get request 517 with A-KID to AAnF 505 to request a new K for UE 300. AF Key. AF 505 may also include its identity (AF_ID) and current access type in request 517.
[0051] Upon receiving request 517, AAnF 503 can check the AKMA context of UE 300 based on A-KID. If the check indicates that the AKMA context of UE 300 exists, AAnF 503 can then send a Nudm_Authentication request 519 to UDM 407, which may include the SUPI and access type of UE 300. If the AKMA context of UE 300 does not exist, AAnF 503 can request the UE ID from AF 505 before sending the Nudm_Authentication request message 519.
[0052] In step 521, UDM 407 can check whether a valid AKMA context and AKMA subscription exist for UE 300. If there is no AKMA subscription corresponding to UE 300, subsequent steps 523, 525, and 417 can be skipped, and UDM 407 can send an authentication response 527 to AAnF 503, as shown, which has an acknowledgment that includes a failure result specifying the reason for the absence of an AKMA subscription.
[0053] If UDM 407 checks for a valid AKMA context and AKMA subscription for UE 300 in 521, and the subscription does exist, then UDM 407 can select AMF / SEAF 403 based on the current access type associated with Application Session Establishment Request message 513 and received in request 519, and send a Home Network Triggered Authentication Request (i.e., Namf_HNAuthentication Request) 523 to the selected AMF / SEAF 403 according to the current access category associated with Application Session Establishment Request message 513. UDM 407 may also include the SUPI and access type of UE 300 in request 523.
[0054] After receiving request 523 from UDM 407, AMF / SEAF 403 can decide whether to perform the primary authentication procedure based on its own local authentication policy and UE 300 state. If AMF / SEAF 403 cannot perform primary authentication, it can skip step 417, and AMF / SEAF 403 can send an authentication response message (i.e., Namf_HNAuthentication response) 525 to UDM 407 with an acknowledgment of failure (including the result of failure); otherwise, the result can be set to success.
[0055] UDM 407 can send an authentication response (i.e., Nudm_Authentication response) 527 to AAnF 503, which may include the received authentication result included together with the authentication response message 525.
[0056] AMF / SEAF 403 can then begin the master certification process 417 in accordance with Clause 6.2.1 of TS 33.501.
[0057] If the primary authentication 417 is successfully executed, AAnF 503 can send a Naanf_AKMA_NewApplicationKey_Get response 529 to AF 505, which contains a SUPI or General Public Subscription Identifier (GPSI) and a new Key. AF Key and K AFExpiration time. Whether to send SUPI or GPSI can be determined by AAnF 503 based on local policies. If AAnF 503 receives a failure result in 527, AAnF 503 can include the reason for the failure in the NaaNF_AKMA_NewApplicationKey_Get response 529.
[0058] AF 505 may send an Application Session Establishment Response 531 to UE 300. If the information in response 529 indicates a failure of the AKMA key request, AF 505 may reject the application session establishment request 513 by including the reason for failure in the application session establishment response 531. If the reason for failure indicates that UE 300 does not have an AKMA subscription in UDM 407, UE 300 may not initiate (i.e., avoid sending) a further application session establishment request 513 to AF 505.
[0059] Figure 6 It is shown in K AKMA Swimlane diagram of example home networks between several entities triggering master authentication communication in the event that the key may be invalid.
[0060] AF 505 can subscribe to 509PCF 507 to be notified of the access types currently available to UE 300 and changes to those access types. The access type can be 3GPP or non-3GPP.
[0061] PCF 507 can forward the access type in notification 511 to AF 505. AF 505 can store the access type.
[0062] When UE 300 initiates communication with AKMAAF 505, UE 300 may send an Application Session Establishment Request Message 513 to AF 505, which may include a derived AKMA key identifier (A-KID). If the UE 300 access type associated with the Application Session Establishment Request Message 513 has changed compared to a previous session, PCF 507 may notify UE 300 of the current access type by forwarding the access type, as described in reference notification 511.
[0063] AF 505 can select AAnF 503 based on the RID in A-KID, and can send a Naanf_AKMA_NewApplicationKey_Get request 517 with A-KID to AAnF 505 to request a new K for UE 300. AFKey. AF505 may also include its identity (AF_ID) and current access type in request 517.
[0064] Upon receiving request 517, AAnF 503 can check the AKMA context of UE 300 based on A-KID to determine K. AKMA Is the key invalid? 601. If the AKMA context of UE 300 has expired (e.g., the associated authentication key timer has expired), subsequent steps 603 and 605 can be skipped.
[0065] If there is no AKMA context for UE 300 (i.e., K AKMA If the key is invalid, then AAnF 503 can send a user information request 603 to AF 505.
[0066] The AF can send a user information response 605 back to the AF 503 in response to the user information request 603. This response may include the UE ID and the current access type. The UE ID may be SUPI or GPSI.
[0067] AAnF 503 can then send a Nudm_Authentication request message 519 to UDM 407, which may include the UE ID and access type of UE 300.
[0068] In step 521, UDM 407 can check whether a valid AKMA context and AKMA subscription exist for UE 300. If there is no AKMA subscription corresponding to UE 300, subsequent steps 523, 525, and 417 can be skipped, and UDM 407 can send an authentication response 527 to AAnF 503, as shown, which has an acknowledgment that includes a failure result specifying the reason for the absence of an AKMA subscription.
[0069] If UDM 407 checks the valid AKMA context and AKMA subscription of UE 300 in 521, and the subscription does exist, then UDM 407 can select AMF / SEAF 403 based on the current access type associated with Application Session Establishment Request message 513 and received in request 519, and send a Home Network Triggered Authentication Request (i.e., NAMf_HNAuthentication Request) 523 to the selected AMF / SEAF 403 according to the current access category associated with Application Session Establishment Request message 513. UDM 407 may also include the SUPI and access type of UE 300 in request 523.
[0070] After receiving request 523 from UDM 407, AMF / SEAF 403 can decide whether to perform the primary authentication procedure based on its own local authentication policy and UE 300 state. If AMF / SEAF 403 cannot perform primary authentication, it can skip step 417, and AMF / SEAF 403 can send an authentication response message (i.e., Namf_HNAuthentication response) 525 to UDM 407 with an acknowledgment of failure (including the result of failure); otherwise, the result can be set to success.
[0071] UDM 407 can send an authentication response (i.e., Nudm_Authentication response) 527 to AAnF 503, which may include the received authentication result included together with the authentication response message 525.
[0072] AMF / SEAF 403 can then begin the master certification process 417 in accordance with Clause 6.2.1 of TS 33.501.
[0073] If the primary authentication 417 is successfully executed, AAnF 503 can send a Naanf_AKMA_NewApplicationKey_Get response 529 to AF 505, which contains a SUPI or General Public Subscription Identifier (GPSI) and a new Key. AF Key and K AF Expiration time. Whether to send SUPI or GPSI can be determined by AAnF 503 based on local policies. If AAnF 503 receives a failure result in 527, AAnF 503 can include the reason for the failure in the NaaNF_AKMA_NewApplicationKey_Get response 529.
[0074] AF 505 may send an application session establishment response 531 to UE 300. If the information in response 529 indicates a failure of the AKMA key request, AF 505 may reject the application session establishment request 513 by including the reason for failure in the application session establishment response 531. If the reason for failure indicates that UE 300 does not have an AKMA subscription in UDM 407, UE 300 may not initiate (i.e., avoid sending) a further application session establishment request 513 to AF 505.
[0075] In summary, this topic describes a method in K AF Invalid key and / or K AKMAIn the event of an invalid key, this technique enables the home network to trigger primary authentication to update the AKMA key. When multiple access types are associated with UE 300, access type information can be considered when determining AMF / SEAF 403 to trigger primary authentication 417. If UE 300 receives a failure reason indicating that AKMA subscription does not exist in UDM 407, UE 300 may not initiate application session establishment request 513 to AF 505.
[0076] The above description and accompanying drawings provide specific example embodiments and implementations. However, the described subject matter can be embodied in a variety of different forms, and therefore, the covered or claimed subject matter is intended to be construed as not being limited to any of the example embodiments set forth herein. A reasonably broad scope is intended for the claimed or covered subject matter. In addition, for example, the subject matter can be embodied as a method, apparatus, component, system, or non-transitory computer-readable medium for storing computer code. Thus, for example, embodiments can take the form of hardware, software, firmware, storage media, or any combination thereof. For example, the above method embodiments can be implemented by executing computer code stored in memory, by a component, apparatus, or system including memory and a processor.
[0077] Throughout the specification and claims, terms may have implied or subtle nuanced meanings in the context that go beyond their expressly stated meanings. Similarly, the phrase "in one embodiment / implementation" as used herein does not necessarily refer to the same embodiment, and the phrase "in another embodiment / implementation" as used herein does not necessarily refer to a different embodiment. For example, the subject matter intended for the claimed protection may include all or part of the combinations of exemplary embodiments.
[0078] Generally, terms can be understood, at least in part, based on their usage in the context. For example, terms used herein, such as “and,” “or,” or “and / or,” can include a variety of meanings that can depend at least in part on the context in which these terms are used. Typically, “or,” if used to associate a list, such as A, B, or C, is intended to mean A, B, and C, here meaning inclusion, and A, B, or C, here meaning exclusion. Furthermore, the term “one or more,” as used herein, depends at least in part on the context and can be used to describe any feature, structure, or characteristic in a singular sense, or can be used to describe a combination of features, structures, or characteristics in a plural sense. Similarly, terms such as “a,” “an,” or “the” can be understood to convey either a singular or a plural usage, depending at least in part on the context. Moreover, the term “based on” can be understood to not necessarily convey an exclusive set of factors and, on the contrary, can allow for the presence of additional factors that are not necessarily explicitly described, again depending at least in part on the context.
[0079] References to features, advantages, or similar language throughout this specification do not imply that all features and advantages achievable with this solution should be or are included in any single implementation thereof. Rather, language relating to features and advantages is to be understood as indicating that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of this solution. Therefore, throughout this specification, the discussion of features and advantages, and similar language, may, but do not necessarily, refer to the same embodiments.
[0080] Furthermore, the features, advantages, and characteristics described herein can be combined in any suitable manner in one or more embodiments. Based on the description herein, those skilled in the art will recognize that this solution can be practiced without one or more specific features or advantages of a particular embodiment. In other instances, additional features and advantages that may not be present in all embodiments of this solution may be recognized in certain embodiments.
[0081] The subject matter of this disclosure may also cover or include, in particular, the following aspects:
[0082] The first aspect includes a method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: sending an application session establishment request to an application function (AF); receiving an application session establishment response from the AF, wherein the application session establishment response includes an indication that there is no application authentication and key management (AKMA) subscription for the user equipment (UE) in the unified data management (UDM); and avoiding initiating further application session establishment requests based on the indication.
[0083] The second aspect includes a method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: an application function (AF) subscribing to a policy control function (PCF) to receive a notification of a user equipment (UE) access type; receiving the access type notification from the PCF; receiving an application session establishment request from the UE; sending the access type to an application authentication and key management anchor function (AAnF); receiving a new authentication key from the AAnF; and sending an application session establishment response to the UE.
[0084] The third aspect includes the method of any of the foregoing aspects, and further includes: determining that a timer for the authentication key has expired, wherein the access type is sent in the request for a new authentication key based on the expired timer.
[0085] The fourth aspect includes the methods of any of the foregoing aspects, wherein the request for a new authentication key also includes the application of an Authentication and Key Management (AKMA) key identifier (A-KID).
[0086] The fifth aspect includes the methods of any of the foregoing aspects, wherein the request for a new authentication key also includes the identifier of the AF.
[0087] The sixth aspect includes the method of any of the foregoing aspects, wherein a new authentication key and an associated timer expiration time are received from AAnF.
[0088] The seventh aspect includes the method of any of the foregoing aspects, wherein a new authentication key is received from AAnF, and the UE’s Subscription Permanent Identifier (SUPI) or the UE’s General Public Subscription Identifier (GPSI) is received.
[0089] The eighth aspect includes the method of any of the foregoing aspects, and also includes: receiving a user information request from AAnF.
[0090] The ninth aspect includes the method of any of the foregoing aspects, and further includes: sending a user information response to AAnF, the user information response including the UE's ID and access type.
[0091] The tenth aspect includes a method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: receiving an authentication request from an anchor function (AAnF) by a unified data management (UDM), the authentication request including a user equipment (UE) access type; checking whether the UE's application authentication and key management (AKMA) subscription exists; and sending an authentication response to the AAnF including a success or failure result.
[0092] The eleventh aspect includes the method of any of the foregoing aspects, wherein the authentication response includes a success result, and the method further includes: selecting an Access and Mobility Management Function / Security Anchor Function (AMF / SEAF) based on the UE access type and the presence of an AKMA subscription to initiate primary authentication between the UE and the Application Function (AF) using an authentication key.
[0093] The twelfth aspect includes the method of any of the foregoing aspects, and further includes: sending a home network triggered authentication request to the selected AMF / SEAF, wherein the home network triggered authentication request includes a subscription permanent identifier (SUPI) and / or the UE's access type.
[0094] The thirteenth aspect includes the method of any of the foregoing aspects, and further includes: receiving a home network triggered authentication response from a selected AMF / SEAF, wherein the home network triggered authentication response includes a success or failure result.
[0095] The fourteenth aspect includes the methods of any of the foregoing aspects, wherein the authentication response includes a failure result or an indication that there is no AKMA subscription.
[0096] The fifteenth aspect includes the methods of any of the foregoing aspects, and further includes: avoiding sending home network triggered authentication requests to the Access and Mobility Management Function / Security Anchor Function (AMF / SEAF).
[0097] The sixteenth aspect includes the method of any of the foregoing aspects, wherein the authentication response is a Nudm_Authentication response.
[0098] The seventeenth aspect includes the method of any of the preceding aspects, wherein the authentication request is a Nudm_Authentication request.
[0099] The eighteenth aspect includes the methods of any of the foregoing aspects, wherein the authentication request also includes the UE's Subscription Permanent Identifier (SUPI).
[0100] The nineteenth aspect includes the methods of any of the foregoing aspects, and also includes: checking whether a valid AKMA context of the UE exists.
[0101] The twentieth aspect includes the method of any of the foregoing aspects, wherein the home network triggers the authentication request as a Namf_HNAuthentication request.
[0102] The twenty-first aspect includes the method of any of the foregoing aspects, wherein the home network trigger authentication response is a Namf_HNAuthentication response.
[0103] The twenty-second aspect includes a method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: receiving a request for a new authentication key for a user equipment (UE) from an application function (AF) via an anchor function (AAnF), wherein the request includes a UE access type; and forwarding the access type to a unified data management (UDM).
[0104] The twenty-third aspect includes the method of any of the foregoing aspects, wherein the request for the new authentication key further includes applying an Authentication and Key Management (AKMA) key identifier (A-KID), and the method further includes checking the AKMA context of the UE based on the A-KID.
[0105] The twenty-fourth aspect includes the method of any of the foregoing aspects, wherein the access type is forwarded in the authentication request, which also includes the UE's Subscription Permanent Identifier (SUPI).
[0106] The twenty-fifth aspect includes the method of any of the foregoing aspects, wherein, in response to a check indicating that the UE's AKMA context exists, the access type is forwarded.
[0107] The twenty-sixth aspect includes the method of any of the foregoing aspects, further comprising: in response to a check indicating that the UE's AKMA context does not exist, sending a UE ID request to the AF before forwarding the access type to the UDM.
[0108] The twenty-seventh aspect includes the method of any of the foregoing aspects, further comprising: in response to a check indicating that the UE's AKMA context has expired, avoiding sending a UE ID request to the AF before forwarding the access type to the UDM.
[0109] The twenty-eighth aspect includes the method of any of the foregoing aspects, wherein the request for a new authentication key further includes applying an Authentication and Key Management (AKMA) key identifier (A-KID), and the method further includes checking the AKMA context of the UE based on the A-KID to determine whether the authentication key is invalid.
[0110] The twenty-ninth aspect includes the method of any of the foregoing aspects, and further includes: in response to determining that the authentication key is invalid, sending a user information request to the AF.
[0111] The thirtieth aspect includes the method of any of the foregoing aspects, and further includes: receiving a user information response from the AF, wherein the user information response includes the UE ID and / or access type.
[0112] The thirty-first aspect includes the method of any of the foregoing aspects, wherein the authentication key is the AKMA application key.
[0113] The thirty-second aspect includes the method of any of the foregoing aspects, wherein the authentication key is an AKMA anchor key.
[0114] The thirty-third aspect includes the method of any of the foregoing aspects, wherein the UDM is pre-configured with an operator authentication policy to determine when to trigger primary authentication.
[0115] The thirty-fourth aspect includes the method of any of the foregoing aspects, wherein the access type is 3GPP or non-3GPP.
[0116] The thirty-fifth aspect includes a device for wireless communication, the device comprising: a processor; and a memory in communication with the processor, the memory storing a plurality of instructions executable by the processor to configure the device to: implement the method of any of the preceding aspects.
[0117] The thirty-sixth aspect includes a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, are operable to: implement the methods of any of the preceding aspects.
Claims
1. A method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: Send an application session establishment request to the application function (AF); Receive an application session establishment response from the AF, wherein: The application session establishment response includes an indication that the User Equipment (UE) does not have an application authentication and key management (AKMA) subscription in the Unified Data Management (UDM); and Based on the aforementioned instructions, avoid initiating further application session establishment requests.
2. A method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: The application function AF subscribes to the policy control function PCF to receive notifications of the user equipment (UE) access type. Receive notification of the access type from the PCF; Receive an application session establishment request from the UE; Send the access type to the application authentication and key management anchor function AAnF; Receive a new authentication key from the AAnF; as well as Send an application session establishment response to the UE.
3. The method according to claim 2, further comprising: Determine that the timer associated with the authentication key has expired, wherein: The access type is sent in the request for the new authentication key based on the expiration of the timer.
4. The method according to claim 3, wherein: The request for the new authentication key also includes the application authentication and key management AKMA key identifier A-KID.
5. The method according to claim 3, wherein: The request for the new authentication key also includes the identifier of the AF.
6. The method according to claim 3, wherein: Receive the new authentication key and the associated timer expiration time from the AAnF.
7. The method according to claim 3, wherein: The new authentication key is received from the AAnF, and the UE's subscription permanent identifier SUPI or the UE's general public subscription identifier GPSI is also received.
8. The method according to claim 2, further comprising: Receive user information requests from the AAnF.
9. The method according to claim 8, further comprising: Send a user information response, including the UE's ID and access type, to the AAnF.
10. A method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: The Unified Data Management (UDM) receives an authentication request from the Anchor Function (AAnF), and the authentication request includes the User Equipment (UE) access type. Check if the UE's application authentication and key management AKMA subscription exists; as well as Send an authentication response, including a success or failure result, to the AAnF.
11. The method of claim 10, wherein: The authentication response includes a success result, and The method further comprises: Based on the UE access type and the existence of the AKMA subscription, the Access and Mobility Management Function / Security Anchor Function (AMF / SEAF) is selected to initiate the primary authentication between the UE and the Application Function AF using the authentication key.
12. The method of claim 11, further comprising: Send a home network-triggered authentication request to the selected AMF / SEAF, where: The home network trigger authentication request includes subscribing to the permanent identifier SUPI and / or the UE's access type.
13. The method of claim 11, further comprising: The authentication response is triggered from the selected AMF / SEAF home network, where: The home network-triggered authentication response includes a success or failure result.
14. The method of claim 10, wherein: The authentication response includes a failure result and an indication that there is no AKMA subscription.
15. The method of claim 14, further comprising: Avoid sending home network triggered authentication requests to the Access and Mobility Management Function / Security Anchor Function (AMF / SEAF).
16. The method of claim 10, wherein: The authentication response is a Nudm_Authentication response.
17. The method of claim 10, wherein: The authentication request is a Nudm_Authentication request.
18. The method of claim 10, wherein: The authentication request also includes the UE's subscription permanent identifier SUPI.
19. The method of claim 10, further comprising: Check if a valid AKMA context exists for the UE.
20. The method of claim 12, wherein: The home network triggers the authentication request as a Namf_HNAuthentication request.
21. The method according to claim 13, wherein: The home network trigger authentication response is the Namf_HNAuthentication response.
22. A method for updating an authentication key in a wireless communication system by triggering master authentication, comprising: The anchor function AAnF receives a request for a new authentication key for the user equipment (UE) from the application function AF, wherein: The request includes the UE access type; and The access type is forwarded to the Unified Data Management (UDM).
23. The method according to claim 22, wherein: The request for the new authentication key also includes the application authentication and key management AKMA key identifier A-KID, and The method further comprises: The AKMA context of the UE is checked based on the A-KID.
24. The method according to claim 23, wherein: The access type is forwarded in the authentication request, which also includes the UE's subscription permanent identifier (SUPI).
25. The method according to claim 23, wherein: In response to the check indicating that the UE's AKMA context exists, the access type is forwarded.
26. The method of claim 23, further comprising: In response to the check indicating that the UE's AKMA context does not exist, a UE ID request is sent to the AF before forwarding the access type to the UDM.
27. The method of claim 23, further comprising: In response to the check indicating that the UE's AKMA context has expired, a UE ID request is avoided from being sent to the AF before the access type is forwarded to the UDM.
28. The method according to claim 22, wherein: The request for the new authentication key also includes the application authentication and key management AKMA key identifier A-KID, and The method further includes: The AKMA context of the UE is checked based on the A-KID to determine whether the authentication key is invalid.
29. The method of claim 28, further comprising: In response to determining that the authentication key is invalid, a user information request is sent to the AF.
30. The method of claim 29, further comprising: Receive user information response from the AF, wherein: The user information response includes the UE ID and / or the access type.
31. The method according to any one of claims 2, 10, or 22, wherein: The authentication key is the AKMA application key.
32. The method according to any one of claims 2, 10 or 22, wherein: The authentication key is an AKMA anchor key.
33. The method according to claim 10, wherein: The UDM is pre-configured with a carrier authentication policy to determine when the primary authentication is triggered.
34. The method according to any one of claims 2, 10, or 22, wherein: The access type is either 3GPP or non-3GPP.
35. A device for wireless communication, comprising: processor; and A memory communicating with the processor, the memory storing a plurality of instructions executable by the processor to configure the device as follows: The method described in any one of claims 1, 2, 10, or 22.
36. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, are operable to: The method described in any one of claims 1, 2, 10, or 22.
Citation Information
Patent Citations
Session request method and device, terminal and storage medium
CN112512043A
Communication method and communication device
CN116074827A
Authentication server function (AUSF) push of authentication and key management (AKMA) material
WO2021209379A1