New keys for generating application authentication and key management

By designing a method in the 5G system for the AF to send the UE identifier directly or via the NEF to the AAnF, the problem of UE access failure caused by the expiration of the AKMA application key without a valid context is solved, and the successful refresh of the AKMA application key and the continuity and security of UE access are achieved.

CN121970391APending Publication Date: 2026-05-01ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZTE CORP
Filing Date
2023-10-30
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In 5G systems, when the AKMA application key KAF expires and there is no valid context, existing technologies cannot effectively refresh the KAF, causing the UE to fail to access the AF.

Method used

A mechanism is provided to enable AAnF to refresh the AKMA application key without a valid AKMA context by sending the UE's identifier (SUPI or GPSI) directly or via NEF to AAnF, including the design of various network function (NF) services to support this process.

Benefits of technology

It enables successful AKMA application key refresh even without a valid AKMA context, ensuring the continuity and security of UE access to AF.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121970391A_ABST
    Figure CN121970391A_ABST
Patent Text Reader

Abstract

Techniques for generating application authentication and key management (AKMA) new keys are described. One example wireless communication method includes receiving, by an anchor function, a first message from an application function, the first message including a wireless device identifier, and transmitting an authentication request message to a data management function, the authentication request message including the identifier. Another example wireless communication method includes transmitting, by an application function, a first message to an anchor function, the first message including an identifier of a wireless device, where the anchor function is configured to transmit an authentication request message to a data management function, the authentication request message including the identifier.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally pertains to digital wireless communications. Background Technology

[0002] Mobile communication technologies are propelling the world toward an increasingly interconnected and networked society. Compared to existing wireless networks, next-generation systems and wireless communication technologies need to support a wider range of use case characteristics and provide more complex and diverse access requirements and flexibility.

[0003] Long Term Evolution (LTE) is a wireless communication standard for mobile devices and data terminals developed by the 3rd Generation Partnership Project (3GPP). LTE Advanced (LTE-A) is a wireless communication standard that enhances the LTE standard. The fifth-generation wireless system, 5G, further improves upon the LTE and LTE-A wireless standards, aiming to support higher data transmission rates, massive connectivity, ultra-low latency, high reliability, and other emerging service requirements. Summary of the Invention

[0004] Methods, systems, and devices for generating new keys for Authentication and Key Management Applications (AKMA) are described. In 5G systems, AKMA services aim to establish authenticated communication between users and application functions and ensure the security of communicating users and applications. Embodiments of the disclosed technology provide mechanisms for refreshing keys using a valid AKMA context.

[0005] In one example aspect, a wireless communication method includes: receiving a first message from an application function by an anchor function, the first message including an identifier of a wireless device; and transmitting an authentication request message to a data management function, the authentication request message including the identifier.

[0006] In another example aspect, a wireless communication method includes: transmitting a first message, including an identifier of a wireless device, from an application function to an anchor function, wherein the anchor function is configured to transmit an authentication request message, including the identifier, to a data management function.

[0007] In yet another example, the above method is implemented as processor-executable code and stored in a non-transitory computer-readable storage medium. When executed by a processor, the code in the storage medium causes the processor to perform the method described in this patent document.

[0008] In yet another example, a device configured to or capable of performing the methods described above is disclosed.

[0009] The above and other aspects and their embodiments are described in more detail in the accompanying drawings, description and claims. Attached Figure Description

[0010] Figure 1 Showing from K AKMA Generate K AF Example timing diagram.

[0011] Figure 2 This diagram illustrates an example timing diagram for an AKMA application key request via the Network Exposure Function (NEF).

[0012] Figure 3 This demonstrates that when an internal Application Function (AF) directly sends a Subscription Permanent Identifier (SUPI) or Generic Public Subscription Identifier (GPSI) to the AKMA Anchor Function (AAnF), the K is refreshed. AF Example timing diagram.

[0013] Figure 4 This shows that when an external AF indirectly sends GPSI to an AAnF via a NEF, K is refreshed. AF Example timing diagram.

[0014] Figure 5 This shows that when the internal AF receives a request from AAnF and directly sends SUPI or GPSI to AAnF, K is refreshed. AF Example timing diagram.

[0015] Figure 6 This shows that when an external AF receives a request from AAnF forwarded via NEF, and indirectly sends GPSI to AAnF, it refreshes K. AF Example timing diagram.

[0016] Figure 7 A flowchart illustrating an example method of wireless communication.

[0017] Figure 8 A flowchart illustrating another example method of wireless communication is shown.

[0018] Figure 9 An example block diagram of a hardware platform is shown, which may be part of a network device or a communication device.

[0019] Figure 10Examples of wireless communication including base stations (BS) and user equipment (UE) based on some implementations of the disclosed technology are shown. Detailed Implementation

[0020] In 5G New Radio (NR), the Application Authentication and Key Management (AKMA) service allows for the authentication and generation of application keys for all User Equipment (UE) types in the 5G NR system, particularly Internet of Things (IoT) devices, based on 3GPP credentials. This ensures bootstrapping security between the UE and applications in the 5G system. Using AKMA, users can only log in to application services based on 3GPP credentials, which are permanent keys stored in the user's tamper-proof smart card (e.g., a Universal Integrated Circuit Card, UICC). Application service providers can also delegate user authentication tasks to mobile network operators using AKMA. The AKMA architecture and procedures are specified in Technical Specification (TS) 33.535, titled "Application Authentication and Key Management (AKMA) Based on 3GPP Credentials in 5G Systems (5GS)".

[0021] According to TS 33.535, the AKMA procedure specifies that when AKMA applies key K... AF Upon expiration, the AF can, according to its policy, deny the UE access to the AF or refresh the K. AF If AF decides to be in K AF If the UE continues to access the AF after the expiration date, the AF should request a new key by sending a Naanf_AKMA_ApplicationKey_Get request to the AF. AF AAnF needs to request Unified Data Management (UDM) to trigger master (re)authentication to obtain the K. AKMA K AKMA This will be further used to generate K. AF However, if the UE's AKMA context is invalid or has been removed from AAnF, AAnF cannot find the UE's SUPI based on the A-KID contained in the received Naanf_AKMA_ApplicationKey_Get request message. Therefore, the lack of a valid AKMA context in AAnF often leads to K... AF Refresh failed. In this case, it is necessary to consider how to derive the new K when the UE's AKMA context is invalid or deleted in AAnF. AF The disclosed embodiments provide a mechanism that enables refreshing the AKMA application key for AAnF without a valid AKMA context.

[0022] The example headings in the following sections are provided to aid in understanding the disclosed subject matter and do not in any way limit the scope of the claimed subject matter. Therefore, one or more features from one example section may be used in conjunction with one or more features from another example section. Furthermore, 5G technology is used for clarity of explanation, but the technology disclosed in this document is not limited to 5G technology and can also be used in wireless systems implementing other protocols.

[0023] AKMA protocol example in 3GPP TS 33.535 Clause 6.2.1 of 3GPP TS 33.535 specifies the procedure for an AF to request an application-specific AKMA key from an AAnF when the AF is located within an operator's network, such as... Figure 1 As shown. Before communication occurs between the UE and the AKMA AF, the UE and AKMA AF need to determine whether to use AKMA. For a specific application on the UE and AKMA AF, whether to use AKMA is implicit or indicated by the AKMA AF to the UE (see Clause 6.5). Figure 1 The operations shown in the timing diagram include: 1. Before initiating communication with AKMA application functions, the UE should obtain information from K... AUSF Generate AKMA anchor key (K AKMA The UE should include the obtained A-KID (see Clause 6.1) in the Application Session Establishment Request message when it begins communication with the AKMAAF. The UE may derive the A-KID before or after sending the message. AF .

[0024] 2. If the AF does not have an activity context associated with the A-KID, then the AF will select the AAnF as specified in Clause 6.7 and send a Naanf_AKMA_ApplicationKey_Get request carrying the A-KID to the AAnF to request the UE's K. AF AF will also include its identity (AF_ID) in the request.

[0025] AF_ID is composed of AF's FQDN and UA The security protocol identifier consists of (see Appendix A.4). The latter parameter identifies the communication protocol that the AF will use with the UE.

[0026] AAnF should check whether it can provide services to AF based on the configured local policy or on the authentication information in the signaling (i.e., the OAuth2.0 token). If successful, the following procedure is executed. Otherwise, AAnF will reject the procedure.

[0027] AAnF should determine whether a UE-specific K ID identified by A-KID exists. AKMA A key is used to verify whether a subscriber is authorized to use AKMA.

[0028] If K exists in AAnF AKMA If so, AAnF will continue to step 3.

[0029] If K does not exist in AAnF AKMA If so, AAnF will continue to step 4 and give an error response.

[0030] 3. Upon receiving a request from the AF, if AAnF determines that the specific AF requires GPSI, AAnF will send a Nudm_SDM_Get request to the UDM to obtain the UE's GPSI, according to its local policy. If the specific AF does not require GPSI, AAnF will proceed to step 5.

[0031] 4. UDM will return the UE's GPSI. AAnF should store the received GPSI as part of the UE's AKMA context.

[0032] 5. If AAnF does not yet possess K AF AAnF will be from K AKMA Derive the AKMA application key (K) AF ).

[0033] K AF The key derivation shall be performed in accordance with the provisions in Appendix A.4.

[0034] 6. AAnF sends a Naanf_AKMA_ApplicationKey_Get response to AF, which includes SUPI and K. AF and K AF The expiration time. AAnF decides whether to send SUPI or GPSI based on its local policy.

[0035] 7. The AF sends an application session establishment response to the UE. If the information in step 4 indicates that the AKMA key request failed, the AF will reject the application session establishment by including the reason for the failure. Afterwards, the UE can use the latest A-KID to trigger a new application session establishment request to the AKMAAF.

[0036] Clause 6.2.2 of 3GPP TS 33.535 specifies that, under certain circumstances, anonymous users may access the AF (e.g., where a UE identifier is not required at the AF). To allow such anonymous user access to the AF, the procedure detailed in Clause 6.2.1 of this document is used, with the following modifications: - In step 2, AF uses the Naanf_AKMA_ApplicationKey_AnonUser_Get request instead of the Naanf_AKMA_ApplicationKey_Get request; and - In step 6, AAnF sends a Naanf_AKMA_ApplicationKey_AnonUser_Get response to AF, which has K AF and K AF Expiry date.

[0037] A-KID is used as a temporary user identifier.

[0038] Clause 6.3 of 3GPP TS 33.535 stipulates that when the AF is located outside the operator's network, the AF requests K from the AAnF via the NEF. AF The process, such as Figure 2 As shown. Figure 2 The operations shown in the timing diagram include: 1. When the AF requests the UE's AKMA application key from the AAnF, for example when the UE initiates an application session establishment request as described in Clause 6.2.1, the AF discovers the UE's HPLMN based on the A-KID and sends the request to the AAnF via the NEF service API. This request should include the A-KID and AF_ID, and the optional UE ID does not need to be indicated.

[0039] Note: In architectures that do not support CAPIF, AF configures the service's API endpoint locally. In architectures that support CAPIF, AF obtains service API information from the CAPIF core functionality via service API availability event notifications or service discovery responses as specified in TS 23.222.

[0040] 2. If NEF authorizes AF to request K AF Including authentication after verifying AF_ID in step 1, NEF will discover and select AAnF as defined in clause 6.7.

[0041] 3. The NEF uses A-KID to send a Naanf_AKMA_ApplicationKey_Get request to the selected AAnF to request the UE's K. AF .

[0042] AAnF shall process requests in the same manner as specified in Clause 6.2.1, with the following modifications: If K exists in AAnF AKMA If so, AAnF should continue with step 3 of this clause.

[0043] If K does not exist in AAnF AKMA If so, AAnF should continue with step 5 of this clause and provide an error response.

[0044] 4. AAnF generates K in accordance with Clause 6.2.1. AF and will include K AF K AF Expiry Time (K) AF The responses from exptime and SUPI are sent to NEF.

[0045] 5. NEF will respond with K AF K AF Expiry Time (K) AF The SUPI (external ID) is forwarded to the AF along with the exptime and optional GPSI (external ID). According to local policy, the NEF uses the Nudm_SubscriberDataManagement service specified in TS 29.503 to convert the SUPI to a GPSI (external ID) and may optionally include the GPSI (internal ID) in the response. If an indication is received in the incoming request that the UE ID is not required, the NEF should not provide the GPSI (external ID) to the AF. The NEF should not send the SUPI to the AF.

[0046] Clause 14.2.6 of 3GPP TS 33.501 specifies the following table, which illustrates the authentication-related services provided by UDM for home network-triggered primary (re)authentication startup.

[0047] Table 1: NF services triggered by authentication provided by UDM

[0048] Service operation name: Nudm_UECM_AuthTrigger.

[0049] Note: This service operation allows NF to request UDM to trigger the primary (re)authentication described in Clause 6.1.5.

[0050] Input, required: SUPI.

[0051] Input, optional: none.

[0052] Output, required: success / failure.

[0053] Output, optional: none.

[0054] Example of Application Function (AF) directly sending UE authentication Example #1. In some embodiments, such as Figure 3 As shown, the AF located within the carrier network is configured to send UE authentication directly to the AAnF. In one example, the AF located within the carrier network indicates that the AF is a trusted entity in the network. Figure 3 The operations shown in the timing diagram include: 1. When the UE initiates communication with the AKMA AF, the UE should include the derived A-KID in the application session establishment request message.

[0055] 2. Upon receiving the request message, AF checks K. AF The state of K. AF The timer has expired, and AF will request a new K. AF .

[0056] 3. AF selects AAnF and sends a Naanf_AKMA_ApplicationKey_Get request to AAnF using A-KID to request the UE's K AF The AF also includes its identity (AF_ID) and the UE's SUPI / GPSI in the request. The AF can decide whether to send SUPI or GPSI based on its local policy; for example, it can prioritize sending GPSI and send SUPI if GPSI is missing, prioritize sending SUPI and send GPSI if SUPI is missing, or send either SUPI or GPSI arbitrarily. In the case of anonymous user access, if the AF does not store SUPI, the AF is configured to send a Naanf_AKMA_ApplicationKey_AnonUser_Get request to AAnF, including the GPSI in the request.

[0057] 4. The ANF sends an authentication request message to the UDM, which includes the UE's SUPI / GPSI received from the AF. The UDM then decides, based on its policy, whether to trigger home network-triggered primary authentication. If the UDM decides to trigger home network-triggered primary authentication, it proceeds to step 5. If the UDM decides not to trigger home network-triggered primary authentication, it skips step 5.

[0058] 5. If the UDM receives the UE's GPSI from the AAnF, the UDM first finds the SUPI based on the GPSI and then initiates the home network-triggered main authentication process. If the UDM receives the UE's SUPI from the AAnF, it directly initiates the home network-triggered main authentication process. After successful main authentication, the AAnF should generate a K. AKMA And A-KID and send it to AAnF.

[0059] 6. UDM sends a Nudm_UECM_AuthTrigger response to notify whether the master authentication triggered by the ANF home network was successfully executed. If the master authentication triggered by the home network is successful, steps 7 and 8 will be skipped. If the master authentication triggered by the home network fails or is not executed according to the UDM's policy, step 7 will continue.

[0060] 7. If the primary authentication triggered by the AAnF home network fails or is not executed, AAnF sends a Naanf_AKMA_ApplicationKey_Get response to the AF to indicate K AF Refresh failed.

[0061] 8. AF should refuse to apply session establishment and state the reason for the failure. Steps 9-11 should be skipped.

[0062] 9. AAnF from K AKMA Derive the AKMA application key (K AF ).

[0063] 10. AAnF sends a Naanf_AKMA_ApplicationKey_Get response to AF, which includes SUPI / GPSI, K AF and K AF Expiration time. AAnF determines whether to send SUPI or GPSI based on its local policy. In the case of anonymous user access, AAnF sends a Naanf_AKMA_ApplicationKey_AnonUser_Get response to AF, which contains K. AF and K AF Expiry date.

[0064] 11. Since the A-KID has also been refreshed, the AF should send an error response to notify the UE that its A-KID has expired, where the error reason value indicates whether the A-KID or K... AF The response has been refreshed. Upon receiving the response, the UE can calculate the new A-KID and K. AF Afterwards, the UE can trigger a new application session establishment request with the latest A-KID to the AKMA AF.

[0065] Note 1: If the UDM decides to trigger primary authentication via the home network, step 6 can be performed before step 5. This means the UDM can first respond to the AAnF by acknowledging the triggering of primary authentication, and then trigger primary authentication. In this case, if the primary authentication process fails, the UDM can send a notification to the AAnF indicating the failure.

[0066] Note 2: In step 6, the result of the primary authentication can also be sent to AAnF by other NFs in the notification message, such as AUSF and AMF.

[0067] Note 3: If AAnF receives the UE's GPSI from AF in step 4, AAnF may also choose to first send a Nudm_SDM_Get request to UDM to obtain the UE's SUPI, and then use the SUPI to request home network-triggered primary authentication. In this case, UDM does not need to find the SUPI based on the GPSI and can directly start the home network-triggered primary authentication process in step 5.

[0068] Example #2. In some embodiments, such as Figure 4 As shown, an AF located outside the operator's network is configured to send UE authentication to the AAnF via the NEF. In one example, an AF located outside the operator's network indicates that the AF is an untrusted entity within the network. Figure 4 The operations shown in the timing diagram include: 1. When the UE initiates communication with the AKMA AF, the A-KID derived from the application session establishment request message should be included.

[0069] 2. After receiving the request message, AF checks K. AF The state of K. AF The timer has expired, and AF will request a new K. AF .

[0070] 3. The AF discovers the UE's HPLMN based on the A-KID and sends a request to the AAnF via the NEF service API. This request should include the A-KID, AF_ID, and the UE's GPSI.

[0071] 4. If NEF authorizes AF to request K AF This includes authentication after verifying AF_ID in step 3, where NEF will discover and select AAnF.

[0072] 5. The NEF uses A-KID, AF_ID, and the UE's GPSI to send a Naanf_AKMA_ApplicationKey_Get request to the selected AAnF to request the UE's K... AF .

[0073] 6. AAnF sends an authentication request message to the UDM, which includes the UE's GPSI. The UDM then decides, based on its policy, whether to trigger home network-triggered primary authentication. If the UDM decides to trigger home network-triggered primary authentication, it proceeds to step 7. If the UDM decides not to trigger home network-triggered primary authentication, it skips step 7.

[0074] 7. UDM first locates SUPI based on the received GPSI, then initiates the primary authentication process triggered by the home network. After successful primary authentication, AUSF should generate a K. AKMA And A-KID and send it to AAnF.

[0075] 8. UDM sends a Nudm_UECM_AuthTrigger response to notify whether the master authentication triggered by the ANF home network was successfully executed. If the master authentication triggered by the home network is successful, steps 9-11 are skipped. If the master authentication triggered by the home network fails or is not executed according to the UDM's policy, step 9 is continued.

[0076] 9. If the primary authentication triggered by the AAnF home network fails or is not executed, AAnF sends a Naanf_AKMA_ApplicationKey_Get response to NEF to indicate K AF Refresh failed.

[0077] 10. NEF will forward the response to AF.

[0078] 11. AF should refuse to apply session establishment and state the reason for the failure. Steps 12-15 should be skipped.

[0079] 12. AAnF from K AKMA Derive the AKMA application key (K AF ).

[0080] 13. AAnF sends a Naanf_AKMA_ApplicationKey_Get response to NEF, which includes SUPI and K. AF and K AF Expiry date.

[0081] 14. NEF will respond with K AF and K AF Expiry Time (K) AF The exptime and optional GPSI (external ID) are forwarded to the AF together.

[0082] 15. Since the A-KID has also been refreshed, the AF should send an error response to notify the UE that its A-KID has expired, where the error reason value indicates whether the A-KID or K... AF The response has been refreshed. Upon receiving the response, the UE can calculate the new A-KID and K. AF Afterwards, the UE can trigger a new application session establishment request with the latest A-KID to the AKMA AF.

[0083] Note 1: If the UDM decides to trigger primary authentication via the home network, step 8 can be performed before step 7. This means the UDM can first respond to the AAnF by acknowledging the triggering of primary authentication before actually triggering it. In this case, if the primary authentication process fails, the UDM can send a notification to the AAnF indicating the failure.

[0084] Note 2: In step 8, another NF may also send the result of the primary authentication to AAnF in the notification message, such as AUSF or AMF.

[0085] Note 3: In step 6, AAnF can also choose to first send a Nudm_SDM_Get request to the UDM to obtain the UE's SUPI, and then use the SUPI to request home network-triggered primary authentication. In this case, the UDM does not need to find the SUPI based on the GPSI, and can directly start the home network-triggered primary authentication process in step 7.

[0086] Example of AF sending UE authentication after receiving a request Example #3. In some embodiments, such as Figure 5 As shown, the AF located within the operator's network is configured to send UE authentication to the AAnF upon receiving a request. Figure 5 The operations shown in the timing diagram include: 1. When a UE initiates communication with an AKMA AF, it should include the derived A-KID in the application session establishment request message.

[0087] 2. After receiving the request message, AF checks K. AF The state of K. AF The timer has expired, and AF will request a new K. AF .

[0088] 3. AF selects AAnF and sends a Naanf_AKMA_ApplicationKey_Get request to AAnF using A-KID to request the UE's K AF AF also includes its identity (AF_ID) in the request.

[0089] 4. AAnF checks the UE's AKMA context based on the A-KID. If the UE's AKMA context is stored in AAnF, steps 5 and 6 can be skipped. If the UE's AKMA context is not stored in AAnF, step 5 will continue.

[0090] 5. If no AKMA context exists for the UE, AAnF should request the UE's identifier from the AF before sending the authentication request message.

[0091] 6. The AF responds to the AAnF using the UE's GPSI / SUPI. The AF can decide whether to send SUPI or GPSI based on its local policy; for example, it can prioritize sending GPSI and send SUPI when GPSI is missing, prioritize sending SUPI and send GPSI when SUPI is missing, or send either SUPI or GPSI arbitrarily. In the case of anonymous user access, the AAnF sends a Naanf_AKMA_ApplicationKey_AnonUser_Get response to the AF, which contains the K... AF And the expiration date of KAF.

[0092] 7. AAnF sends an authentication request message to the UDM, which includes the UE's SUPI / GPSI. The UDM then determines, based on its policy, whether to trigger home network-triggered primary authentication. If the UDM decides to trigger home network-triggered primary authentication, it proceeds to step 8. If the UDM decides not to trigger home network-triggered primary authentication, step 8 is skipped.

[0093] 8. If the UDM receives the UE's GPSI from the AAnF, the UDM first finds the SUPI based on the GPSI and then initiates the home network-triggered main authentication process. If the UDM receives the UE's SUPI from the AAnF, it directly initiates the home network-triggered main authentication process. After successful main authentication, the AAnF should generate a K. AKMA And A-KID, and send it to AAnF.

[0094] 9. UDM sends a Nudm_UECM_AuthTrigger response to notify whether the master authentication triggered by the ANF home network was successfully executed. If the master authentication triggered by the home network is successful, steps 10 and 11 are skipped. If the master authentication triggered by the home network fails or is not executed according to the UDM's policy, step 10 is continued.

[0095] 10. If the primary authentication triggered by the AAnF home network fails or is not executed, AAnF sends a Naanf_AKMA_ApplicationKey_Get response to the AF to indicate K AF Refresh failed.

[0096] 11. AF should reject the application session establishment and state the reason for the failure. Steps 12-14 should be skipped.

[0097] 12. AAnF from K AKMA Derive the AKMA application key (K AF ).

[0098] 13. AAnF sends a Naanf_AKMA_ApplicationKey_Get response to AF, which includes SUPI / GPSI, K AF and K AF Expiration time. AAnF determines whether to send SUPI or GPSI based on its local policy. In the case of anonymous user access, AAnF sends a Naanf_AKMA_ApplicationKey_AnonUser_Get response to AF, which contains K. AF and K AF Expiry date.

[0099] 14. Since the A-KID has also been refreshed, the AF should send an error response to notify the UE that its A-KID has expired, where the error reason value indicates whether the A-KID or K... AF The response has been refreshed. Upon receiving the response, the UE can calculate the new A-KID and K. AF Afterwards, the UE can trigger a new application session establishment request with the latest A-KID to the AKMA AF.

[0100] Note 1: If the UDM decides to trigger primary authentication via the home network, step 9 can be performed before step 8. This means the UDM can first respond to the AAnF by acknowledging the triggering of primary authentication, and then trigger primary authentication. In this case, if the primary authentication process fails, the UDM can send a notification to the AAnF indicating the failure.

[0101] Note 2: In step 9, other NFs may also send the result of the primary authentication to AAnF in the notification message, such as AUSF or AMF.

[0102] Note 3: In step 7, AAnF can also choose to first send a Nudm_SDM_Get request to the UDM to obtain the UE's SUPI, and then use the SUPI to request home network-triggered primary authentication. If so, the UDM does not need to find the SUPI based on the GPSI, and can directly start the home network-triggered primary authentication process in step 8.

[0103] Example #4. In some embodiments, such as Figure 6 As shown, the AF located outside the operator's network is configured to send UE authentication to the AAnF upon receiving a request. Figure 6 The operations shown in the timing diagram include: 1. When a UE initiates communication with an AKMA AF, it should include the derived A-KID in the application session establishment request message.

[0104] 2. After receiving the request message, AF checks K. AF The state of K.AF The timer has expired, and AF will request a new K. AF .

[0105] 3. The AF discovers the UE's HPLMN based on the A-KID and sends a request to the AAnF via the NEF service API. This request should include the A-KID and AF_ID.

[0106] 4. If NEF authorizes AF to request K AF This includes authentication after verifying AF_ID in step 3, where NEF will discover and select AAnF.

[0107] 5. The NEF uses A-KID and AF_ID to send a Naanf_AKMA_ApplicationKey_Get request to the selected AAnF to request the UE's K... AF .

[0108] 6. AAnF checks the UE's AKMA context based on the A-KID. If the UE's AKMA context is stored in AAnF, steps 7-10 can be skipped. If the UE's AKMA context is not stored in AAnF, step 7 will continue.

[0109] 7. If no AKMA context exists for the UE, AAnF should send a request message to NEF to obtain the UE's identifier before sending the authentication request message.

[0110] 8. NEF will forward the request to AF.

[0111] 9. AF uses the UE's GPSI to respond to NEF.

[0112] 10. The NEF will forward the response along with the UE's GPSI to the AAnF.

[0113] 11. AAnF sends an authentication request message to the UDM, which includes the UE's GPSI. The UDM then determines, based on its policy, whether to trigger home network-triggered primary authentication. If the UDM decides to trigger home network-triggered primary authentication, it proceeds to step 12. If the UDM decides not to trigger home network-triggered primary authentication, it skips step 12.

[0114] 12. UDM first locates SUPI based on the received GPSI, then initiates the primary authentication process triggered by the home network. After successful primary authentication, AUSF should generate a K. AKMA And A-KID and send it to AAnF.

[0115] 13. UDM sends a Nudm_UECM_AuthTrigger response to notify whether the primary authentication triggered by the ANF home network was successfully executed. If the primary authentication triggered by the home network is successful, steps 14-16 are skipped. If the primary authentication triggered by the home network fails or is not executed according to the UDM's policy, steps 14-16 are continued.

[0116] 14. If the primary authentication triggered by the AAnF home network fails or is not executed, AAnF sends a Naanf_AKMA_ApplicationKey_Get response to NEF to indicate K AF Refresh failed.

[0117] 15. NEF forwards the response to AF.

[0118] 16. AF should reject the application session establishment and state the reason for the failure. Steps 17-21 should be skipped.

[0119] 17. AAnF from K AKMA Derive the AKMA application key (K AF ).

[0120] 18. AAnF sends a Naanf_AKMA_ApplicationKey_Get response to NEF, which includes SUPI and K. AF and K AF Expiry date.

[0121] 19. NEF will respond with K AF and K AF Expiry Time (K) AF The exptime and optional GPSI (external ID) are forwarded to the AF together.

[0122] 20. Since the A-KID has also been refreshed, the AF should send an error response to notify the UE that the A-KID it is using has expired, where the error reason value indicates whether the A-KID or K... AF The response has been refreshed. Upon receiving the response, the UE can calculate the new A-KID and K. AF Afterwards, the UE can trigger a new application session establishment request with the latest A-KID to the AKMA AF.

[0123] Note 1: If the UDM decides to trigger primary authentication via the home network, step 13 can be performed before step 12. This means the UDM can first respond to the AAnF by acknowledging the triggering of primary authentication before actually triggering it. In this case, if the primary authentication process fails, the UDM can send a notification to the AAnF indicating the failure.

[0124] Note 2: In step 13, another NF may also send the result of the primary authentication to AAnF in the notification message, such as AUSF or AMF.

[0125] Note 3: In step 11, AAnF may also choose to first send a Nudm_SDM_Get request to the UDM to obtain the UE's SUPI, and then use the SUPI to request home network-triggered primary authentication. In this case, the UDM does not need to find the SUPI based on the GPSI, and can directly start the home network-triggered primary authentication process in step 12.

[0126] In some embodiments, in order to implement steps 5 and 6 in embodiment #3 and steps 8 and 9 in embodiment #4, the following network function (NF) services are specified for the AF: Table 2: NF Services Provided by AF

[0127] In some embodiments, in order to implement steps 7 and 10 in embodiment #4, the following NF services are specified for NEF: Table 3: NF Services Provided by NEF

[0128] like Figure 3-6 As described in the context, embodiments of the disclosed technology provide a mechanism for enabling AKMA application key refresh for AAnF in the absence of a valid AKMA context. Specifically, the following two methods are designed for AAnF to obtain the UE's GPSI in the absence of a valid AKMA context.

[0129] (1) The AF sends the UE's identifier directly to the AAnF. For internal AFs, the AF sends either SUPI or GPSI directly to the AAnF. For external AFs, the AF sends GPSI to the NEF, and the NEF forwards the UE's identifier to the AAnF. Even if the AAnF does not have a valid AKMA context, the AAnF can directly use the identifier received from the UE for the authentication request.

[0130] (2) Upon receiving the request, the AF sends the UE's identifier. For internal AFs, upon receiving the request from AAnF, the AF sends SUPI or GPSI to AAnF. For external AFs, upon receiving the request from NEF, the AF sends the UE's identifier to NEF. This method requires AAnF to first check its AKMA context based on the received A-KID. If no valid AKMA context for the UE is found, it will further request the AF to provide the UE's identifier.

[0131] In some embodiments, in order to implement the second method in embodiment #4, an NF service for AF and an NF service for NEF can be designed.

[0132] Example methods and implementations of the disclosed technology Figure 7 A flowchart of an example wireless communication method 700 is shown. Method 700 includes operation 710, by an anchor function, receiving a first message from an application function, the first message including an identifier of a wireless device.

[0133] Method 700 includes operation 720, transmitting an authentication request message to a data management function, the authentication request message including an identifier.

[0134] Figure 8 A flowchart of an example wireless communication method 800 is shown. Method 800 includes operation 810, in which an application function transmits a first message to an anchor function, the first message including an identifier of a wireless device. In some embodiments, the anchor function is configured to transmit an authentication request message to a data management function, the authentication request message including the identifier.

[0135] The aforementioned features can be implemented to further provide one or more of the following technical solutions: 1. A wireless communication method, comprising: receiving a first message from an application function via an anchor function, the first message including an identifier of a wireless device; and transmitting an authentication request message to a data management function, the authentication request message including the identifier. In some examples, the anchor function receiving the first message corresponds to step 3 of embodiment #1, step 5 of embodiment #2, step 6 of embodiment #3, or step 10 of embodiment #4. In some examples, the identifier of the wireless device is SUPI or GPSI. In some examples, the anchor function transmitting the authentication request message to the data management function corresponds to step 4 of embodiment #1, step 6 of embodiment #2, step 7 of embodiment #3, or step 11 of embodiment #4.

[0136] 2. A wireless communication method, comprising: transmitting a first message from an application function to an anchor function, the first message including an identifier of a wireless device, wherein the anchor function is configured to transmit an authentication request message to a data management function, the authentication request message including the identifier. In some examples, the transmission of the first message from the application function to the anchor function corresponds to step 3 of embodiment #1, step 5 of embodiment #2, step 6 of embodiment #3, or step 10 of embodiment #4. In some examples, the identifier of the wireless device is SUPI or GPSI.

[0137] 3. The method according to technical solution 1 or 2, wherein the anchor function is AKMA (Application Authentication and Key Management) anchor function (AAnF), the application function is Application Function, the authentication request message is Nudm_UECM_AuthTrigger request, the wireless device is User Equipment (UE), the identifier is General Public Subscription Identifier (GPSI) or Subscription Permanent Identifier (SUPI), and the data management function is Unified Data Management (UDM) function.

[0138] 4. The method according to technical solution 3, wherein the application function is a trusted entity, and wherein the application function selects to include GPSI or SUPI in the authentication request message according to a local policy. In some examples, the application function as a trusted entity corresponds to an application function located within the operator's network.

[0139] 5. The method according to technical solution 3, wherein the application function is an untrusted entity, and wherein the identifier is a GPSI. In some examples, the application function as an untrusted entity corresponds to an application function located outside the operator's network.

[0140] 6. The method according to technical solution 3, wherein the first message is a Naanf_AKMA_ApplicationKey_Get request or a Naanf_AKMA_ApplicationKey_AnonUser_Get request. In some examples, the first message may be initiated by the NEF or AF, and is a service operation used by the NF to request the UE's AMKA application key information.

[0141] 7. The method according to any one of technical solutions 1 to 3, wherein the anchor function is further configured to transmit a second message before receiving the first message, the second message including a request for an identifier of the wireless device.

[0142] 8. The method according to any one of technical solutions 1 to 7, wherein the anchor function is further configured to receive a third message, the third message including a response to the authentication request message.

[0143] 9. The method according to technical solution 8, wherein the third message is received from the data management function, and wherein the third message is a Nudm_UECM_AuthTrigger response. In some examples, the third message allows the NF to request the Unified Data Management (UDM) to trigger primary (re)authentication.

[0144] 10. The method according to technical solution 8, wherein the third message is a notification message received from the backup network function.

[0145] 11. The method according to technical solution 10, wherein the backup network function is an authentication server function (AUSF) or an access and mobility management function (AMF).

[0146] 12. The method according to any one of technical solutions 1 to 11, wherein the anchor function does not include the valid key authentication context of the wireless device.

[0147] 13. The method according to technical solution 12, wherein the application function is a trusted entity, and wherein the authentication request message is received directly from the application function by the anchor function.

[0148] 14. The method according to technical solution 12, wherein the application function is not a trusted entity, and wherein the authentication request message is received by the anchor function via an open function.

[0149] 15. The method according to technical solution 14, wherein the open function is a network open function.

[0150] 16. An apparatus for wireless communication, comprising a processor configured to perform the method according to any one of claims 1 to 15.

[0151] 17. A non-transitory computer-readable program storage medium having code stored thereon, which, when executed by a processor, causes the processor to perform the method according to any one of claims 1 to 15.

[0152] Figure 9 An exemplary block diagram of a hardware platform 900 is shown, which may be part of a network device (e.g., a base station) or a communication device (e.g., a user equipment (UE)). The hardware platform 900 includes at least one processor 910 and a memory 905 storing instructions. The instructions executed by the processor 910 configure the hardware platform 900 to perform... Figures 1 to 8 And the operations described in the various embodiments described in this patent document. Transmitter 915 transmits or sends information or data to another device. For example, a network device transmitter can send a message to a user equipment. Receiver 920 receives information or data transmitted or sent by another device. For example, a user equipment can receive a message from a network device.

[0153] The implementation described above will be applied to wireless communication. Figure 10An example of a wireless communication system (e.g., a 5G or NR cellular network) including a base station 1020 and one or more user equipments (UEs) 1011, 1012, and 1013 is illustrated. In some embodiments, the UE accesses the BS (e.g., the network) using a communication link to the network (sometimes referred to as the uplink direction, as shown by dashed arrows 1031, 1032, and 1033), and then subsequent communication from the BS to the UE is implemented (e.g., the direction from the network to the UE is shown, sometimes referred to as the downlink direction, as shown by arrows 1041, 1042, and 1043). In some embodiments, the BS sends information to the UE (sometimes referred to as the downlink direction, as shown by arrows 1041, 1042, and 1043), and then subsequent communication from the UE to the BS is implemented (e.g., the direction from the UE to the BS, sometimes referred to as the uplink direction, as shown by dashed arrows 1031, 1032, and 1033). The UE can be, for example, a smartphone, tablet, mobile computer, machine-to-machine (M2M) device, Internet of Things (IoT) device, etc.

[0154] Some of the embodiments described herein are set in the general context of methods or processes. In one embodiment, these methods or processes can be implemented by a computer program product embodied in a computer-readable medium, including computer-executable instructions, such as program code, that are executed by a computer in a networked environment. The computer-readable medium can include removable and non-removable storage devices, including but not limited to read-only memory (ROM), random access memory (RAM), optical disc (CD), digital versatile optical disc (DVD), etc. Therefore, the computer-readable medium can include non-transitory storage media. Typically, program modules can include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. Computer or processor-executable instructions, associated data structures, and program modules represent examples of program code for performing the method steps disclosed herein. A particular sequence of such executable instructions or associated data structures represents examples of corresponding actions for implementing the functionality described in these steps or processes.

[0155] Some of the disclosed embodiments can be implemented as devices or modules using hardware circuitry, software, or a combination thereof. For example, hardware circuitry implementations may include discrete analog and / or digital components, such as those integrated as part of a printed circuit board. Alternatively or additionally, the disclosed components or modules may be implemented as application-specific integrated circuits (ASICs) and / or field-programmable gate arrays (FPGAs) devices. Some implementations may additionally or alternatively include a digital signal processor (DSP), which is a special-purpose microprocessor with an architecture optimized for the operational requirements of digital signal processing related to the disclosed functions of this application. Similarly, various components or sub-components within each module can be implemented using software, hardware, or firmware. Connectivity between modules and / or components within modules can be provided using any of the connection methods and media known in the art, including but not limited to communication over the Internet, wired, or wireless networks using appropriate protocols.

[0156] While this document contains numerous details, these details should not be construed as limiting the scope of the claimed invention or any potentially claimed content, but rather as descriptions of features specific to particular embodiments. Certain features described in this document within the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described within the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments. Furthermore, although the foregoing features may be described as operating in certain combinations, or even initially claimed in this way, in some cases one or more features from the claimed combination may be removed, and the claimed combination may refer to a sub-combination or a variation of a sub-combination. Similarly, although operations are depicted in a specific order in the drawings, this should not be construed as requiring these operations to be performed in the specific order or sequence shown, or requiring all of the shown operations to achieve the desired result.

[0157] Only a few implementations and examples have been described, and other implementations, enhancements and variations may be made based on what is described and shown in this disclosure.

Claims

1. A wireless communication method, comprising: The anchor function receives a first message from the application function, the first message including the identifier of the wireless device; as well as An authentication request message is transmitted to the data management function, the authentication request message including the identifier.

2. A wireless communication method, comprising: The application function transmits a first message to the anchor function, the first message including the identifier of the wireless device. The anchor point function is configured to transmit an authentication request message to the data management function, and the authentication request message includes the identifier.

3. The method according to claim 1 or 2, wherein, The anchor point function is the Application Authentication and Key Management AKMA Anchor Function AAnF, the application function is the Application Function, the authentication request message is the Nudm_UECM_AuthTrigger request, the wireless device is the User Equipment (UE), the identifier is the General Public Subscription Identifier (GPSI) or the Subscription Permanent Identifier (SUPI), and the data management function is the Unified Data Management (UDM) function.

4. The method according to claim 3, wherein, The application function is a trusted entity, wherein the application function selects whether the authentication request message includes GPSI or SUPI according to a local policy.

5. The method according to claim 3, wherein, The application function is an untrusted entity, wherein the identifier is GPSI.

6. The method according to claim 3, wherein, The first message is either a Naanf_AKMA_ApplicationKey_Get request or a Naanf_AKMA_ApplicationKey_AnonUser_Get request.

7. The method according to any one of claims 1 to 3, wherein, The anchor function is also configured to transmit a second message, which includes a request for an identifier for the wireless device, before receiving the first message.

8. The method according to any one of claims 1 to 7, wherein, The anchor function is also configured to receive a third message, which includes a response to the authentication request message.

9. The method according to claim 8, wherein, The third message is received from the data management function, wherein the third message is a Nudm_UECM_AuthTrigger response.

10. The method according to claim 8, wherein, The third message is a notification message received from the backup network function.

11. The method according to claim 10, wherein, The backup network function is either the Authentication Server Function (AUSF) or the Access and Mobility Management Function (AMF).

12. The method according to any one of claims 1 to 11, wherein, The anchor point function does not include the valid key authentication context of the wireless device.

13. The method according to claim 12, wherein, The application function is a trusted entity, wherein the authentication request message is received directly from the application function by the anchor function.

14. The method according to claim 12, wherein, The application function is not a trusted entity, wherein the authentication request message is received by the anchor function via the open function.

15. The method according to claim 14, wherein, The open function mentioned is the network open function.

16. An apparatus for wireless communication, comprising a processor configured to perform the method according to any one of claims 1 to 15.

17. A non-transitory computer-readable program storage medium having code stored thereon, which, when executed by a processor, causes the processor to perform the method according to any one of claims 1 to 15.