Authentication mechanism for user equipment

By deriving the AKMA key and A-TID using the security context information of the source network in the target network, the problem of unavailable authentication context when user equipment switches communication networks is solved, achieving seamless AKMA authentication service and reducing authentication latency and energy consumption.

CN122139340APending Publication Date: 2026-06-02NOKIA TECHNOLOGIES OY

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2024-10-21
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

When a user device switches from one communication network to another, especially when switching networks without primary authentication, existing technologies cannot provide seamless AKMA authentication services, resulting in the authentication context and key being unavailable at the anchor function, making it impossible to authenticate and manage the user device's keys.

Method used

By utilizing the security context information of the source network in the target network, the AKMA key and A-TID can be derived. For example, by interacting with the BSF or HSS in the source network through AAnF, key materials can be obtained to generate the AKMA key and A-TID, thus avoiding master authentication in the target network.

Benefits of technology

It enables seamless AKMA authentication services for user equipment without a master authentication, ensuring the continuity of authentication and key management processes in the communication network and reducing authentication latency and energy consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122139340A_ABST
    Figure CN122139340A_ABST
Patent Text Reader

Abstract

An apparatus includes at least one processor and at least one memory for storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: complete an authentication process for a user equipment (UE) in a second communication network; perform a registration process for the UE in a first communication network without performing a primary authentication in a first communication network; and derive authentication context information for authentication of the UE via the first communication network at at least one application function, based on security context information related to the authentication of the UE in the second communication network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Examples of embodiments described herein relate to apparatus, methods, systems, computer programs, computer program products, and (non-transient) computer-readable media that can be used to perform an authentication process for a user equipment (UE) that has not registered a primary authenticator in a communication network. Background Technology

[0002] The following background description may include insights, discoveries, understandings, or disclosures, or related information, as well as disclosures that are not yet known but are provided as examples of one or more embodiments by way of the disclosure herein. Some examples of embodiments may be specifically pointed out below, while other such contributions will be apparent from the relevant context.

[0003] The abbreviations used in this article have the following meanings: 3GPP Third Generation Partnership Project 4G fourth generation 5G fifth generation 5GC 5G Core Network KID AKMA Key ID TID AKMA Temporary ID AAnF AKMA anchor function AF application functions AKA Authentication and Key Negotiation Authentication and key management for AKMA applications AMF access and mobility management functions AS Application Server ASME Access Security Management Entity AUSF Authentication Server Functionality BSF Boot Server Function CPU Central Processing Unit eNBE-UTRAN Node B EPC Evolution Packet Core Network EPS Evolution Grouping System GBA General Boot Architecture gNB Next Generation Node B HSS belongs to user server ID identifier, identifier IP Internet Protocol KDF Key Derivation Function KID Key Identifier LTE Long Term Evolution LTE-ALTE Advanced MME Mobility Management Entity NAI Network Access ID NAS Non-Access Layer NF Network Functions NEF Network Open Functions NG Next Generation NRF Network Repository Functionality NW network, network side PLMN Public Land Mobile Network RAN Radio Access Network RID Route Indicator SUPI subscription permanent ID UDM Unified Data Manager UDR Unified Data Repository UE User Equipment USIM Universal Subscriber Identity Module WLAN wireless local area network Summary of the Invention According to an example embodiment, an apparatus is provided, including at least one processor and at least one memory for storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: complete an authentication process for a user equipment (UE) in a second communication network; perform a registration process for the UE in a first communication network without performing primary authentication in a first communication network; and derive authentication context information for authentication of the UE via the first communication network at at least one application function, based on security context information related to the UE's authentication in the second communication network.

[0004] Furthermore, according to an example embodiment, a method is provided, for example, comprising: performing an authentication process for a user equipment (UE) in a second communication network; performing a registration process for the UE in a first communication network without performing primary authentication in a first communication network; and deriving authentication context information for authentication of the UE via the first communication network at at least one application function based on security context information related to the authentication of the UE in the second communication network.

[0005] With further improvements, these examples may include the following features: - The authentication context information used by the UE for authentication via the first communication network at at least one application function may include at least one of the following: an anchor key for AKMA for authentication and key management of the application, or an AKMA key identifier.

[0006] According to an example embodiment, an apparatus is provided, including at least one processor and at least one memory for storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: receive a registration request from a user equipment (UE) to a first communication network; check whether the UE is registered as having performed primary authentication with the first communication network; and, if the check result indicates that the UE has not yet performed primary authentication with the first communication network, initiate a derivation process to derive authentication context information for the UE to perform authentication via the first communication network at at least one application function, based on security context information related to the UE's authentication in a second communication network.

[0007] Furthermore, according to an example embodiment, a method is provided, for example, comprising: receiving a registration request from a user equipment (UE) to a first communication network; checking whether the UE has been registered as having performed primary authentication with the first communication network; and, if the check result indicates that the UE has not yet performed primary authentication with the first communication network, initiating a derivation process to derive authentication context information for the UE to perform authentication via the first communication network at at least one application function based on security context information related to the UE's authentication in a second communication network.

[0008] With further improvements, these examples may include one or more of the following features: - The authentication context information used by the UE for authentication via the first communication network at at least one application function may include at least one of the following: an anchor key for AKMA for authentication and key management of the application, or an AKMA key identifier; - It can check whether the UE has been authenticated in the second communication network. If the check result is that the UE has been authenticated in the second communication network, the derivation process can be started. Or if the check result is that the UE has not been authenticated in the second communication network, the main authentication process can be started in the first communication network. - When the inference process is initiated, the anchor function can be notified via a specific first interface: UE registration is performed against the AKMA registration profile, in which the routing identifier and the UE's subscription identifier can be provided to the anchor function; - When the derivation process is initiated, the home subscriber server of the second communication network can be contacted via a specific second interface to request security context information related to the authentication of the UE in the second communication network. The security context information related to the authentication of the UE in the second communication network can be received, and the received security context information related to the authentication of the UE in the second communication network can be processed to obtain authentication context information. - When processing the received security context information related to UE authentication in the second communication network to obtain authentication context information, the anchor key as part of the authentication context information can be determined by generating an anchor key from the received security context information or by requesting the authentication server function to generate an anchor key from the received security context information, and the anchor function can be notified via a specific first interface: UE registration is performed against the AKMA registration profile, in which the routing identifier, the UE's subscription identifier and the generated anchor key can be provided to the anchor function; - When the anchor key is determined by requesting the authentication server function to generate an anchor key from the received security context information, the anchor function can be notified via the third interface: UE registration is performed against the AKMA registration profile, in which the anchor can be provided with a routing identifier, the UE's subscription identifier and the generated anchor key; - The measures can be implemented within the unified data management service function of the first communication network.

[0009] According to an example embodiment, an apparatus is provided, including at least one processor and at least one memory for storing instructions, which, when executed by the at least one processor, cause the apparatus to perform at least: a derivation process for a user equipment (UE) registered to a first communication network, wherein the derivation process includes: obtaining authentication context information for authentication performed by the UE via the first communication network at at least one application function, based on security context information related to authentication of the UE in a second communication network.

[0010] Furthermore, according to an example embodiment, a method is provided, for example, that includes a derivation process for a user equipment (UE) registered to a first communication network, wherein the derivation process includes: obtaining authentication context information for authentication performed by the UE via the first communication network at at least one application function, based on security context information related to authentication of the UE in a second communication network.

[0011] With further improvements, these examples may include one or more of the following features: - The authentication context information used by the UE for authentication via the first communication network at at least one application function may include at least one of the following: an anchor key for AKMA for authentication and key management of the application, or an AKMA key identifier.

[0012] - It can receive information that the UE registers against the AKMA registration profile via a specific first interface, wherein the information may include a routing identifier and the UE's subscription identifier, and can perform communication with the boot server function of the second communication network to obtain authentication context information for the UE to authenticate via the first communication network at at least one application function based on security context information related to the UE's authentication in the second communication network. - The system can receive an anchor key and a temporary identifier of the UE as part of the authentication context information from the bootstrap server function, and can generate an AKMA key identifier based on the temporary identifier of the UE. - The system can receive key information related to the authentication of the UE in the second communication network from the boot server function, and based on the received key information, it can generate an anchor key and an AKMA key identifier for the UE as part of the authentication context information. - The boot server function for communication can be discovered based on pre-stored configuration information of the identifier boot server function or based on information provided by the repository function of the first communication network; - It can receive information that the UE registers for the AKMA registration profile via a specific first interface, including the routing identifier, the UE's subscription identifier, and the anchor key as part of the authentication context information, and can generate an AKMA key identifier for the UE; - The measures can be implemented in the AKMA anchor function of the first communication network.

[0013] According to an example embodiment, an apparatus is provided, including at least one processor and at least one memory for storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: communicate with network functions of a first communication network to obtain authentication context information for authentication performed by the UE via the first communication network at at least one application function, based on security context information related to authentication of the UE in a second communication network.

[0014] Furthermore, according to an example embodiment, a method is provided, for example, which includes communicating with network functions of a first communication network to obtain authentication context information for authentication performed by the UE via the first communication network at at least one application function, based on security context information related to authentication of the UE in a second communication network.

[0015] With further improvements, these examples may include one or more of the following features: - The authentication context information used by the UE for authentication via the first communication network at at least one application function may include at least one of the following: an anchor key for Authentication and Key Management AKMA for the application, or an AKMA key identifier; - It can receive requests to the network functions of the first communication network to provide key information related to the authentication of the UE in the second communication network, and can provide the requested key information; - It can store key information related to the UE's authentication in the second communication network; - It can receive a request to provide the authentication context information of the UE to the network function of the first communication network, and can generate an anchor key and a temporary identifier for the UE as part of the authentication context information based on the key information related to the authentication of the UE in the second communication network, and can provide the anchor key and the temporary identifier for the UE. - The measures can be implemented in the bootstrap server function of the second communication network or in the home subscriber server of the second communication network.

[0016] Furthermore, according to embodiments, a computer program product for a computer is provided, for example, comprising software code portions for performing steps of the methods defined above when the product is run on the computer. The computer program product may include a computer-readable medium on which the software code portions are stored. Furthermore, the computer program product may be directly loaded into the computer's internal memory and / or transmitted over a network via: uploading; downloading; and / or a push process. Attached Figure Description

[0017] The following description, by way of example only, refers to the accompanying drawings and provides some examples of the disclosure related to the embodiments, wherein: Figure 1 A diagram illustrating an example of a network architecture in which an authentication process according to an embodiment can be implemented; Figure 2 A signaling diagram is shown, illustrating an example of the authentication and key management process in a first type of communication network; Figure 3 A signaling diagram is shown, illustrating an example of the authentication process in a second type of communication network; Figure 4 A signaling diagram is shown, illustrating an example of an authentication procedure according to an embodiment example; Figure 5 A signaling diagram is shown, illustrating an example of an authentication procedure according to an embodiment example; Figure 6 A flowchart illustrating some examples of processes performed in the control element of a first communication network according to an embodiment is shown; Figure 7 A flowchart illustrating some examples of processes performed in the control element of a first communication network according to an embodiment is shown; Figure 8 A flowchart illustrating some examples of processes performed in the control element of a second communication network according to an embodiment is shown; Figure 9 illustrates a flowchart of a process performed in a user equipment according to some embodiments; Figure 10 shows a schematic diagram of the communication network control elements of a first communication network according to some embodiments; Figure 11 shows a schematic diagram of the communication network control elements of a first communication network according to some embodiments; Figure 12 shows a schematic diagram of the communication network control elements of a second communication network according to some embodiments; and Figure 13 shows a schematic diagram of an example UE according to some embodiments. Detailed Implementation

[0018] Over the past few years, the expansion of communication networks has been increasing, including wired communication networks such as Integrated Services Digital Network (ISDN) and Digital Subscriber Line (DSL), or wireless communication networks such as CDMA2000 (Code Division Multiple Access) systems, cellular 3G such as Universal Mobile Telecommunications System (UMTS), 4G communication networks, or enhanced communication networks based on, for example, Long Term Evolution (LTE) or Long Term Evolution-Advanced (LTE-A), 5G communication networks, cellular 2G such as Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Global Evolution Enhanced Data Rate (EDGE), or other wireless communication systems such as Wireless Local Area Network (WLAN), Bluetooth, or Global Microwave Access Interoperability (WiMAX), which have been developed around the world. Various organizations, such as the European Telecommunications Standards Institute (ETSI), the 3rd Generation Partnership Project (3GPP), the Telecommunications and Internet Convergence Services and Protocols for Advanced Networks (TISPAN), the International Telecommunication Union (ITU), 3rd Generation Partnership Project 2 (3GPP2), the Internet Engineering Task Force (IETF), IEEE (Institute of Electrical and Electronics Engineers), and the WiMAX Forum, are developing standards or specifications for telecommunications networks and access environments.

[0019] Basically, to properly establish and process communication between two or more endpoints (e.g., communication stations or elements, such as terminal equipment, user equipment (UE) or other communication network elements, databases, servers, hosts, etc.), one or more network elements or functions (e.g., physical nodes or virtualized network functions) may be involved. These include communication network control elements or functions, such as access network elements like access points, radio base stations, relay stations, eNBs, gNBs, etc., and core network elements or functions, such as control nodes, support nodes, service nodes, gateways, user plane functions, access and mobility functions, etc., which may belong to one communication network system or different communication network systems. However, it should be noted that communication without intermediate network elements is also essentially possible.

[0020] In communication networks, such as 3GPP-based networks, a crucial feature of every communication is communication security. 3GPP has developed different security mechanisms for different types of communication networks. For example, security features in 5G-based networks include Authentication and Application Key Management (AKMA), which enables applications to utilize UE authentication performed by the PLMN and use it for further application authentication and authorization, as well as to pass on necessary application security keys to the UE.

[0021] Essentially, when a UE registers with a 5G PLMN for the first time, the network performs primary authentication on the UE. The purpose of primary authentication, which includes a key negotiation process, is to achieve mutual authentication between the UE and the network and to provide key material that can be used between the UE and the serving network in subsequent security processes. The key material generated by primary authentication produces an anchor key. Keys for multiple security contexts can be derived from the anchor key without requiring new authentication runs. Only after the UE's primary authentication is successful is the UE authorized to obtain additional network services. 3GPP has specified two protocols for primary authentication, 5G-AKA and EAP-AKA, both of which can be implemented through 3GPP access and non-3GPP access. During primary authentication, the subscription credentials and shared secret stored in the UE's USIM are verified, as well as the same content stored in the operator's UDM / UDR. Upon successful completion of primary authentication, the UE is granted access to the network, and the derived session key is used to secure the connection.

[0022] In 5G, a secure network function called the Authentication Server Function (AUSF) in the 5GC is used to manage UE authentication and manage the root session key K. AUSF AUSF stores the root session key K. AUSF And other keys are derived from this key. The UE and network obtain this key from K. AUSF Other keys are derived. The connection between the UE, base station, and core network is protected using the derived keys. Key K is used due to successful master authentication.AUSF Available at AUSF and UE, this key allows the generation of other keys that can be bootstrapped to protect different applications. For example, from key K... AUSF Derive the AKMA-specific key K AKMA To protect various applications, from K AKMA Derive the application-specific key K AF Therefore, the AKMA anchor function (AAnF) is implemented to support AKMA features. That is, from K... AUSF AUSF generates AKMA key K AKMA This is then sent to AAnF. When the UE attempts to connect to the application server, it provides the application server with a temporary identifier, AKMA. Based on this temporary identifier, the application server interacts with AAnF to receive a specific session key, K. AF and UE identifier. AF can use the received session key K AF Or based on session key K AF The key is further derived to protect the communication between the UE and the application server. Therefore, the AKMA function provides a reliable framework for application authentication of the UE and protection of the communication between the UE and the application server, thereby leveraging highly secure master authentication.

[0023] That is, in key management, the application in the UE will obtain the AKMA application key (K) for its application. AF Access to the AF identifier (AF_ID) related to the UE. The key (K) in the UE. AF This is derived and utilized from the master authentication performed by the UE and the 5G network. The process involved here is that the AS (or AF) uses A-KID (derived from A-TID and K) AUSF (Derivation) and K AF (from K) AKMA The UE is authenticated using A-KID (derived from K). A-KID typically uses the NAI format, i.e., username@realm, which is derived from A-TID (from K). AUSF It consists of SUPI derivation, routing indicator (RID) and PLMN.

[0024] In the above description, it is obvious that AF only works when AAnF has UE authentication context information (i.e., A-KID and K) from AUSF. AKMA Only when this is done can authentication be performed from AAnF and K obtained. AF However, there exists an authentication context and therefore, things like K... AKMAThis refers to situations where keys like these are unavailable at the AAnF. For example, when a UE moves from another communication network (such as 4G EPC) to a 5G communication network, the authentication service from the AAnF described above will fail. That is, when a user switches from 4G to 5G, the required authentication information will not be available because the UE has not performed primary authentication. While such primary authentication can certainly be performed, it will not occur immediately, so re-authentication at the 5G location may take longer (the time required for this measure may depend on operator configuration). Another situation where the authentication service from the AAnF described above will fail is, for example, when some failure occurs at the AAnF causing the authentication context to be lost.

[0025] Therefore, it is desirable to provide a measure that allows authentication services to be obtained from AS / AF in an uninterrupted manner, as described above.

[0026] In the following description, various examples of embodiments will be described to illustrate the processing of the authentication procedure for a UE under the above indications. For this purpose, as an example of a communication network to which the examples of embodiments can be applied, a communication network architecture based on 3GPP standards (e.g., 5G) is used, but this disclosure is not limited to such an architecture. It will be apparent to those skilled in the art that the examples of embodiments can also be applied to other types of communication networks, such as Wi-Fi, Global Microwave Access Interoperability (WiMAX), Bluetooth®, Personal Communication Services (PCS), ZigBee®, Wideband Code Division Multiple Access (WCDMA), systems using Ultra Wideband (UWB) technology, Mobile Ad Hoc Networks (MANET), wired access, etc. Furthermore, without loss of generality, while some of the descriptions of the example embodiments relate to mobile communication networks, the principles described herein can be extended and applied to any other type of communication network, such as wired communication networks.

[0027] The following examples and embodiments should be understood as illustrative examples only. Although the text herein may refer to "a," "one," or "some" examples or embodiments in multiple places, this does not necessarily mean that every such reference relates to the same example or embodiment, or that the feature applies only to a single example or embodiment. Individual features of different embodiments may also be combined to provide other embodiments. Furthermore, terms such as "comprising" and "including" should be understood not to limit the described embodiments to consisting only of those features mentioned; such examples and embodiments may also include features, structures, units, modules, etc., not specifically mentioned.

[0028] The basic system architecture of a (telecommunications) communication network (including mobile communication systems) (examples of some embodiments are applicable) may include the architecture of one or more communication networks, including wireless or wired access network subsystems and a core network. This architecture may include one or more communication network control elements or functions, access network elements, wireless access network elements, access service network gateways, or base transceiver stations, such as base stations (BS), access points (APs), NodeBs (NBs), eNBs or gNBs, distributed or centralized units that control corresponding coverage areas or cells, and one or more communication stations (communication elements or communication functions), such as user equipment (UEs) (e.g., user equipment or terminal equipment) or another device with similar functionality (e.g., modem chipsets, chips, modules, etc., which may also be part of a communication-enabled station, element, function, or application, such as a UE, an element or function that can be used in a machine-to-machine communication architecture, or attached as a separate element to such a communication-enabled element, function, or application, etc.), are capable of communicating with it via one or more channels and one or more communication beams to transmit several types of data in multiple access domains. In addition, it may include core network elements or network functions, such as gateway network elements / functions, mobility management entities, mobile switching centers, servers, databases, etc.

[0029] The general functions and interconnections of the described elements and functions (which also depend on the actual network type) are understood by those skilled in the art and are described in the relevant specifications, and therefore their detailed description is omitted here. However, it should be noted that, in addition to those described in detail below, several additional network elements and signaling links may be employed to communicate with or from elements, functions, or applications, such as communication endpoints, communication network control elements (such as servers, gateways, wireless network controllers), and other elements of the same or other communication networks.

[0030] The communication network architecture considered in the examples of the embodiments can also communicate with other networks, such as the public switched telephone network or the Internet, and with individual devices or groups of devices that are not considered part of the network, such as surveillance devices like cameras, sensors, and sensor arrays. The communication network can also support the use of cloud services for virtual network elements or their functions. It should be noted that the virtual network portion of a telecommunications network can also be provided by non-cloud resources, such as internal networks. It should be understood that network elements and / or corresponding functions of access systems, core networks, etc., can be implemented using any node, host, server, access node, or entity suitable for such purposes. Typically, network functions can be implemented as network elements on dedicated hardware, software instances running on dedicated hardware, or virtualized functions instantiated on a suitable platform (e.g., cloud infrastructure).

[0031] Furthermore, network elements or network functions, such as 5GC nodes (e.g., UDM), AAnF, or 4G network nodes (e.g., BSF or HSS), or UEs, or other network elements or network functions as described herein, and any other elements, functions, or applications, may be implemented via software (e.g., via computer program products for computers) and / or via hardware. To perform their respective processing, the corresponding devices, nodes, functions, or network elements may include several parts, modules, units, components, etc. (not shown), which are used for control, processing, and / or communication / signaling functions. These components, modules, units, and parts may include, for example, one or more processors or processor units, including one or more processing sections for executing instructions and / or programs and / or processing data; storage units or storage components for storing instructions, programs, and / or data, serving as working areas for said processors or processing sections, etc. (e.g., read-only memory (ROM), random access memory (RAM), electrically erasable programmable read-only memory (EEPROM), etc.); input or interface components for inputting data and instructions via software (e.g., floppy disk, optical disc read-only memory (CD-ROM), EEPROM, etc.); user interfaces for providing users with monitoring and operation possibilities (e.g., screen, keyboard, etc.); other interfaces or components for establishing links and / or connections under the control of said processor unit or section (e.g., wired and wireless interface components, radio interface components (including, for example, antenna units, etc.), components for forming radio communication sections, etc.), wherein the corresponding components forming the interface (e.g., radio communication section) may also be located at a remote site (e.g., radio head end or radio station, etc.). It should be noted that the processing section should not be considered merely as a physical part of one or more processors, but also as a logical division of the processing tasks involved that are performed by one or more processors.

[0032] It should be understood that, based on some examples, a so-called "liquid" or flexible network concept can be adopted, in which the operation and function of network elements, network functions, or other entities of the network can be performed in a flexible manner across different entities or functions, such as nodes, hosts, or servers. For example, the "division of labor" among the network elements, functions, or entities involved can vary depending on the situation.

[0033] As used in this application, the term "circuit" may refer to one or more of the following: the following: (a) Pure hardware circuit implementation (e.g., implementation only in analog and / or digital circuits) and (b) A combination of hardware circuitry and software, such as (if applicable): (i) The combination of analog and / or digital hardware circuitry with software / firmware and (ii) Any portion of a hardware processor and software (including digital signal processors), software and memory (working together to enable a device (such as a mobile phone or server) to perform various functions), and hardware circuitry and / or processors, such as microprocessors or portions thereof, that require software (e.g., firmware) to operate, but may be absent when the software is not required to operate. This definition of circuitry applies to all uses of the term in this application, including in any claim. As another example, as used herein, the term circuitry also covers only hardware circuitry or processors (or processors) or portions thereof and their accompanying software and / or firmware implementations. The term circuitry also covers, for example and if applicable to a particular claim element, baseband integrated circuits or processor integrated circuits for mobile devices or similar integrated circuits in servers, cellular network devices, or other computing or networking devices.

[0034] Furthermore, as used herein, "at least one of the following:" and "at least one" and similar wording, wherein a list of two or more elements is connected by "and" or "or", means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0035] Figure 1 A schematic diagram of an example network architecture is shown, in which the authentication process according to an embodiment is feasible.

[0036] Specifically, in Figure 1 In this configuration, UE 10 is configured to connect to / register to various communication network types, such as the first PLMN 130 being a 5G-based communication network, and the second PLMN 2 20 being a 4G communication network.

[0037] As mentioned above, different security features are used for UE 10 authentication when connecting to the corresponding network.

[0038] In the 5G-based network 30, AKMA is implemented. UE 10 connects to 5GC 37 via RAN 31, specifically to UDM 33. UDM 33 manages data used for access authorization, user registration, and data network profiles. Furthermore, UDM 33 stores subscription data for AKMA subscribers. Additionally, AAnF 35 is provided, which serves as the anchor function in PLMN1 30. AAnF 35, for example, stores the AKMA anchor key (K... AKMA) and SUPI for AKMA services. AAnF 35 also generates key materials to be used between the UE and Application Function (AF) 36 and maintains the UE AKMA context. NEF 38, which is located between the 5G core network and external third-party application functions (and possibly some internal AFs), is responsible for managing external open network data, and all external applications that want to access the internal data of the 5G core must go through NEF 38.

[0039] AF 36 can use A-KID to request the AKMA application key K from AAnF. AF .

[0040] It should be noted that the examples of the embodiments described below apply to both internal and external AFs. In the latter case, communication between the 5G network and the external AF is via NEF 38.

[0041] In addition, AUSF 34 is provided, which supports authentication for both 3GPP and non-3GPP access. AUSF 34 connects to UDM 33 and AMF 32 and provides AUSF services. Furthermore, AUSF 34 can provide the UE's SUPI and AKMA key materials (A-KID, K...) to AAnF. AKMA ).

[0042] In the 4G-based network 20, as a security feature, an authentication and key negotiation mechanism is implemented to guide application security.

[0043] UE 10 connects to the 4G core network 24 via RAN 21. Here, a bootstrap server function (BSF) 22 is provided. BSF 22 and UE 10 authenticate each other using the AKA protocol and negotiate a session key, which is then applied between the UE and the network application function (NAF).

[0044] In addition, HSS 23 is provided, which serves as the main database repository for subscriber information. Regarding the security features described herein, HSS 23 stores user security settings.

[0045] Next, refer to Figure 2 This describes the traditional AKMA-based process performed between the UE and the 5G network.

[0046] In S210, primary authentication between the UE and the 5G communication network is performed. During the primary authentication process, AUSF interacts with UDM to obtain authentication information, such as subscription credentials (e.g., the AKA authentication vector).

[0047] In S230, the UDM indicates to the AUSF whether an AKMA anchor key needs to be generated for the UE. If the AKMA indication is included, the UDM may also include the UE's RID.

[0048] In S245, AUSF stores K. AUSF And after the main authentication process is successfully completed, from K AUSF Generate AKMA anchor key (K AKMA ) and A-KID. Furthermore, in S240, the UE, before initiating communication with the AKMA application function, obtains information from K... AUSF Generate AKMA anchor key K AKMA And A-KID.

[0049] In S250, after the AKMA key material is generated, AUSF selects AAnF and combines the generated A-KID and K... AKMA The UE's SUPI is sent to AAnF along with the SUPI. AAnF stores the latest information sent by AUSF.

[0050] In S255, the UE generates the AKMA anchor key K. AKMA After obtaining the A-KID, the UE initiates communication with the AKMA application function by sending an application session establishment request. In this request, the UE includes the derived A-KID.

[0051] In S260, if the AF does not have an active context associated with A-KID, the AF selects AAnF and sends an AKMA_ApplicationKey_Get request to AAnF, which includes A-KID, to request the UE's K. AF AF also includes its identity (AF_ID) in the request.

[0052] AAnF checks whether it can provide services to AF based on configured local policies or authorization information available in AAnF signaling. If the check is positive, in S265, AAnF retrieves the service from K. AKMA Derive the AKMA application key (K AF ).

[0053] Then, in S270, AAnF sends a Naanf_AKMA_ApplicationKey_Get response to AF, which includes SUPI and K. AF and K AF Expiration date.

[0054] It should be noted that the example above represents the case of an internal AF. In the case of an external AF, signaling is performed via the NEF.

[0055] Then, in S280, the AF sends an application session establishment response message to the UE.

[0056] Next, refer to Figure 3This describes the traditional boot process performed between the UE and the 4G network.

[0057] When a UE wants to interact with the NAF in the 4G network, or has received the necessary boot initiation message or boot negotiation instruction from the NAF, it performs boot authentication.

[0058] In S310, the UE sends a Hypertext Transfer Protocol (HTTP) request to the BSF, which includes the user ID.

[0059] In S320, the BSF retrieves the complete set of GBA user security settings and an authentication vector (AV) from the HSS via the reference point Zh.

[0060] Then, in S330, the BSF forwards a random challenge (RAND) and an authentication token (AUTN) to the UE in the message to request the UE to authenticate itself.

[0061] In S340, the UE runs the AKA algorithm and checks the AUTN to verify that the challenge originates from an authorized network. Additionally, the UE calculates the key and user response (RES). This generates a session key in both the BSF and the UE.

[0062] In S350, the UE sends another request to the BSF, which includes a summary AKA response (calculated using RES).

[0063] In S360, BSF authenticates the UE by verifying the digest AKA response.

[0064] In S370, BSF generates key material Ks by connecting the received keys (encryption key CK, integrity key IK). It also generates a bootstrap transaction ID (B-TID) value in NAI format.

[0065] In S380, the BSF sends a 200 OK message (including the B-TID) to the UE to indicate successful authentication. Additionally, the 200 OK message provides the lifetime of the key Ks.

[0066] In S390, the UE generates key material Ks by connecting CK and IK. Both the UE and BSF use Ks to derive key material Ks_NAF for protecting communication with the NAF.

[0067] When considering the traditional security features in 5G and 4G networks described above, it is clear that, for example, if a user wants to obtain AKMA authentication used in 5G applications without 5G master authentication, an AKMA-based solution is impossible. When the master key (such as K...) AKMAProviding AKMA service is impossible when the security key is not present in AANF. This issue occurs, for example, when a user moves from 4G EPC to 5G, such as when the 5G network's AMF retrieves the security context from the MME, thus skipping master authentication. However, because of this, AANF / AAnF lacks a security key, and AKMA will not function in this situation.

[0068] It's conceivable that this problem could be solved by initiating primary authentication when the UE moves from 4G to 5G. However, triggering primary authentication is not optimal due to the energy consumption of both the UE and the network.

[0069] Therefore, according to the examples of the embodiments, a solution is proposed to address the above-mentioned problem, wherein the UE and the network to which it is to connect (e.g., a 5G network) can generate the required authentication context information (e.g., an AKMA key) by using the EPC security context, thereby avoiding the need for the UE to perform primary authentication in the 5G network. That is, according to the examples of the embodiments, measures are proposed that allow the AF / AS to authenticate the UE using primary authentication (which typically occurs when the UE accesses the network) according to the AKMA process, providing seamless authentication by extending the AKMA framework, even when the AF does not have a primary authentication context (e.g., because primary authentication is not performed when the UE moves from EPC to 5G).

[0070] In other words, according to examples of embodiments, measures are provided to allow the UE and the 5G network to generate AKMA keys and A-TIDs based on the EPC security context when the UE moves from EPC to 5GC, without requiring 5G master authentication.

[0071] Based on examples from the embodiments, different methods have been developed to achieve this objective.

[0072] For example, in one approach, AAnF interacts with a BSF in a 4G network within a 5G network. As an example, AAnF retrieves security context information, such as key material (Ks), from the BSF and uses said Ks to derive the AKMA key K. AKMA And A-TID. Alternatively, BSF generates an AKMA key and A-TID (based on security context information, such as key material (Ks)) and returns the generated AKMA key and A-TID to AAnF. For this method, interfaces are provided between AAnF and BSF for retrieving Ks during the interaction process. Furthermore, operations are provided for generating the required key and for piggybacking some additional information in the data stream between the involved network elements. In this way, the AKMA key can be derived, allowing AKMA security features to work without master authentication.

[0073] In another approach, the AUSF in the 5G network retrieves security context information from the HSS in the 4G network, for example... K ASME From the HSS in the 4G network, K ASME It is used to derive AKMA keys and A-TID. K ASME This is the key derived from CK and IK by the UE and HSS during AKA operation. K ASME The data is transmitted from the HSS to the Access Security Management Entity (ASME), or MME, as part of the EPS-specific authentication vector response, for example. In this way, the AKMA key can be derived, allowing AKMA security features to function without master authentication.

[0074] It should be noted that in both methods, the UE generates the AKMA key and A-TID in the same way.

[0075] Figure 4 and Figure 5 The signaling diagram illustrates a corresponding example of the authentication process, which is based on a combination of... Figure 1 The described embodiments are performed in an example communication scenario, i.e., when the UE moves from the EPC to the 5G network.

[0076] Specifically, Figure 4 This describes a scenario where AAnF interacts with BSF in a 4G network within a 5G network.

[0077] In S400, UE 10 successfully performed the authentication process in the 4G network, where the BSF service for GBA against certain NAFs was used. That is, the security context information of the UE after authentication in the 4G network, such as KAMSE, KNAF, and B-TID, exists (see S405).

[0078] In S410, after moving to the 5G network, UE 10 performs the regular 5G registration process with 5GC.

[0079] During this registration process, since the security context is derived from the MME at the AMF in the 5G network, the AMF does not perform the authentication process. In this case, the AUSF does not have a usable AUSF key K. AUSF When the UDM receives a registration request, it determines that the UE has not been registered to have performed primary authentication with the 5G network because, for example, the AUSF is not registered in the UDM, or the AUSF does not store the authentication result, or the user authentication status is invalid in the UDM.

[0080] In S415, since it is determined that the UE has not performed primary authentication with the 5G network, the UDM initiates the AKMA context information derivation process. Specifically, the UDM notifies the AAnF that UE registration has occurred for the AKMA registration profile. In this regard, the UDM also provides RID information to the AAnF. According to an example of the embodiment, for this purpose, a specific interface (also referred to as the first specific interface) is used, which is indicated as the Naanf_AKMA_ContinuityTrigger_POST interface (described later).

[0081] It is important to note that, as mentioned above, it is conceivable that the UDM would perform primary authentication for the UE in this scenario. However, the UDM may refuse to perform primary authentication due to various factors, such as local policy settings. Furthermore, performing primary authentication even if valid security context information is available in the AMF would be a waste of UE and network resources.

[0082] In S420, AAnF interacts with 4GEPC (i.e., BSF) to obtain / generate authentication context information, i.e., K. AKMA And A-TID. It should be noted that this information is derived independently by the UE.

[0083] AAnF can discover the correct BSF from the NRF of the 5G network, or the operator can configure the BSF details in AAnF. BSF registration with the NRF is possible so that AAnF can discover the BSF based on appropriate information, such as NF type, service type, PLMN, etc.

[0084] The following is how to obtain K AKMA An alternative. In this regard, it is important to note that the generation rules for K... AKMA The explanation will follow below.

[0085] In an alternative approach, BSF derives K from the available key material Ks. AKMA and A-TID, and the resulting K AKMA The A-TID is provided to AAnF. Based on the A-TID, AAnF then generates the A-KID. The rules for generating the A-KID are explained below.

[0086] In another alternative, AAnF retrieves the key material Ks from the BSF and then derives K. AKMA Therefore, the BSF is configured to expose Ks to the AAnF. Alternatively, the UDM can be supplied with key material Ks by the BSF, in which case the UDM provides Ks to the AAnF, where the AAnF can generate the key.

[0087] As a result, in S425, AAnF generates or obtains K. AKMA And A-KID.

[0088] It is important to note that if the UE has not registered for GBA (i.e., there is no GBA bootstrapping process in the 4G network), the BSF will return an error indication during S420 processing, and the AAnF will be unable to derive the required key. In this case, processing will fall back to performing 5G master authentication.

[0089] Furthermore, according to the example of the embodiment, the UDM is configured to check whether the UE is authenticated in the 4G network. If the UE is not registered with GBA, the UDM does not notify AAnF (i.e., skips S420) and initiates 5G primary authentication.

[0090] Similarly, the UE also derives K based on the corresponding generation rules. AKMA And A-KID (see S430). When the UE accesses the AF, it will also generate A-KID and K. AF .

[0091] In S440, the UE sends an application session establishment request to one or more AF / AS. This request includes A-KID.

[0092] In S445, AS / AF uses AAnF's AKMA_application key to forward a request to AAnF, which includes the A-KID and the AF's ID.

[0093] It should be noted that the processing described above in S440 and S445 refers to the case of internal AF. In the case of external AF, signaling is performed via NEF 38.

[0094] AAnF finds the corresponding K in its context. AF And A-KID, and send the AKMA_application key in S450 to obtain a response message, including subscriber ID (SUPI) and AKMA application key K. AF and K AF Expiration information (expiration time).

[0095] It should be noted that if AAnF cannot find the context, it can fall back to re-authentication in 5G.

[0096] In S455, the AF sends a success response to the UE for the establishment of the application session.

[0097] Figure 5 This describes how AUSF in a 5G network retrieves security context information (e.g., from HSS in a 4G network) K ASME (Scene)

[0098] In S500, UE 10 successfully performs the authentication process in the 4G network, where the BSF service for GBA against certain NAFs has been used. That is, the security context information of the UE after authentication in the 4G network, such as KAMSE, KNAF, and B-TID, exists (see S505). Furthermore, in S510, the HSS stores the KAMSE.

[0099] In S515, after moving to the 5G network, UE 10 performs the regular 5G registration process with 5GC.

[0100] During this registration process, since the security context is derived from the MME at the AMF in the 5G network, the AMF does not perform the authentication process. In this case, the AUSF does not have a usable AUSF key K. AUSF When the UDM receives a registration request, it determines that the UE has not been registered to have performed primary authentication with the 5G network because, for example, the AUSF is not registered in the UDM, or the AUSF does not store the authentication result, or the user authentication status is invalid in the UDM.

[0101] In S525, since it is determined that the UE has not performed primary authentication with the 5G network, the UDM initiates the process of deriving AKMA context information. Specifically, the UDM contacts the HSS to retrieve... K ASME Key. According to an example of the embodiment, for this purpose, a specific interface (also called a second specific interface) is used, which is indicated as the Nhss_UEAthentication_GetKeys_POST interface (described later). In S525, HSS will... K ASME The key is forwarded to the UDM.

[0102] Then, in S530, UDM from K ASME Generate K AKMA .from K ASME Generate K AKMA The generation rules are explained below.

[0103] It should be noted that, as an alternative, UDM can also contact AUSF, which is located in [location unclear]. K ASME Generate K AKMA .

[0104] In S535, the UDM notifies the AAnF that a UE registration has occurred for the AKMA registration profile. During this connection, the UDM also provides the AAnF with RID information, the UE's subscriber ID information, and K... AKMAAccording to an example of an embodiment, for this purpose, a specific interface (also referred to as the first specific interface) is used, which is indicated as the Naanf_AKMA_ContinuityTrigger_POST interface (described later).

[0105] In S540, AAnF generates A-KID and K. AF .

[0106] Similarly, the UE also derives K based on the corresponding generation rules. AKMA And A-KID (see S550). When the UE accesses the AF, it will also generate A-KID and K. AF .

[0107] In S555, the UE sends an application session establishment request to one or more AF / AS. The request includes A-KID.

[0108] In S560, AS / AF uses an AKMA_application key retrieval request to forward the request to AAnF, the AKMA_application key retrieval request including A-KID and the ID of the AF.

[0109] It should be noted that the above processing in S555 and S560 refers to the case of internal AF. In the case of external AF, signaling is performed via NEF 38.

[0110] AAnF finds the corresponding K in its context. AF And A-KID, and send the AKMA_application key in S565 to obtain a response message, the message including subscriber ID (SUPI), AKMA application key K AF and K AF Expiration information (expiration time).

[0111] It is important to note that if AAnF cannot find the context, it can fall back to re-authentication in 5G.

[0112] In S570, the AF sends a success response to the UE for the establishment of the application session.

[0113] Next, the description is based on Figure 4 and Figure 5 The interface used in the example above.

[0114] In the example of AAnF interacting with BSF, the following interfaces are provided for security-related services.

[0115] - Service operation name: Nbsf_AKMA_Iwk_ApplicationKey_Get.

[0116] This service is used when an NF consumer, such as AAnF, requests an AKMA application key or a Ks key from a BSF. This is used, for example, in an S420.

[0117] For this service, use the following parameters: Input, required: SUPI, RID Input, optional: none.

[0118] Output, required: K AKMA A-TID.

[0119] Output, optional: none.

[0120] - Service operation name: Naanf_AKMA_ContinuityTrigger_POST.

[0121] This service is used when an NF consumer, such as a UDM, requests AAnF to retrieve a key from a BSF. This is used, for example, in S415.

[0122] For this service, use the following parameters: Input, required: SUPI, RID, K AKMA Input, optional: none.

[0123] Output, required: None.

[0124] Output, optional: none.

[0125] In the example of UDM / AUSF interacting with HSS, the following interfaces are provided for security-related services.

[0126] - Service operation name: Nhss_UEAthentication_GetKeys_POST.

[0127] When NF consumers such as UDM / AUSF request HSS retrieval K ASME Use this service when obtaining the key. This is used, for example, in S520 / S525.

[0128] For this service, use the following parameters: Input, required: IMSI Input, optional: none.

[0129] Output, required: K ASME Output, optional: none.

[0130] Next, the rules for deriving authentication context information are described. Specifically, the Key Deduction Function (KDF) used in key deduction according to an example is described. The input parameters and their lengths are concatenated into a string S, as follows: - The length of each input parameter, measured in octets, is encoded as a string of two octets: a) Represent the number of octets in the input parameter Pi as a number k in the range [0, 65535].

[0131] b) Li is the 16-bit long code of the number k.

[0132] - The string S is constructed from n+1 input parameters as follows: S = FC || P0 || L0 || P1 || L1 || P2 || L2 || P3 || L3 ||... || Pn ||Ln FC is used to distinguish different instances of the algorithm and consists of a single octet or two octets of the form FC1||FC2, where FC1 = 0xFF and FC2 is a single octet. P0 ... Pn is the encoding of n+1 input parameters, and L0 ... Ln is the two-octet representation of the length of the corresponding input parameter encoding P0.. Pn.

[0133] - The final output, i.e. the derived key, is equal to the KDF calculated using the key pair string S, denoted as KEY.

[0134] In the first example, K was explained. AKMA Derivation logic.

[0135] When K AKMA When deriving from the key material Ks provided by BSF, perform the following operations. K AKMA Based on Ks, Ks is used as the input key instead of K. AUSF .

[0136] Regarding the key K AKMA Generate using the following rules: K AKMA Derivation function When derived from Ks K AKMA When using this method, the following parameters should be used to form the input S of the KDF: - FC = 0x80; - P0 = "AKMA"; - L0 = the length of "AKMA"; (i.e., 0x00 0x04) - P1 = SUPI; - L1 = the length of SUPI.

[0137] The key KEY should be Ks.

[0138] SUPI should be the same as the value of parameter P0 in Appendix A.7.0 of 3GPP specification TS 33.501.

[0139] The rules for A-TID generation are described as the next example.

[0140] When deriving A-TID from Ks, the following parameters should be used to form the input S of the KDF: -FC = 0x81; -P0 = "A-TID"; -L0 = the length of "A-TID"; (i.e., 0x00 0x05) -P1 = SUPI; -L1 = the length of SUPI.

[0141] The key KEY should be Ks.

[0142] SUPI should be the same as the value of parameter P0 in Appendix A.7.0 of 3GPP specification TS 33.501.

[0143] When K AKMA from K ASME During derivation, the following operations are performed, where K ASME Provided by HSS. K AKMA based on K ASME , K ASME Used as input key instead of K AUSF K AKMA Derivation function When from K ASME Derivation K AKMA When using this method, the following parameters should be used to form the input S of the KDF: - FC = 0x80; - P0 = "AKMA"; - L0 = the length of "AKMA"; (i.e.) 0x00 0x04 ) - P1 = SUPI; - L1 = the length of SUPI.

[0144] The key should be K. ASME 。

[0145] SUPI should be the same as the value of parameter P0 in Appendix A.7.0 of 3GPP specification TS 33.501.

[0146] The rules for A-TID generation are described as the next example.

[0147] When from K ASME When deriving A-TID, the following parameters should be used to form the input S of the KDF: -FC = 0x81; -P0 = "A-TID"; -L0 = the length of "A-TID"; (i.e., 0x00 0x05) -P1 = SUPI; -L1 = the length of SUPI.

[0148] The input key KEY should be K ASME .

[0149] SUPI should be the same as the value of parameter P0 in Appendix A.7.0 of 3GPP specification TS 33.501.

[0150] Figure 6 A flowchart illustrating the processes executed within the unified data management service function of a first communication network (5G network) is shown, which performs an authentication process according to some examples of embodiments, such as in conjunction with Figure 4 and Figure 5 As described. That is, Figure 6 It shows the relationship with the Figure 1 The flowchart related to the processing performed by the first PLMN1 30 UDM 33.

[0151] In S610, the UDM receives a registration request from the UE in order to register with the first communication network (i.e., PLMN1).

[0152] In S620, the UDM checks whether the UE has been registered as having performed primary authentication with the first communication network. In other words, it checks whether the UE has already performed primary authentication with PLMN1.

[0153] In S630, if the check result indicates that the UE has not yet performed primary authentication with the first communication network, the UDM initiates a derivation process. During this derivation process, the objective is to derive authentication context information (i.e., the anchor key (K) for AKMA) for the UE to authenticate at at least one AF via the first communication network, based on the security context information related to the UE's authentication in the second communication network (i.e., PLMN2 as a 4G network). AKMA (or A-KID).

[0154] According to an example of an embodiment, when the derivation process is initiated, the UDM notifies the AAnF via a specific first interface to perform UE registration for the AKMA registration profile, wherein the RID and the UE's subscription identifier (e.g., SUPI) are provided to the AAnF (e.g., as described in conjunction with S415).

[0155] Alternatively, according to an example of an embodiment, when the derivation process is initiated, the UDM contacts the HSS of the second communication network (PLMN2) via a specific second interface and requests security context information related to the UE's authentication in the second communication network (e.g., K ASME In response to the request, the UDM receives security context information related to the authentication of the UE in the second communication network, and the UDM processes the received security context information related to the authentication of the UE in the second communication network to obtain the authentication context information (e.g., as described in conjunction with S520, S525 and S530).

[0156] Specifically, according to some examples of embodiments, when processing received security context information related to UE authentication in a second communication network to obtain the authentication context information, the authentication context information is obtained by means of the received security context information (e.g., K ASME The anchor key (K) is obtained as part of the authentication context information by generating an anchor key or by requesting AUSF to generate an anchor key from the received security context information. AKMA Then, the UDM notifies the AAnF via a specific first interface to perform UE registration against the AKMA registration profile, wherein the AAnF is provided with the RID, the UE's subscription identifier (SUPI), and the generated anchor key (K). AKMA ).

[0157] In this regard, when the anchor key is determined by requesting the AUSF to generate the anchor key from the received security context information, the AAnF is notified via a third interface to perform UE registration for the AKMA registration profile, wherein the AAnF is provided with the RID, the UE's subscription identifier (SUPI), and the generated anchor key (K). AKMA ).

[0158] According to a further example of the embodiment, the UDM is also configured to check whether the UE has been authenticated in the second communication network. If the check result indicates that the UE has been authenticated in the second communication network, the derivation process is initiated. Otherwise, if the check result indicates that the UE has not been authenticated in the second communication network, the UDM initiates the main authentication process in the first communication network.

[0159] Figure 7 A flowchart illustrating the processes performed in the AKMA anchor function of a first communication network (5G network) is shown, which performs the authentication process according to some examples of embodiments, such as in conjunction with Figure 4 and Figure 5 As described. That is, Figure 7 A flowchart related to the processing performed by AAnF 35 of the first PLMN1 30 is shown.

[0160] In S710, the AAnF performs a derivation process for a UE registered to the first communication network.

[0161] As indicated in S720, the derivation process includes obtaining authentication context information (i.e., the anchor key (K) for AKMA) for the UE to authenticate at at least one AF via the first communication network (PLMN1) based on security context information related to the UE's authentication in the second communication network (PLMN2). AKMA (or A-KID).

[0162] For example, according to an example of an embodiment, such as in combination Figure 4 As described, the AAnF receives information for performing UE registration against an AKMA registration profile via a specific first interface, wherein the information includes the RID and the UE's Subscription Identifier (SUPI). The AAnF then communicates with the BSF of the second communication network (PLMN2) to obtain authentication context information for the UE to authenticate at at least one application function via the first communication network, based on security context information related to the UE's authentication in the second communication network.

[0163] For example, the AAnF receives an anchor key and a UE-specific temporary identifier (A-TID) from the BSF as part of the authentication context information. Then, the AAnF generates an A-KID based on the UE-specific A-TID.

[0164] Alternatively, the AAnF receives key information (Ks) related to the UE's authentication in the second communication network (PLMN2) from the BSF. The AAnF then generates an anchor key (K) based on the received Ks. AKMA (This is used as part of the authentication context information and for the A-KID of the UE.)

[0165] According to an example embodiment, the AAnF is configured to discover the BSF for communication based on configuration information stored in the AAnF that identifies the BSF. Alternatively, the BSF can be discovered based on information provided by the repository function (NRF) of the first communication network (PLMN1).

[0166] Alternatively, such as in combination Figure 5 As described, the AAnF receives UE registration information via a specific first interface, which is based on the AKMA registration profile. This information includes the RID, the UE's Subscription Identifier (SUPI), and the Anchor Key (K). AKMA This is used as part of the authentication context information. In this case, AAnF generates an A-KID for the UE.

[0167] Figure 8 A flowchart illustrating the processing performed in the bootstrap server function or home subscriber server of a second communication network (4G network) is shown, which performs an authentication process according to some examples of embodiments, such as in conjunction with Figure 4 and Figure 5 As described. That is, Figure 8 It shows the relationship with the Figure 1 The flowchart related to the processing performed by the second PLMN2 20 BSF 22 or HSS 23.

[0168] In S810, the BSF or the HSS communicates with the network function of the first communication network (e.g., the AAnF or UDM / AUSF) to obtain authentication context information (i.e., the anchor key (K) for AKMA) for the UE to authenticate at at least one AF via the first communication network, based on security context information related to the UE's authentication in the second communication network. AKMA (or A-KID).

[0169] According to some examples of the embodiments, such as those also combined Figure 4 or Figure 5 As described, the BSF or the HSS receives key information (e.g., Ks or ...) related to the authentication of the UE in the second communication network, which is provided to the network function of the first communication network. K ASME The request is made in the form of a key, which is then provided with the requested key information.

[0170] According to an example of an embodiment, the HSS is configured to store key information related to the authentication of the UE in a second communication network (e.g., K ASME This allows the information to be provided upon request.

[0171] According to some examples of the embodiments, such as those also combined Figure 4As described, the BSF receives a request to provide the network functions of the first communication network with the UE's authentication context information (e.g., KAKME). In this case, the BSF generates an anchor key (KAKME) as part of the authentication context information, along with an A-TID for the UE, based on key information (e.g., Ks) related to the UE's authentication in the second communication network. The BSF then provides the anchor key and the UE-specific A-TID to the 5G network side.

[0172] Figure 9 A flowchart illustrating the processes performed in the UE is shown, which executes the authentication process according to some examples of embodiments, such as in combination with Figure 4 and Figure 5 As described. That is, Figure 9 It shows the relationship with the Figure 1 The flowchart related to the processing performed by UE 10.

[0173] In S910, the UE completes the authentication process in the second communication network (PLMN2) (e.g., in conjunction with...). Figure 2 (as described).

[0174] In S920, the UE performs the registration process in the first communication network (PLMN) without performing master authentication in the first communication network.

[0175] In S930, the UE uses security context information related to the UE's authentication in the second communication network (e.g., K ASME Or Ks) to derive the authentication context information (i.e., the anchor key (K) for AKMA) used by the UE to authenticate at at least one AF via the first communication network. AKMA (or A-KID).

[0176] Figure 10 A schematic diagram of a network element or network function 330 is shown, such as a 5GC network element or function like a UDM, which performs an authentication process according to some examples of embodiments, such as in conjunction with Figure 4 and Figure 5 As described. It should be noted that network elements or functions 330 (e.g., UDM) may include other elements or functions besides those described below. Furthermore, even when referring to a network element or function, that element or function may be another device or function with a similar task, such as a chipset, chip, module, application, etc., which may be part of a network element or attached to a network element as a separate element, etc. It should be understood that each block and any combination thereof may be implemented by various components or combinations thereof, such as hardware, software, firmware, one or more processors and / or circuitry.

[0177] Figure 10 The illustrated UDM 330 may include processing circuitry, processing functions, a control unit, or a processor 331, such as a CPU, adapted to execute instructions given by a program or similar document related to a control process. The processor 331 may include one or more processing portions or functions dedicated to a specific process as described below, or the processing may run within a single processor or processing function. The portion used to perform such a specific process may also be provided as a discrete element, or within one or more other processors, processing functions, or processing portions, for example, in a physical processor (such as a CPU) or in one or more physical or virtual entities. Reference numerals 332 and 333 denote input / output (I / O) units or functions (interfaces) connected to the processor or processing function 331. I / O unit 332 may be used to communicate with a first network (e.g., a 5G-based network). I / O unit 333 may be used to communicate with a second network (e.g., a 4G-based network). I / O units 332 and 333 may be combined units including communication devices facing several entities, or may include a distributed structure having multiple different interfaces for different entities. Reference numeral 334 indicates available memory, such as memory for storing data and programs to be executed by the processor or processing function 331 and / or as working memory for the processor or processing function 331. It should be noted that memory 334 can be implemented using one or more memory portions of the same or different types of memory.

[0178] The processor or processing function 331 is configured to perform processing related to the aforementioned authorization process. Specifically, the processor or processing circuitry or function 331 includes one or more of the following sub-parts. Sub-part 3301 is a processing portion that can be used as a portion for receiving registration requests. Part 3301 can be configured according to... Figure 6 The S610 performs the processing. Furthermore, the processor or processing circuitry or function 331 may include a sub-section 3302 that can be used as a part for checking the main authentication. Section 3302 can be configured according to... Figure 6 The S620 performs the processing. Additionally, the processor, processing circuitry, or function 331 may include a sub-section 3303 that can be used as a portion for performing derivation processing. Section 3303 can be configured according to... Figure 6 The S630 performs the processing.

[0179] Figure 11 A schematic diagram of a network element or network function 350 is shown, such as a 5GC network element or function like AAnF, which performs an authentication process according to some examples of embodiments, such as in conjunction with Figure 4 and Figure 5As described. It should be noted that network elements or functions 350 (e.g., AAnF) may include other elements or functions besides those described below. Furthermore, even when referring to a network element or function, that element or function may be another device or function with a similar task, such as a chipset, chip, module, application, etc., which may be part of a network element or attached to a network element as a separate element, etc. It should be understood that each block and any combination thereof can be implemented by various components or combinations thereof, such as hardware, software, firmware, one or more processors and / or circuitry.

[0180] Figure 11 The illustrated AAnF 350 may include processing circuitry, processing functions, a control unit, or a processor 351, such as a CPU, adapted to execute instructions given by a program or similar document related to a control process. The processor 351 may include one or more processing portions or functions dedicated to a specific process as described below, or the processing may run within a single processor or processing function. The portion used to perform such a specific process may also be provided as a discrete element, or within one or more other processors, processing functions, or processing portions, for example, in a physical processor (such as a CPU) or in one or more physical or virtual entities. Reference numerals 352 and 353 denote input / output (I / O) units or functions (interfaces) connected to the processor or processing function 351. I / O unit 352 may be used to communicate with a first network (e.g., a 5G-based network). I / O unit 353 may be used to communicate with a second network (e.g., a 4G-based network). I / O units 352 and 353 may be combined units including communication devices facing several entities, or may include a distributed structure with multiple different interfaces for different entities. Reference numeral 354 indicates available memory, such as memory for storing data and programs to be executed by the processor or processing function 351 and / or as working memory for the processor or processing function 351. It should be noted that memory 354 can be implemented using one or more memory portions of the same or different types of memory.

[0181] The processor or processing function 351 is configured to perform processing related to the aforementioned authorization process. Specifically, the processor or processing circuitry or function 351 includes one or more of the following sub-parts. Sub-part 3501 is a processing portion that can be used as a portion for performing derivation processing. Part 3501 can be configured according to... Figure 7 The S710 performs the processing. Furthermore, the processor, processing circuitry, or function 351 may include a sub-section 3502 that can be used as a part for obtaining authentication context information. Section 3502 can be configured according to... Figure 7 The S720 performs the processing.

[0182] Figure 12A schematic diagram of a network element or network function 240, such as a 4G network element or function like a BSF, is shown, which performs an authentication process according to some examples of embodiments, such as in conjunction with Figure 4 and Figure 5 As described. It should be noted that network elements or functions 240 (e.g., BSF) may include other elements or functions besides those described below. Furthermore, even when referring to a network element or function, that element or function may be another device or function with a similar task, such as a chipset, chip, module, application, etc., which may be part of a network element or attached to a network element as a separate element, etc. It should be understood that each block and any combination thereof may be implemented by various components or combinations thereof, such as hardware, software, firmware, one or more processors and / or circuitry.

[0183] Figure 12 The illustrated BSF 240 may include processing circuitry, processing functions, a control unit, or a processor 241, such as a CPU, adapted to execute instructions given by a program or similar document related to a control process. The processor 241 may include one or more processing portions or functions dedicated to a particular processing described below, or the processing may run within a single processor or processing function. The portion used to perform such a particular processing may also be provided as a discrete element, or within one or more other processors, processing functions, or processing portions, for example, in a physical processor (such as a CPU) or in one or more physical or virtual entities. Reference numerals 242 and 243 denote input / output (I / O) units or functions (interfaces) connected to the processor or processing function 241. I / O unit 242 may be used to communicate with a second network (e.g., a 4G-based network). I / O unit 243 may be used to communicate with a first network (e.g., a 5G-based network). I / O units 242 and 243 may be combined units including communication devices facing several entities, or may include a distributed structure with multiple different interfaces for different entities. Reference numeral 244 indicates available memory, such as memory for storing data and programs to be executed by the processor or processing function 241 and / or as working memory for the processor or processing function 241. It should be noted that memory 244 can be implemented using one or more memory portions of the same or different types of memory.

[0184] The processor or processing function 241 is configured to perform processing related to the aforementioned authorization process. Specifically, the processor or processing circuitry or function 241 includes one or more of the following sub-parts. Sub-part 2401 is a processing portion that can be used for communicating with the first network. Part 2401 can be configured according to... Figure 8 The S810 performs the processing.

[0185] Figure 13A schematic diagram of a network element or network function 10, such as a UE, is shown, which performs an authentication process according to some examples of embodiments, such as in conjunction with Figure 4 and Figure 5 As described below. It should be noted that network elements or functions 10 (e.g., UE) may include other elements or functions besides those described below. Furthermore, even when referring to a network element or function, that element or function may be another device or function with a similar task, such as a chipset, chip, module, application, etc., which may be part of a network element or attached to a network element as a separate element, etc. It should be understood that each block and any combination thereof may be implemented by various components or combinations thereof, such as hardware, software, firmware, one or more processors and / or circuitry.

[0186] Figure 13 The illustrated UE 10 may include processing circuitry, processing functions, control units, or a processor 101, such as a CPU, adapted to execute instructions given by programs related to control processes. The processor 101 may include one or more processing portions or functions dedicated to a specific process as described below, or the processing may run within a single processor or processing function. The portion used to perform such a specific process may also be provided as a discrete element, or within one or more other processors, processing functions, or processing portions, for example, in a physical processor (such as a CPU) or in one or more physical or virtual entities. Reference numerals 102 and 103 denote input / output (I / O) units or functions (interfaces) connected to the processor or processing function 101. I / O unit 102 may be used to communicate with a first communication network (e.g., a 5G network). I / O unit 103 may be used to communicate directly with a second communication network (e.g., a 4G network). I / O units 102 and 103 may be combined units including communication devices facing several entities, or may include a distributed structure with multiple different interfaces for different entities. Reference numeral 104 indicates available memory, such as memory for storing data and programs to be executed by the processor or processing function 101 and / or as working memory for the processor or processing function 101. It should be noted that memory 104 can be implemented using one or more memory portions of the same or different types of memory.

[0187] The processor or processing function 101 is configured to perform processing related to the aforementioned authorization process. Specifically, the processor or processing circuitry or function 101 includes one or more of the following sub-parts. Sub-part 1001 is a processing portion that can be used to perform authentication processing in a second communication network. Part 1001 can be configured according to... Figure 9The S910 performs the processing. Furthermore, the processor or processing circuitry or function 101 may include a sub-part 1002 that can be used as a part for performing registration in the first communication network. Part 1002 can be configured according to... Figure 9 The S920 performs the processing. Additionally, the processor, processing circuitry, or function 101 may include a sub-section 1003 that can be used to derive authentication context information. Section 1003 can be configured to... Figure 9 The S930 performs the processing.

[0188] According to another example of the embodiments, an apparatus is provided, including: a component configured to complete an authentication process for a user equipment (UE) in a second communication network; a component configured to perform a registration process for the UE in a first communication network without performing primary authentication in the first communication network; and a component configured to derive authentication context information for the UE to authenticate via the first communication network at at least one application function based on security context information related to the authentication of the UE in the second communication network.

[0189] Furthermore, according to some other examples of the embodiments, the apparatus defined above may also include components for performing at least one of the processes defined in the above methods, for example, according to the combination Figure 9 The method described.

[0190] According to another example of the embodiments, a non-transient computer-readable medium is provided, including program instructions for causing a device to perform processes including: completing an authentication process for a user equipment (UE) in a second communication network; performing a registration process for the UE in a first communication network without performing primary authentication in the first communication network; and deriving authentication context information for the UE to authenticate via the first communication network at at least one application function based on security context information related to the UE's authentication in the second communication network.

[0191] According to another example of the embodiments, an apparatus is provided, including: a component configured to receive a registration request from a user equipment (UE) to a first communication network; a component configured to check whether the UE has been registered as having performed primary authentication with the first communication network; and a component configured to initiate a derivation process to derive authentication context information for the UE to authenticate via the first communication network at at least one application function based on security context information related to the UE's authentication in a second communication network if the check result indicates that the UE has not performed primary authentication with the first communication network.

[0192] Furthermore, according to some other examples of the embodiments, the apparatus defined above may also include components for performing at least one of the processes defined in the above methods, for example, according to the combination Figure 6 The method described.

[0193] According to another example of the embodiments, a non-transient computer-readable medium is provided, including program instructions for causing a device to perform the following processes: receiving a registration request from a user equipment (UE) to a first communication network; checking whether the UE has been registered as having performed primary authentication with the first communication network; and, if the check result is that the UE has not yet performed primary authentication with the first communication network, initiating a derivation process to derive authentication context information for the UE to authenticate via the first communication network at at least one application function based on security context information related to the UE's authentication in a second communication network.

[0194] According to another example of the embodiments, an apparatus is provided, for example, including components configured to perform a derivation process on a user equipment (UE) registered to a first communication network, wherein the derivation process includes: obtaining authentication context information for the UE to authenticate via the first communication network at at least one application function based on security context information related to authentication of the UE in a second communication network.

[0195] Furthermore, according to some other examples of the embodiments, the apparatus defined above may also include components for performing at least one of the processes defined in the above methods, for example, according to the combination Figure 7 The method described.

[0196] According to another example of the embodiments, a non-transient computer-readable medium is provided, which includes program instructions for causing a device to perform a process including: performing a derivation process on a user equipment (UE) registered to a first communication network, wherein the derivation process includes: obtaining authentication context information for authentication performed by the UE via the first communication network at at least one application function, based on security context information related to authentication of the UE in a second communication network.

[0197] According to another example of the embodiments, an apparatus is provided, for example, including components configured to communicate with network functions of a first communication network for obtaining authentication context information for authentication of a UE via the first communication network at at least one application function, the authentication context information being based on security context information related to authentication of the UE in a second communication network.

[0198] Furthermore, according to some other examples of the embodiments, the apparatus defined above may also include components for performing at least one of the processes defined in the above methods, for example, according to the combination Figure 8 The method described.

[0199] According to another example of the embodiment, a non-transient computer-readable medium is provided, comprising program instructions for causing a device to perform processing including: communicating with network functions of a first communication network to obtain authentication context information for authentication of a UE via the first communication network at at least one application function, the authentication context information being based on security context information related to authentication of the UE in a second communication network.

[0200] According to an example of an embodiment, AKMA key generation can be achieved based on the EPC security context without 5G master authentication after the UE moves from 4G to 5G.

[0201] It should be understood - The access technologies that transmit traffic to and from entities in the communication network can be any suitable existing or future technologies, such as WLAN (Wireless Local Area Network), WiMAX (Global Microwave Access Interoperability), LTE, LTE-A, 5G, Bluetooth, infrared, etc.; in addition, the embodiments can also apply wired technologies, such as IP-based access technologies, such as wired networks or fixed lines. - An embodiment suitable as software code or a portion thereof and to be run using a processor or processing function is software code independent and can be specified using any known or future-developed programming language, such as high-level programming languages ​​like Objective-C, C, C++, C#, Java, Python, Javascript, other scripting languages, etc., or low-level programming languages ​​like machine language or assembly language; - The implementation of the embodiments is hardware-independent and can be implemented using any known or future-developed hardware technology or any combination of these technologies, such as microprocessors or CPUs (central processing units), MOS (metal-oxide-semiconductor), CMOS (complementary MOS), BiMOS (bipolar MOS), BiCMOS (bipolar CMOS), ECL (emitter-coupled logic) and / or TTL (transistor-transistor logic). - Implementations may be implemented as separate devices, apparatuses, units, components or functions, or in a distributed manner. For example, one or more processors or processing functions may be used or shared in a process, or one or more processing portions or processing units may be used and shared in a process, wherein one or more processing portions dedicated to a particular process as described may be implemented using one or more physical processors. - The device can be implemented by a semiconductor chip, chipset, or (hardware) module including such a chip or chipset; - The implementation can also be carried out as any combination of hardware and software, such as ASIC (Application-Specific Integrated Circuit) components, FPGA (Field Programmable Gate Array) or CPLD (Complex Programmable Logic Device) components or DSP (Digital Signal Processor) components; - The embodiments can also be implemented as computer program products, including a computer-usable medium having computer-readable program code embedded therein, the computer-readable program code being adapted to perform the processes described in the embodiments, wherein the computer-usable medium may be a non-transient medium.

[0202] Although this disclosure has been described prior with reference to specific embodiments thereof, it is not limited thereto and various modifications may be made thereto.

Claims

1. An apparatus comprising At least one processor, and At least one memory for storing instructions that, when executed by the at least one processor, cause the device to perform at least the following: The authentication process for the User Equipment (UE) is completed in the second communication network. Without performing primary authentication in the first communication network, the registration process for the UE is performed in the first communication network. Based on the security context information related to the UE's authentication in the second communication network, authentication context information for the UE's authentication via the first communication network at at least one application function is derived.

2. The apparatus of claim 1, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function includes at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

3. An apparatus comprising: At least one processor, and At least one memory for storing instructions that, when executed by the at least one processor, cause the device to perform at least the following: Receive a registration request to the first communication network from the user equipment (UE). Check whether the UE has been registered as having performed master authentication with the first communication network. If the check result indicates that the UE has not yet performed primary authentication with the first communication network, a derivation process is initiated to derive authentication context information for the UE to perform authentication via the first communication network at at least one application function, based on security context information related to the UE's authentication in the second communication network.

4. The apparatus of claim 3, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function includes at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

5. The apparatus of claim 3 or 4, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: Check whether the UE has been authenticated in the second communication network. If the check result indicates that the UE has been authenticated in the second communication network, the derivation process is initiated, or If the inspection result indicates that the UE has not yet been authenticated in the second communication network, the main authentication process is initiated in the first communication network.

6. The apparatus according to any one of claims 3 to 5, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: When the derivation process is initiated, the anchor function is notified via a specific first interface: UE registration is performed against the AKMA registration profile, in which a routing identifier and the UE's subscription identifier are provided to the anchor function.

7. The apparatus according to any one of claims 3 to 5, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: When the derivation process is initiated, the home subscriber server of the second communication network is contacted via a specific second interface, and security context information related to the UE's authentication in the second communication network is requested. Receive the security context information related to the authentication of the UE in the second communication network, and The received security context information related to the authentication of the UE in the second communication network is processed to obtain the authentication context information.

8. The apparatus of claim 7, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: When processing the received security context information related to the UE's authentication in the second communication network to obtain the authentication context information... The anchor key, which is part of the authentication context information, is determined by generating the anchor key from the received security context information or by requesting the authentication server function to generate the anchor key from the received security context information. The anchor function is notified via a specific first interface: UE registration is performed against an AKMA registration profile, in which a routing identifier, the UE's subscription identifier, and the generated anchor key are provided to the anchor function.

9. The apparatus of claim 8, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: When the anchor key is determined by requesting the authentication server function to generate the anchor key from the received security context information, the anchor function is notified via a third interface that UE registration is performed against an AKMA registration profile, wherein a routing identifier, the UE's subscription identifier, and the generated anchor key can be provided to the anchor.

10. The apparatus according to any one of claims 3 to 9, wherein the apparatus is included in the unified data management service function of the first communication network.

11. An apparatus comprising At least one processor, and At least one memory for storing instructions that, when executed by the at least one processor, cause the device to perform at least the following: A derivation process is performed for a user equipment (UE) registering to the first communication network, wherein the derivation process includes: Based on the security context information related to the UE's authentication in the second communication network, authentication context information is obtained for the UE to authenticate via the first communication network at at least one application function.

12. The apparatus of claim 11, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function comprises at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

13. The apparatus of claim 11 or 12, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: The system receives information from the UE regarding the AKMA registration profile via a specific first interface. This information includes a routing identifier and the UE's subscription identifier. The system communicates with the boot server function of the second communication network to obtain authentication context information for the authentication of the UE via the first communication network at at least one application function, based on security context information related to the authentication of the UE in the second communication network.

14. The apparatus of claim 13, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: The system receives an anchor key and a temporary identifier for the UE as part of the authentication context information from the boot server function. An AKMA key identifier is generated based on the temporary identifier for the UE.

15. The apparatus of claim 13, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: The system receives key information related to the authentication of the UE in the second communication network from the boot server function. An anchor key and an AKMA key identifier for the UE are generated based on the received key information as part of the authentication context information.

16. The apparatus according to any one of claims 13 to 15, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: The boot server function for communication is discovered based on pre-stored configuration information identifying the boot server function or based on information provided by the repository function of the first communication network.

17. The apparatus of claim 11 or 12, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: The system receives information via a specific first interface that is executed for UE registration against an AKMA registration profile. This information includes a route identifier, the UE's subscription identifier, and an anchor key as part of the authentication context information. Generate an AKMA key identifier for the UE.

18. The apparatus according to any one of claims 11 to 17, wherein the apparatus is included in the AKMA anchor function of the first communication network.

19. An apparatus comprising At least one processor, and At least one memory for storing instructions that, when executed by the at least one processor, cause the device to perform at least the following: The network functions communicate with the first communication network to obtain authentication context information for the UE to authenticate via the first communication network at at least one application function, based on security context information related to the UE's authentication in the second communication network.

20. The apparatus of claim 19, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function comprises at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

21. The apparatus of claim 19 or 20, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: Receive a request to provide the network functions of the first communication network with key information related to the authentication of the UE in the second communication network, and Provide the requested key information.

22. The apparatus of claim 21, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: The key information related to the authentication of the UE in the second communication network is stored.

23. The apparatus of claim 19 or 20, wherein the instructions, when executed by the at least one processor, further cause the apparatus to perform at least: Receive a request to provide the network function of the first communication network with the authentication context information of the UE. An anchor key and a temporary identifier for the UE are generated as part of the authentication context information based on key information related to the UE's authentication in the second communication network. Provide the anchor key and the temporary identifier for the UE.

24. The apparatus according to any one of claims 19 to 23, wherein the apparatus is included in the bootstrap server function of the second communication network or in the home subscriber server of the second communication network.

25. A method comprising The authentication process for the User Equipment (UE) is completed in the second communication network. Without performing primary authentication in the first communication network, the registration process for the UE is performed in the first communication network. Based on the security context information related to the UE's authentication in the second communication network, authentication context information for the UE's authentication via the first communication network at at least one application function is derived.

26. The method of claim 25, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function comprises at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

27. A method comprising Receive a registration request to the first communication network from the user equipment (UE). Check whether the UE has been registered as having performed master authentication with the first communication network. If the check result indicates that the UE has not yet performed primary authentication with the first communication network, a derivation process is initiated to derive authentication context information for the UE to perform authentication via the first communication network at at least one application function, based on security context information related to the UE's authentication in the second communication network.

28. The method of claim 27, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function comprises at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

29. The method according to claim 27 or 28, further comprising: Check whether the UE has been authenticated in the second communication network. If the check result indicates that the UE has been authenticated in the second communication network, the derivation process is initiated, or If the inspection result indicates that the UE has not yet been authenticated in the second communication network, the main authentication process is initiated in the first communication network.

30. The method according to any one of claims 27 to 29, further comprising: When the derivation process is initiated, the anchor function is notified via a specific first interface: UE registration is performed against the AKMA registration profile, in which a routing identifier and the UE's subscription identifier are provided to the anchor function.

31. The method according to any one of claims 27 to 29, further comprising: When the derivation process is initiated, the home subscriber server of the second communication network is contacted via a specific second interface, and security context information related to the UE's authentication in the second communication network is requested. Receive the security context information related to the authentication of the UE in the second communication network, and The received security context information related to the authentication of the UE in the second communication network is processed to obtain the authentication context information.

32. The method of claim 31, further comprising: When processing the received security context information related to the UE's authentication in the second communication network to obtain the authentication context information... The anchor key, which is part of the authentication context information, is determined by generating the anchor key from the received security context information or by requesting the authentication server function to generate the anchor key from the received security context information. The anchor function is notified via a specific first interface: UE registration is performed against an AKMA registration profile, in which a routing identifier, the UE's subscription identifier, and the generated anchor key are provided to the anchor function.

33. The method of claim 32, further comprising: When the anchor key is determined by requesting the authentication server function to generate the anchor key from the received security context information, the anchor function is notified via a third interface that UE registration is performed against an AKMA registration profile, wherein a routing identifier, the UE's subscription identifier, and the generated anchor key can be provided to the anchor.

34. The method according to any one of claims 27 to 33, wherein the method is performed in the unified data management service function of the first communication network.

35. A method comprising A derivation process is performed for a user equipment (UE) registering to the first communication network, wherein the derivation process includes: Based on the security context information related to the UE's authentication in the second communication network, authentication context information is obtained for the UE to authenticate via the first communication network at at least one application function.

36. The method of claim 35, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function comprises at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

37. The method of claim 35 or 36, further comprising: The system receives information from the UE regarding the AKMA registration profile via a specific first interface. This information includes a routing identifier and the UE's subscription identifier. The system communicates with the boot server function of the second communication network to obtain authentication context information for the authentication of the UE via the first communication network at at least one application function, based on security context information related to the authentication of the UE in the second communication network.

38. The method of claim 37, further comprising: The system receives an anchor key and a temporary identifier for the UE as part of the authentication context information from the boot server function. An AKMA key identifier is generated based on the temporary identifier for the UE.

39. The method of claim 37, further comprising: The system receives key information related to the authentication of the UE in the second communication network from the boot server function. An anchor key and an AKMA key identifier for the UE are generated based on the received key information as part of the authentication context information.

40. The method according to any one of claims 37 to 39, further comprising: The boot server function for communication is discovered based on pre-stored configuration information identifying the boot server function or based on information provided by the repository function of the first communication network.

41. The method of claim 35 or 36, further comprising: The system receives information via a specific first interface that is executed for UE registration against an AKMA registration profile. This information includes a route identifier, the UE's subscription identifier, and an anchor key as part of the authentication context information. Generate an AKMA key identifier for the UE.

42. The method according to any one of claims 35 to 41, wherein the method is performed in the AKMA anchor function of the first communication network.

43. A method, comprising The network functions communicate with the first communication network to obtain authentication context information for the UE to authenticate via the first communication network at at least one application function, based on security context information related to the UE's authentication in the second communication network.

44. The method of claim 43, wherein the authentication context information for authentication performed by the UE via the first communication network at at least one application function comprises at least one of the following: Anchor keys for AKMA used for authentication and key management in applications, or AKMA key identifier.

45. The method of claim 43 or 44, further comprising: Receive a request to provide the network functions of the first communication network with key information related to the authentication of the UE in the second communication network, and Provide the requested key information.

46. ​​The method of claim 45, further comprising: The key information related to the authentication of the UE in the second communication network is stored.

47. The method according to claim 43 or 44, further comprising: Receive a request to provide the network function of the first communication network with the authentication context information of the UE. An anchor key and a temporary identifier for the UE are generated as part of the authentication context information based on key information related to the UE's authentication in the second communication network. Provide the anchor key and the temporary identifier for the UE.

48. The method according to any one of claims 43 to 47, wherein the method is performed in the bootstrap server function of the second communication network or in the home subscriber server of the second communication network.

49. A computer program comprising instructions for performing the method of at least any one of claims 25 to 26, or any one of claims 27 to 34, or any one of claims 35 to 42, or any one of claims 43 to 48.