Method and apparatus for communication

By introducing Key Management Function (KMF) to generate keys between devices and network functions, the problem of high security context exchange and maintenance overhead in existing technologies is solved, achieving more efficient and secure key management and enhancing communication efficiency and scalability.

CN121925879APending Publication Date: 2026-04-24HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2024-01-10
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In 3GPP, the master authentication and key negotiation process between user equipment and the network in the existing technology results in excessive overhead for security context exchange and maintenance, which affects communication efficiency.

Method used

Introducing Key Management Function (KMF) to generate and manage keys decouples authentication and key management functions, reduces the overhead of network functions (NF) maintaining security contexts, and generates keys between devices and network functions through KMF.

Benefits of technology

It reduces message exchange overhead, improves the security of key generation, and makes the key framework more scalable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121925879A_ABST
    Figure CN121925879A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a communication method and device. The method comprises: receiving a first message, the first message comprising an identifier (ID) of a device and a shared key known to the device, the first message further indicating a name or ID of a first network function (NF); generating a first key based on the first message, the first key being used for determining whether authentication is required between the device and the first network function; sending a second message to a second KMF, the second message including the first key, the identifier of the first key, and the identifier of the algorithm for generating the first key or the identifier of the algorithm for generating a terminal key; wherein the first key is used for generating a second key, and the second key comprises a terminal key used for protecting communication between the device and the first network function. This may reduce message exchange overhead and reduce overhead for the NF to maintain the security context.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-references to related applications

[0001] This application relates to and claims priority to U.S. Provisional Patent Application No. 63 / 586,617, filed on September 29, 2023, entitled “System and Method for Key Framework in the Future Network”.

[0002] The public information disclosed in the aforementioned application is incorporated herein by reference in its entirety. Technical Field

[0003] The embodiments of this application relate to the field of communication technology, and more specifically, to methods and apparatus for communication. Background Technology

[0004] The primary authentication and key negotiation process aims to achieve mutual authentication between user equipment (UE) and the network, and to provide key material that can be used to indirectly derive keys, thereby securing communication between the UE and the network. In 3GPP, different terminal keys and intermediate keys are generated by different network functions (NFs). For example, the key KSEAF is generated by the authentication server function (AUSF), and the key KAMF can be generated by the security anchor function (SEAF) or the access and mobility management function (AMF). All these NFs should maintain security information associated with the keys. When some keys are refreshed, the NFs should update the new information associated with the keys. This incurs the overhead of exchanging and maintaining security contexts. Summary of the Invention

[0005] Embodiments of this application provide methods and apparatus for communication that can reduce message exchange overhead.

[0006] According to a first aspect, embodiments of this application provide a method for communication, the method being executed by a first key management function (KMF) or a chip installed in the first key management function (KMF). The KMF is a network function responsible for key management. The method includes: receiving a first message, wherein the first message includes a device identifier (ID) and a shared key known to the device, and the first message further indicates the name or ID of a first network function (NF); generating a first key based on the first message, wherein the first key is used to determine whether authentication is required between the device and the first network function; sending a second message to a second KMF, wherein the second message includes the first key, an identifier of the first key, and an identifier of an algorithm for generating the first key or an identifier of an algorithm for generating a terminal key; wherein the first key is used to generate a second key, the second key including a terminal key for protecting communication between the device and the first network function.

[0007] According to the above technical solution, Key Management Function (KMF) is introduced for key management. The first key and the key used to protect communication between the device and the first network function are generated by the KMF. For the relevant network functions, these keys cannot be generated by themselves. This reduces message exchange overhead and the overhead of the NF maintaining the security context. Furthermore, the key framework associated with this technical solution can be scalable for the network.

[0008] In conjunction with the first aspect, in some embodiments, generating the first key based on the first message includes: deriving an intermediate key from the shared key and at least one of the following: the name or random number of the first KMF; and deriving the first key from the intermediate key.

[0009] Based on the above technical solution, introducing an intermediate key can decouple the authentication function and the key management function. This can enhance the security of key generation and the security of the first key.

[0010] In conjunction with the first aspect, in some embodiments, the method further includes: determining, from a plurality of algorithms, the algorithm for generating the first key or the algorithm for generating the terminal key.

[0011] In conjunction with the first aspect, in some embodiments, the second key includes one or more of the following: a terminal key for protecting the communication between the user equipment and the first network function using an encryption algorithm; or a terminal key for protecting the communication between the user equipment and the first network function using an integrity algorithm.

[0012] According to a second aspect, embodiments of this application provide a method for communication, which can be executed by a second KMF or a chip installed in the second KMF. The method includes: receiving a second message from a first KMF, wherein the second message includes a first key, an identifier of the first key, and an identifier of an algorithm for generating the first key or an identifier of an algorithm for generating a terminal key, wherein the first key is used to determine whether authentication is required between the user equipment and a first network function; generating a second key based on the second message, wherein the second key is used to protect communication between the user equipment and the first network function; and sending a third message to the first network function, wherein the third message includes the second key and a security context of the first network function.

[0013] In conjunction with the second aspect, in some embodiments, the method further includes: generating a third key based on the second message, wherein the third key is used to generate a fourth key, the fourth key being used to protect communication between the device and the second network function; sending a fourth message to a third KMF, wherein the third KMF is used to generate the fourth key, the fourth message including the ID of the first key, the third key, and an identifier of an algorithm for generating the third key or an algorithm for generating a terminal key.

[0014] In conjunction with the second aspect, in some embodiments, the method further includes: receiving a first request to refresh the second key, wherein the first request includes factors for refreshing the second key; and refreshing the second key based on the first request.

[0015] Based on the above technical solution, KMF can refresh the intermediate key itself. This can reduce additional communication overhead.

[0016] In some embodiments, the security context of the first network function includes the ID of the first key.

[0017] In some embodiments, the security context of the first network function includes one or more of the following: an ID of an encryption algorithm used for encrypting communication between the device and the first network function; or an ID of an integrity algorithm used for ensuring the integrity of communication between the device and the first network function.

[0018] According to a third aspect, embodiments of this application provide a method for communication, which can be executed by a third KMF or a chip installed in the third KMF. The method includes: receiving a fourth message from a second KMF, wherein the fourth message includes an ID of a first key, a third key, and an ID of an algorithm for generating the third key or an ID of an algorithm for generating a terminal key, wherein the first key is used to determine whether authentication is required between a device and a first network function; generating a fourth key based on the fourth message, wherein the fourth key includes a terminal key for protecting communication between the device and a second network function; and sending a fifth message to the second network function, wherein the fifth message includes the fourth key and a security context of the second network function.

[0019] In conjunction with the third aspect, in some embodiments, the method further includes: receiving a second request to refresh the fourth key, wherein the second request includes factors for refreshing the fourth key; and refreshing the fourth key based on the second request.

[0020] In conjunction with the third aspect, in some embodiments, the fourth key includes one or more of the following: a terminal key for protecting the communication between the device and the second network function using an encryption algorithm; or a terminal key for protecting the communication between the device and the second network function using an integrity algorithm.

[0021] In some embodiments, the security context of the second network function includes the ID of the first key.

[0022] In some embodiments, the security context of the second network function includes one or more of the following: an ID of an encryption algorithm used for encrypting communication between the device and the second network function; or an ID of an integrity algorithm used for ensuring the integrity of communication between the device and the second network function.

[0023] According to a fourth aspect, embodiments of this application provide a method for communication, the method being executable by a first network function or a chip installed in the first network function. The method includes: receiving a third message from a second KMF, wherein the third message includes a second key and a security context of the first network function, wherein the second key is generated based on a first key used to determine whether authentication is required between the device and the first network function; and configuring the second key based on the security context of the first network function.

[0024] In conjunction with the fourth aspect, in some embodiments, the method further includes: sending a first request to refresh the second key, wherein the first request includes factors for refreshing the second key; and receiving a sixth message, wherein the sixth message includes the refreshed second key.

[0025] According to a fifth aspect, embodiments of this application provide a method for communication, which can be executed by a second network function or a chip installed in the second network function. The method includes: receiving a fifth message from a third KMF, wherein the fifth message includes a fourth key and a security context of the second network function, wherein the fourth key includes a terminal key used to protect communication between the device and the second network function; and configuring the fourth key based on the security context of the second network function.

[0026] In conjunction with the fifth aspect, in some embodiments, the method further includes: sending a second request to refresh the fourth key, wherein the second request includes factors for refreshing the fourth key; and receiving a seventh message, wherein the seventh message includes the refreshed fourth key.

[0027] According to a sixth aspect, embodiments of this application provide a method for communication, which can be executed by a first KMF or a chip installed in the first KMF. The method includes: receiving a first message, wherein the first message includes a device ID and a shared key known to the device, and the first message further indicates the name or ID of a first network function (NF); sending a second message to a second KMF, wherein the second message includes a first key, an identifier of the first key, and an identifier of an algorithm for generating the first key or an identifier of an algorithm for generating a terminal key.

[0028] The first key is generated based on the first message, and the first key is used to generate the second key. The second key includes a terminal key for protecting communication between the device and the first network function.

[0029] According to a seventh aspect, embodiments of this application provide a method for communication, which can be executed by a second KMF or a chip installed in the second KMF. The method includes: receiving a second message from a first KMF, wherein the second message includes a first key, an identifier of the first key, and an identifier of an algorithm for generating the first key or an identifier of an algorithm for generating the terminal key, wherein the first key is used to determine whether authentication is required between the user equipment and a first network function; and sending a third message to the first network function, wherein the third message includes the second key and a security context of the first network function.

[0030] The second key is generated based on the second message. The second key is used to protect communication between the user equipment and the first network function.

[0031] According to the eighth aspect, a communication device is provided, the communication device having functions or modules for performing methods in any one of the first to seventh aspects or any implementation thereof.

[0032] According to a ninth aspect, a chip (or chip system) is provided. The chip includes at least one processor coupled to at least one memory. The at least one memory is used to store one or more instructions and / or executable computer code. The at least one processor is used to invoke the one or more instructions and / or executable computer code to cause a communication device on which the chip is mounted to perform a method of any one of the first to seventh aspects or any possible implementation thereof.

[0033] Optionally, the chip may also include at least one memory.

[0034] Optionally, the chip may also include a communication interface for inputting and / or outputting information or data.

[0035] According to a tenth aspect, a communication device is provided. The communication device includes one or more circuits and one or more communication interfaces. The one or more communication interfaces may include a first interface and a second interface, wherein the first interface is used to receive (i.e., input) information and / or data to be processed by the one or more circuits, and the second interface is used to transmit (i.e., output) the information and / or data processed by the one or more circuits. The one or more circuits are used to process the information and / or data to be processed, causing the communication device to perform a method of any one of the first to seventh aspects or any implementation thereof.

[0036] According to the eleventh aspect, a communication system is provided. The communication system may include the communication apparatus described in the eighth or tenth aspect. For example, the communication system may include one or more of the following: a first KMF, a second KMF, a third KMF, a first network function, or a second network function. The communication system may also include devices.

[0037] According to the twelfth aspect, a computer storage medium is provided for storing executable computer code for performing one or more instructions of a method in any one of the first to seventh aspects or any implementation thereof.

[0038] According to the thirteenth aspect, a computer program product is provided, comprising one or more instructions, wherein when the computer program product is run on a computer, the computer performs a method of any one of the first to seventh aspects or any implementation thereof. Attached Figure Description

[0039] One or more embodiments have been described by way of example with reference to the accompanying drawings. These exemplary descriptions and drawings are not intended to limit the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements, and the drawings are not limited to scale, wherein: Figure 1 This is a schematic diagram of a communication system; Figure 2 An exemplary communication system is shown; Figure 3 Another example of an ED and a base station is shown; Figure 4 This shows the units or modules in the device; Figure 5 This illustrates the conceptual architecture of a 6G system; Figure 6 The generation of the key hierarchy in the fifth-generation system is illustrated. Figure 7 Network scenarios provided for some embodiments of this application; Figure 8 The key management architecture provided for some embodiments of this application; Figure 9 A key hierarchy structure for C / M signaling protection and data protection is provided for some embodiments of this application; Figure 10 A schematic flowchart illustrating a method for communication provided for some embodiments of this application; Figure 11 A schematic flowchart illustrating a method for communication provided for some embodiments of this application; Figure 12A schematic block diagram of a communication device provided for embodiments of this application; Figure 13 A schematic block diagram of a communication device provided for embodiments of this application. Detailed Implementation

[0040] To gain a detailed understanding of the features and technical content of the embodiments of this application, the implementation methods of the embodiments of this application will be described in detail below with reference to the accompanying drawings. The drawings are for reference and illustration only and are not intended to limit the embodiments of this application. In the following technical description, many details are set forth for ease of explanation, in order to provide a thorough understanding of the disclosed embodiments.

[0041] This application includes at least the following parts.

[0042] (1) Design a key management architecture.

[0043] The basic concept is that network functions (called key management functions, KMFs) are used for key generation and key configuration. This concept offers several advantages, such as the fact that the NF does not maintain key-related information and does not generate keys itself, which reduces overhead.

[0044] (2) Design a key derivation framework.

[0045] This embodiment provides a key derivation framework under a key management architecture. It demonstrates how to derive the C / M session keys, data session keys, C / M RB keys, and data RB keys. To enhance security, K... AUSF K generated by KMF KMF This replacement can decouple authentication and key management functions.

[0046] (3) Provide the process of key generation and key configuration.

[0047] This embodiment provides details about the key generation and key configuration process under a key management architecture.

[0048] This invention generally relates to wireless communication.

[0049] Many emerging trends will trigger considerations and designs for 6G / future wireless networks: new network infrastructure capabilities (e.g., widely deployed cloud-friendly infrastructure); new or relatively mature technologies (e.g., large-scale models of artificial intelligence (AI), data privacy, blockchain, etc.), which have made significant progress and have had a major impact on society and human life; new applications and services (e.g., AI services, data or sensing services, digital world services, etc.), which are widely used in industries / businesses and by individual customers; and a more globalized / open / collaborative operating trend (i.e., more open and collaborative operating models are becoming prevalent in many sectors).

[0050] New expectations and stricter requirements for future networks have also driven a rethinking and development of next-generation wireless networks. These requirements include privacy and trustworthiness, simplified standardization, and rapid deployment.

[0051] All of these factors have driven the research on the sixth-generation (6G) network architecture.

[0052] The proposed 6G network architecture (centered on X) is based on SBA (XaaS service) and / or cloud-native. X, as a service, can be represented as XaaS.

[0053] The requirements for 6G system network architecture design include: - The proposed 6G network architecture needs to support new 6G services, which can be developed / deployed by third parties; - The proposed 6G network architecture needs to embrace a more open ecosystem and be open to third parties with strong technical capabilities; - The proposed 6G network architecture needs to achieve better trust management.

[0054] A solution is needed to meet the above requirements.

[0055] To facilitate understanding of the embodiments of this application, let's first take... Figures 1 to 4 The following describes in detail the communication system to which the embodiments of this application are applicable, using the communication system shown as an example.

[0056] refer to Figure 1This simplified schematic diagram of a communication system is provided as an illustrative example, but not a limitation. Communication system 100 includes a radio access network 120. Radio access network 120 may be a next-generation (e.g., 6G or later) radio access network or a traditional (e.g., fifth-generation (5G) or fourth-generation (4G)) radio access network. One or more electronic devices (EDs) 110a to 110j (collectively referred to as 110) may be interconnected with each other or connected to one or more network nodes (170a, 170b, collectively referred to as 170) within radio access network 120. Core network 130 may be part of the communication system and may depend on or be independent of the radio access technology used in communication system 100. Furthermore, communication system 100 includes a public switched telephone network (PSTN) 140, the Internet 150, and other networks 160.

[0057] Figure 2 An exemplary communication system 100 is illustrated. Typically, the communication system 100 enables multiple wireless or wired components to transmit data and other content. The purpose of the communication system 100 may be to provide content such as voice, data, video, and / or text via broadcast, multicast, unicast, etc. The communication system 100 can operate by sharing resources (e.g., carrier spectrum bandwidth) among its constituent components. The communication system 100 may include terrestrial communication systems and / or non-terrestrial communication systems. The communication system 100 can provide a wide range of communication services and applications (e.g., earth monitoring, remote sensing, passive sensing and positioning, navigation and tracking, autonomous delivery and mobility, etc.). The communication system 100 can provide high availability and robustness through the joint operation of terrestrial and non-terrestrial communication systems. For example, integrating a non-terrestrial communication system (or components thereof) into a terrestrial communication system can realize a heterogeneous network comprising multiple layers. Compared to traditional communication networks, heterogeneous networks can achieve better overall performance through efficient multi-link joint operation, more flexible function sharing, and faster physical layer link switching between terrestrial and non-terrestrial networks.

[0058] Terrestrial communication systems and non-terrestrial communication systems can be considered subsystems of a communication system. Figure 2In the example shown, communication system 100 includes electronic devices (EDs) 110a to 110d (generally referred to as ED 110), radio access networks (RANs) 120a and 120b, a non-terrestrial communication network 120c, a core network 130, a public switched telephone network (PSTN) 140, the Internet 150, and other networks 160. RANs 120a and 120b include corresponding base stations (BSs) 170a and 170b, which may generally be referred to as terrestrial transmit and receive points (T-TRPs) 170a and 170b. The non-terrestrial communication network 120c includes access nodes 172, which may generally be referred to as non-terrestrial transmit and receive points (NT-TRPs) 172.

[0059] Alternatively, any ED 110 can be used to connect, access, or communicate with any T-TRP 170a and 170b and NT-TRP 172, Internet 150, core network 130, PSTN 140, other network 160, or any combination thereof. In some examples, ED 110a can perform uplink and / or downlink transmission with T-TRP 170a via terrestrial air interface 190a. In some examples, ED 110a to 110d can also communicate directly with each other via one or more sidelink air interfaces 190b. In some examples, ED 110d can perform uplink and / or downlink transmission with NT-TRP 172 via non-terrestrial air interface 190c.

[0060] Air interfaces 190a and 190b can use similar communication technologies, such as any suitable wireless access technology. For example, communication system 100 can implement one or more channel access methods in air interfaces 190a and 190b, such as code division multiple access (CDMA), space division multiple access (SDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal FDMA (OFDMA), or single-carrier FDMA (SC-FDMA) (also known as discrete Fourier transform spread OFDMA (DFT-s-OFDMA)). Air interfaces 190a and 190b can utilize other high-dimensional signal spaces, which may involve combinations of orthogonal and / or non-orthogonal dimensions.

[0061] The non-terrestrial air interface 190c enables communication between the ED 110d and one or more NT-TRP 172s via a wireless link, or simply a link. For some examples, the link is a dedicated connection for unicast transmission, a connection for broadcast transmission, or a connection for multicast transmission between a group of ED 110s and one or more NT-TRP 172s.

[0062] RANs 120a and 120b communicate with core network 130 to provide various services, such as voice, data, and other services, to EDs 110a, 110b, and 110c. RANs 120a and 120b and / or core network 130 may communicate directly or indirectly with one or more other RANs (not shown), which may or may not be directly served by core network 130, and may or may not use the same radio access technology as RANs 120a, RAN 120b, or both. Core network 130 may also act as a gateway access between (i) RANs 120a and 120b and / or EDs 110a, 110b, and 110c, and between (ii) other networks (e.g., PSTN 140, Internet 150, and other networks 160). Additionally, some or all of ED110a, 110b, and 110c may include the ability to communicate with different wireless networks via different wireless links using different wireless technologies and / or protocols. Instead of wireless communication (or other than wireless communication), ED 110a, 110b, and 110c may also communicate with service providers or exchanges (not shown) via wired communication channels and with the Internet 150. PSTN 140 may include a circuit-switched telephone network for providing plain old telephone service (POTS). The Internet 150 may include a network of computers and subnets (intranets) or both, incorporating protocols such as Internet Protocol (IP), Transmission Control Protocol (TCP), and User Datagram Protocol (UDP). ED 110a, 110b, and 110c may be multimode devices capable of operating according to multiple wireless access technologies and include multiple transceivers required to support these technologies.

[0063] Figure 3Another example of the ED 110 and base stations 170a, 170b, and / or 170c is shown. The ED 110 is used to connect people, objects, machines, etc. The ED 110 can be widely used in various scenarios, including, for example, cellular communication, device-to-device (D2D), vehicle-to-everything (V2X), peer-to-peer (P2P), machine-to-machine (M2M), machine-type communications (MTC), Internet of Things (IoT), virtual reality (VR), augmented reality (AR), mixed reality (MR), metaverse, digital twins, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, smart cities, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and mobility, etc.

[0064] Each ED 110 represents any end-user equipment suitable for wireless operation and may include (or be referred to as): user equipment / device (UE), wireless transmit / receive unit (WTRU), mobile station, fixed or mobile subscriber unit, cellular phone, station (STA), machine type communication (MTC) device, personal digital assistant (PDA), smartphone, laptop, computer, tablet, wireless sensor, consumer electronics device, smartbook, vehicle, automobile, truck, bus, train, or IoT device, wearable device (e.g., watch, glasses, head-mounted device, etc.), industrial equipment, or devices comprising or including the foregoing (e.g., communication module, modem, or chip), etc. Future generations of ED 110 may be referred to using other terms. Base stations 170a and 170b are T-TRPs and will be referred to as T-TRP 170 below. Figure 3As also shown, NT-TRP will be referred to as NT-TRP 172 below. Each ED 110 connected to T-TRP 170 and / or NT-TRP 172 can be dynamically or semi-statically turned on (i.e., established, activated, or enabled), turned off (i.e., released, deactivated, or disabled), and / or configured in response to one or more of the availability and necessity of the connection.

[0065] ED 110 includes a transmitter 201 and a receiver 203 coupled to one or more antennas 204. Only one antenna 204 is shown in the figure to avoid congestion. One, some, or all of the antennas 204 may also be panels. For example, the transmitter 201 and receiver 203 may be integrated as a transceiver. The transceiver is used to modulate data or other content for transmission by at least one antenna 204 or a network interface controller (NIC). The transceiver is also used to demodulate data or other content received through at least one antenna 204. Each transceiver includes any suitable structure for generating signals for wireless or wired transmission and / or for processing signals received wirelessly or wiredly. Each antenna 204 includes any suitable structure for transmitting and / or receiving wireless or wired signals.

[0066] ED 110 includes at least one memory 208. Memory 208 stores instructions and data used, generated, or acquired by ED 110. For example, memory 208 may store software instructions or modules for implementing some or all of the functions and / or embodiments described herein and executed by one or more processing units (e.g., processor 210). Each memory 208 includes any suitable one or more volatile and / or non-volatile storage and retrieval devices. Any suitable type of memory can be used, such as random access memory (RAM), read-only memory (ROM), hard disk, optical disk, subscriber identity module (SIM) card, memory stick, secure digital (SD) memory card, on-processor cache, etc.

[0067] ED 110 may also include one or more input / output devices (not shown) or interfaces (e.g., connected to...). Figure 1 (Wired interface of Internet 150 in the network). Input / output devices or interfaces support interaction with users or other devices in the network. Each input / output device or interface includes any suitable structure for providing or receiving information from the user, and / or for communication on the network interface. For example, suitable structures include speakers, microphones, keypads, keyboards, displays, touchscreens, etc.

[0068] ED 110 includes a processor 210 for performing operations, including operations related to preparing for uplink transmissions to NT-TRP 172 and / or T-TRP 170; operations related to processing downlink transmissions received from NT-TRP 172 and / or T-TRP 170; and operations related to processing sidelink transmissions to and from another ED 110. Processing operations related to preparing for uplink transmissions may include operations such as encoding, modulation, transmit beamforming, and generating symbols for transmission. Processing operations related to processing downlink transmissions may include operations such as receive beamforming, demodulation, and decoding of received symbols. According to an embodiment, the downlink transmission may be received by receiver 203, possibly using receive beamforming, and processor 210 may extract signaling from the downlink transmission (e.g., by detecting and / or decoding signaling). Examples of signaling may be reference signals transmitted by NT-TRP 172 and / or T-TRP 170. In some embodiments, processor 210 performs transmit beamforming and / or receive beamforming based on beam direction indications (e.g., beam angle information (BAI)) received from T-TRP 170. In some embodiments, processor 210 may perform operations related to network access (e.g., initial access) and / or downlink synchronization, such as operations related to detecting synchronization sequences, decoding, and acquiring system information. In some embodiments, processor 210 may perform channel estimation using reference signals received from NT-TRP 172 and / or T-TRP 170.

[0069] Although not shown, processor 210 may form part of transmitter 201 and / or receiver 203. Although not shown, memory 208 may form part of processor 210.

[0070] The processing components of processor 210, transmitter 201, and receiver 203 may be implemented by the same or different processors, which execute instructions stored in memory (e.g., memory 208). Alternatively, some or all of the processing components of processor 210, transmitter 201, and receiver 203 may be implemented using dedicated circuitry, such as a programmable field-programmable gate array (FPGA), application-specific integrated circuit (ASIC), or hardware accelerators such as graphics processing units (GPUs) or artificial intelligence (AI) accelerators.

[0071] The T-TRP 170 may be known by other names in some implementations, such as base station, base-transceiver station (BTS), wireless base station, network node, network device, network-side device, transmit / receive node, NodeB, evolved NodeB (eNodeB or eNB), home eNodeB, next-generation NodeB (gNB), transmission point (TP), site controller, access point (AP), wireless router, relay station, ground node, ground network device, ground base station, base band unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The T-TRP 170 can be a macro BS, pico BS, relay node, host node, or a combination thereof. T-TRP 170 may refer to the aforementioned device or a component of the aforementioned device (e.g., a communication module, modem, or chip).

[0072] In some embodiments, the various parts of T-TRP 170 may be distributed. For example, some modules of T-TRP 170 may be located remotely from the device housing the antenna 256 of T-TRP 170 and may be coupled to the device housing the antenna 256 via a communication link (not shown) sometimes referred to as a fronthaul (e.g., a common public radio interface, CPRI). Therefore, in some embodiments, the term T-TRP 170 may also refer to modules on the network side that perform processing operations such as determining the location of ED 110, resource allocation (scheduling), message generation, and encoding / decoding; these modules are not necessarily part of the device housing the antenna 256 of T-TRP 170. These modules may also be coupled to other T-TRPs. In some embodiments, T-TRP 170 may actually be multiple T-TRPs that operate together to provide services such as coordinated multicast to ED 110.

[0073] T-TRP 170 includes at least one transmitter 252 and at least one receiver 254 coupled to one or more antennas 256. Only one antenna 256 is shown in the figure to avoid congestion. One, some, or all of the antennas 256 may also be panels. The transmitter 252 and receiver 254 may be integrated as a transceiver. T-TRP 170 also includes a processor 260 for performing operations including operations related to: preparing transmissions for downlink transmission to ED 110, processing uplink transmissions received from ED 110, preparing transmissions for backhaul transmission to NT-TRP 172, and processing transmissions received from NT-TRP 172 via backhaul. Processing operations related to preparing transmissions for downlink or backhaul transmission may include operations such as encoding, modulation, precoding (e.g., multiple-input multiple-output (MIMO) precoding), transmit beamforming, and generating symbols for transmission. Processing operations related to transmissions received in the uplink or via backhaul may include receiving beamforming, demodulating received symbols, and decoding received symbols. Processor 260 may also perform operations related to network access (e.g., initial access) and / or downlink synchronization, such as generating the contents of a synchronization signal block (SSB), generating system information, etc. In some embodiments, processor 260 also generates beam direction indications, such as BAI, that can be scheduled for transmission by scheduler 253. Processor 260 performs other network-side processing operations described herein, such as determining the location of ED 110, determining the deployment location of NT-TRP 172, etc. In some embodiments, processor 260 may generate signaling, such as for configuring one or more parameters of ED 110 and / or one or more parameters of NT-TRP 172. Any signaling generated by processor 260 is transmitted by transmitter 252. It should be noted that the term "signaling" used herein may also be referred to as control signaling. Signaling can be transmitted in physical layer control channels (e.g., physical downlink control channel (PDCCH)). In this case, the signaling can be called dynamic signaling. Signaling transmitted in the downlink physical layer control channel can be called downlink control information (DCI). Signaling transmitted in the uplink physical layer control channel can be called uplink control information (UCI). Signaling transmitted in the sidelink physical layer control channel can be called sidelink control information (SCI).Signaling can be included in higher-layer (e.g., above the physical layer) messages transmitted on physical layer data channels (e.g., physical downlink shared channel, PDSCH). In this case, the signaling can be referred to as higher-layer signaling, static signaling, or semi-static signaling. Higher-layer signaling can refer to radio resource control (RRC) protocol signaling or media access control-control element (MAC-CE) signaling.

[0074] Scheduler 253 may be coupled to processor 260. Scheduler 253 may be included within T-TRP 170 or may operate separately from T-TRP 170. Scheduler 253 may schedule uplink, downlink, lateral link, and / or backhaul transmissions, including issuing scheduling authorizations and / or configuring schedule-free (e.g., "configuration authorization") resources. T-TRP 170 also includes memory 258 for storing information and data. Memory 258 stores instructions and data used, generated, or acquired by T-TRP 170. For example, memory 258 may store software instructions or modules executed by processor 260 for implementing some or all of the functions and / or embodiments described herein.

[0075] Although not shown, processor 260 may form part of transmitter 252 and / or receiver 254. Furthermore, although not shown, processor 260 may implement scheduler 253. Although not shown, memory 258 may form part of processor 260.

[0076] The processing components of processor 260, scheduler 253, transmitter 252, and receiver 254 may be implemented by the same or different processors, which execute instructions stored in memory (e.g., memory 258). Alternatively, some or all of the processing components of processor 260, scheduler 253, transmitter 252, and receiver 254 may be implemented using dedicated circuitry, such as a programmable FPGA, hardware accelerator (e.g., GPU or AI accelerator), or ASIC.

[0077] Although the NT-TRP 172 is shown as an example of a drone only, it can be implemented in any suitable non-terrestrial form, such as satellites and high-altitude platforms, including international mobile communication base stations and unmanned aerial vehicles. Furthermore, the NT-TRP 172 may be known by other names in some implementations, such as a non-terrestrial node, a non-terrestrial network device, or a non-terrestrial base station. The NT-TRP 172 includes a transmitter 272 and a receiver 274 coupled to one or more antennas 280. Only one antenna 280 is shown in the figure to avoid congestion. One, some, or all of the antennas may also be panels. The transmitter 272 and receiver 274 may be integrated as a transceiver. The NT-TRP 172 also includes a processor 276 for performing operations including: preparing transmissions for downlink transmission to ED 110, processing uplink transmissions received from ED 110, preparing transmissions for backhaul transmission to T-TRP 170, and processing transmissions received from T-TRP 170 via backhaul. Processing operations related to preparing a transmission for downlink or backhaul transmission may include operations such as encoding, modulation, precoding (e.g., MIMO precoding), transmit beamforming, and generating symbols for transmission. Processing operations related to processing transmissions received in the uplink or via backhaul may include operations such as receive beamforming, demodulating received symbols, and decoding received symbols. In some embodiments, processor 276 performs transmit beamforming and / or receive beamforming based on beam direction information (e.g., BAI) received from T-TRP 170. In some embodiments, processor 276 may generate signaling, such as for configuring one or more parameters of ED110. In some embodiments, NT-TRP 172 implements physical layer processing but does not implement higher-level functions such as those at the medium access control (MAC) or radio link control (RLC) layers. Since this is only an example, more generally, NT-TRP 172 may implement higher-level functions in addition to physical layer processing.

[0078] The NT-TRP 172 also includes a memory 278 for storing information and data. Although not shown, a processor 276 may form part of the transmitter 272 and / or the receiver 274. Although not shown, the memory 278 may form part of the processor 276.

[0079] The processing components of processor 276, transmitter 272, and receiver 274 may be implemented by the same or different one or more processors, which execute instructions stored in memory (e.g., memory 278). Alternatively, some or all of the processing components of processor 276, transmitter 272, and receiver 274 may be implemented using dedicated circuitry, such as a programmable FPGA, hardware accelerator (e.g., GPU or AI accelerator), or ASIC. In some embodiments, NT-TRP 172 may actually be multiple NT-TRPs operating together to coordinate services such as multicast transmission ED 110.

[0080] T-TRP 170, NT-TRP 172 and / or ED 110 may include other components, but for clarity these components are omitted.

[0081] One or more steps of the methods in the embodiments provided herein can be based on Figure 4 The corresponding unit or module is executed. Figure 4 The diagram illustrates units or modules within a device, such as in ED 110, T-TRP 170, or NT-TRP 172. For example, signals may be transmitted by a transmitting unit or transmitting module. Signals may be received by a receiving unit or receiving module. Signals may be processed by a processing unit or processing module. Other steps may be performed by an AI or machine learning (ML) module. The corresponding units or modules may be implemented using hardware, one or more components or devices executing software, or a combination thereof. For example, one or more units or modules may be circuits such as integrated circuits. Examples of integrated circuits include programmable FPGAs, GPUs, or ASICs. For example, one or more units or modules may be logic, such as a part of a circuit, an integrated circuit, or a logical function executed by software instructions executed by a processor. It should be understood that if these modules are implemented, for example, using software executed by a processor, then these modules may be retrieved by the processor, wholly or partially, individually or collectively, for processing, in one or more instances, as needed, and these modules themselves may include instructions for further deployment and instantiation.

[0082] Additional details regarding ED 110, T-TRP 170, and NT-TRP 172 are known to those skilled in the art. Therefore, these details are omitted herein.

[0083] The solutions described in this application are applicable to next-generation (e.g., 6G or higher) networks, or traditional (e.g., 5G or 4G) networks.

[0084] The proposed 6G system architecture is defined as supporting 6G XaaS services through the use of technologies such as network function virtualization and network slicing. The 6G system architecture leverages service-based interactions between 6G services.

[0085] 6G systems adopt a service-based architecture and the XaaS concept. XaaS services in 6G systems are categorized into three layers. For ease of explanation, Figure 5 The conceptual architecture of a 6G system is shown.

[0086] The infrastructure layer includes the infrastructure that supports 6G services. This includes wireless network infrastructure (such as RAN and core network (CN)), cloud / data center infrastructure, satellite networks, storage / database infrastructure, and sensing networks. This infrastructure can be provided by a single provider or by multiple providers.

[0087] Each infrastructure can have control and management functions for infrastructure management, represented as C / M functions. Each of these infrastructures is an Infrastructure as a Service.

[0088] The control and management (C / M) layer comprises the control and management services for the 6G system. These are developed and deployed using slicing technology and leveraging the resources provided by the infrastructure layer. In the conceptual architecture of a 6G system: Resource management (RM) as a service provides the ability to manage the lifecycle of various slices and allocate air resources to wireless devices.

[0089] Mission management (MM) refers to the ability of a service provider to program the configuration of XaaS services at the service layer to provide mission services. A 6G mission is defined as a service provided by a 6G system to a customer. A mission can be a service type provided by a single 6G XaaS service, or it can be a service type that requires contributions from multiple XaaS services.

[0090] - The Confederation Network (CONET) as a Service provides the ability for multiple partners to jointly deliver 6G services. This capability is provided through protocol negotiation involving alliance formation, mutual authentication, mutual authorization, and the recording and retrospective of selected actions performed by partners, ensuring a trusted environment for the operation of 6G systems.

[0091] Service provisioning management (SPM) refers to the ability of service providers to control and manage customer access to 6G services and configure requested services. This capability is provided through unified mutual authentication, authorization and policies, key management, quality of service (QoS) guarantees, and accounting between any pair of XaaS service providers and customers. Customers include not only end customers in the physical world but also digital representatives in the digital world.

[0092] - Connectivity management (CM) as a service leverages 5G connectivity management capabilities but extends to include the digital world.

[0093] Protocol as a Service (PCA) provides the ability to customize protocol stacks for the design services of the identified interfaces. Protocol stacks can be predefined for selection on demand, or designed on demand.

[0094] - Cybersecurity as a Service provides infrastructure owners with the ability to detect potential security risks to their infrastructure.

[0095] XaaS services in the C / M layer support the control and management of the 6G system itself and provide support to vertical industries upon request. For example, the RM service can provide air resource management services to the RAN, and can also provide air resource allocation services to end customers in vertical industries. XaaS in the C / M layer can be deployed using slicing technology.

[0096] The service layer includes 6G services provided to customers. In the 6G system conceptual architecture: - AI services are represented as NET4AI as a Service. Artificial intelligence services provide AI capabilities to support a wide range of AI applications.

[0097] Data acquisition, data cleansing, data analysis, and data delivery services are referred to as DAM as a Service. This service provides the ability to manage the lifecycle of statistical data, including acquiring, de-privatizing, analyzing, and delivering data—statistical data from any type of sensor, device, network function, etc.

[0098] - The data storage and sharing service is represented as NET4Data as a Service. This service provides the ability to reliably store and share data, under the control of the data owner and in accordance with the regulations of recognized authorities regarding the control of identified data.

[0099] Services that provide access to the digital world are represented as NET4DW as a Service. Digital world services provide the ability to build, control, and manage the digital world. The digital world is defined as the digital realization of the physical world.

[0100] The 6G blockchain service is represented as NET4BC as a service. This service provides the capability to support 6G blockchain services.

[0101] -6G connectivity services are represented as NET4CON as a service. Enhanced connectivity services, such as Connection-Oriented Networking (NET4CON) as a service, provide the ability to exchange messages and data between supporting new 6G services.

[0102] All XaaS services in this layer are developed and deployed using resources provided within the infrastructure and leveraging network function virtualization and slicing technologies. The capabilities of each 6G service are provided by its control and management functions, as well as service-specific data processing capabilities.

[0103] In addition to supporting 6G XaaS services at the service layer, the 6G system also leverages the 5G system to configure vertical services. The difference between 6G XaaS services and other vertical industries is that a vertical industry is a pure customer that needs other XaaS services to enable its operation, while each XaaS service provides its capabilities to the 6G customer.

[0104] Any pair of XaaS services in a 6G system can also be each other's customers and providers. Some examples are: the infrastructure owner provides its resources to the XaaS services in the service layer and the C / M layer; the RM service may need the capabilities provided by NET4AI, DAM, and NET4DW to enable its resource management for vertical slices; the CONET service and the NET4Data service may need the capabilities provided by NET4BC to run.

[0105] Key concepts of 6G systems include: - Basic XaaS services are defined by decoupling comprehensive types of services into basic XaaS services. Basic XaaS services provide unique capabilities to enable specific types of services, such as NET4AI services, NET4DW services, DAM services, NET4Data services, blockchain services, task management services, etc.

[0106] - Allows multiple partners to jointly operate the 6G system.

[0107] - Define the data plane of the 6G system, including the data plane processing functions of XaaS services. By programming the interconnection of these functions through task management services, a variety of customized customer services can be supported.

[0108] -Simplify the 6G system architecture by categorizing basic control and management services and combining them into basic XaaS services in the control and C / M layers.

[0109] - Define the C / M plane of the 6G system, including the C / M function in XaaS services, which may include 5G CP (e.g., AMF) depending on the implementation.

[0110] - Define the basic architecture structure (BAS), which is a unified basic structure with a minimal number of interfaces and is independent of the infrastructure type.

[0111] - The BAS concept simplifies the standardization, development, and deployment of 6G systems, while supporting a variety of infrastructure deployment scenarios.

[0112] - By applying BAS or subsets of it to the infrastructure based on the capabilities, capacity, and requirements of the infrastructure network, it can be adapted to a variety of deployment scenarios.

[0113] -Utilize the SBI interface concept and apply SBI interaction in both the 6G C / M plane and the 6G data plane.

[0114] -Simplify the SBI interface by introducing a trusted gateway (GW) in the data plane and C / M plane of the 6G system.

[0115] - Improve trustworthiness from the perspective of 6G system operation by introducing CONET capabilities, NET4BC capabilities and anonymity service configurations provided by a trusted GW into the C / M plane and data plane of the 6G system.

[0116] - Trustworthiness is enhanced from the perspective of end-customer privacy protection by providing unified mutual authentication, IDM, and data purification through SPM service, DAM service and 6G blockchain service.

[0117] -Simplify roaming management of wireless devices in the physical and digital worlds through unified certification that includes all participating partners and customers.

[0118] - By defining multiple architecture options, it supports multiple development paths from 5G systems to 6G systems, requiring less work due to the introduction of the BAS concept.

[0119] - By leveraging the advantages of SBA and its additional features, backward compatibility is supported. 5G users can use 6G systems to access 5G services.

[0120] - Supports future expansion by adding new XaaS services, minimizing the impact on standardization and deployment due to the introduction of anonymous service configuration concepts in the trusted GW of the 6G C / M plane and 6G data plane.

[0121] Currently, when user equipment is able to connect to a network, a security process is involved between the user equipment and network functions. Figure 6This illustrates the generation of the key hierarchy in a 5G system.

[0122] like Figure 6 As shown, the key hierarchy or key framework involved in the current security process may include the following intermediate keys and / or terminal keys: K AUSF K SEAF K AMF K NASint K NASenc K N3IWF K gNB K RRCint K RRCenc K UPint and K UPenc Here, K AUSF The intermediate key, K, is generated by AUSF. SEAF It was made by AUSF from K AUSF Derived anchor key, K AMF It is from SEAF from K SEAF The derived intermediate key. K NASint and K NASenc It is AMF from K AMF The derived terminal key, where K NASint K is used to protect non-access stratum (NAS) signaling using specific integrity algorithms. NASenc Used to protect NAS signaling using specific encryption algorithms. K N3IWF and K gNB It is AMF from K AMF The derived key. K RRCint and K RRCenc It is gNB from K gNB The derived terminal key, where K RRCint K is used to protect RRC signaling using a specific integrity algorithm. RRCenc Used to protect RRC signaling using a specific encryption algorithm. K UPint and K UPenc It is gNB from K gNB The derived terminal key, where K UPint Used to protect user plane (UP) traffic using specific integrity algorithms, K UPenc Used to protect UP traffic using specific encryption algorithms.

[0123] In the current key framework mentioned above, these intermediate keys and / or terminal keys are generated by different NFs, which should maintain key-related security information (also known as key information). Key-related security information may include the algorithm used to generate the key, or the parameters used to generate the key. For example, AUSF should maintain or preserve information related to K. AUSF and KSEAF Relevant security information. For example, AMF should maintain information related to K. NASint K NASenc K N3IWF or K gNB At least one related security information in the NF. On the one hand, when one of these NFs is compromised, the security information maintained by the compromised NF may be used by an attacker to construct terminal keys or intermediate keys. On the other hand, when some keys are refreshed, the security information associated with those keys should be updated. The exchange of security information associated with the refreshed keys incurs signaling overhead. For example, when from K... SEAF Vertical derivation of the new K AMF At that time, with the new K AMF Relevant security information should be communicated to the AMF and gNB. Furthermore, since one or more new NFs may be adopted in 6G systems or future networks, these new NFs should maintain security information and may need to support key generation. However, the key framework mentioned above is not scalable for the network.

[0124] In other words, in 3GPP 33.501, such as Figure 6 As shown, all keys include terminal keys (e.g., NAS key, UP key, RRC key) and intermediate keys (e.g., K key). SEAF K AMF K AUSF These are all generated by different NFs. For example, K SEAF Generated by AUSF, K AMF It can be generated by SEAF or AMF. UP keys and RRC keys are generated by gNB. This key framework has the following issues.

[0125] All of these functionalities should maintain security information associated with the keys. If one of the functionalities (NFs) is compromised, the key-related information could be used by an attacker to construct terminal or intermediate keys. This security information may include the algorithm used to generate the keys and the parameters used to generate them.

[0126] If some keys are refreshed, the NF should update the new information associated with those keys. For example, if new... KAMF From K SEAF Vertical derivation, then with the new K AMF The relevant information should be communicated to AMF and gNB.

[0127] If a new feature (e.g., data-TW-GW) is deployed to the network, that new feature should support the above requirements. This is not scalable for the network.

[0128] As mentioned above, future networks will support new applications and services, such as AI services, data services, sensing services, and digital world services. These services can be developed and deployed using resources provided in infrastructure (e.g., wireless access networks, data centers, or other infrastructure) and leveraging network function virtualization and slicing technologies. Each of these services can be referred to as XaaS. Within an XaaS module, multiple network functions may exist. These network functions can be categorized into two types: client / management (C / M) functions and data processing functions. Data processing functions are used for data processing and can only exist in the service layer. C / M functions are used for control and management and can exist in both the service layer and the C / M layer. XaaS service providers can also be referred to as XaaS services.

[0129] Figure 7 Network scenarios provided for some embodiments of this application. For example... Figure 7 As shown, a control / management trustworthy gateway (C / M-TW-GW) is a network function that can be defined as an endpoint of a network-side C / M session. The establishment of a C / M session is used by devices or XaaS services to transmit control messages related to the XaaS service. A C / M session can be defined as a secure logical connection between a device (e.g., a UE) and its serving C / M-TW-GW. A data trustworthy gateway (Data-TW-GW) is a network function that can be defined as an endpoint of a device's data session. The establishment of a data session is to enable devices or XaaS services to participate in data processing. A data session can be defined as a secure logical connection between a device and its serving Data-TW-GW. A radio bearer (RB) handler is a network function that can be implemented as a radio access network (RAN). RB handlers can connect to both other infrastructure (e.g., the core network and third-party clouds) and the C / M-TW-GW. In this scenario, there may be additional network functions, such as authentication servers and authorization servers.

[0130] like Figure 7 As shown, there are several interfaces within the network scenario used to connect these NFs. For example, interface I can be defined as a set of security functions that enable devices / clients to securely authenticate and access services and prevent attacks on the wireless interface. In other words, interface I can support the connection between the device and the RB handler. Similarly, interface II can be defined as a set of security functions that enable... Figure 7The system shown can securely exchange C / M sessions between the device / client and the C / M-TW-GW, or securely exchange data sessions between the client and the data-TW-GW. For example, Interface III can be defined as a set of security functions enabling the system to securely exchange C / M sessions between the XaaS service and the C / M-TW-GW, or securely exchange data sessions between the XaaS service and the data-TW-GW. For example, Interface IV can support connections between the RB handler and the C / M-TW-GW / data-TW-GW.

[0131] In this scenario, when a device (e.g., a UE) is able to connect to the network, a secure process between the user equipment and network functions will be involved. For example, when a device (e.g., a UE) is able to connect to the C / M-TW-GW and / or to the RAN infrastructure (e.g., Figure 6 The security process may include a primary authentication and key negotiation process when the RAN infrastructure is connected to other infrastructures (such as CN infrastructure, third-party cloud) and C / M-TW-GW. The purpose of the primary authentication and key negotiation process is to achieve mutual authentication between the device and the service network and to provide key materials that can be used between the device and the service network. These key materials can be used for signaling security protection of Interface I and Interface II in subsequent security processes. Alternatively, when a device requests a service, the security process may include a secondary primary authentication and key negotiation process. The purpose of the secondary authentication and key negotiation process is to achieve mutual authentication between the device and the XaaS service and to provide key materials that can be used between the device and the XaaS service in subsequent security processes. These key materials can be used for data security protection of Interface I and Interface II in subsequent security processes. Internet Protocol Security (IPsec) or Transport Layer Security (TLS) protocols can be implemented on Interface III, Interface IV, and Interface V to achieve secure communication. In addition to IPsec, datagram transport layer security (DTLS) should also be supported to provide mutual authentication, integrity protection, replay protection, and confidentiality protection. The security configuration files for DTLS implementations and usage should conform to the TLS configuration files given in Section 6.2 of TS 33.210 and the certificate configuration files given in Section 6.1.3a of TS 33.310.

[0132] As mentioned above, future networks may involve new services and network functions. Furthermore, the current key framework suffers from the problems discussed above.

[0133] To address this issue, a system and method for a key framework for future networks are provided. This research offers a key management architecture in which network functions generate keys and maintain security contexts. This reduces the overhead of network functions maintaining security contexts. Furthermore, a key derivation framework is provided to illustrate how network functions generate keys. This application improves efficiency and enhances security.

[0134] To reduce the overhead of security context exchange and maintenance, a key management function (also known as KMF) was introduced, which is responsible for key generation and security context maintenance.

[0135] First, we introduce some basic concepts related to some embodiments of this application.

[0136] The key management function (KMF) is a network function responsible for key generation and configuration. Furthermore, KMF can handle key refresh and revocation. For ease of explanation, let's consider... Figure 7 Taking the scenario shown as an example, multiple intermediate and terminal keys can exist to secure communication on Interface I and Interface II. These could include keys for protecting the C / M session (also called C / M session keys), keys for protecting the data session (also called data session keys), keys for protecting the C / M RB (also called C / M RB keys), and keys for protecting the data RB (also called data RB keys). These keys will be generated by one or more KMFs and configured for the relevant network functions (e.g., C / M-TW-GW, Data-TW-GW, and RB handlers). Therefore, these keys cannot be generated by the relevant network functions themselves.

[0137] Future networks should allow the use of encryption and integrity protection algorithms for C / M session keys, C / M RB keys, data session keys, and data RB keys indirectly derived from EMSK. The keys used for C / M sessions, C / M RB, data sessions, and data RB should depend on the algorithm used. Keys for C / M sessions and data sessions are configured to the C / M-TW-GW / Data-TW-GW. Keys for C / M RB and data RB are derived from the key derivation of the RB processor and then configured to the RB processor. All keys are generated by the KMF. The KMF is responsible for key generation, key refresh, and key revocation. The KMF should also be responsible for managing the security context of the device.

[0138] KMF can also be responsible for managing the device's security context. A security context is a state that should be established locally at the device and service network domain. A security context can at least include the device's security capabilities. A security context can include algorithms used to generate keys. The device's security capabilities can be a set of identifiers corresponding to encryption and integrity algorithms implemented in the device. In some implementations, the security context includes algorithms for key generation and / or inputs for key generation.

[0139] Compared to the current key framework, the overhead of the NF in maintaining the security context can be reduced because the KMF is responsible for maintaining the security context and activating security protection for communication between devices and the network.

[0140] Technical terms, such as “C / M-TW-GW,” “Data-TW-GW,” and “KMF,” are not limited to the specific exemplary names presented herein. These terms or the concepts they refer to may also be called by other names. For example, a key management function may be called a key generation and configuration function. As another example, a control / management trusted gateway may be called a control / management gateway.

[0141] The following technical issues exist.

[0142] (1) How to design the key management architecture Since the key is used for security protection of communications on Interface I and Interface II, what is the interface between C / M-TW-GW / Data-TW-GW and KMF? What is the interface between the RB handler and KMF? What is the interface between KMF and other functions (e.g., the authentication server for device authentication)? What are the main functions provided by KMF? (2) How to design a key derivation framework We should discuss how to generate keys using KMF. What information should be exchanged between NF and KMF?

[0143] To address these technical issues, the following section will combine... Figure 8 An architectural example describing the key management functionality is provided for reference. Furthermore, it will be combined with... Figure 9 An example describing a key derivation framework.

[0144] Figure 8 The architecture of key management functionality provided for some embodiments of this application.

[0145] like Figure 8 As shown, the KMF anchor can be responsible for generating and refreshing anchor keys. Anchor keys can be used to determine whether authentication is required between the device and the network.

[0146] KMF-Session can be responsible for generating and refreshing session keys. Session keys are used to protect the session between the device and the C / M-TW-GW / Data-TW-GW. In other words, session keys can include keys for protecting the C / M session and / or keys for protecting the data session. KMF-Session can be responsible for activating security protections for communication between the device and the C / M-TW-GW / Data-TW-GW.

[0147] In some implementations, the KMF session can be responsible for generating the key for the RB processor. The key for the RB processor can be used to derive the key for protecting the C / M RB and / or the key for protecting the data RB.

[0148] In addition, the KMF session can be responsible for maintaining the security context and configuring session keys. For example, a C / M-TW-GW or a data-TW-GW can connect to the KMF session, and the KMF session can configure session keys for the C / M-TW-GW or the data-TW-GW.

[0149] by Figure 7 Taking the scenario shown as an example, the KMF-session can generate keys to protect C / M sessions and configure these C / M session keys to the C / M-TW-GW, and / or generate keys to protect data sessions and configure these data session keys to the data-TW-GW. Furthermore, the KMF-session can be responsible for activating security protection for communication between the device and the C / M-TW-GW / data-TW-GW.

[0150] KMF-RB can be responsible for generating and refreshing RB keys. RB keys are used to protect the RB between the device and the RB handler. In other words, RB keys can include keys for protecting the C / M RB and / or keys for protecting the data RB. KMF-RB can also be responsible for configuring RB keys. For example, an RB handler can connect to KMF-RB, and KMF-RB can configure the RB keys for the RB handler. Furthermore, KMF-RB can be responsible for activating security protections for communication between the device and the RB handler. KMF-RB can also be used to maintain security contexts.

[0151] An authentication server is a network function responsible for triggering C / M signaling protection. C / M signaling protection may include C / M key generation and C / M key configuration. The C / M key may include at least one of a C / M session key and a C / M RB key. The authentication server may connect to a KMF anchor. After a device is successfully authenticated by the authentication server, a shared key can be transmitted to the KMF anchor. For clarity, the shared key can be a long-term key, such as an extended master session key (EMSK). The shared key should be known to the device. These intermediate and terminal keys, such as the C / M session key, C / M RB key, and data session key, can be indirectly derived from the shared key.

[0152] The authorization server can be a network function used for service management. The authorization server can be responsible for triggering data protection, which may include data key generation and data key configuration. The data key may include at least one of a data session key and a data RB key. The authorization server can connect to a KMF-anchor point. After the device is successfully authorized by the authorization server, a key for protecting the data session can be generated and configured for the data-TW-GW.

[0153] In some implementations, at least two of KMF-RB, KMF-Session, and KMF-Anchor are integrated into a single network function, such as KMF. For example, KMF#1 is a network function in which KMF-RB, KMF-Session, and KMF-Anchor can be integrated. In this scenario, KMF-RB, KMF-Session, and KMF-Anchor can be viewed as different modules, units, or functions of KMF#1.

[0154] In some implementations, KMF-RB, KMF-session, and KMF-anchor are distributed across different network functions. For ease of illustration, in one embodiment, KMF#2, KMF#3, and KMF#4 are different network functions, and KMF#2, KMF#3, and KMF#4 can be examples of KMF-anchor, KMF-session, and KMF-RB, respectively. In another embodiment, KMF-session can be integrated into C / M-TW-GW or Data-TW-GW, and / or KMF-RB can be integrated into RB handlers, wherein KMF#2 may include KMF-anchor.

[0155] The RB handler connects to the KMF-RB, and the C / M-TW-GW or data-TW-GW connects to the KMF-session.

[0156] In some embodiments, there are interfaces between KMF-anchors, KMF-sessions, and KMF-RBs. For example, KMF-anchors and KMF-sessions can be interconnected, and KMF-sessions and KMF-RBs can be interconnected.

[0157] Compared to the current key framework, since the session key and RB key are generated by the KMF, there is no need to maintain or retain key information for related NFs such as the RB processor. This reduces the overhead of maintaining key information for NFs. For example, key information may include the algorithm used for key generation, as well as the parameters or inputs used for key generation.

[0158] Compared to existing technologies in 3GPP 33.501, the above key management architecture can have the following new features: (1) Decouple network service operations from security management. KMF maintains the security context and activates security protection for communication between devices and the network, while NF in 3GPP 33.501 maintains the security context. This can reduce the overhead caused by NF maintaining the security context.

[0159] (2) Decoupling network service operations from key management. The KMF generates session keys and RB keys. Therefore, the NF does not maintain key information (e.g., the algorithm used for key generation), parameters used for key generation, or inputs (e.g., intermediate keys). This reduces the overhead of the NF maintaining key information. Currently, updating the intermediate key may involve exchanging key information between related NFs. In this invention, the KMF refreshes the intermediate key itself. Compared to existing technologies, this reduces additional communication overhead.

[0160] The key management architecture mentioned above can support the use of encryption and integrity algorithms for C / M session keys, data session keys, C / M RB keys, and data RB keys.

[0161] For ease of explanation, Figure 9 This is a key hierarchy structure used for C / M signaling protection and data protection.

[0162] Future network systems should allow the use of encryption and integrity protection algorithms for C / M session keys, C / M RB keys, data session keys, and data RB keys derived from EMSK. For example... Figure 9 As shown, the intermediate key and terminal key are as follows: (1) The intermediate key is K KMF This indicates that the key is a mobile device (ME) and a KMF-anchor that can be derived from the EMSK. For clarity, the key used to generate the KMF is... KMFThe input can include at least one of the following: the name of the KMF anchor, a random number, or an indication parameter from the authentication server used to generate the KMF. KMF By introducing K KMF This decouples authentication and key management functions. Therefore, it enhances the security of key generation and anchor keys.

[0163] (2) The anchor key is K anchor This indicates that the ME and KMF anchor points can be accessed from K. KMF The derived key.

[0164] (3) The key for the RB processing program is K RBhandler This indicates that the ME and KMF sessions can be accessed from K. anchor The derived key.

[0165] (4) The C / M session key is provided by K C / M-session-int This indicates that it is a key used to protect the C / M session using a specific integrity algorithm. K C / M-session-int It can be generated from K by ME and KMF-session anchor Derivation.

[0166] (5) Another C / M session key is provided by K C / M-session-enc This indicates that it is a key used to protect the C / M session using a specific encryption algorithm. K C / M-session-enc It can be generated from K by ME and KMF-session anchor Derivation.

[0167] (6) The data session key is K data-session-int This indicates that it is a key used to protect data sessions using a specific integrity algorithm. K data-Session-int It can be generated from K by ME and KMF-session anchor Derivation.

[0168] (7) Another data session key is K data-session-enc This indicates that it is a key used to protect data sessions using a specific encryption algorithm. K data-session-enc It can be generated from K by ME and KMF-session anchor Derivation.

[0169] (8) The C / M RB key is given by K C / M-RB-int This indicates that it is a key used to protect the C / M RB using a specific integrity algorithm. K C / M-RB-int It can be obtained from K by ME and KMF-RB RBhandler Derivation.

[0170] (9) Another C / M RB key is K C / M-RB-enc This indicates that it is a key used to protect the C / M RB using a specific encryption algorithm. K C / M-RB-encIt can be obtained from K by ME and KMF-RB RBhandler Derivation.

[0171] (10) The data RB key is given by K data-RB-int This indicates that it is a key used to protect data RB using a specific integrity algorithm. K data-RB-int It can be obtained from K by ME and KMF-RB RBhandler Derivation.

[0172] (11) Another data RB key is given by K data-RB-enc This indicates that it is the key used to protect data RB using a specific encryption algorithm. K data-RB-enc It can be obtained from K by ME and KMF-RB RBhandler Derivation.

[0173] The identifier (ID) of the anchor key can be called the 6G keyset identifier (6gKSI). The 6gKSI can be assigned by the KMF-anchor. The purpose of the 6gKSI is to enable the device and C / M-TW-GW to identify the security context without invoking their authentication processes. If the anchor key changes, the 6gKSI should also change. The 6gKSI should be stored in both the device and the C / M-TW-GW. One or more security parameters used for authentication, integrity protection, and encryption should be bound to the session security context and identified by the 6gKSI.

[0174] The above key derivation framework may have the following new functions: (1) Generate keys for data sessions to protect data sessions. These keys do not exist in existing technologies. (2) Introduce K KMF To enhance the security of the anchor key. It can decouple the authentication function and the key management function. This can enhance the security of key generation. (3) In 3GPP 33.501, K SEAF and K AUSF All are implemented using AUSF. In this application, K has been removed. SEAF and K AUSF K was introduced KMF This improves the security of the anchor key. This reduces complexity.

[0175] Figure 10 This is a schematic flowchart of a communication method 500 provided for some embodiments of this application. The steps involved in the method are described in detail below.

[0176] In S502, the first KMF receives a first message, which includes the device identifier and the device's known shared key, and also indicates a first network function.

[0177] In some embodiments, the shared key may be an EMSK. The EMSK may be known to both the authentication server and the device, and the device's identifier may be referred to as the device's ID.

[0178] In some embodiments, to indicate a first network function, the first message includes at least one of the following: the name of the first network function or the ID of the first network function. The first network function may be a C / M-TW-GW or a service communication proxy (SCP). The SCP may be a network function used to control C / M signaling.

[0179] The first network function or authentication server can send the first message, and correspondingly, the first KMF can receive the first message. After successful authentication, the authentication server or the first network function can send the first message.

[0180] For ease of explanation, the first KMF includes Figure 8 The KMF-anchor mentioned in the text. In some implementations, the first KMF can be a network function that integrates the KMF-anchor.

[0181] In S504, the first KMF generates the first key based on the first message.

[0182] The first key is used to determine whether authentication is required between the device and the first network function. In other words, the first key can be an anchor key. For example, the first key could be... Figure 9 K in anchor .

[0183] For ease of explanation, in one embodiment, the first key can be generated based on the device ID, the ID of the first network function, and the shared key. In another embodiment, the first key can be generated based on the device ID, the name of the first network function, and the shared key. For example, K anchor It can be generated from KMF-anchor points and devices based on the device ID, C / M-TW-GW ID, and EMSK.

[0184] In some implementations, generating the first key based on the first message includes: deriving an intermediate key from the shared key; and deriving the first key from the intermediate key. The intermediate key used to derive the first key can also be called the first intermediate key. For example, Figure 9 K in KMF This can be considered an example of a first intermediate key, and K anchor From K KMF Derivation.

[0185] In some embodiments, other inputs may also be used to generate the first intermediate key. For ease of illustration, the inputs used to generate the first intermediate key may include the name of the first KMF, a random number, or an indication parameter from the authentication server. For example, the inputs used to generate the KMF may be... KMF The input can include the name of C / M-TW-GW or a random number.

[0186] In some embodiments, multiple algorithms can be used to generate a first key and / or a first intermediate key. The first KMF can also select from these algorithms either the algorithm for generating the first key or the algorithm for generating the first intermediate key.

[0187] In some implementations, method 500 further includes at least one of steps S506 to S518.

[0188] In S506, the first KMF sends a second message to the second KMF. Correspondingly, the second KMF receives the second message.

[0189] The second message includes the first key and the ID of the first key.

[0190] In some implementations, the key hierarchy involves intermediate keys and terminal keys, such as K. anchor K RBhandler K C / M-session-int K C / M-session-enc and K C / M-RB-int The same algorithm was used to generate the terminal key. In this scenario, the second message may also include the ID of the algorithm used to generate the terminal key.

[0191] In one embodiment, Algorithm #1 and Algorithm #2 can be used to generate K. anchor K RBhandler K C / M-session-int K C / M-session-enc K C / M-RB-int and K C / M-RB-enc Algorithm #1 and Algorithm #2 can be configured for the first KMF and the second KMF. For example, when the first KMF selects Algorithm #1 to generate K... anchor At that time, the second message includes the ID of Algorithm #1. Algorithm #1 can be considered as an example of an algorithm used to generate the terminal key.

[0192] In some implementations, the key hierarchy involves intermediate keys and terminal keys, such as K. anchor K C / M-session-int K C / M-session-enc and K C / M-RB-int These are generated by different algorithms. In this scenario, the second message may also include the ID of the algorithm used to generate the first key.

[0193] In one embodiment, algorithms #3 to #5 can be used to generate K. anchor Algorithms #6 through #8 can be used to generate session keys. Algorithms #3 through #5 can be configured for the first KMF, and algorithms #6 through #8 can be configured for the second KMF. For example, when the first KMF determines to generate a KMF based on algorithm #3... anchor At that time, the second message includes the ID of Algorithm #3. Algorithm #3 can be considered as an example of the algorithm used to generate the first key.

[0194] The second KMF can be used to generate a second key based on the first key. The second key can be used to protect communication between the device and the first network function. For ease of explanation, Figure 8 The KMF-session mentioned above can serve as an example of a second KMF. In some implementations, the second KMF can be a network function that integrates a KMF-session.

[0195] In S508, the second KMF generates the second key based on the second message.

[0196] In some implementations, the second key may include at least one of the following: a terminal key for protecting communication between the device and the first network function using an encryption algorithm, or a terminal key for protecting communication between the device and the first network function using an integrity algorithm.

[0197] For ease of illustration, the C / M-TW-GW / Data-TW-GW can be used as an example of a first network function. Correspondingly, the session key used to protect the device between the device and the C / M-TW-GW / Data-TW-GW can be used as an example of a second key. For example, the second key may include one or more of the following: K C / M-session-int K C / M-session-enc K data-session-int or K data-session-enc .

[0198] In some embodiments, when the intermediate keys and terminal keys involved in the key hierarchy are generated using the same algorithm, the second message also includes the ID of the algorithm used to generate the terminal key. In this scenario, the second KMF can derive the second key from the first key using the algorithm indicated by the second message.

[0199] In some embodiments, when the intermediate key and terminal key involved in the key hierarchy are generated using different algorithms, the second message also includes the ID of the algorithm used to generate the first key. In this scenario, the second KMF can determine the algorithm used to generate the second key based on the ID of the algorithm used to generate the first key.

[0200] In S510, the second KMF sends a third message to the first network function. Correspondingly, the first network function receives the third message.

[0201] The third message includes the second key and the security context of the first network function. The security context of the first network function may include the ID of the first key. The ID of the first key enables the device and the first network function to identify the security context without invoking the authentication process.

[0202] In some implementations, since the second key may include a key for protecting communication between the device and the first network function using an encryption algorithm and / or a key for protecting communication between the device and the first network function using an integrity algorithm, the security context of the first network function may include at least one of the following: an ID of an encryption algorithm for encrypting communication between the user equipment and the first network function, or an ID of an integrity algorithm for ensuring the integrity of communication between the user equipment and the first network function.

[0203] The first network function can protect its communication with the device based on the second key. The first network function can maintain or preserve its security context.

[0204] In some implementations, a first network function sends a first request to refresh the second key. Accordingly, a second KMF receives the first request. Furthermore, the second KMF can refresh the second key based on the first request. The first request may include factors for key refresh. For example, the factors may be inputs used to derive a terminal key (e.g., an RB key).

[0205] In S512, the second KMF generates the third key based on the second message.

[0206] The third key is used to generate the fourth key, which is used to protect communication between the device and the second network function. In other words, the third key can be an intermediate key.

[0207] The second network function is a network function that is connected to the first network function and the device has connectivity capabilities. For ease of explanation, Figure 8 The RB processing procedure in the code can serve as an example of a second network function. Accordingly, the RB key can serve as an example of a fourth key, and the key used by the RB processing procedure to derive the RB key can serve as an example of a third key.

[0208] In S514, the second KMF sends a fourth message to the third KMF. Correspondingly, the third KMF receives the fourth message.

[0209] The fourth message includes the IDs of the third key and the first key.

[0210] In some implementations, the key hierarchy involves intermediate keys and terminal keys, such as K. anchor K RBhandler K C / M-RB-int K C / M-RB-enc and K data-RB-int They are generated using the same algorithm. In this scenario, the fourth message may also include the ID of the algorithm used to generate the terminal key.

[0211] In one embodiment, Algorithm #1 and Algorithm #2 can be used to generate K. anchor K RBhandler K C / M-session-int K C / M-session-enc K C / M-RB-int and K C / M-RB-enc For example, when the second KMF selection algorithm #1 is used to generate K... RBhandler At that time, the fourth message includes the ID of Algorithm #1. Algorithm #1 can serve as an example of an algorithm used to generate a terminal key.

[0212] In some implementations, the key hierarchy involves intermediate keys and terminal keys, such as K. anchor K RBhandler K C / M-RB-int K C / M-RB-enc and K data-RB-int These are generated using different algorithms. In this scenario, the fourth message may also include the ID of the algorithm used to generate the third key.

[0213] In one embodiment, algorithms #9 to #11 can be used to generate K. RBhandler Algorithms #12 through #14 can be used to generate RB keys. Algorithms #9 through #11 can be configured for the second KMF, while algorithms #12 through #14 can be configured for the third KMF. For example, when the second KMF determines to generate a K key according to algorithm #9... RBhandler At that time, the fourth message includes the ID of algorithm #9. Algorithm #9 can be considered as an example of an algorithm used to generate the third key.

[0214] The third KMF can be used to generate the fourth key. For ease of explanation, Figure 8 The KMF-RB in the example can be considered as an example of a third KMF. In some implementations, the third KMF can be a network function that integrates KMF-RB.

[0215] In some implementations, the first KMF, the second KMF, and the third KMF can be different KMFs. In other words, the first KMF, the second KMF, and the third KMF can be distributed across different network functions.

[0216] In some implementations, the first KMF, the second KMF, and the third KMF can be the same KMF. In other words, the first KMF, the second KMF, and the third KMF can be integrated into the same network function.

[0217] In S516, the third KMF generates the fourth key based on the fourth message.

[0218] In some implementations, the fourth key may include at least one of the following: a terminal key for protecting communication between the device and the second network function using an encryption algorithm, or a terminal key for protecting communication between the device and the second network function using an integrity algorithm.

[0219] For ease of explanation, Figure 8 The RB processing procedure in the code can serve as an example of a second network function. For instance, the fourth key may include one or more of the following: K C / M-RB-int K C / M-RB-enc K data-RB-int or K data-RB-enc .

[0220] In some embodiments, when the intermediate keys and terminal keys involved in the key hierarchy are generated using the same algorithm, the fourth message also includes the ID of the algorithm used to generate the terminal key. In this scenario, the third KMF can derive the fourth key from the third key using the algorithm indicated by the fourth message.

[0221] In some embodiments, when the intermediate and terminal keys involved in the key hierarchy are generated using different algorithms, the fourth message also includes the ID of the algorithm used to generate the third key. In this scenario, the third KMF can determine the algorithm used to generate the fourth key based on the ID of the algorithm used to generate the third key.

[0222] In S518, the third KMF sends the fifth message to the second network function. Correspondingly, the second network function receives the fifth message.

[0223] The fifth message includes the fourth key and the security context of the second network function. The security context of the second network function may include the ID of the first key. The ID of the first key enables the device and the second network function to identify the security context without invoking the authentication process.

[0224] In some implementations, since the fourth key may include a key for protecting communication between the device and the second network function using an encryption algorithm and / or a key for protecting communication between the device and the second network function using an integrity algorithm, the security context of the second network function may include at least one of the following: an ID of an encryption algorithm for encrypting communication between the user equipment and the second network function, or an ID of an integrity algorithm for ensuring the integrity of communication between the user equipment and the second network function.

[0225] The second network function can protect its communication with the device based on the fourth key. The second network function can maintain or preserve its security context.

[0226] In some implementations, the second network function sends a second request to refresh the fourth key. Correspondingly, the third KMF receives the second request. Furthermore, the third KMF can refresh the fourth key based on the second request. The second request may include factors for key refresh.

[0227] For ease of explanation, Figure 11 This is a schematic flowchart of a method 600 provided in some embodiments of this application. Figure 11 An example of the call flow for key generation and key configuration is shown. Figure 11 As shown, C / M-TW-GW is an example of the first network function, RB handler is an example of the second network function, KMF-anchor is an example of the first KMF, KMF-session is an example of the second KMF, and KMF-RB is an example of the third KMF.

[0228] In S601, the authentication server or C / M-TW-GW sends message 1 to the KMF-anchor.

[0229] Message 1 may include the device ID, the C / M-TW-GW ID, and the EMSK.

[0230] In one embodiment, the key generation and key configuration process can be triggered by the authentication server. After successful authentication, the authentication server sends message 1 to the KMF-anchor.

[0231] In another embodiment, the key generation and key configuration process can be triggered by the C / M-TW-GW. The C / M-TW-GW sends message 1 to the KMF-anchor.

[0232] Message 1 can serve as an example of the first message in method 500.

[0233] In S602, KMF-anchor generates anchor keys.

[0234] KMF - Anchor Selection uses one or more algorithms to generate the following keys: K KMFand K anchor K KMF and K anchor KMF anchors can be generated using the same or different algorithms. KMF and K anchor .

[0235] In addition, KMF-anchor points can be set with K anchor The ID. In other words, the KMF-anchor can determine the 6gKSI.

[0236] In S603, the KMF-anchor sends message 3 to the KMF-session.

[0237] In one embodiment, multiple keys involved in the key hierarchy can be generated using the same algorithm. These keys in the key hierarchy include anchor keys and other keys, such as K. KMF K C / M-session-int K C / M-session-enc and K C / M-RB-int .

[0238] In another embodiment, the keys involved in the key hierarchy can be generated using different algorithms.

[0239] Message 3 may include the anchor key, 6gKSI, and the key used to generate K. anchor The type and identifier of the algorithm.

[0240] Message 3 can serve as an example of the second message in method 500.

[0241] In S604, the KMF-session generates a C / M session key.

[0242] KMF - Sessions can be accessed from K anchor Derivation of K C / M-session-int and K C / M-session-enc Furthermore, the KMF session can configure device security capabilities. In other words, the KMF session can determine the security capabilities of the device. C / M-session-int The ID and K related to the specific integrity algorithm C / M-session-enc The ID of the specific encryption algorithm. The KMF session can set the security context for the C / M-TW-GW, and the security context of the C / M-TW-GW includes at least the device security capabilities.

[0243] In some embodiments, the security context of C / M-TW-GW may include 6gKSI.

[0244] In S605, the KMF-session sends message 5 to C / M-TW-GW.

[0245] Message 5 may include the C / M session key, 6gKSI, and the security context of C / M-TW-GW.

[0246] Message 5 can serve as an example of the third message in method 500.

[0247] In S606, C / M-TW-GW sends message 6 to the KMF-session.

[0248] Upon receiving message 5, the C / M-TW-GW maintains or preserves the C / M session key and 6gKSI. The C / M-TW-GW may also maintain or preserve the security context included in message 5.

[0249] Message 6 may include parameters for session key refresh. Message 6 can serve as an example of the first request in method 500.

[0250] In S607, the KMF-session generates keys for the RB processor.

[0251] KMF - Sessions can be accessed from K anchor Derivation of K RBhandler .

[0252] In S608, the KMF-session sends message 8 to the KMF-RB.

[0253] Message 8 may include the key for the RB processor, 6gKSI, and the key used to generate K. RBhandler The type and identifier of the algorithm.

[0254] Message 8 can serve as an example of the fourth message in method 500.

[0255] In S609, KMF-RB generates C / M RB keys.

[0256] KMF-RB can be derived from K RBhandle Derivation of K C / M-RB-int and K C / M-RB-enc Furthermore, the KMF-RB can configure device security capabilities. In other words, the KMF-RB can determine the security capabilities associated with K. C / M-RB-int The ID and K related to the specific integrity algorithm C / M-RB-enc The ID of the specific encryption algorithm. KMF-RB can set the security context for C / M-TW-GW, and the security context of the RB handler includes at least the device security capabilities.

[0257] In some embodiments, the security context of the RB handler may include 6gKSI.

[0258] In S610, KMF-RB sends message 10 to the RB handler.

[0259] Message 10 may include the C / M RB key, 6gKSI, and the security context of the RB processor.

[0260] Message 10 can serve as an example of the fifth message in method 500.

[0261] In S611, the RB handler sends message 11 to KMF-RB.

[0262] Upon receiving message 10, the RB handler maintains or preserves the C / M RB key and 6gKSI. The RB handler may maintain or preserve the security context included in message 10. Message 11 may include parameters for RB key refresh. Message 11 may serve as an example of a second request in method 500.

[0263] In one embodiment, the call flow for the key generation and key configuration process can be detailed as follows: (1) The key generation and key configuration process can be triggered by the authentication server or the C / M-TW-GW. After successful authentication, the authentication server sends message 1 to the KMF-anchor. Message 1 may include the device ID, the C / M-TW-GW ID, and the EMSK. In some embodiments, this is triggered by the C / M-TW-GW. The C / M-TW-GW sends message 1 to the KMF-anchor. Message 1 may include the device ID, the C / M-TW-GW ID, and the EMSK.

[0264] Message 1 can serve as an example of the first message in method 500.

[0265] (2) The KMF-anchor point performs the following actions: - Select the algorithm used to generate the following keys and set 6gKSI. - Generate KKMF.

[0266] - Generate anchor key.

[0267] (3) KMF-anchor sends message 3 to KMF-session.

[0268] Message 3 can serve as an example of the second message in method 500.

[0269] (4) The KMF session performs the following actions: - Configure device security capabilities - Generate C / M session key - Set up a security context for C / M-TW-GW.

[0270] (5) KMF-session sends message 5 to C / M-TW-GW.

[0271] Message 5 can serve as an example of the third message in method 500.

[0272] (6) The C / M-TW-GW stores the session key and 6gKSI. The C / M-TW-GW can store the security context. Then, the C / M-TW-GW sends message 6 to the KMF-session.

[0273] Message 6 can serve as an example of the first request in method 500.

[0274] (7) The KMF session generates a key for the RB processor.

[0275] (8) KMF-session sends message 8 to KMF-RB.

[0276] Message 8 can serve as an example of the fourth message in method 500.

[0277] (9) KMF-RB performs the following actions: - Configure device security capabilities - Generate C / M RB key - Set the security context for the RB handler.

[0278] (10) KMF-RB sends message 10 to the RB handler.

[0279] Message 10 can serve as an example of the fifth message in method 500.

[0280] (11) The RB handler saves the session key and 6gKSI. The RB handler can save the security context. Then, the RB handler sends message 11 to the KMF-RB.

[0281] In some embodiments, device security capabilities can be configured to the RB processor or C / M-TW-GW after the key generation and key configuration process. This may occur during the secure activation process of communication between the device and the RB processor, or between the device and the C / M-TW-GW.

[0282] In some embodiments, the KMF-RB or KMF-Session should configure a security context for the device. The security context may include the device's security capabilities, 6gKSI, and the type and ID of one or more algorithms used to generate the anchor key, session key, and RB key. Upon receiving the security context, the device can use one or more received algorithms to generate the anchor key, the corresponding session key, and the RB key.

[0283] This example provides details on how to generate and configure keys within a key management architecture.

[0284] In this application, a key management architecture is designed. The basic concepts are (1) decoupling network service operations from security management; and (2) decoupling network service operations from key management. KMF is used to maintain security context and keys (therefore reducing overhead) and generate session keys / RB keys (therefore, NF does not store key information).

[0285] Furthermore, a key derivation framework based on a key management architecture was designed. Within this framework, keys are generated for data sessions to protect them, and KKMF is introduced to enhance the security of key generation.

[0286] It provides details about key generation and key configuration, and aims to declare messages between these functions.

[0287] These technical solutions can bring some benefits.

[0288] (1) Regarding expenses KMF maintains the security context and activates security protections for device and network communications, while NF in 3GPP 33.501 maintains the security context. Compared to existing technologies, it can reduce the overhead caused by NF maintaining the security context.

[0289] KMF generates session keys and RB keys. Therefore, NF does not maintain key information (e.g., the algorithm used for key generation), parameters used for key generation, or inputs (e.g., intermediate keys). Compared to existing technologies, it reduces the overhead of NF maintaining key information.

[0290] In existing technologies, updating the intermediate key may involve exchanging key information between related functional networks (NFs). In this invention, the KMF refreshes the intermediate key itself. Compared to existing technologies, this reduces additional communication overhead.

[0291] (2) Regarding scalability Network functions (e.g., data-TW-GW) are easy to add to the system.

[0292] The methods proposed in the embodiments of this application have been described in detail above. The communication device provided in this application will be described in detail below.

[0293] Figure 12 This is a schematic block diagram of a communication device 10 provided in some embodiments of this application. The communication device may be a communication equipment or a device applied to a communication equipment, capable of implementing the corresponding function of any network function in the embodiments of this application. For example, the device may be a chip, a chip system, or a circuit, without limitation. The communication equipment may be a first KMF, a second KMF, a third KMF, a first network function, or a second network function, or a chip installed in any of these network functions.

[0294] The communication device 10 includes a processing module 11. The processing module 11 may be a processor, processing circuit, processing board, processing unit, or processing device, etc. The processing module 11 is used to perform processing and / or operations within the communication device, other than transmitting and receiving operations.

[0295] The communication device 10 may further include a communication module 12. The communication module 12 is used to implement sending and / or receiving operations. The communication module 12 may also be called a transceiver module, transceiver, or transceiver device, etc., and is used to implement receiving (which may be called input) and / or sending (which may be called output) operations.

[0296] For example, if communication device 10 corresponds to Figure 10 If the first KMF is in the first KMF, then the communication module 12 can be used to receive the first message. The communication module 12 can also be used to send a second message to the second KMF.

[0297] For example, if communication device 10 corresponds to Figure 10 If the second KMF is configured, then the communication module 12 can be used to receive a second message from the first KMF. The communication module 12 can also be used to send a third message to the first network function.

[0298] For example, if communication device 10 corresponds to Figure 10 If the third KMF is in the second KMF, then the communication module 12 can be used to receive the fourth message from the second KMF.

[0299] For example, if communication device 10 corresponds to Figure 10 If the first network function is used, then the communication module 12 can be used to receive a third message from the second KMF.

[0300] For example, if communication device 10 corresponds to Figure 5 If the second network function is used, then the communication module 12 can be used to receive the fifth message from the third KMF.

[0301] In short, the operation and / or function of device 10 are for implementing the corresponding steps of the above method embodiments.

[0302] Figure 13This is a schematic block diagram of a communication device provided for embodiments of this application. The communication device 20 includes at least one processor 21. The at least one processor 21 is coupled to at least one memory 22. The at least one memory 22 is used to store one or more instructions and / or executable computer code. The at least one processor 21 is used to invoke one or more instructions and / or executable computer code to cause the communication device 20 to implement the methods provided in the embodiments of this application. Optionally, the communication device 20 may further include at least one memory 22. Optionally, the communication device 20 may further include at least one communication interface 23, which is used for inputting and / or outputting information or data.

[0303] In one implementation, the communication device 20 can be any of the network functions in the method embodiments. For example, the communication device 20 can be a first KMF, a second KMF, a third KMF, a first network function, or a second network function. In this implementation, the processor 21 can be a baseband device, and the communication interface 23 can be a radio frequency device.

[0304] In another implementation, the communication device 20 can be a chip (or chip system) installed in a communication device such as a first KMF, second KMF, third KMF, first network function, or second network function. In this implementation, the processor 21 can be a circuit, such as a logic circuit or integrated circuit. The communication interface 23 can be a transceiver, interface circuit, input / output interface, bus, module, pin, or other type of interface.

[0305] Embodiments of this application also provide a communication system. The communication system may include any communication device according to any method embodiment. For example, the communication system may include one or more of the following network functions: a first KMF, a second KMF, a third KMF, a first network function, or a second network function. The communication system may also include a device (e.g., a UE) or other network functions, without limitation.

[0306] Embodiments of this application also provide a computer storage medium that can store one or more instructions for performing any of the methods described above.

[0307] Embodiments of this application also provide a computer program product that can store one or more instructions for performing any of the methods described above.

[0308] In the embodiments of this application, "and / or" describes the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can represent the following three cases: only A exists, both A and B exist, and only B exists. The character " / " generally represents an "OR" relationship between associated objects. "At least one" refers to one or more. "At least one of A and B," similar to "A and / or B," describes the association relationship between associated objects, indicating that three relationships may exist. For example, at least one of A and B can represent the following three cases: only A exists, both A and B exist, and only B exists.

[0309] Furthermore, unless the context clearly indicates otherwise, the use of the singular forms of “a” and “the” in the embodiments of this application and the appended claims is also intended to include the plural forms.

[0310] Those skilled in the art will recognize that the various examples described in conjunction with the embodiments disclosed in this specification, the units and algorithm steps, can be implemented by electronic hardware or by a combination of computer software and electronic hardware. Whether the function is executed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such embodiments should not be considered beyond the scope of this application.

[0311] Those skilled in the art will clearly understand that, for convenience and brevity, the specific working process of the above-described systems, devices, and units can be referred to the corresponding process in the above-described method embodiments, and will not be repeated here.

[0312] In the several embodiments provided in this application, the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the described apparatus embodiments are merely exemplary. For example, the units are divided into logical functional divisions, and other division methods may be used in actual embodiments. For example, multiple units or components may be merged or integrated into another system, or some features may be ignored or not performed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be implemented using various communication interfaces. Indirect coupling or communication connection between devices or units can be implemented electronically, mechanically, or otherwise.

[0313] In addition, the functional units in the embodiments of this application can be integrated into a processing unit, each of which can exist physically separately, or two or more units can be integrated into a unit.

[0314] When these functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. The technical solution of this application can be implemented as a software product. The software product is stored in a storage medium and includes several instructions to instruct a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the embodiments of this application. The aforementioned storage medium includes any medium capable of storing program code, such as a USB flash drive, portable hard drive, ROM, RAM, magnetic disk, optical disk, etc.

[0315] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; they may be located in one place or distributed across multiple network units. Some or all of the units can be selected based on actual needs to achieve the purpose of the embodiment. Furthermore, the functional units in the embodiments of this application may be integrated into one processing unit, or each unit may exist physically independently, or two or more units may be integrated into one unit.

[0316] The above description is merely a specific implementation of this application and is not intended to limit the scope of protection of this application. Any variations or substitutions easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method executed by a first key management function (KMF), characterized in that, include: Receive a first message, wherein the first message includes an identifier of the device and a known shared key of the device, and the first message also indicates the name or identifier of a first network function; A first key is generated based on the first message, wherein the first key is used to determine whether authentication is required between the device and the first network function; Send a second message to the second KMF, wherein the second message includes the first key, an identifier of the first key, and an identifier of an algorithm for generating the first key or an identifier of an algorithm for generating a terminal key; wherein the first key is used to generate a second key, and the second key includes a terminal key for protecting communication between the device and the first network function.

2. The communication method according to claim 1, characterized in that, The step of generating the first key based on the first message includes: Derive the intermediate key from the shared key and at least one of the following: the name or random number of the first KMF; The first key is derived from the intermediate key.

3. The communication method according to claim 1 or 2, characterized in that, Also includes: The algorithm for generating the first key or the algorithm for generating the terminal key is determined from multiple algorithms.

4. The communication method according to any one of claims 1 to 3, characterized in that, The second key includes one or more of the following: A terminal key used to protect the communication between the device and the first network function using an encryption algorithm; or A terminal key used to protect the communication between the device and the first network function using an integrity algorithm.

5. A communication method executed by a second KMF, characterized in that, include: Receive a second message from the first KMF, wherein the second message includes a first key, an identifier of the first key, and an identifier (ID) of an algorithm for generating the first key or an identifier of an algorithm for generating a terminal key, wherein the first key is used to determine whether authentication is required between the device and the first network function. A second key is generated based on the second message, wherein the second key is used to protect communication between the device and the first network function; A third message is sent to the first network function, wherein the third message includes the second key and the security context of the first network function.

6. The communication method according to claim 5, characterized in that, Also includes: A third key is generated based on the second message, wherein the third key is used to generate a fourth key, and the fourth key is used to protect the communication between the device and the second network function; A fourth message is sent to the third KMF, wherein the third KMF is used to generate the fourth key, and the fourth message includes the ID of the first key, the third key, and an identifier of the algorithm used to generate the third key or the algorithm used to generate the terminal key.

7. The communication method according to claim 5 or 6, characterized in that, Also includes: Receive a first request to refresh the second key, wherein the first request includes factors for refreshing the second key; The second key is refreshed based on the first request.

8. The communication method according to any one of claims 5 to 7, characterized in that, The security context of the first network function includes the ID of the first key.

9. The communication method according to any one of claims 5 to 8, characterized in that, The security context of the first network function includes one or more of the following: The ID of the encryption algorithm used for encrypting communication between the device and the first network function; or The ID of the integrity algorithm used for communication integrity between the device and the first network function.

10. The communication method according to any one of claims 5 to 9, characterized in that, The second key includes one or more of the following: A terminal key used to protect the communication between the device and the first network function using an encryption algorithm; or A terminal key used to protect the communication between the device and the first network function using an integrity algorithm.

11. A communication method performed by a third KMF, characterized in that, include: A fourth message is received from the second KMF, wherein the fourth message includes the ID of the first key, the third key, and the ID of the algorithm used to generate the third key or the ID of the algorithm used to generate the terminal key, wherein the first key is used to determine whether authentication is required between the device and the first network function. A fourth key is generated based on the fourth message, wherein the fourth key includes a terminal key for protecting communication between the device and the second network function; A fifth message is sent to the second network function, wherein the fifth message includes the fourth key and the security context of the second network function.

12. The communication method according to claim 11, characterized in that, The security context of the second network function includes the ID of the first key.

13. The communication method according to claim 11 or 12, characterized in that, The security context of the second network function includes one or more of the following: The ID of the encryption algorithm used for encrypting communication between the device and the second network function; or The ID of the integrity algorithm used for communication integrity between the device and the second network function.

14. The communication method according to any one of claims 11 to 13, characterized in that, The fourth key includes one or more of the following: A terminal key used to protect the communication between the device and the second network function using an encryption algorithm; or A terminal key used to protect the communication between the device and the second network function using an integrity algorithm.

15. The communication method according to any one of claims 11 to 14, characterized in that, Also includes: Receive a second request to refresh the fourth key, wherein the second request includes factors for refreshing the fourth key; The fourth key is refreshed based on the second request.

16. A communication method performed by a first network function, characterized in that, include: Receive a third message from the second KMF, wherein the third message includes a second key and a security context of the first network function, wherein the second key is generated based on the first key, and the first key is used to determine whether authentication is required between the device and the first network function; Configure the second key based on the security context of the first network function.

17. The communication method according to claim 16, characterized in that, Also includes: Send a first request to refresh the second key, wherein the first request includes factors for refreshing the second key; Receive a sixth message, wherein the sixth message includes the refreshed second key.

18. The communication method according to claim 16 or 17, characterized in that, The security context of the first network function includes the ID of the first key.

19. A communication method performed by a second network function, characterized in that, include: A fifth message is received from the third KMF, wherein the fifth message includes a fourth key and a security context of the second network function, wherein the fourth key includes a terminal key used to protect communication between the device and the second network function; Configure the fourth key based on the security context of the second network function.

20. The communication method according to claim 19, characterized in that, The security context of the second network function includes the ID of a first key, wherein the first key is used to determine whether authentication is required between the device and the first network function, and wherein communication between the device and the first network function is performed through the second network function.

21. The communication method according to claim 19 or 20, characterized in that, Also includes: Send a second request to refresh the fourth key, wherein the second request includes factors for refreshing the fourth key; Receive a seventh message, wherein the seventh message includes the refreshed fourth key.

22. A communication device, characterized in that, The communication device includes a processor configured to execute one or more instructions stored in a memory to cause the communication device to implement the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 10, or the method according to any one of claims 11 to 15, or the method according to any one of claims 16 to 18, or the method according to any one of claims 19 to 21.

23. The communication device according to claim 22, characterized in that, The communication device also includes the memory.

24. The communication device according to claim 22 or 23, characterized in that, The communication device includes a communication interface, which is used to input and / or output information or data.

25. A communication device, characterized in that, The communication device includes functions or units for implementing the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 10, or the method according to any one of claims 11 to 15, or the method according to any one of claims 16 to 18, or the method according to any one of claims 19 to 21.

26. A communication device, characterized in that, The communication device includes a circuit and a communication interface, the communication interface being used to receive information and / or data to be processed by the circuit and to send the information and / or data to the circuit; the circuit is used to implement the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 10, or the method according to any one of claims 11 to 15, or the method according to any one of claims 16 to 18, or the method according to any one of claims 19 to 21.

27. The communication device according to claim 26, characterized in that, The communication interface is also used to output information and / or data processed by the circuit.

28. A communication system, characterized in that, Includes one or more of the following communication devices: A communication apparatus for performing the method according to any one of claims 1 to 5; A communication apparatus for performing the method according to any one of claims 6 to 10; A communication apparatus for performing the method according to any one of claims 11 to 15; A communication apparatus for performing the method according to any one of claims 16 to 18; A communication device that performs the method according to claims 19 to 21.

29. A computer-readable storage medium, characterized in that, It includes one or more instructions, wherein when the one or more instructions are executed on a computer, the computer implements the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 10, or the method according to any one of claims 11 to 15, or the method according to any one of claims 16 to 18, or the method according to any one of claims 19 to 21.

30. A computer program product, characterized in that, It includes one or more instructions, wherein when the one or more instructions are executed on a computer, the computer implements the method according to any one of claims 1 to 5, or the method according to any one of claims 6 to 10, or the method according to any one of claims 11 to 15, or the method according to any one of claims 16 to 18, or the method according to any one of claims 19 to 21.