Updating or refreshing keys for authentication and key management of applications

By notifying the UE to update the application key and key identifier in the application session establishment response message, the problem of UE key expiration and non-update in the prior art is solved, and the security bootstrapping and authentication continuity of UE and application in 5G system are realized.

CN121970392APending Publication Date: 2026-05-01ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZTE CORP
Filing Date
2023-10-30
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies fail to effectively notify user equipment (UE) to update application keys and key identifiers (A-KID), leading to security risks and authentication discontinuities.

Method used

By sending relevant information in the application session establishment response message, the user device is notified to update the application key (KAF) and key identifier (A-KID), and the main authentication process is triggered to refresh the anchor key (KAKMA) and A-KID when necessary.

Benefits of technology

This ensures secure bootstrapping between the UE and the application, avoids authentication failures due to key expiration, and improves system security and continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121970392A_ABST
    Figure CN121970392A_ABST
Patent Text Reader

Abstract

Techniques for updating and refreshing a key for an authentication and key management application (AKMA) are described. An example wireless communication method includes receiving, by an application function, an indication that an application key expires, and transmitting a message to a wireless device based on the indication, and wherein the wireless device is configured to generate a new value for the application key and a key identifier associated with the application key based on the message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure generally relates to digital wireless communications. Background Technology

[0002] Mobile telecommunications technologies are propelling the world toward an increasingly interconnected and networked society. Compared to existing wireless networks, next-generation systems and wireless communication technologies will need to support a wider range of use case characteristics and provide more complex and sophisticated access requirements and flexibility.

[0003] Long-Term Evolution (LTE) is a wireless communication standard for mobile devices and data terminals developed by the 3rd Generation Partnership Project (3GPP). LTE-Advanced (LTE-A) is a wireless communication standard that enhances the LTE standard. The fifth-generation wireless system, known as 5G, advances both the LTE and LTE-A wireless standards and aims to support higher data rates, massive connectivity, ultra-low latency, high reliability, and other emerging service requirements. Summary of the Invention

[0004] Methods, systems, and devices for updating and refreshing keys used in Authentication and Key Management Applications (AKMA) are described. In 5G systems, AKMA services aim to establish authenticated communication between users and application functions and ensure the security of communicating users and applications. Embodiments of the disclosed technology provide mechanisms for updating and refreshing keys and key identifiers.

[0005] In one example aspect, a wireless communication method includes receiving an indication that an application key has expired by an application function, and transmitting a message to a wireless device based on the indication, wherein the wireless device is configured to generate a new value for the application key and a key identifier associated with the application key based on the message.

[0006] In yet another example, the above-described method is embodied in processor-executable code and stored in a non-transitory computer-readable storage medium. When executed by a processor, the code included in the computer-readable storage medium causes the processor to implement the method described in this patent document.

[0007] In yet another example, a device configured or operable to perform the methods described above is disclosed.

[0008] The above and other aspects and their embodiments are described in more detail in the accompanying drawings, description and claims. Attached Figure Description

[0009] Figure 1 This demonstrates how to export the AKMA anchor key (K) after master authentication. AKMA Example timing diagram.

[0010] Figure 2 It shows the result from K AKMA Generate K AF Example timing diagram.

[0011] Figure 3 An example timing diagram of an AKMA application key request via the Network Exposure Function (NEF) is shown.

[0012] Figure 4 An example timing diagram is shown for an internal application function (AF) that sends the cause of the error to the user equipment (UE).

[0013] Figure 5 An example timing diagram is shown for the internal AF sending the error reason and A-KID to the UE.

[0014] Figure 6 An example timing diagram is shown where the internal AF directly sends a normal response to the UE.

[0015] Figure 7 It shows that it can be used for Figures 4 to 6 The example in the example was modified to support the example timing diagram of external AF.

[0016] Figure 8 A flowchart of another example method of wireless communication is shown.

[0017] Figure 9 An exemplary block diagram of a hardware platform that may be part of a network device or a communication device is shown.

[0018] Figure 10 Examples of wireless communication including a base station (BS) and a user equipment (UE) based on some implementations of the disclosed technology are shown. Detailed Implementation

[0019] In 5G New Radio (NR), the Authentication and Key Management Application (AKMA) service enables authentication and application key generation for all User Equipment (UE) types in the 5G NR system, particularly Internet of Things (IoT) devices, based on 3GPP credentials. This ensures bootstrapping security between the UE and applications in the 5G system. Using AKMA, users can log in to application services solely based on 3GPP credentials, which are permanent keys stored in the user's tamper-proof smart card (e.g., a Universal Integrated Circuit Card, UICC). Application service providers can also delegate user authentication tasks to mobile network operators using AKMA. The AKMA architecture and process are defined in Technical Specification (TS) 33.535, entitled "Authentication and Key Management (AKMA) for Applications Based on 3GPP Credentials in 5G Systems (5GS)".

[0020] According to TS 33.535, the AKMA procedure specifies that when a UE requires AKMA service, it will send an application session establishment request message (which includes A-KID) to the AKMA AF. If K AF If the UE's lifetime expires and the AF decides to continue the UE's access based on its policy, it will request the ANF to obtain a new K. AF Then, ANF requests Unified Data Management (UDM) to trigger master (re)authentication to obtain the K. AKMA K AKMA This will be further used to generate K. AF After master authentication, K AKMA K AF The A-KID will be refreshed, causing the A-KID in the application session establishment request message sent by the UE to expire. Existing implementations do not consider or provide notification to the UE to refresh the A-KID and K. AF The disclosed technology provides a method to notify the UE to update A-KID and K by sending relevant information in the application session establishment response message. AF The mechanism.

[0021] The example headings in the following sections are used to facilitate understanding of the disclosed subject matter and do not limit the scope of the claimed subject matter in any way. Therefore, one or more features of one example section may be combined with one or more features of another example section. Furthermore, the term "5G" is used for clarity, but the technologies disclosed in this document are not limited to 5G technology and can be used in wireless systems implementing other protocols.

[0022] Example of the AKMA protocol in 3GPP TS 33.535

[0023] 3GPP TS 33.535 Clause 6.2.1 specifies that there is no separate authentication for the UE to support AKMA functionality. Instead, AKMA reuses the 5G master authentication process, for example, performed during UE registration, to authenticate the UE. Successful 5G master authentication results in K... AUSF Stored at AUSF and UE. Figure 1 This shows the export of K after successful master authentication. AKMA The process. Figure 1 The operations shown in the timing diagram include:

[0024] 1) During the main authentication process, AUSF interacts with UDM to use the Nudm_UEAuthentication_Get request service operation to obtain authentication information such as subscription credentials (e.g., AKA authentication vector) and authentication methods.

[0025] 2) In the response, the UDM may also indicate to the AUSF whether an AKMA anchor key needs to be generated for the UE. If the AKMA indication is included, the UDM should also include the UE's RID.

[0026] 3) If the AUSF receives an AKMA instruction from the UDM, the AUSF should store the K... AUSF And from K after the main authentication process is successfully completed AUSF Generate AKMA anchor key (K AKMA ) and A-KID.

[0027] Before initiating communication with AKMA application functions, the UE should obtain information from K... AUSF Generate AKMA anchor key (K AKMA ) and A-KID.

[0028] 4) After generating the AKMA key material, AUSF selects the AAnF as defined in Clause 6.7, and should use the Naanf_AKMA_KeyRegistration request service operation to transfer the generated A-KID and K... AKMA The SUPI of the UE is sent to AAnF. AAnF should store the latest information sent by AUSF.

[0029] Note 1: After delivery to AAnF, AUSF does not need to store any AKMA key material.

[0030] Note 1a: When re-authenticating, AUSF generates a new A-KID and a new K. AKMA And the newly generated A-KID and K AKMASend to AAnF. Upon receiving the newly generated A-KID and K... AKMA Afterwards, AAnF deleted the old A-KID and K. AKMA And store the newly generated A-KID and K AKMA .

[0031] 5) AAnF uses the Naanf_AKMA_AnchorKey_Register response service operation to send a response to AUSF.

[0032] A-KID identifies the K of the UE. AKMA Key.

[0033] The A-KID should be in the NAI format specified in Clause 2.2 of IETF RFC 7542[6], namely username@realm. The username part should include the RID and A-TID (AKMA temporary UE identifier), and the realm part should include the home network identifier.

[0034] A-TID should originate from the K specified in Annex A.3. AUSF .

[0035] AUSF should use the RID received from UDM as described in step 2 to derive the A-KID.

[0036] Note 2: The probability of an A-TID conflict is not zero, but rather very low, because the A-TID derivation is based on the KDF specified in Appendix B of TS33.220[4]. The detection of A-TID conflicts and potential handling of conflicts are not addressed in this document.

[0037] K AKMA It should originate from K as specified in Annex A.2 AUSF Because of the K in A-KID AKMA Both A-TID and K-TID are based on master authentication and run from K. AUSF It is exported, therefore K can only be refreshed through a new successful master authentication. AKMA And A-KID.

[0038] 3GPP TS 33.535 Clause 6.2.1 further specifies that when the AF is located within the operator's network, and... Figure 2 The diagram illustrates the process by which the AF requests an application-specific AKMA key from the AKMA AF. Before communication between the UE and the AKMA AF can begin, both the UE and the AKMA AF need to know whether AKMA is being used. This knowledge is either implicit for a specific application on the UE and the AKMA AF, or indicated by the AKMA AF to the UE (see Clause 6.5). Figure 2 The operations shown in the timing diagram include:

[0039] 1. Before initiating communication with AKMA application functions, the UE should obtain information from K... AUSF Generate AKMA anchor key (K AKMA The UE should include the derived A-KID in the Application Session Establishment Request message when initiating communication with the AKMA AF (see Clause 6.1). The UE may derive the A-KID before or after sending the message. AF .

[0040] 2. If the AF does not have an activity context associated with the A-KID, the AF selects an AAnF as defined in Clause 6.7 and sends a Naanf_AKMA_ApplicationKey_Get request with the A-KID to the AAnF to request the UE's K. AF AF also includes its identifier (AF_ID) in the request.

[0041] The AF_ID consists of the AF's FQDN and the Ua* security protocol identifier (see Annex A.4). The latter parameter identifies the security protocol that the AF will use with the UE.

[0042] AAnF should check whether it can provide services to AF based on the configured local policy or on the authorization information available in the signaling (i.e., OAuth2.0 token). If successful, the following procedure should be executed. Otherwise, AAnF should reject the procedure.

[0043] AAnF should be based on the UE-specific K identified by A-KID. AKMA The presence of the key is used to verify whether a subscriber is authorized to use AKMA.

[0044] If K AKMA If it exists in AAnF, AAnF should continue to step 3.

[0045] If K AKMA If it does not exist in AAnF, AAnF should continue to step 4 and give an error response.

[0046] 3. Upon receiving a request from the AF, if AAnF determines, based on its local policy, that the specific AF requires GPSI, then AAnF sends a Nudm_SDM_Get request to the UDM to obtain the UE's GPSI. If the specific AF does not require GPSI, AAnF should proceed to step 5.

[0047] 4. The UDM responds with the UE's GPSI. The AAnF should store the received GPSI as part of the UE's AKMA context.

[0048] 5. If AAnF does not yet have K.AF Then AAnF from K AKMA Export AKMA application key (K AF ).

[0049] K AF The key derivation shall be performed in accordance with the provisions of Appendix A.4.

[0050] 6. AAnF sends a message with SUPI and K to AF. AF and K AF The Naanf_AKMA_ApplicationKey_Get response for the expiration time. Whether to send SUPI or GPSI is determined by AAnF based on local policies.

[0051] 7. The AF sends an application session establishment response to the UE. If the information in step 4 indicates that the AKMA key request failed, the AF should reject the application session establishment by including the reason for the failure. Afterwards, the UE can trigger a new application session establishment request with the latest A-KID to the AKMA AF.

[0052] 3GPP TS 33.535 Clause 6.3 specifies the provisions for when the AF is located outside the operator's network, and as follows: Figure 3 As shown, AF is used to request K from AAnF via NEF. AF The process. Figure 3 The operations shown in the timing diagram include:

[0053] 1. When the AF is about to request the UE's AKMA application key from the AAnF, for example when the UE initiates an application session establishment request as described in Clause 6.2.1, the AF discovers the UE's HPLMN based on the A-KID and sends a request to the AAnF via the NEF service API. This request should include the A-KID and AF_ID, and the optional UE ID is not required.

[0054] Note: In architectures without CAPIF support, AF configures the service's API endpoint locally. In architectures with CAPIF support, AF obtains service API information from the CAPIF core functionality through the availability of service API event notifications or service discovery responses as specified in TS 23.222.

[0055] 2. If AF is authorized by NEF to request K AF If the authorization following the verification of AF_ID in step 1 is performed, then NEF will discover and select AAnF as defined in clause 6.7.

[0056] 3. The NEF sends a Naanf_AKMA_ApplicationKey_Get request with A-KID to the selected AAnF to request the UE's K AF .

[0057] AAnF shall process requests in the same manner as specified in Clause 6.2.1, with the following changes:

[0058] If K AKMA If it exists in AAnF, AAnF should continue with step 4 in this clause.

[0059] If K AKMA If the error does not exist in AAnF, AAnF should proceed to step 5 of this clause and provide an error response.

[0060] 4. AAnF generates K in accordance with Clause 6.2.1. AF and send K to NEF AF K AF Expiry Time (K) AF (Expiration) and SUPI's response.

[0061] 5. NEF will have K AF K AF Expiry Time (K) AF The NEF forwards the SUPI (expiration date) and optional GPSI (external ID) response to the AF. Based on local policy, the NEF uses the Nudm_SubscriberDataManagement service as specified in TS 29.503 to convert the SUPI to a GPSI (external ID) and optionally includes the GPSI (external ID) in the response. If an indication is received in the incoming request that the UE Id is not required, the NEF should not provide the GPSI (external ID) to the AF. The NEF must not send the SUPI to the AF.

[0062] 3GPP TS 33.535 Clause 6.4.3 specifies that explicit K is not supported in this document. AF Refresh process. If primary authentication has not been performed, then K... AUSF K AKMA and K AF This has remained unchanged since the most recent master authentication. According to the AAnF's decision, it can be done via K as defined in Clause 6.4.4. AKMA Refresh to refresh K AF .

[0063] Note 1: AAnF can determine K based on a local strategy. AKMA Refresh. The Ua* protocol supports refreshing from K. AF Exported session key. If the Ua* protocol supports refreshing from K... AFThe exported session key can then be refreshed at any time using the Ua* protocol. AF .

[0064] Note 2: How to export the refresh key for AKMA depends on the implementation of the Ua* protocol.

[0065] Note 3: K-based updates using the Ua* protocol AF The session key is known only to the UE and AF.

[0066] 3GPP TS 33.535 Clause 6.4.4 specifies that, as defined in TS 33.501 Clause 6.1.5, ANF can determine whether to refresh the K based on the operator's local authentication policy by sending a Nudm_UECM_AuthTrigger request message to the UDM. AKMA UDM can also determine whether to trigger the master authentication as defined in Clause 6.1.5 of TS 33.501.

[0067] Notify UE to update K AF Examples of A-KID

[0068] Example #1. In some embodiments, and as... Figure 4 As shown, the AF located inside the operator's network is configured to send the error reason to the UE. In the example, the AF located inside the operator's network indicates that the AF is a trusted entity in the network. Figure 4 The operations shown in the timing diagram include:

[0069] 1. When a UE initiates communication with an AKMA AF, it should include the exported A-KID in the application session establishment request message.

[0070] 2. After receiving the request message, AF checks K. AF The state of K. AF The timer has expired, and AF will request a new K. AF .

[0071] 3. The AF selects AAnF and sends a Naanf_AKMA_ApplicationKey_Get request with A-KID to AAnF to request the UE's K AF AF also includes its identifier (AF_ID) in the request.

[0072] 4. If AAnF decides to refresh K based on its local policy AKMAIf so, AAnF sends an authentication request message to the UDM, including the UE's SUPI. The UDM then determines, based on its policy, whether to trigger home network-triggered primary authentication. If the UDM decides to trigger home network-triggered primary authentication, it proceeds to step 5. If the UDM decides not to trigger home network-triggered primary authentication, it skips step 5.

[0073] 5. The UDM initiates the primary authentication process triggered by the home network. After successful primary authentication, the AUSF should generate a key. AKMA And A-KID and send it to AAnF.

[0074] 6. The UDM sends a Nudm_UECM_AuthTrigger response to notify AAnF whether the home network-triggered primary authentication was successfully performed. If the home network-triggered primary authentication fails or is not performed according to the UDM's policy, step 7 is skipped, and AAnF will proceed to step 8 with an error response.

[0075] 7. AAnF from K AKMA Export AKMA application key (K AF ).

[0076] 8. AAnF sends data containing SUPI / GPSI and K to AF. AF and K AF The Naanf_AKMA_ApplicationKey_Get response with the expiration time. Whether to send SUPI or GPSI is determined by AAnF based on local policies. If the information in step 6 indicates that the primary authentication triggered by the home network failed or was not performed, AAnF should send a Naanf_AKMA_ApplicationKey_Get response to the AF including the reason for the failure.

[0077] 9. If the information in step 8 indicates that the AKMA key request failed, then AF should, via an instruction including K AF The error message indicates that the application session was refused due to an expiration date, and the primary authentication triggered by the home network failed. If K... AF The refresh was successful. Since the A-KID was also refreshed, the AF will send an error response to notify the UE that its A-KID has expired, where the error reason value indicates the A-KID and K. AF The response has been refreshed. Upon receiving the response, the UE can calculate the new A-KID and K. AF Afterwards, the UE can trigger a new application session establishment request with the latest A-KID to the AKMA AF.

[0078] Example #2. In some embodiments, and as... Figure 5As shown, the AF located inside the operator's network is configured to send the error reason and A-KID to the UE. Figure 5 The operations shown in the timing diagram include:

[0079] 1. When a UE initiates communication with an AKMA AF, it should include the exported A-KID in the application session establishment request message.

[0080] 2. After receiving the request message, AF checks K. AF The state of K. AF The timer has expired, and AF will request a new K. AF .

[0081] 3. The AF selects AAnF and sends a Naanf_AKMA_ApplicationKey_Get request with A-KID to AAnF to request the UE's K AF AF also includes its identifier (AF_ID) in the request.

[0082] 4. If AAnF decides to refresh K based on its local policy AKMA If so, AAnF sends an authentication request message to the UDM, including the UE's SUPI. The UDM then determines, based on its policy, whether to trigger home network-triggered primary authentication. If the UDM decides to trigger home network-triggered primary authentication, it proceeds to step 5. If the UDM decides not to trigger home network-triggered primary authentication, it skips step 5.

[0083] 5. The UDM initiates the primary authentication process triggered by the home network. After successful primary authentication, the AUSF should generate a key. AKMA And A-KID and send it to AAnF.

[0084] 6. The UDM sends a Nudm_UECM_AuthTrigger response to notify AAnF whether the home network-triggered primary authentication was successfully performed. If the home network-triggered primary authentication fails or is not performed according to the UDM's policy, step 7 is skipped, and AAnF will proceed to step 8 with an error response.

[0085] 7. AAnF from K AKMA Export AKMA application key (K AF ).

[0086] 8. AAnF sends data containing SUPI / GPSI and K to AF. AF and K AFThe Naanf_AKMA_ApplicationKey_Get response with the expiration time. Whether to send SUPI or GPSI is determined by AAnF based on local policies. If the information in step 6 indicates that the primary authentication triggered by the home network failed or was not performed, AAnF should send a Naanf_AKMA_ApplicationKey_Get response to the AF including the reason for the failure.

[0087] 9. If the information in step 8 indicates that the AKMA key request failed, then AF should, via an instruction including K AF The application session establishment is rejected due to an error reason indicating that the primary authentication triggered by the home network has expired. AF The refresh was successful. Since the A-KID was also refreshed, the AF will send an error response to notify the UE that its A-KID has expired, where the error reason value indicates either the A-KID or the K... AF The message is refreshed. The new A-KID is also included in the message. Upon receiving the response, the UE can calculate the new A-KID and K. AF The calculated A-KID is then compared with the received A-KID to check if it is the latest A-KID. Afterward, the UE can trigger a new application session establishment request with the latest A-KID to the AKMA AF.

[0088] Example #3. In some embodiments, and as... Figure 6 As shown, the AF located inside the operator's network is configured to send a normal response to the UE. Figure 6 The operations shown in the timing diagram include:

[0089] 1. When a UE initiates communication with an AKMA AF, it should include the exported A-KID in the application session establishment request message.

[0090] 2. After receiving the request message, AF checks K. AF The state of K. AF The timer has expired, but AF can still use the expired K. AF Verify the integrity and authenticity of the request. If the request is valid, AF will request to obtain the new K. AF If the request is invalid, AF continues to step 9 and provides an error response.

[0091] 3. The AF selects AAnF and sends a Naanf_AKMA_ApplicationKey_Get request with A-KID to AAnF to request the UE's K AF AF also includes its identifier (AF_ID) in the request.

[0092] 4. If AAnF decides to refresh K based on its local policy AKMA If so, AAnF sends an authentication request message to the UDM, including the UE's SUPI. The UDM then determines, based on its policy, whether to trigger home network-triggered primary authentication. If the UDM decides to trigger home network-triggered primary authentication, it proceeds to step 5. If the UDM decides not to trigger home network-triggered primary authentication, it skips step 5.

[0093] 5. The UDM initiates the primary authentication process triggered by the home network. After successful primary authentication, the AUSF should generate a key. AKMA And A-KID and send it to AAnF.

[0094] 6. The UDM sends a Nudm_UECM_AuthTrigger response to notify AAnF whether the home network-triggered primary authentication was successfully performed. If the home network-triggered primary authentication fails or is not performed according to the UDM's policy, step 7 is skipped, and AAnF will proceed to step 8 with an error response.

[0095] 7. AAnF from K AKMA Export AKMA application key (K AF ).

[0096] 8. AAnF sends data containing SUPI / GPSI and K to AF. AF and K AF The Naanf_AKMA_ApplicationKey_Get response with the expiration time. Whether to send SUPI or GPSI is determined by AAnF based on local policies. If the information in step 6 indicates that the primary authentication triggered by the home network failed or was not performed, AAnF should send a Naanf_AKMA_ApplicationKey_Get response to the AF including the reason for the failure.

[0097] 9. If the information in step 8 indicates that the AKMA key request failed, then AF should, via an instruction including K AF The application session establishment is rejected due to an error reason indicating that the primary authentication triggered by the home network has expired. AF The update was successful. Although the A-KID used by the UE has expired, the AF can send a normal response to the UE, including an indicator that the A-KID should be updated. The new A-KID can also be included in the message. Upon receiving the response, the UE can calculate the new A-KID and K. AF The calculated A-KID is then compared with the received A-KID (if received) to check if it is the latest A-KID. Afterward, the UE can use the latest A-KID. AFContinue the AKMA session with AF.

[0098] Example #4. In some embodiments, and as... Figure 7 As shown, the AF located outside the carrier network is configured, for example, by using a location located Figures 4-6 The external AF replaces the internal AF to implement... Figures 4-6 The methods and techniques shown are illustrated. In the example, an AF located outside the carrier network indicates that the AF is an untrusted entity within the network. Figure 7 The operations of steps 3 and 8 shown in the timing diagram replace the operations of steps 8 and 9. Figures 4-6 The corresponding operations include:

[0099] Step 3:

[0100] 3(a). When the AF is about to request the UE's AKMA application key from the AAnF, the AF discovers the UE's HPLMN based on the A-KID and sends a request to the AAnF via the NEF service API. The request should include the A-KID and AF_ID.

[0101] 3(b). If AF is authorized by NEF to request K AF If the authorization following the verification of AF_ID in step 3(a) is performed, then NEF will discover and select AAnF.

[0102] 3(c). The NEF sends a Naanf_AKMA_ApplicationKey_Get request with A-KID and AF_ID to the selected AAnF to request the UE's K AF .

[0103] Step 8:

[0104] 8(a). AAnF sends a message with SUPI, K to NEF AF and K AF The response to Naanf_AKMA_ApplicationKey_Get with the expiration time.

[0105] 8(b). NEF will have K AF and K AF Expiry Time (K) AF The response (expiration) and optional GPSI (external ID) are forwarded to the AF.

[0106] As in Figures 4-7 In the context described herein, embodiments of the disclosed technology provide a way for the AF to notify the UE to update A-KID and K by sending an application session establishment response message. AF The mechanism is as follows. Specifically, the following three methods for responding to UE AF are designed.

[0107] (1) The AF sends an application session establishment response with an error reason to the UE. In the example, the error reason value indicates A-KID or K. AF The response has been refreshed. Upon receiving the response, the UE can calculate the new A-KID and K. AF Afterwards, the UE can trigger a new application session establishment request with the latest A-KID to the AF.

[0108] (2) The AF sends an application session establishment response to the UE with an error reason and a new A-KID. In the example, the error reason value indicates either A-KID or K. AF The response has been refreshed. Upon receiving the response, the UE can calculate the new A-KID and K. AF The calculated A-KID is then compared with the received A-KID to check if it is the latest A-KID. Afterward, the UE can trigger a new application session establishment request with the latest A-KID to the AF.

[0109] (3) The AF sends a normal application session establishment response to the UE, which includes an A-KID update indication and an optional A-KID. In the example, the AF can use the expired KID. AF Verify the request sent by the UE. If valid, the AF can send a normal response to the UE, including an indicator that the A-KID should be updated. The new A-KID can also be included in the message. Upon receiving the response, the UE can calculate the new A-KID and K. AF The calculated A-KID is then compared with the received A-KID (if received) to check if it is the latest A-KID. Afterward, the UE can use the latest A-KID. AF Continue the AKMA session with AF.

[0110] Example methods and implementations of the disclosed technology

[0111] Figure 8 A flowchart of an example wireless communication method 800 is shown. Method 800 includes, at operation 810, receiving an indication that an application key has expired by an application function. Method 800 includes, at operation 820, transmitting a message to a wireless device based on the indication. In method 800, the wireless device is configured to generate a new value for the application key and a key identifier associated with the application key based on the message.

[0112] The described features can be implemented to further provide one or more of the following technical solutions:

[0113] 1. A wireless communication method comprising: receiving, by an application function, an indication that an application key has expired; and transmitting a message to a wireless device based on the indication, wherein the wireless device is configured to generate a new value for the application key and a key identifier associated with the application key based on the message. In some examples, the application function transmitting the message to the wireless device corresponds to step 9 in one of embodiments #1 to #4.

[0114] 2. The method according to Scheme 1, wherein the application key is an AKMA (Application Authentication and Key Management) application key, the application function is an application function, the message is an application session establishment response, and the key identifier is an AKMA key identifier (A-KID). In some examples, the key identifier is an identifier used for the key and includes at least one of a temporary identifier or identity for the home network.

[0115] 3. The method according to scheme 1 or 2, wherein the message includes an error reason associated with the expiration of the application key, and wherein the error reason indicates that the application key or key identifier has been refreshed.

[0116] 4. The method according to scheme 1 or 2, wherein the message includes an error reason associated with the expiration of the application key and another value of the key identifier, and wherein the error reason indicates that the application key or key identifier has been refreshed.

[0117] 5. The method according to Scheme 4, wherein the wireless device is configured to compare another value of the key identifier with the new value of the key identifier.

[0118] 6. The method according to any one of claims 1 to 5, wherein the wireless device is configured to transmit an application session establishment request, including a new value of a key identifier, to the application function.

[0119] 7. The method according to Scheme 1 or 2 further includes: receiving a request to use application functions from a wireless device; and using an expiration value of the application key to determine the validity of the request, wherein the message includes an indicator that configures the wireless device to update the key identifier and the application key upon receiving the key identifier and the application key.

[0120] 8. The method according to scheme 7, wherein the message further includes another value of the key identifier.

[0121] 9. The method according to Scheme 8, wherein the wireless device is configured to compare another value of the key identifier with the new value of the key identifier.

[0122] 10. The method according to any one of schemes 7 to 9, wherein the wireless device is configured to continue the authenticated session with the application function using a new value of the application key.

[0123] 11. The method according to any one of schemes 1 to 10, wherein the key identifier identifies the anchor key, and wherein the application key is derived from the anchor key.

[0124] 12. The method according to Scheme 1, wherein the anchor key is an AKMA anchor key (K AKMA ).

[0125] 13. An apparatus for wireless communication, comprising a processor configured to implement the method according to one or more of claims 1 to 12.

[0126] 14. A non-transitory computer-readable program storage medium having code stored thereon that, when executed by a processor, causes the processor to perform one or more of the methods according to schemes 1 to 12.

[0127] Figure 9 An exemplary block diagram of a hardware platform 900, which may be part of a network device (e.g., a base station) or a communication device (e.g., a user equipment (UE)), is shown. The hardware platform 900 includes at least one processor 910 and a memory 905 on which instructions are stored. The instructions, when executed by the processor 910, configure the hardware platform 900 to perform... Figures 1 to 8 The operations described in the various embodiments described in this patent document are as follows: Transmitter 915 transmits or sends information or data to another device. For example, a network device transmitter may send a message to a user device. Receiver 920 receives information or data transmitted or sent by another device. For example, a user device may receive a message from a network device.

[0128] The implementation methods described above will be applied to wireless communication. Figure 10An example of a wireless communication system (e.g., a 5G or NR cellular network) including a base station 1020 and one or more user equipments (UEs) 1011, 1012, and 1013 is illustrated. In some embodiments, the UE accesses the BS (e.g., the network) using a communication link to the network (sometimes referred to as the uplink direction, as depicted by dashed arrows 1031, 1032, and 1033), which then enables subsequent communication from the BS to the UE (e.g., shown in the direction from the network to the UE, sometimes referred to as the downlink direction, as shown by arrows 1041, 1042, and 1043). In some embodiments, the BS sends information to the UE (sometimes referred to as the downlink direction, as depicted by arrows 1041, 1042, and 1043), which then enables subsequent communication from the UE to the BS (e.g., shown in the direction from the UE to the BS, sometimes referred to as the uplink direction, as shown by dashed arrows 1031, 1032, and 1033). UE can be, for example, a smartphone, tablet, mobile computer, machine-to-machine (M2M) device, Internet of Things (IoT) device, etc.

[0129] Some embodiments described herein are described in the general context of a method or process. In one embodiment, the method or process may be implemented by a computer program product embodied in a computer-readable medium, the computer program product including computer-executable instructions, such as program code, that are executed by a computer in a networked environment. The computer-readable medium may include removable and non-removable storage devices, including but not limited to read-only memory (ROM), random access memory (RAM), compact discs (CD), digital versatile discs (DVD), etc. Therefore, the computer-readable medium may include non-transitory storage media. Typically, program modules may include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. Computer or processor-executable instructions, associated data structures, and program modules represent examples of program code for performing steps of the methods disclosed herein. A particular sequence of such executable instructions or associated data structures represents examples of corresponding actions for implementing the functionality described in such steps or processes.

[0130] Some of the disclosed embodiments can be implemented as devices or modules using hardware circuitry, software, or a combination thereof. For example, hardware circuitry implementations may include discrete analog and / or digital components, for instance, integrated as part of a printed circuit board. Alternatively or additionally, the disclosed components or modules may be implemented as application-specific integrated circuits (ASICs) and / or field-programmable gate arrays (FPGAs). Some implementations may additionally or alternatively include digital signal processors (DSPs), which are dedicated microprocessors with an architecture optimized for the operational requirements of digital signal processing associated with the functions disclosed herein. Similarly, various components or sub-components within each module may be implemented in software, hardware, or firmware. Interconnectivity between modules and / or components within modules may be provided using any of the connection methods and media known in the art, including but not limited to communication over the Internet, wired, or wireless networks using appropriate protocols.

[0131] While this document contains numerous details, these should not be construed as limiting the scope of the claimed invention or what may be claimed, but rather as descriptions of features specific to particular embodiments. Some features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments. Furthermore, although features may be described above as functioning in certain combinations and even initially claimed in this way, one or more features from a claimed combination may be removed from that combination in some cases, and the claimed combination may be for sub-combinations or variations thereof. Similarly, although operations are depicted in a specific order in the drawings, this should not be construed as requiring the performance of such operations in the specific order shown or in sequential order, or requiring the performance of all illustrated operations to achieve the desired result.

[0132] Only a few implementations and examples have been described, and other implementations, enhancements and variations may be made based on what is described and shown in this disclosure.

Claims

1. A wireless communication method, comprising: The application function receives an indication that the application key has expired; as well as Based on the instruction, a message is transmitted to the wireless device. The wireless device is configured to generate a new value for the application key and a key identifier associated with the application key based on the message.

2. The method according to claim 1, wherein, The application key is an AKMA (Application Authentication and Key Management) application key, the application function is an application function, the message is an application session establishment response, and the key identifier is an AKMA key identifier (A-KID).

3. The method according to claim 1 or 2, wherein, The message includes an error reason associated with the expiration of the application key, wherein the error reason indicates that the application key or the key identifier has been refreshed.

4. The method according to claim 1 or 2, wherein, The message includes an error reason associated with the expiration of the application key and another value of the key identifier, wherein the error reason indicates that the application key or the key identifier has been refreshed.

5. The method according to claim 4, wherein, The wireless device is configured to compare another value of the key identifier with the new value of the key identifier.

6. The method according to any one of claims 1 to 5, wherein, The wireless device is configured to send an application session establishment request, including a new value of the key identifier, to the application function.

7. The method according to claim 1 or 2, further comprising: Receive a request from the wireless device to use the application function; as well as The validity of the request is determined using the expiration value of the application key. The message includes an indicator that configures the wireless device to update the key identifier and the application key upon receiving the key identifier and the application key.

8. The method according to claim 7, wherein, The message also includes another value for the key identifier.

9. The method according to claim 8, wherein, The wireless device is configured to compare another value of the key identifier with the new value of the key identifier.

10. The method according to any one of claims 7 to 9, wherein, The wireless device is configured to continue the authenticated session with the application function using the new value of the application key.

11. The method according to any one of claims 1 to 10, wherein, The key identifier identifies the anchor key, and the application key is derived from the anchor key.

12. The method according to claim 1, wherein, The anchor key is an AKMA anchor key (K AKMA ).

13. An apparatus for wireless communication, comprising a processor configured to implement the method according to one or more of claims 1 to 12.

14. A non-transitory computer-readable program storage medium having code stored thereon, said code, when executed by a processor, causing the processor to perform the method according to one or more of claims 1 to 12.