Apparatus, methods and computer programs

CN122579116APending Publication Date: 2026-08-14NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-02-12
Publication Date
2026-08-14

Smart Images

  • Figure CN122579116A_ABST
    Figure CN122579116A_ABST
Patent Text Reader

Abstract

This disclosure relates to an apparatus configured to perform: generating a first encrypted and integrity-protected authorization and key negotiation response based on an authorization and key negotiation response and a first profile; generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a second profile; generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a third profile; and sending the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to a base station.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to techniques for managing security in communication systems. Background Technology

[0002] A communication system can be viewed as a facility that enables communication sessions between two or more entities (such as communication equipment, base stations (BS), and / or other nodes) by providing carriers between various entities involved in the communication path.

[0003] A communication system can be a wireless communication system. Examples of wireless systems include Public Land Mobile Networks (PLMNs) based on radio standards provided by 3GPP, satellite-based communication systems, and various wireless local area networks (such as wireless local area networks (WLANs)). Wireless systems can typically be divided into cells and are therefore often referred to as cellular systems.

[0004] Communication systems and associated equipment typically operate according to a given standard or specification that outlines what the various entities associated with the system are allowed to do and how they should be implemented. The communication protocols and / or parameters that should be used for the connection are also usually defined. Examples of standards are 4G, 5G, or 6G standards. Summary of the Invention

[0005] According to one aspect, an apparatus is provided, the apparatus comprising at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured, together with the at least one processor, to cause the apparatus to at least: generate a first encrypted and integrity-protected authorization and key negotiation response based on an authorization and key negotiation response and a first profile; generate a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a second profile; generate a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a third profile; and transmit the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to a base station.

[0006] The first profile may be the same as the second profile; or the first profile may be different from the second profile.

[0007] The third profile may include a default profile, wherein the default profile includes at least one default algorithm for at least one of the encryption or integrity protection algorithms.

[0008] At least one default algorithm can be standardized.

[0009] Generating a first encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the first profile may include: generating a first encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response, the first profile, and at least one first key for encryption and integrity protection.

[0010] At least one first key used for encryption and integrity protection may include a non-access stratum key K for encryption. NASenc and the non-access stratum key K used for integrity protection NASint .

[0011] Generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the second profile may include: generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response, the second profile, and at least one second key for encryption and integrity protection.

[0012] The second key used for encryption and integrity protection may include at least one radio resource control key K for encryption. RRCenc and the radio resource control key K used for integrity protection RRCenc .

[0013] Generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the third profile may include: generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response, the third profile, and at least one third key for encryption and integrity protection.

[0014] At least one third key used for encryption and integrity protection may include an authentication server function key K for encryption. AUSFenc and the authentication server function key K used for integrity protection AUSFint .

[0015] At least one first key for encryption and integrity protection may be derived from at least one third key for encryption and integrity protection; and at least one second key for encryption and integrity protection may be derived from at least one first key for encryption and integrity protection.

[0016] At least one memory and computer code are configured, together with at least one processor, to cause the apparatus to at least: send an instruction to a base station to support an optimized authentication process; wherein the optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and wherein the optimized authentication process does not include: exchanging a non-access stratum security mode command, exchanging a non-access stratum security mode command completion, exchanging an access stratum security mode command, and exchanging an access stratum security mode command completion.

[0017] The device may include user equipment.

[0018] According to one aspect, an apparatus is provided, comprising components for: generating a first encrypted and integrity-protected authorization and key negotiation response based on an authorization and key negotiation response and a first profile; generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a second profile; generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a third profile; and transmitting the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to a base station.

[0019] According to one aspect, a method is provided, comprising: generating a first encrypted and integrity-protected authorization and key negotiation response based on an authorization and key negotiation response and a first profile; generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a second profile; generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a third profile; and sending the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to a base station.

[0020] This method can be performed by a device.

[0021] The first profile may be the same as the second profile; or the first profile may be different from the second profile.

[0022] The third profile may include a default profile, wherein the default profile includes at least one default algorithm for at least one of the encryption or integrity protection algorithms.

[0023] At least one default algorithm can be standardized.

[0024] Generating a first encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the first profile may include: generating a first encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response, the first profile, and at least one first key for encryption and integrity protection.

[0025] At least one first key used for encryption and integrity protection may include a non-access stratum key K for encryption. NASenc and the non-access stratum key K used for integrity protection NASint .

[0026] Generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the second profile may include: generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response, the second profile, and at least one second key for encryption and integrity protection.

[0027] The second key used for encryption and integrity protection may include at least one radio resource control key K for encryption. RRCenc and the radio resource control key K used for integrity protection RRCenc .

[0028] Generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the third profile may include: generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response, the third profile, and at least one third key for encryption and integrity protection.

[0029] At least one third key used for encryption and integrity protection may include an authentication server function key K for encryption. AUSFenc and the authentication server function key K used for integrity protection AUSFint .

[0030] At least one first key for encryption and integrity protection may be derived from at least one third key for encryption and integrity protection; and at least one second key for encryption and integrity protection may be derived from at least one first key for encryption and integrity protection.

[0031] The method may include: sending an instruction to a base station to support an optimized authentication process; wherein the optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and wherein the optimized authentication process does not include: exchanging non-access stratum security mode commands, exchanging non-access stratum security mode command completion, exchanging access stratum security mode commands, and exchanging access stratum security mode command completion.

[0032] The device may include user equipment.

[0033] According to one aspect, an apparatus is provided, including circuitry configured to perform: generating a first encrypted and integrity-protected authorization and key negotiation response based on an authorization and key negotiation response and a first profile; generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a second profile; generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a third profile; and transmitting the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to a base station.

[0034] According to one aspect, a computer program product is provided, comprising computer-executable instructions that execute at runtime: generating a first encrypted and integrity-protected authorization and key negotiation response based on an authorization and key negotiation response and a first profile; generating a second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a second profile; generating a third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and a third profile; and transmitting the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to a base station.

[0035] According to one aspect, an apparatus is provided, including at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured, together with the at least one processor, to cause the apparatus to at least perform: sending an authorization and key negotiation challenge to a user equipment; and receiving from the user equipment a first encrypted and integrity-protected authorization and key negotiation response, a second encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0036] At least one memory and computer code can be configured, together with at least one processor, to cause the device to at least: perform successful verification of a second encrypted and integrity-protected authorization and key negotiation response; and send a first encrypted and integrity-protected authorization and key negotiation response and a third encrypted and integrity-protected authorization and key negotiation response to a mobility management network function.

[0037] Successful verification of the second encrypted and integrity-protected authorization and key negotiation response may include: performing decryption and integrity protection verification of the second encrypted and integrity-protected authorization and key negotiation response based on the second profile.

[0038] Performing at least one of the following based on the second profile: decrypting or performing an integrity calculation on the first encrypted or integrity-protected authorization and key negotiation response. This may include performing at least one of the following based on the second profile and at least one second encryption and integrity protection key: decrypting or performing an integrity protection verification on the second encrypted and integrity-protected authorization and key negotiation response.

[0039] At least one second key used for encryption and integrity protection may include a radio resource control key K for encryption. RRCenc and the radio resource control key K used for integrity protection RRCenc .

[0040] At least one memory and computer code may be configured, together with at least one processor, to cause the apparatus to at least: receive from a user equipment an instruction to support an optimized authentication process; and send to a mobility management network function an instruction to support an optimized authentication process; wherein the optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and wherein the optimized authentication process does not include: exchanging a non-access stratum security mode command, exchanging a non-access stratum security mode command completion, exchanging an access stratum security mode command, and exchanging an access stratum security mode command completion.

[0041] The device may include a base station.

[0042] According to one aspect, an apparatus is provided, comprising units for performing the following operations: sending an authorization and key negotiation challenge to a user equipment; and receiving from the user equipment a first encrypted and integrity-protected authorization and key negotiation response, a second encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0043] According to one aspect, a method is provided, comprising: sending an authorization and key negotiation challenge to a user equipment; and receiving from the user equipment a first encrypted and integrity-protected authorization and key negotiation response, a second encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0044] This method can be performed by a device.

[0045] The method may include: performing successful verification of a second encrypted and integrity-protected authorization and key negotiation response; and sending a first encrypted and integrity-protected authorization and key negotiation response and a third encrypted and integrity-protected authorization and key negotiation response to a mobility management network function.

[0046] Successful verification of the second encrypted and integrity-protected authorization and key negotiation response may include: performing decryption and integrity protection verification of the second encrypted and integrity-protected authorization and key negotiation response based on the second profile.

[0047] Performing at least one of the following based on the second profile: decrypting or performing an integrity calculation on the first encrypted or integrity-protected authorization and key negotiation response. This may include performing at least one of the following based on the second profile and at least one second encryption and integrity protection key: decrypting or performing an integrity protection verification on the second encrypted and integrity-protected authorization and key negotiation response.

[0048] At least one second key used for encryption and integrity protection may include a radio resource control key K for encryption. RRCenc and the radio resource control key K used for integrity protection RRCenc .

[0049] The method may include: receiving from a user equipment an indication of supporting an optimized authentication process; and sending an indication of supporting an optimized authentication process to a mobility management network function; wherein the optimized authentication process includes exchanging an authentication and key negotiation challenge and an authentication and key negotiation response; and wherein the optimized authentication process does not include: exchanging a non-access stratum security mode command, exchanging a non-access stratum security mode command completion, exchanging an access stratum security mode command, and exchanging an access stratum security mode command completion.

[0050] The device may include a base station.

[0051] According to one aspect, an apparatus is provided, including circuitry configured to perform: sending an authorization and key negotiation challenge to a user equipment; and receiving from the user equipment a first encrypted and integrity-protected authorization and key negotiation response, a second encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0052] According to one aspect, a computer program product is provided, including computer-executable instructions that execute at runtime: sending an authorization and key negotiation challenge to a user equipment; and receiving from the user equipment a first encrypted and integrity-protected authorization and key negotiation response, a second encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0053] According to one aspect, an apparatus is provided, including at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured together with the at least one processor to cause the apparatus to at least: send instructions to a base station for a first profile and an authentication and key negotiation challenge; and receive from the base station a first encrypted and integrity-protected authorization and key negotiation response and a third encrypted and integrity-protected authorization and key negotiation response.

[0054] At least one memory and computer code may be configured, together with at least one processor, to cause the device to at least: perform successful verification of a first encrypted and integrity-protected authorization and key negotiation response; and send a third encrypted and integrity-protected authorization and key negotiation response to an authentication server function.

[0055] Successful verification of the first encrypted and integrity-protected authorization and key negotiation response may include: performing decryption and integrity protection verification of the first encrypted and integrity-protected authorization and key negotiation response based on the first profile.

[0056] Performing decryption and integrity calculations on the first encrypted and integrity-protected authorization and key negotiation response based on the first profile may include: performing decryption and integrity protection verification on the first encrypted and integrity-protected authorization and key negotiation response based on the first profile and at least one first key used for encryption and integrity protection.

[0057] At least one first key used for encryption and integrity protection may include a non-access stratum key K for encryption. NASenc and the non-access stratum key K used for integrity protection NASint .

[0058] At least one memory and computer code may be configured, together with at least one processor, to cause the apparatus to at least: receive from a base station an instruction to support an optimized authentication process; wherein the optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and wherein the optimized authentication process does not include: exchanging a non-access stratum security mode command, exchanging a non-access stratum security mode command completion, exchanging an access stratum security mode command, and exchanging an access stratum security mode command completion.

[0059] The device may include mobility management network functionality.

[0060] According to one aspect, an apparatus is provided, comprising: sending to a base station an instruction for a first profile and an authentication and key negotiation challenge; and receiving from the base station a first encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0061] According to one aspect, a method is provided, comprising: sending to a base station an instruction for a first profile and an authentication and key negotiation challenge; and receiving from the base station a first encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0062] This method can be performed by a device.

[0063] The method may include: performing successful verification of a first encrypted and integrity-protected authorization and key negotiation response; and sending a third encrypted and integrity-protected authorization and key negotiation response to the authentication server function.

[0064] Successful verification of the first encrypted and integrity-protected authorization and key negotiation response may include: performing decryption and integrity protection verification of the first encrypted and integrity-protected authorization and key negotiation response based on the first profile.

[0065] Performing decryption and integrity calculations on the first encrypted and integrity-protected authorization and key negotiation response based on the first profile may include: performing decryption and integrity protection verification on the first encrypted and integrity-protected authorization and key negotiation response based on the first profile and at least one first key used for encryption and integrity protection.

[0066] At least one first key used for encryption and integrity protection may include a non-access stratum key K for encryption. NASenc and the non-access stratum key K used for integrity protection NASint .

[0067] The method may include: receiving from a base station an indication of supporting an optimized authentication process; wherein the optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and wherein the optimized authentication process does not include: exchanging non-access stratum security mode commands, exchanging non-access stratum security mode command completion, exchanging access stratum security mode commands, and exchanging access stratum security mode command completion.

[0068] The device may include mobility management network functionality.

[0069] According to one aspect, an apparatus is provided, including circuitry configured to perform the following operations: sending an instruction to a base station for a first profile and an authentication and key negotiation challenge; and receiving from the base station a first encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0070] According to one aspect, a computer program product is provided, including computer-executable instructions that execute at runtime: sending instructions to a base station for a first profile and an authentication and key negotiation challenge; and receiving from the base station a first encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

[0071] According to one aspect, an apparatus is provided, including at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured, together with the at least one processor, to cause the apparatus to at least perform: sending an authentication and key negotiation challenge to a mobility management network function; and receiving a third encrypted and integrity-protected authorization and key negotiation response from the mobility management network function.

[0072] At least one memory and computer code can be configured, together with at least one processor, to enable the device to perform at least: successful verification of a third encrypted and integrity-protected authorization and key negotiation response; and sending an indication of successful authentication to the mobility management network function.

[0073] Successful verification of a third encrypted and integrity-protected authorization and key negotiation response may include: performing decryption and integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response based on the third profile.

[0074] Successful verification of a third encrypted and integrity-protected authorization and key negotiation response may include: performing decryption or integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response based on the third profile.

[0075] Successful verification of a third encrypted and integrity-protected authorization and key negotiation response may include: performing decryption or integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response based on the third profile.

[0076] At least one third key used for encryption and integrity protection may include an authentication server key K used for encryption. AUSFenc and the authentication server key K used for integrity protection AUSFint .

[0077] The device may include at least one of the following: authentication server functionality or unified data management.

[0078] According to one aspect, an apparatus is provided, comprising components for: sending an authentication and key negotiation challenge to a mobility management network function; and receiving a third, encrypted and integrity-protected authorization and key negotiation response from the mobility management network function.

[0079] According to one aspect, a method is provided, comprising: sending an authentication and key negotiation challenge to a mobility management network function; and receiving a third, encrypted and integrity-protected authorization and key negotiation response from the mobility management network function.

[0080] This method can be performed by a device.

[0081] The method may include: performing successful verification of a third encrypted and integrity-protected authorization and key negotiation response; and sending an indication of successful authentication to the mobility management network function.

[0082] Successful verification of a third encrypted and integrity-protected authorization and key negotiation response may include: performing decryption and integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response based on the third profile.

[0083] Successful verification of a third encrypted and integrity-protected authorization and key negotiation response may include: performing decryption or integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response based on the third profile.

[0084] Successful verification of a third encrypted and integrity-protected authorization and key negotiation response may include: performing decryption or integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response based on the third profile.

[0085] At least one third key used for encryption and integrity protection may include an authentication server key K used for encryption. AUSFenc and the authentication server key K used for integrity protection AUSFint .

[0086] The device may include at least one of the following: authentication server functionality or unified data management.

[0087] According to one aspect, an apparatus is provided, including circuitry configured to perform: sending an authentication and key negotiation challenge to a mobility management network function; and receiving a third, encrypted and integrity-protected authorization and key negotiation response from the mobility management network function.

[0088] According to one aspect, a computer program product is provided, including computer-executable instructions that execute at runtime: sending an authentication and key negotiation challenge to a mobility management network function; and receiving a third, encrypted and integrity-protected authorization and key negotiation response from the mobility management network function.

[0089] According to one aspect, a computer-readable medium is provided having program instructions stored thereon for performing at least one of the methods described above.

[0090] According to one aspect, a non-transitory computer-readable medium is provided, on which program instructions for performing at least one of the above methods are stored.

[0091] According to one aspect, a non-volatile tangible storage medium is provided, on which program instructions for performing at least one of the above methods are stored.

[0092] Many different aspects have been described above. It should be understood that additional aspects can be provided through any combination of two or more of the aspects described above.

[0093] Various other aspects are also described in the following detailed description and the appended claims.

[0094] List of abbreviations AKA: Authentication and Key Negotiation AMF: Access and Mobility Management Functions AS: Access Layer AUSF: Authentication Server Function BS: Base Station CN: Core Network EF: Base Files gNB: gNodeB HN: Home Network ID: Identifier IoT: Internet of Things MAC: Message Authentication Code ME: Mobile Device MM NF: Mobility Management Network Function MS: Mobile Station MTC: Machine Type Communication NAS: Non-Access Layer NF: Network Functions RAM: Random Access Memory (R)AN: (Radio) Access Network ROM: Read-Only Memory SEAF: Security Anchor Point Function SIDF: Subscriber ID Hiding Function SMC: Safe Mode Command SN: Service Network SUCI: Subscriber Hidden Identifier SUPI: Subscriber Permanent Identifier UDM: Unified Data Management UE: User Equipment UICC: General Purpose Integrated Circuit Card USIM: Universal Subscriber Universal Integrated Circuit Card 4G: Fourth Generation 5G: Fifth Generation 6G: Sixth generation. Attached Figure Description

[0095] Embodiments will now be described by way of example only with reference to the accompanying drawings, in which: Figure 1 A schematic representation of an example 6G communication system is shown; Figure 2 A schematic diagram of an example control device is shown; Figure 3 A schematic representation of an example user device is shown; Figure 4a and Figure 4b A signaling diagram illustrating an example process for managing security in a 6G communication system is shown. Figure 5 The radio resource control key K for encryption based on the selected profile is shown. RRCenc and the radio resource control key K used for integrity protection RRCenc A schematic representation of an example process for generating an encrypted and integrity-protected authentication and key negotiation response; Figure 6 The diagram shows the non-access stratum key K used for encryption based on the selected profile. NASenc and the non-access stratum key K used for integrity protection NASint A schematic representation of an example process for generating an encrypted and integrity-protected authentication and key negotiation response; Figure 7 The radio resource control key K for encryption based on the selected profile is shown. RRCenc and the radio resource control key K used for integrity protection RRCenc A schematic representation of an example process for verifying an encrypted and integrity-protected authentication and key negotiation response; Figure 8 The diagram shows the non-access stratum key K used for encryption based on the selected profile. NASenc and the non-access stratum key K used for integrity protection NASintA schematic representation of an example process for verifying an encrypted and integrity-protected authentication and key negotiation response; Figure 9 A schematic representation of an example list of profiles identified by profile identifiers is shown; Figure 10 A block diagram illustrating an example of a method for managing security in a communication system performed by a user equipment is shown. Figure 11 A block diagram illustrating an example of a method for managing security in a communication system, performed by a base station; Figure 12 A block diagram illustrating an example of a method for managing security in a communication system, performed by mobility management network functions; Figure 13 A block diagram illustrating an example of a method for managing security in a communication system performed by an authentication server function; Figure 14 A block diagram illustrating an example of a method for managing security in a communication system performed by a user equipment is shown. Figure 15 A block diagram illustrating an example of a method for managing security in a communication system, performed by a base station; Figure 16 A block diagram illustrating an example of a method for managing security in a communication system, performed by mobility management network functions; Figure 17 A block diagram illustrating an example of a method for managing security in a communication system performed by an authentication server function; Figure 18 A block diagram illustrating an example of a method for managing security in a communication system performed by a general-purpose integrated circuit card; Figure 19 A block diagram illustrating an example of a method for managing security in a communication system performed by a mobile device; Figure 20 A block diagram illustrating an example of a method for managing security in a communication system performed by a general-purpose integrated circuit card; Figure 21 A block diagram illustrating an example of a method for managing security in a communication system performed by a mobile device; and Figure 22 A schematic representation of a non-volatile memory medium illustrating a store instruction that, when executed by the processor, allows the processor to perform... Figures 10 to 21 One or more of the steps in any of the methods. Detailed Implementation

[0096] Figure 1A schematic representation of an example communication system is shown. The communication system may include a 6G communication system. A 6G communication system may include some or all components of a 5G communication system.

[0097] It should be understood that single or multiple aspects are discussed in the context of 6G communication systems, which can be used in conjunction with other communication systems.

[0098] The communication system may include user equipment, a radio access network (RAN), and one or more core networks (CNs). The one or more CNs may include a serving network (SN) and a home network (HN).

[0099] The RAN may include one or more base stations (BS). One or more BS may include one or more gNodeBs (gNBs). A gNodeB may include one or more gNB distributed unit functions connected to one or more gNB centralized unit functions.

[0100] A SN may include one or more network functions (NFs). One or more NFs may include a mobility management network function (MM NF) and a security anchor function (SEAF). An MM NF may be an access and mobility management function (AMF).

[0101] HN can include one or more Network Functions (NFs). One or more NFs can include Unified Data Management (UDM), Authentication Server Function (AUSF), and Subscriber Identity De-hiding Function (SIDF).

[0102] Figure 2 It shows the control such as Figure 1 An example of a control device 200 for the functions of RAN, SN, or HN is shown. The control device may include at least one random access memory (RAM) 211a, at least one read-only memory (ROM) 211b, at least one processor (processor 212, processor 213), and an input / output interface 214. At least one processor (processor 212, processor 213) may be coupled to RAM 211a and ROM 211b. At least one processor (processor 212, processor 213) may be configured to execute appropriate software code 215. Software code 215 may, for example, allow the execution of one or more steps to perform one or more of the aspects herein. Software code 215 may be stored in ROM 211b. Control device 200 may be interconnected with another control device 200 that controls another function of RAN, SN, or HN. In some embodiments, each function of RAN, SN, or HN includes control device 200. In alternative embodiments, two or more functions of RAN, SN, or HN may share a control device.

[0103] Figure 3 An example of user equipment 300 is shown, such as Figure 1 The user equipment shown is UE 300. UE 300 can be provided by any device capable of transmitting and receiving radio signals. Non-limiting examples include mobile stations (MS) or mobile devices, such as mobile phones or devices referred to as "smartphones," computers equipped with wireless interface cards or other wireless interface facilities (e.g., USB dongles), personal data assistants (PDAs) or tablet computers providing wireless communication capabilities, machine-type communication (MTC) devices, Internet of Things (IoT) devices, or any combination thereof. UE 300 can provide communication, for example, for carrying data. Communication can be one or more of the following: voice, email, text messages, multimedia, data, machine data, etc.

[0104] UE 300 can receive signals over the air or on radio interface 307 via appropriate means for receiving, and can transmit signals via appropriate means for transmitting radio signals. Figure 3 In the diagram, a transceiver device is schematically designated by box 306. Transceiver device 306 may be provided, for example, via a radio section and an associated antenna arrangement. The antenna arrangement may be located inside or outside the mobile device.

[0105] UE 300 may include at least one processor 301, at least one memory ROM 302a, at least one RAM 302b, and other possible components 303 for use in the software and hardware-assisted execution of the tasks it is designed to perform, including access to access systems and other communication devices, and control of communication with access systems and other communication devices. At least one processor 301 is coupled to RAM 302b and ROM 302a. At least one processor 301 may be configured to execute appropriate software code 308. Software code 308 may, for example, allow the execution of one or more of these aspects. Software code 308 may be stored in ROM 302a.

[0106] Processors, storage devices, and other related control units can be mounted on appropriate circuit boards and / or chipsets. This feature is indicated by reference numeral 304. The device may optionally have a user interface, such as a keypad 305, a touch-sensitive screen or keypad, or a combination thereof. Optionally, depending on the type of device, one or more of a display, speakers, and microphone may be provided.

[0107] One or more aspects of this disclosure relate to managing security in communication systems, particularly in 6G communication systems.

[0108] 6G is expected to provide global coverage in the air, space, on land, and at sea. There are many scenarios where reducing security-related signaling is necessary, such as satellite and lightweight IoT. Therefore, 6G systems will minimize security-related signaling (such as authentication and secure activation) while maintaining current security levels.

[0109] 6G networks will break down communication barriers between various networks, such as public terrestrial networks, satellite networks, the Internet of Things (IoT), and body area networks (BLA), enabling cross-network collaboration in communication. Furthermore, compared to the terminal forms of the 5G era, 6G terminals will be more diverse, with available devices in various shapes and sizes to cater to different levels of complexity and cost, and all will be able to access 6G networks for mobile services.

[0110] To protect mobile communications, 5G has implemented independent security procedures, such as network-initiated authentication request / response messages to ensure mutual authentication between the UE and the network, and security mode command / completion messages for algorithmic negotiation between the UE and the network. These procedures are specifically designed for SA3. Since security is a mandatory feature, these signaling procedures are mandatory for each UE when registering with the network.

[0111] In the early stages of 5G, full support for standalone security-related signaling was not an issue when most use cases involved mobile broadband services, as such signaling had little impact on smartphones. However, as 5G Advanced (5GA) expands service scenarios, standalone security signaling becomes less suitable for scenarios such as satellite communications. Satellite node resources are limited, and the distance between the satellite and the UE is very long; yet, it requires six messages to register with the network: registration request, authentication request, authentication response, security mode command, security mode completion, and registration completion. This interaction significantly increases the latency between the UE and the satellite. Similarly, for lightweight IoT devices that can be charged by electromagnetic waves (such as AIoT devices), fewer signaling interactions will reduce the capability requirements of IoT devices, thereby reducing their cost and simplifying commercialization.

[0112] Given that 6G will initially support all of these scenarios, it is important from the outset to minimize mandatory security signaling (such as authentication and secure mode commands) as much as possible without compromising the current security level. This will result in performance-friendly and backward-compatible security features.

[0113] Figure 4a and Figure 4bA signaling diagram illustrating an example procedure for managing security in a 6G communication system is shown. This procedure can be performed by a UE, BS (e.g., gNB), MM NF (e.g., AMF), AUSF, and UDM. The UE may include a Universal Integrated Circuit Card (UICC) and a Mobile Equipment (ME). The UICC may include a Universal Subscriber Identification Module (USIM).

[0114] In step 1a, the BS may pre-store multiple profiles. Each profile includes at least one algorithm for encryption and integrity protection. Each profile may include multiple algorithms (e.g., an algorithm for encryption and an algorithm for integrity protection). Alternatively, each profile may include a single algorithm (e.g., an algorithm for encryption and integrity protection). The multiple profiles may be pre-stored by the operator of the SN.

[0115] In this disclosure, the terms "profile" and "security profile" are used interchangeably.

[0116] The MM NF can pre-store multiple profiles. Each profile includes at least one algorithm for encryption and integrity protection. Each profile may include multiple algorithms (e.g., an algorithm for encryption and an algorithm for integrity protection). Alternatively, each profile may include a single algorithm (e.g., an algorithm for both encryption and integrity protection). The multiple profiles can be pre-stored by the SN operator.

[0117] In step 1b, AUSF may send one or more messages to USIM via MM NF, BS, and ME. The one or more messages may include multiple profiles. Each profile includes at least one algorithm for encryption and integrity protection. Each profile may include multiple algorithms (e.g., an algorithm for encryption and an algorithm for integrity protection). Alternatively, each profile may include a single algorithm (e.g., an algorithm for encryption and integrity protection).

[0118] In step 2, USIM can store multiple profiles. Each profile includes at least one algorithm for encryption and integrity protection. Each profile may include multiple algorithms (e.g., an algorithm for encryption and an algorithm for integrity protection). Alternatively, each profile may include a single algorithm (e.g., an algorithm for both encryption and integrity protection). USIM can store multiple profiles in a base file (EF).

[0119] Alternatively, the UE can pre-store multiple profiles provided by the HN operator.

[0120] It should be understood that multiple profiles stored or pre-stored by the USIM may be the same as multiple profiles stored by the BS and / or multiple profiles stored by the MM NF. Alternatively, multiple profiles stored or pre-stored by the USIM may be different from multiple profiles stored by the BS and / or multiple profiles stored by the MM NF.

[0121] In step 3, the ME can initiate the initial registration process with the SN.

[0122] In step 4a, the ME may send one or more messages to the USIM (e.g., an identity request). These messages may include an indication to receive a hidden UE identifier. The hidden UE identifier may include a Subscriber Hidden Identifier (SUCI). The messages may include an indication to receive at least one profile selected from a plurality of profiles stored or pre-stored by the USIM. The messages may also include indications for a plurality of profiles stored or pre-stored by the USIM. The messages may include a SN identifier. The SN identifier may include a Public Land Mobile Network (PLMN) code.

[0123] In the implementation (Option 1), at step 4b1, the USIM can select at least one profile from a plurality of profiles stored or pre-stored by the USIM based on the SN. The SN can be identified by an SN identifier.

[0124] Multiple profiles stored or pre-stored by the USIM may include at least one profile associated with a SN. Selecting at least one profile from multiple profiles stored or pre-stored by the USIM based on the SN may include selecting at least one profile associated with the SN.

[0125] It should be understood that selecting at least one profile from a plurality of profiles stored or stored by the USIM based on the SN may include: selecting at least one profile from a plurality of profiles stored or stored by the USIM when the SN is a first SN, and selecting at least one other profile from a plurality of profiles stored or stored by the USIM when the SN is a second SN.

[0126] In step 4c1, the USIM may send one or more messages to the ME. The one or more messages may include a hidden UE identifier. The one or more messages may include an indication of at least one selected profile.

[0127] In another implementation (Option 2), at step 4b2, USIM can select multiple profiles that are stored or pre-stored by USIM.

[0128] In step 4c2, the USIM may send one or more messages to the ME. The one or more messages may include a hidden UE identifier. The one or more messages may include indications of multiple profiles stored or pre-stored by the USIM.

[0129] At step 4d2, the ME can select at least one profile from a plurality of profiles stored or pre-stored by the USIM based on the ME’s ability to support at least one profile.

[0130] It should be understood that if ME can support at least one algorithm for encryption and integrity protection of at least one profile, then ME can support at least one profile.

[0131] In step 5, the ME can initiate a registration request based on the hidden UE identifier and at least one selected profile.

[0132] In step 6a, the ME may send one or more messages (e.g., a registration request) to the MM NF via the BS. The one or more messages may include a hidden UE identifier. The one or more messages may include an indication of at least one selected profile.

[0133] One or more messages may include indications that the ME can support an optimized authentication process. The optimized authentication process may include an exchanged authentication and key negotiation (AKA) challenge and an AKA response. However, the optimized authentication process may not include an exchanged Non-Access Stratum (NAS) Security Mode Command (SMC), an exchanged NAS SMC completion, an exchanged Access Stratum (AS) Security Mode Command (SMC), and an exchanged AS SMC completion.

[0134] At step 6b, the MM NF may store at least one of the selected profiles. The MM NF may also store indications that the ME can support an optimized authentication process (e.g., setting a true flag).

[0135] At step 6c, the MM NF may send one or more messages (e.g., authentication requests) to the AUSF. The one or more messages may include a hidden UE identifier. The one or more messages may include an instruction to dehide the hidden UE identifier.

[0136] The AUSF can send one or more messages to the UDM. These messages may include a hidden UE identifier. They may also include instructions to unhide the hidden UE identifier.

[0137] The UDM can send one or more messages to the SIDF. These messages may include a hidden UE identifier. They may also include instructions to unhide the hidden UE identifier.

[0138] The UDM can receive one or more messages from the SIDF. These messages include a de-hidden UE identifier. The de-hidden UE identifier may include a Subscriber Permanent Identifier (SUPI).

[0139] UDM can generate AKA challenges.

[0140] The UDM can generate (i.e., derive) an encryption key CK or an integrity key IK based on a long-term key K and one or more key derivation functions. The long-term key can be stored on the UDM.

[0141] UDM can generate (e.g., derive) the AUSF key K based on the encryption key "CK" and the integrity key "IK" and one or more key derivation functions. AUSF .

[0142] The UDM can send one or more messages (e.g., authentication responses) to the AUSF. One or more messages may include an AKA challenge. One or more messages may include a de-hidden UE identifier. One or more messages may include the AUSF key K. AUSF Alternatively, AUSF can generate (e.g., derive) the AUSF key K based on the encryption key "CK" and the integrity key "IK". AUSF .

[0143] AUSF can be based on the AUSF key K AUSF and one or more key export functions to generate (e.g., export) the SEAF key K. SEAF AUSF can store the AUSF key K. AUSF and SEAF key K SEAF .

[0144] In step 7b, the AUSF may send one or more messages to the MM NF. The one or more messages may include an AKA challenge. The one or more messages may include a de-hidden UE identifier. The one or more messages may include the SEAF key K. SEAF .

[0145] In step 7c, MM NF may select the first profile from the at least one selected profile.

[0146] In step 7d, the MM NF may send one or more messages to the BS. The one or more messages may include indications of at least one selected profile. The one or more messages may include indications of a first profile. The one or more messages may include indications of initial context establishment.

[0147] BS can select a second profile from at least one of the selected profiles. The second profile can be the same as the first profile. Alternatively, the second profile can be different from the first profile.

[0148] In step 7e, MM NF can be based on SEAF key K SEAF And one or more key derivation functions to generate (i.e., derive) the MM NF key K. MM NF .

[0149] MM NF can be based on SEAF key K SEAF and one or more key export functions to generate (i.e., export) a NAS key K for encryption. NASenc and NAS key K used for integrity protection NASint .

[0150] MM NF can be based on MM NF key K MM NF and one or more key export functions to generate (e.g., export) the BS key K. BS .

[0151] MM NF can send one or more messages to BS. One or more messages may include the BS key K. BS Instructions.

[0152] BS can be based on BS key K BS And one or more key export functions to generate (i.e., export) the RRC key K for encryption. RRCenc and the RRC key K used for integrity protection RRCint .

[0153] In this disclosure, "RRC key K used for encryption" is stated. RRCenc "and "AS key K used for encryption" Asenc "Can be used interchangeably. The expression "RRC key K used for integrity protection" RRCint "and "AS key KAS for integrity protection" int "They can be used interchangeably."

[0154] At step 7f, the BS may send one or more messages (e.g., authentication requests) to the ME. The one or more messages may include an AKA challenge. The one or more messages may include instructions for a first profile. The one or more messages may include instructions for a second profile.

[0155] At step 8a, the ME may send one or more messages to the USIM. The one or more messages may include the AKA challenge.

[0156] USIM can perform successful verification of the AKA challenge (i.e., the AKA challenge matches the expected AKA challenge).

[0157] USIM can generate an AKA response.

[0158] USIM can generate (i.e., derive) an encryption key CK or an integrity key IK based on a long-term key K and one or more key derivation functions. The long-term key can be stored on USIM.

[0159] USIM can send one or more messages to ME. One or more messages may include an AKA response. One or more messages may include an encryption key CK. One or more messages may include an integrity key IK.

[0160] ME can generate (i.e. derive) the AUSF key K based on the cryptographic key "CK", the integrity key "IK", and one or more key derivation functions. AUSF .

[0161] ME can be based on the AUSF key K AUSF and one or more key export functions to generate (e.g., export) the SEAF key K. SEAF .

[0162] ME can be based on SEAF key K SEAF And one or more key derivation functions to generate (i.e., derive) the MM NF key K. MM NF .

[0163] ME can be based on SEAF key K SEAF and one or more key export functions to generate (i.e., export) a NAS key K for encryption. NASenc and NAS key K used for integrity protection NASint ME can be based on MM NF key K MM NF and one or more key export functions to generate (e.g., export) the BS key K. BS .

[0164] ME can be based on BS key K BS And one or more key export functions to generate (i.e., export) the RRC key K for encryption. RRCenc and the RRC key K used for integrity protection RRCint .

[0165] ME can generate the following based on the AKA response: a first encrypted and integrity-protected AKA response, at least one encryption and integrity protection algorithm for the first profile, and at least one first key for encryption and integrity protection (e.g., a NAS key K for encryption). NASenc and NAS key K used for integrity protection NASint).

[0166] ME can generate a second encrypted and integrity-protected AKA response based on the AKA response, wherein at least one algorithm is used for encryption and integrity protection of the second profile, and at least one second key is used for encryption and integrity protection (e.g., an RRC key K for encryption). RRCenc and the RRC key K used for integrity protection RRCint ).

[0167] ME can be based on an AKA response, at least one algorithm for encryption and integrity protection of the third document, and at least one third key for encryption and integrity protection (e.g., an AUSF key K). AUSF ), generating a third encrypted and integrity-protected AKA response.

[0168] Unlike the first and second profiles, the third profile may include a default profile. The default profile may include multiple default algorithms (e.g., a default algorithm for encryption and a default algorithm for integrity protection). These multiple default algorithms may be standardized. Alternatively, the default profile may include a single default algorithm (e.g., a default algorithm for encryption and a default algorithm for integrity protection). This single default algorithm may be standardized.

[0169] In step 8c, the ME may send one or more messages (e.g., authentication responses) to the MM NF. The one or more messages may include a first encrypted and integrity-protected AKA response (e.g., MM NF RES / MM NF RES). One or more messages may include a second encrypted and integrity-protected AKA response (e.g., RAN RES / RAN RES). One or more messages may include a third encrypted and integrity-protected AKA response (e.g., HN RES / HN RES). ).

[0170] In step 8d, BS may base its encryption on at least one algorithm for encrypting the second profile and at least one second key for encryption (e.g., RRC key K for encryption). RRCenc ), decrypt the second encrypted and integrity-protected AKA response (e.g., RAN RES / RAN RES) ).

[0171] BS can be based on at least one algorithm for integrity protection of the second profile and at least one second key for integrity protection (e.g., an RRC key K for integrity protection). RRCint This verifies the integrity of the decrypted but still integrity-protected AKA response.

[0172] In step 8e, the BS may send one or more messages (e.g., authentication responses) to the MM NF. The one or more messages may include a first encrypted and integrity-protected AKA response (e.g., MM NF RES / MM NF RES). One or more messages may include a third encrypted and integrity-protected AKA response (e.g., HN RES / HN RES). ).

[0173] In step 8f, MM NF can be based on at least one algorithm for encrypting the first profile and at least one first key for encryption (e.g., NAS key K for encryption). NASenc Decrypt the first encrypted and integrity-protected AKA response (e.g., MM NF RES / MM NF RES). ).

[0174] MM NF can be based on at least one algorithm for integrity protection of the first profile and at least one first key for integrity protection (e.g., NAS key K for integrity protection). NASint This verifies the integrity of the decrypted but still integrity-protected AKA response.

[0175] In step 8f, the MM NF may send one or more messages (e.g., authentication requests) to the AUSF. The one or more messages may include a hidden UE identifier. The one or more messages may include a third encrypted and integrity-protected AKA response (e.g., HN RES / HN RES). ).

[0176] AUSF or UDM can be based on at least one algorithm used to encrypt the third document and at least one third key (e.g., AUSF key K). AUSF ), to a third encrypted and integrity-protected AKA response (e.g., HN NF RES / HN RES) Decryption is performed.

[0177] AUSF or UDM can be based on at least one algorithm for integrity protection of the third profile and at least one third key for integrity protection (e.g., AUSF key K). AUSF This verifies the integrity of the decrypted but still integrity-protected AKA response.

[0178] In step 9a, the AUSF may send one or more messages (e.g., an authentication response) to the MM NF. The one or more messages may include an indication of successful authentication.

[0179] In step 9b, the MM NF may send one or more messages (e.g., an authentication response) to the BS. The one or more messages may include indications of successful authentication. The one or more messages may include indications of initial context establishment.

[0180] In step 9c, no AS SMC or NAS SMC process runs independently between the ME, BS, and MM NF. The AS security context and NAS security context are implicitly established in the ME, BS, and MM NF.

[0181] In MM NF, BS and UE can establish security contexts in AS and NAS.

[0182] Figure 5 The algorithm for encryption based on the selected profile and the algorithm for integrity protection of the selected profile are shown, along with the RRC key K for encryption. RRCenc and the RRC key K used for integrity protection RRCenc Generates encrypted and integrity-protected AKA responses (e.g., RAN RES / RAN RES). A schematic representation of an example process.

[0183] This process can be found in section 7.2.1 of 3GPP TS 33.501. The process may include three phases.

[0184] In Phase 1, the BS can select a profile (e.g., profile A) from a list of profiles chosen by the UE. The profile includes an algorithm for encryption and another algorithm for integrity protection. The profile may require an RRC key K for encryption. RRCenc and the RRC key K used for integrity protection RRCenc Alternatively, the profile may include a single encryption and / or integrity protection algorithm (e.g., AEAD). The profile may require a single RRC key K for encryption and / or integrity protection. RRCenc and / or int .

[0185] In Phase 2, the BS can base its actions on the AKA response, brief, and RRC key K used for integrity protection. RRCint This generates an integrity-protected AKA response (e.g., MAC-I). The BS can then use the AKA response, shorthand, and the RRC key K for encryption as a basis. RRCenc To generate an encrypted AKA response.

[0186] In phase 3, BS can generate an integrity-protected and an encrypted AKA response based on the integrity-protected AKA response and the encrypted AKA response.

[0187] Figure 6The diagram illustrates the algorithms used for encryption and integrity protection based on the selected profile, and the NAS key K used for encryption. NASenc and NAS key K used for integrity protection NASint To generate an encrypted and integrity-protected AKA response (e.g., MM NF RES / MM NF RES). A schematic representation of an example procedure.

[0188] This process can be found in section 7.2.2 of 3GPP TS 33.501. The process may include three phases.

[0189] In Phase 1, the MM NF can select a profile (e.g., profile D) from a list of profiles chosen by the UE. The profile includes an algorithm for encryption and another algorithm for integrity protection. The profile may require a NAS key K for encryption. NASenc and NAS key K used for integrity protection NASenc Alternatively, the profile may include a single encryption and / or integrity protection algorithm (e.g., AEAD). The profile may require a single NAS key K for encryption and / or integrity protection. NASenc and / or int .

[0190] In Phase 2, MM NF can be based on AKA response, brief, and NAS key K used for integrity protection. NASint This generates an integrity-protected AKA response (e.g., MAC-I). MM NF can be based on the AKA response, a brief, and the NAS key K used for encryption. NASenc To generate an encrypted AKA response.

[0191] In Phase 3, MM NF can generate integrity-protected and encrypted AKA responses based on integrity-protected and encrypted AKA responses.

[0192] It should be understood that, with Figure 5 The process and Figure 6 Similar processes can be performed by AUSF and / or UDM. However, unlike BS and MM NF, AUSF and / or UDM can dynamically select profiles from the list of profiles selected by the UE. AUSF and / or UDM can select static (e.g., standardized) profiles.

[0193] In Phase 1, AUSF and / or UDM can choose a static profile. The profile includes the algorithm used for encryption and another algorithm used for integrity protection. The profile may require an AUSF key K for encryption. AUSFenc and the AUSF key K used for integrity protection AUSFencAlternatively, the profile may include a single encryption and / or integrity protection algorithm (e.g., AEAD). The profile may require a single AUSF key K for encryption and / or integrity protection. AUSFenc and / or int .

[0194] In Phase 2, AUSF and / or UDM can be based on the AKA response, brief, and AUSF key K used for integrity protection. AUSFenc This generates an integrity-protected AKA response (e.g., MAC-I). AUSF and / or UDM can be based on the AKA response, the shorthand, and the AUSF key K used for encryption. AUSFenc To generate an encrypted AKA response.

[0195] In Phase 3, AUSF and / or UDM can generate integrity-protected and encrypted AKA responses based on integrity-protected and encrypted AKA responses.

[0196] Figure 7 The algorithm for encryption and the algorithm for integrity protection based on the selected profile are shown, along with the RRC key K for encryption. RRCenc and the RRC key K used for integrity protection RRCint To verify encrypted and integrity-protected AKA responses (e.g., RAN RES / RAN RES) A schematic representation of an example procedure.

[0197] This process can be found in Section 7.3 of 3GPP TS 38.331. The process may include three phases.

[0198] In Phase 1, the BS can select a profile (e.g., profile A) from a list of profiles chosen by the UE. The profile includes an algorithm for encryption and another algorithm for integrity protection. The profile may require an RRC key K for encryption. RRCenc and the RRC key K used for integrity protection RRCenc Alternatively, the profile may include a single encryption and / or integrity protection verification algorithm (e.g., AEAD). The profile may require a single RRC key K for encryption and / or integrity protection. RRCenc and / or int .

[0199] In Phase 2, the BS can base its work on the encrypted AKA response, the profile, and the RRC key K used for encryption. RRCenc To generate a decrypted AKA response.

[0200] In Phase 3, the BS can base its actions on the decrypted AKA response, the brief, and the RRC key K used for integrity protection. RRCintTo verify the integrity of the decrypted AKA response (e.g., XMAC-I).

[0201] Figure 8 The diagram illustrates the algorithms used for encryption and integrity protection based on the selected profile, and the NAS key K used for encryption. NASenc and NAS key K used for integrity protection NASint To verify encrypted and integrity-protected AKA responses (e.g., MM NF RES / MM NF RES). A schematic representation of an example procedure.

[0202] In Phase 1, the MM NF can select a profile (e.g., profile D) from a list of profiles chosen by the UE. The profile includes an algorithm for encryption and another algorithm for integrity protection. The profile may require a NAS key K for encryption. NASenc and NAS key K used for integrity protection NASenc Alternatively, the profile may include a single encryption and / or integrity protection authentication algorithm (e.g., AEAD). The profile may require a single NAS key K for encryption and / or integrity protection. NASenc and / or int .

[0203] In Phase 2, MM NF can be based on an encrypted AKA response, a shorthand document, and a NAS key K used for encryption. NASenc To generate a decrypted AKA response.

[0204] In Phase 3, MM NF can be based on the decrypted AKA response, brief, and NAS key K used for integrity protection. NASint To verify the integrity of the decrypted AKA response (e.g., XMAC-I).

[0205] It should be understood that, with Figure 7 The process and Figure 8 Similar processes can be performed by AUSF and / or UDM. However, unlike BS and MM NF, AUSF and / or UDM can dynamically profile files not selected by the UE from the profile list. AUSF and / or UDM can select static (e.g., normalized) profiles.

[0206] In Phase 1, AUSF and / or UDM can choose a static profile. The profile includes the algorithm used for encryption and another algorithm used for integrity protection. The profile may require an AUSF key K for encryption. AUSFenc and the AUSF key K used for integrity protection AUSFencAlternatively, the profile may include a single encryption and / or integrity protection algorithm (e.g., AEAD). The profile may require a single AUSF key K for encryption and / or integrity protection. AUSFenc and / or int .

[0207] In Phase 2, AUSF and / or UDM can be based on the encrypted AKA response, profile, and AUSF key K used for encryption. AUSFenc To generate a decrypted AKA response.

[0208] In Phase 3, AUSF and / or UDM can be based on the decrypted AKA response, brief, and AUSF key K used for integrity protection. AUSFint To verify the integrity of the decrypted AKA response (e.g., XMAC-I).

[0209] Figure 9 A schematic representation of an example list of profiles identified by profile identifiers is shown. Profile identifier "0000" can identify 6G AKA profile A. Profile identifier "0001" can identify 6G AKA profile B. Profile identifier "0010" can identify 6G AKA profile C. Profile identifiers "0100" through "1011" can be reserved. Profile identifiers "1100" through "1111" can be associated with a specific service network (e.g., having a specific PLMN code).

[0210] Figure 10 A block diagram illustrating an example of a method for managing security in a communication system performed by a UE is shown.

[0211] At step 1000, the UE may select at least one profile including at least one algorithm for encryption and integrity protection.

[0212] At step 1002, the UE may send a hidden device identifier and an indication of at least one profile to the BS.

[0213] At step 1004, the UE may receive from the BS an AKA challenge, an instruction for a first profile selected by the MM NF from at least one profile, and an instruction for a second profile selected by the BS from at least one profile.

[0214] At step 1006, the UE can perform a successful verification of the AKA challenge.

[0215] At step 1008, the UE may generate a first encrypted and integrity-protected AKA response based on the AKA response and the first profile.

[0216] At step 1010, the UE may generate a second encrypted and integrity-protected AKA response based on the AKA response and the second profile.

[0217] At step 1012, the UE can generate a third encrypted and integrity-protected AKA response based on the AKA response and the third profile.

[0218] At step 1014, the UE may send a first encrypted and integrity-protected AKA response, a second encrypted and integrity-protected AKA response, and a third encrypted and integrity-protected AKA response to the BS.

[0219] Figure 11 A block diagram illustrating an example of a method for managing security in a communication system implemented by a BS is shown.

[0220] At step 1100, the BS may receive from the UE a hidden UE identifier and an indication of at least one profile selected by the UE, wherein the at least one profile includes at least one algorithm for encryption and integrity protection.

[0221] At step 1102, the BS may send a hidden UE identifier and an indication of at least one profile selected by the UE to the MM NF.

[0222] At step 1104, the BS can receive from the MM NF an instruction for at least one profile selected by the UE, an instruction for a first profile selected by the MM NF from at least one profile, and an AKA challenge.

[0223] At step 1106, the BS may select a second profile from at least one profile selected by the UE.

[0224] At step 1108, the BS may send the UE an AKA challenge, an instruction for the first profile selected by the MM NF, and an instruction for the second profile selected by the BS.

[0225] At step 1110, the BS can receive a first encrypted or integrity-protected AKA response, a second encrypted or integrity-protected AKA response, and a third encrypted or integrity-protected AKA response from the UE.

[0226] Figure 12 A block diagram illustrating an example of a method for managing security in a communication system implemented by MM NF is shown.

[0227] At step 1200, the MM NF can receive from the BS a hidden UE identifier and an indication of at least one profile selected by the UE, wherein the at least one profile includes at least one algorithm for encryption and integrity protection.

[0228] At step 1202, the MM NF can send a hidden UE identifier to the AUSF.

[0229] At step 1204, the MM NF can receive the de-hidden UE identifier and AKA challenge from the AUSF.

[0230] In step 1206, MM NF may select a first profile from at least one profile selected by the UE.

[0231] At step 1208, MM NF can send instructions to BS regarding the first profile and AKA challenge.

[0232] In step 1210, the MM NF can receive a first encrypted and integrity-protected AKA response and a third encrypted and integrity-protected authorization and key negotiation response from the BS.

[0233] Figure 13 A block diagram illustrating an example of a method for managing security in a communication system implemented by AUSF is shown.

[0234] In step 1300, AUSF can send an AKA challenge to MM NF.

[0235] In step 1302, AUSF can receive a third encrypted and integrity-protected AKA response from MM NF.

[0236] Figure 14 A block diagram illustrating an example of a method for managing security in a communication system performed by a UE is shown.

[0237] At step 1400, the UE may generate a first encrypted and integrity-protected AKA response based on the AKA response and the first profile.

[0238] At step 1402, the UE may generate a second encrypted and integrity-protected AKA response based on the AKA response and the second profile.

[0239] At step 1404, the UE can generate a third encrypted and integrity-protected AKA response based on the AKA response and the third profile.

[0240] At step 1406, the UE may send a first encrypted and integrity-protected AKA response, a second encrypted and integrity-protected AKA response, and a third encrypted and integrity-protected AKA response to the BS.

[0241] Figure 15 A block diagram illustrating an example of a method for managing security in a communication system implemented by a BS is shown.

[0242] At step 1500, the BS can send an AKA challenge to the UE.

[0243] At step 1502, the BS can receive a first encrypted and integrity-protected AKA response, a second encrypted and integrity-protected AKA response, and a third encrypted and integrity-protected AKA response from the UE.

[0244] Figure 16 A block diagram illustrating an example of a method for managing security in a communication system implemented by MM NF is shown.

[0245] At step 1600, MM NF can send instructions to BS regarding the first profile and the AKA challenge.

[0246] In step 1602, the MM NF can receive a first encrypted and integrity-protected AKA response and a third encrypted and integrity-protected AKA response from the BS.

[0247] Figure 17 A block diagram illustrating an example of a method for managing security in a communication system implemented by AUSF is shown.

[0248] In step 1700, AUSF can send an AKA challenge to MM NF.

[0249] In step 1702, AUSF can receive a third encrypted and integrity-protected AKA response from MM NF.

[0250] Figure 18 A block diagram illustrating an example of a method for managing security in a communication system implemented by UICC is shown.

[0251] In step 1800, the UICC may store multiple profiles, each of which includes at least one algorithm for encryption and integrity protection.

[0252] At step 1802, the UICC may receive a request from the ME for an indication to receive a hidden UE identifier and at least one profile.

[0253] In step 1804, UICC can select at least one profile from multiple profiles based on the service network.

[0254] At step 1806, the UICC may send a hidden UE identifier and an indication of at least one profile to the ME.

[0255] Figure 19 A block diagram illustrating an example of a method for managing security in a communication system performed by an ME is shown.

[0256] At step 1900, the ME may send a request to the UICC for an indication to receive a hidden UE identifier and at least one profile, wherein the at least one profile includes at least one algorithm for encryption and integrity protection.

[0257] At step 1902, the ME can receive a hidden UE identifier and an indication of at least one profile from the UICC.

[0258] Figure 20 A block diagram illustrating an example of a method for managing security in a communication system implemented by UICC is shown.

[0259] In step 2000, the UICC may store multiple profiles, each of which includes at least one algorithm for encryption and integrity protection.

[0260] At step 2002, the UICC can receive a request from the ME for instructions to receive a hidden UE identifier and multiple profiles.

[0261] At step 2004, the UICC can send a hidden UE identifier and instructions for multiple profiles to the ME.

[0262] Figure 21 A block diagram illustrating an example of a method for managing security in a communication system performed by an ME is shown.

[0263] At step 2100, the ME may receive a hidden UE identifier and instructions for multiple profiles from the UICC, wherein each of the multiple profiles includes at least one algorithm for encryption and integrity protection.

[0264] At step 2102, the ME may receive a hidden UE identifier and instructions for multiple profiles from the UICC, wherein each of the multiple profiles includes at least one algorithm for encryption and integrity protection.

[0265] Figure 22 A schematic diagram of a non-volatile memory medium 2000 for storing instructions is shown, which allows the processor to execute instructions when executed by the processor. Figures 10 to 21 One or more steps of any of the methods.

[0266] Note that although example embodiments have been described above, several changes and modifications may be made to the disclosed solutions without departing from the scope of this disclosure.

[0267] Therefore, embodiments may vary within the scope of the appended claims. Typically, some embodiments may be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. For example, some aspects may be implemented in hardware, while others may be implemented in firmware or software, which may be executed by a controller, microprocessor, or other computing device, but embodiments are not limited thereto. While various embodiments may be illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it is well understood that the blocks, apparatuses, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware, or controllers or other computing devices, or some combination thereof, as non-limiting examples.

[0268] The embodiments can be implemented by computer software, which is stored in memory and can be executed by at least one data processor in the entities involved, or by hardware, or by a combination of software and hardware. Furthermore, in this regard, it should be noted, for example, as in... Figures 10 to 21 Any process in any diagram may represent a program step, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. Software may be stored in physical media such as memory chips, or memory blocks implemented within a processor, magnetic media such as hard disks or floppy disks, and optical media such as, for example, DVDs and their data variants CDs.

[0269] The memory can be of any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor can be of any type suitable for the local technical environment and, by way of non-limiting example, can include one or more of the following: general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), gate-level circuits, and processors based on multi-core processor architectures.

[0270] Alternatively or additionally, some embodiments may be implemented using circuitry. The circuitry may be configured to perform one or more of the previously described functions and / or method steps. This circuitry may be located in a base station and / or communication equipment.

[0271] As used in this application, the term "circuit" may refer to one or more or all of the following: (a) Hardware circuit only options (such as options in analog and / or digital circuits only); (b) A combination of hardware circuitry and software, for example: (i) A combination of (multiple) analog and / or digital hardware circuits and software / firmware, and (ii) Any part of a hardware processor having software (including (multiple) digital signal processors), software, and memory, which work together to enable an apparatus (such as a communication device or base station) to perform the various functions previously described; and (c) Multiple hardware circuits and / or multiple processors, such as multiple microprocessors or a portion thereof, that require software (e.g., firmware) to operate, but the software may not be present when operation is not required.

[0272] This definition of "circuit" applies to all uses of the term in this application, including in any claim. As another example, as used in this application, the term "circuit" also covers the option of: hardware circuitry or a processor (or processors) alone, or a portion of hardware circuitry or a processor and its accompanying software and / or firmware. The term "circuit" also covers, for example, integrated devices.

[0273] As used in the specification and claims, the term "component" can refer to one or more individual elements configured to perform a corresponding described function or feature, or it can refer to several elements performing such a function or feature. Furthermore, the functions recited in the claims can be performed by the same individual components or combinations of the same components. For example, performing such a function or feature can be caused within the device by a processor executing instructions stored in the device's memory.

[0274] The foregoing description has provided a complete and informative description of some embodiments by way of exemplary and non-limiting examples; however, various modifications and adaptations will become apparent to those skilled in the art when read in conjunction with the accompanying drawings and appended claims, given the foregoing description. Nevertheless, all such and similar modifications to this teaching will still fall within the scope defined in the appended claims.

Claims

1. An apparatus for communication, comprising at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured, together with the at least one processor, to cause the apparatus to perform at least: Based on the authorization and key negotiation response and the first profile, generate a first encrypted and integrity-protected authorization and key negotiation response; Based on the authorization and key negotiation response and the second profile, a second encrypted and integrity-protected authorization and key negotiation response is generated; Based on the authorization and key negotiation response and the third profile, a third encrypted and integrity-protected authorization and key negotiation response is generated; as well as Send the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to the base station.

2. The apparatus according to claim 1, wherein the first profile is the same as the second profile; or The first profile differs from the second profile.

3. The apparatus according to claim 1 or claim 2, wherein the third profile includes a default profile, wherein the default profile includes at least one default algorithm for at least one of the encryption algorithm or integrity protection algorithm.

4. The apparatus of claim 1 or claim 2, wherein generating the first encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the first profile comprises: The first encrypted and integrity-protected authorization and key negotiation response is generated based on the authorization and key negotiation response, the first profile, and at least one first key for encryption and integrity protection.

5. The apparatus of claim 1 or claim 2, wherein generating the second encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the second profile comprises: The second encrypted and integrity-protected authorization and key negotiation response is generated based on the authorization and key negotiation response, the second profile, and at least one second key for encryption and integrity protection.

6. The apparatus of claim 1 or claim 2, wherein generating the third encrypted and integrity-protected authorization and key negotiation response based on the authorization and key negotiation response and the third profile comprises: The third encrypted and integrity-protected authorization and key negotiation response is generated based on the authorization and key negotiation response, the third profile, and at least one third key for encryption and integrity protection.

7. The apparatus of claim 4, wherein the at least one first key for encryption and integrity protection is derived from at least one third key for encryption and integrity protection; and The at least one second key used for encryption and integrity protection is derived from the at least one first key used for encryption and integrity protection.

8. The apparatus of claim 1 or claim 2, wherein the at least one memory and the computer code are configured, together with the at least one processor, to cause the apparatus to perform at least: Send an instruction to the base station to support the optimized authentication process; The optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and The optimized authentication process described herein does not include: switching non-access stratum security mode commands, switching non-access stratum security mode command completion, switching access stratum security mode commands, and switching access stratum security mode command completion.

9. The apparatus of claim 8, wherein the apparatus includes user equipment.

10. An apparatus for communication, comprising at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured, together with the at least one processor, to cause the apparatus to perform at least: Send an authorization and key negotiation challenge to the user equipment; and The user equipment receives a first encrypted and integrity-protected authorization and key negotiation response, a second encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

11. The apparatus of claim 10, wherein the at least one memory and the computer code are configured, together with the at least one processor, to cause the apparatus to perform at least: Perform successful verification of the second encrypted and integrity-protected authorization and key negotiation response; and Send the first encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to the mobility management network function.

12. The apparatus of claim 11, wherein performing successful verification of the second encrypted and integrity-protected authorization and key negotiation response comprises: Based on the second profile, decryption and integrity protection verification are performed on the second encrypted and integrity-protected authorization and key negotiation response.

13. The apparatus of claim 12, wherein performing at least one of the decryption or integrity calculation of the first encrypted or integrity-protected authorization and key negotiation response based on the second profile comprises: Based on the second profile and at least one second encryption and integrity protection key, perform at least one of decryption and integrity protection verification of the second encrypted and integrity protected authorization and key negotiation response.

14. The apparatus according to any one of claims 10 to 13, wherein the at least one memory and the computer code are configured, together with the at least one processor, to cause the apparatus to perform at least: Receive instructions from the user equipment to support an optimized authentication process; as well as Send the instruction to the mobility management network function to support the optimized authentication process; The optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and The optimized authentication process described herein does not include: switching non-access stratum security mode commands, switching non-access stratum security mode command completion, switching access stratum security mode commands, and switching access stratum security mode command completion.

15. The apparatus according to any one of claims 10 to 13, wherein the apparatus comprises a base station.

16. An apparatus for communication, comprising at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured, together with the at least one processor, to cause the apparatus to perform at least: Send instructions to the base station regarding the first profile and the authentication and key negotiation challenge; and Receive from the base station a first encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

17. The apparatus of claim 16, wherein the at least one memory and the computer code are configured, together with the at least one processor, to cause the apparatus to perform at least: Perform successful verification of the first encrypted and integrity-protected authorization and key negotiation response; and Send the third encrypted and integrity-protected authorization and key negotiation response to the authentication server function.

18. The apparatus of claim 17, wherein performing successful verification of the first encrypted and integrity-protected authorization and key negotiation response comprises: Based on the first profile, perform decryption and integrity protection verification on the first encrypted and integrity-protected authorization and key negotiation response.

19. The apparatus of claim 18, wherein performing the decryption and integrity calculation of the first encrypted and integrity-protected authorization and key negotiation response based on the first profile comprises: Based on the first profile and at least one first key for encryption and integrity protection, decryption and integrity protection verification are performed on the first encrypted and integrity-protected authorization and key negotiation response.

20. The apparatus according to any one of claims 16 to 19, wherein the at least one memory and the computer code are configured, together with the at least one processor, to cause the apparatus to perform at least: Receive instructions from the base station to support an optimized authentication process; The optimized authentication process includes exchanging authentication and key negotiation challenges and authentication and key negotiation responses; and The optimized authentication process described herein does not include: switching non-access stratum security mode commands, switching non-access stratum security mode command completion, switching access stratum security mode commands, and switching access stratum security mode command completion.

21. The apparatus according to any one of claims 16 to 19, wherein the apparatus includes a mobility management network function.

22. An apparatus for communication, comprising at least one processor and at least one memory, the at least one memory including computer code for one or more programs, the at least one memory and the computer code being configured, together with the at least one processor, to cause the apparatus to perform at least: Send authentication and key negotiation challenges to mobility management network functions; and Receive a third encrypted and integrity-protected authorization and key negotiation response from the mobility management network function.

23. The apparatus of claim 22, wherein the at least one memory and the computer code are configured, together with the at least one processor, to cause the apparatus to perform at least: Perform successful verification of the third encrypted and integrity-protected authorization and key negotiation response; and Send a successful authentication indication to the mobility management network function.

24. The apparatus of claim 23, wherein successful verification of the third encrypted and integrity-protected authorization and key negotiation response comprises: Based on the third profile, decryption and integrity protection verification are performed on the third encrypted and integrity-protected authorization and key negotiation response.

25. The apparatus of claim 24, wherein successful verification of the third encrypted and integrity-protected authorization and key negotiation response comprises: Based on the third profile, perform decryption or integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response.

26. The apparatus of claim 25, wherein performing the decryption and integrity protection verification calculation of the third encrypted and integrity-protected authorization and key negotiation response based on the third profile comprises: Based on the third profile and at least one third encryption and integrity protection key, perform decryption and integrity protection verification of the third encrypted and integrity-protected authorization and key negotiation response.

27. The apparatus according to any one of claims 22 to 26, wherein the apparatus includes at least one of authentication server functionality or unified data management.

28. A method for communication, comprising: Based on the authorization and key negotiation response and the first profile, generate a first encrypted and integrity-protected authorization and key negotiation response; Based on the authorization and key negotiation response and the second profile, a second encrypted and integrity-protected authorization and key negotiation response is generated; Based on the authorization and key negotiation response and the third profile, a third encrypted and integrity-protected authorization and key negotiation response is generated; as well as Send the first encrypted and integrity-protected authorization and key negotiation response, the second encrypted and integrity-protected authorization and key negotiation response, and the third encrypted and integrity-protected authorization and key negotiation response to the base station.

29. A method for communication, comprising: Send an authorization and key negotiation challenge to the user equipment; as well as The user equipment receives a first encrypted and integrity-protected authorization and key negotiation response, a second encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

30. A method for communication, comprising: Send instructions to the base station regarding the first profile and the authentication and key negotiation challenges; as well as Receive from the base station a first encrypted and integrity-protected authorization and key negotiation response, and a third encrypted and integrity-protected authorization and key negotiation response.

31. A method for communication, comprising: Send authentication and key negotiation challenges to the mobility management network function; as well as Receive a third encrypted and integrity-protected authorization and key negotiation response from the mobility management network function.

32. A computer program product comprising computer-executable instructions, which, when executed, cause one or more processors to perform the method according to any one of claims 28 to 31.