Secure acquisition of user equipment identifiers

CN122700539APending Publication Date: 2026-09-04NOKIA NETWORKS OY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480087213.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-08
Publication Date
2026-09-04

Smart Images

  • Figure CN122700539A_ABST
    Figure CN122700539A_ABST
Patent Text Reader

Abstract

Various example embodiments relate to devices, methods, apparatuses, and computer-readable media for securely obtaining an identifier of a user equipment to provide edge computing services to the user equipment. A user equipment can be configured to send, to an application server, an application service request including at least one of a temporary identifier of the user equipment or an authentication and key management, AKMA, key identifier for an application associated with a protocol data unit session supporting the application service, and receive, from the application server, an application service response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The various example embodiments described herein generally relate to wireless communication technologies, and more specifically, to devices, methods, apparatuses, and computer-readable media for securely obtaining an identifier of a user equipment (UE) to provide edge computing services to the UE. Background Technology

[0002] Some abbreviations found in the specification and / or figures are defined as follows:

[0003] AAnF AKMA Anchoring Function

[0004] AF Application Functions

[0005] AKMA is used for application authentication and key management.

[0006] API (Application Programming Interface)

[0007] AUSF Authentication Server Functionality

[0008] DN Data Network

[0009] EAS Edge Application Server

[0010] EEC Edge Enabler Client

[0011] GPSI General Public Subscription Identifier

[0012] IP Internet Protocol

[0013] MAC Media Access Control

[0014] NEF Network Exposure Function

[0015] PDU Protocol Data Unit

[0016] SMF Session Management Function

[0017] SUPI subscription permanent identifier

[0018] UDM Unified Data Management

[0019] UDR Unified Data Repository

[0020] Edge computing is a network architecture concept that implements cloud computing capabilities and service environments deployed at the network "edge" close to the user equipment (UE). The most significant benefit of edge computing is reduced latency. For example, applications can send and receive data through edge application servers (EAS) installed geographically close to base stations, without needing servers located in external data networks (DNs) such as the internet. When providing edge computing services to UEs in a mobile communication network, the EAS may need to obtain the UE's identifier (ID) from the network. Summary of the Invention

[0021] The following provides a brief overview of various exemplary embodiments to provide a basic understanding of some aspects of the various embodiments. It should be noted that this overview is not intended to identify key features of the basic elements or define the scope of the embodiments, and its sole purpose is to introduce some concepts in a simplified form as a prelude to the more detailed description provided below.

[0022] In a first aspect, an example embodiment of an application client is provided. The application client may include instructions for sending an application service request to an application server and receiving an application service response from the application server. The application service request may include a temporary identifier of a user device on which the application client is running.

[0023] In a second aspect, an example embodiment of a user equipment is provided. The user equipment may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the user equipment to at least: send an application service request to an application server and receive an application service response from the application server. The application service request may include at least one of a temporary identifier of the user equipment associated with a Protocol Data Unit session supporting the application service, or an AKMA key identifier for application authentication and key management.

[0024] In a third aspect, an example embodiment of an application server is provided. The application server may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the application server to at least: receive an application service request from a user equipment, including a temporary identifier of the user equipment associated with a Protocol Data Unit (PDU) session supporting the application service; send a user equipment identifier request including the temporary identifier to a Network Exposure Function (NET) entity; receive a user equipment identifier response including an application-specific user equipment identifier from the NET; send a user equipment information request including the application-specific user equipment identifier to the NET; receive a user equipment information response including the requested user equipment information from the NET; and send an application service response to the user equipment.

[0025] In a fourth aspect, an example embodiment of a session management function entity is provided. The session management function entity may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the session management function entity to at least: receive a Protocol Data Unit (PDU) session request from a user equipment; send information about the PDU session associated with the PDU session request to a unified data management function entity; receive a temporary identifier associated with the PDU session from the unified data management function entity; and send a message including the temporary identifier to the user equipment. The message including the temporary identifier may be a PDU session establishment or modification response message or an Extended Protocol Configuration Options (ePCO) message.

[0026] In a fifth aspect, an example embodiment of a network exposure function entity is provided. The network exposure function entity may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the network exposure function entity to at least: receive a user device identifier request including a temporary identifier of a user device from an application server; obtain a user device identifier from a unified data management function entity based on the temporary identifier; obtain an application-specific user device identifier from the unified data management function entity based on the user device identifier and an application function identifier; and send a user device identifier response including the application-specific user device identifier to the application server.

[0027] In a sixth aspect, an example embodiment of a unified data management function entity is provided. The unified data management function entity may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the unified data management function entity to at least: receive protocol data unit session information from a session management function entity; generate a temporary identifier for the protocol data unit session, the temporary identifier containing information identifying a unified data management group identifier associated with the unified data management function entity; store a mapping between the temporary identifier and a user equipment identifier in a unified data repository function entity, the user equipment identifier representing a user equipment associated with the protocol data unit session; and send the temporary identifier to the session management function entity.

[0028] In a seventh aspect, an example embodiment of a unified data management function entity is provided. The unified data management function entity may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the unified data management function entity to at least: receive a user equipment identifier (UE) retrieval request containing a temporary identifier of a user equipment from a network exposure function entity; send a UE retrieval response to the network exposure function entity, including a UE identifier mapped to the temporary identifier; receive an application-specific UE retrieval request from the network exposure function entity containing the UE identifier and an application function identifier; and send an application-specific UE retrieval response to the network exposure function entity, including an application-specific UE retrieval identifier corresponding to the UE identifier and the application function identifier.

[0029] In an eighth aspect, an example embodiment of an application server is provided. The application server may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the application server to at least: receive from a user equipment an application service request including an Authentication and Key Management (AKMA) key identifier for the application; send an application key request including the AKMA key identifier to a Network Exposure Function (NET) entity; receive an application key response from the NET NET entity, including an application key for the application server and a General Public Subscription (GPS) identifier for the user equipment; send a user equipment information request including the GPS identifier to the NET NET entity; receive a user equipment information response including the requested user equipment information from the NET NET entity; and send an application service response to the user equipment.

[0030] In a ninth aspect, an example embodiment of a network exposure function entity is provided. The network exposure function entity may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the network exposure function entity to at least: receive an application key request from an application server, including an Authentication and Key Management (AKMA) key identifier for the application; obtain an application key and a subscription permanent identifier for the application server from an AKMA anchoring function entity based on the AKMA key identifier; convert the subscription permanent identifier into a general public subscription identifier; send an application key response to the application server, including the application key for the application server and the general public subscription identifier; receive a user equipment information request from the application server, including the general public subscription identifier; and send a user equipment information response to the application server.

[0031] In a tenth aspect, an example embodiment of an application server is provided. The application server may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the application server to at least: receive an application service request from a user equipment, the request including at least one of a temporary identifier of the user equipment or an Authentication and Key Management (AKMA) key identifier for an application; send a user equipment information request including at least one of the temporary identifier and the AKMA key identifier to a network exposure function entity; receive a user equipment information response including the requested user equipment information from the network exposure function entity; and send an application service response to the user equipment.

[0032] In an eleventh aspect, an example embodiment of a network exposure function entity is provided. The network exposure function entity may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the network exposure function entity to at least: receive a user equipment information request including a temporary identifier of a user equipment from an application server; obtain a user equipment identifier from a unified data management function entity based on the temporary identifier; obtain the requested user equipment information based on the user equipment identifier; and send a user equipment information response to the application server.

[0033] In a twelfth aspect, an example embodiment of a network exposure function entity is provided. The network exposure function entity may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, cause the network exposure function entity to at least: receive a user equipment information request from an application server, including an AKMA key identifier for authentication and key management of the application; obtain a subscription permanent identifier from an AKMA anchoring function entity based on the AKMA key identifier; obtain the requested user equipment information based on the subscription permanent identifier; and send a user equipment information response to the application server.

[0034] Example embodiments of the methods, apparatus, and computer-readable media are also provided. These example embodiments of the methods, apparatus, and computer-readable media generally correspond to the example embodiments described above in aspects one through twelfth, and for convenience, repeated descriptions thereof are omitted herein.

[0035] Other features and advantages of the exemplary embodiments of this disclosure will also become apparent from the following description of specific embodiments when read in conjunction with the accompanying drawings, which illustrate the principles of exemplary embodiments of this disclosure by way of example. Attached Figure Description

[0036] Some exemplary embodiments will now be described by way of non-limiting examples with reference to the accompanying drawings.

[0037] Figure 1 This is a message flow diagram illustrating the process of providing application services to user equipment.

[0038] Figure 2 This is a schematic flowchart illustrating the process of generating a temporary identifier for a user equipment according to an example embodiment of the present disclosure.

[0039] Figure 3 This is a schematic flowchart illustrating a process for providing application services to a user device according to an example embodiment of the present disclosure.

[0040] Figure 4 This is a schematic flowchart illustrating a process for providing application services to a user device according to an example embodiment of the present disclosure.

[0041] Figure 5 This is a schematic flowchart illustrating a process for providing application services to a user device according to an example embodiment of the present disclosure.

[0042] Figure 6 This is a schematic flowchart illustrating a process for providing application services to a user device according to an example embodiment of the present disclosure.

[0043] Figure 7This is a schematic flowchart illustrating a process for providing application services to a user device according to an example embodiment of the present disclosure.

[0044] Figure 8 This is a schematic flowchart illustrating a process for providing application services to a user device according to an example embodiment of the present disclosure.

[0045] Figure 9A This is a schematic block diagram illustrating a terminal device according to an example embodiment of the present disclosure.

[0046] Figure 9B This is a schematic block diagram illustrating a core network device according to an example embodiment of the present disclosure.

[0047] Figure 9C This is a schematic block diagram illustrating an application server device according to an example embodiment of the present disclosure.

[0048] Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Repeated descriptions of the same elements will be omitted. Detailed Implementation

[0049] Some exemplary embodiments are described in detail below with reference to the accompanying drawings. The following description includes specific details intended to provide a thorough understanding of various concepts. However, it will be apparent to those skilled in the art that these concepts can be practiced without these specific details. In some cases, well-known circuits, technologies, and components are shown in block diagram form to avoid obscuring the described concepts and features.

[0050] Figure 1 This is a message flow diagram illustrating a process 100 for providing application services to user equipment (UE) 102. For example, an application client (AC) 101, such as an edge application client (EAC), may be installed in UE 102 and receive services from an application server (AS) 103, such as an edge application server (EAS). (See reference...) Figure 1At 110, UE 102 (or application client 101) may send an application service request (or simply "application request") to application server 103. In order to provide services to UE 102, application server 103 may need to know some information about UE 102. For example, assuming a user is using UE 102 to enjoy a hiking game, the game server needs to know the user's location. The game server may invoke the application programming interface (API) exposed by network exposure function (NEF) 105 to obtain UE information from the mobile / cellular network serving UE 102. NEF 105 serves as an entry point into the operator's network by exposing network capabilities and events provided by network functions (NFs) to the application function / server, and by providing a pathway for the application function / server to provide information to the network. In procedure 100, at 112, application server 103 may invoke the API exposed by NEF to send a UE information (e.g., location) request to NEF 105. The request includes a UE identifier (ID) that identifies UE 102. NEF 105 can obtain requested UE information from other network functions or nodes based on the UE ID at 114, and return the UE information to application server 103 in an NEF response message at 116. Using the UE information, application server 103 can provide services to UE 102 in an application response message at 118.

[0051] In process 100, application server 103 needs to know the UE ID that identifies UE 102 in the mobile / cellular network in order to obtain UE information, such as location, from the mobile network. According to current 3GPP standards, application server 103, acting as an application function (AF), can use the network identifier of UE 102, such as IP address or MAC address, to obtain the UE ID to be used in subsequent API calls. More specifically, application server (AS) or application function (AF) 103 can use the Nnef_UEId_Get service with inputs of the required UE address (i.e., IP address or MAC address) and AS / AF identifier (AF_ID) to obtain the AF-specific UE identifier (AF_UE_ID) of UE 102. The AF-specific UE identifier can be represented as a General Public Subscription Identifier (GPSI) in the form of an external identifier. When used as an AF-specific UE identifier, the external identifier provided by the core network should be different for different AFs.

[0052] The Nnef_UEId API used in edge application use cases may present privacy issues when providing actual services. When an application client on the UE (which may be untrusted) sends the network UE identifier (e.g., private IP address) as part of the application layer protocol to the application server, the UE may not provide its own identifier, but instead provide the identifier of another UE. Therefore, this is not a secure solution. Without appropriate security mechanisms in place, the Nnef_UEId service can be abused, allowing the UE ID to be disclosed to unauthorized entities, enabling them to, for example, track the UE, thus compromising the UE's privacy. Any application server / function that knows the UE's IP address can use the Nnef_UEId service to obtain the AF-specific UE identifier, even if it is not authorized to do so. Even if the API is subject to existing authentication and authorization procedures provided by network operators and service providers, sensitive privacy-preserving UE / subscriber information, such as IP address and UE ID, may still be exposed to third-party applications, violating the need-to-know security principle.

[0053] Several solutions have been proposed to protect UE IP addresses and prevent multiple attacks. For example, user information (e.g., private UE IP addresses) provided by the edge enabler client (EEC) in the UE or the edge enabler server (EES) in the edge data network should be verified, and the EEC and EES should be authorized to use this information. Random or token-generated features from the core network, or authentication and key management (AKMA) features used for applications, can be used to assist the network in verifying the IP addresses provided by the EEC or EES. Unfortunately, these solutions do not address the main security concerns associated with UE privacy compromise because the UE's IP address and identifier are still unnecessarily exposed to all applications in the edge service producer chain, and, of course, the use of UE IP addresses is always susceptible to spoofing attacks. In fact, using the UE IP address allows application servers to obtain additional information about the UE that can be misused. For example, application servers can use the IP address to track the UE, aggregate similar IPs corresponding to similar locations, and perform additional analysis on groups of UEs.

[0054] Another security concern involves the possibility of malicious application servers executing replay attacks. In fact, after initially obtaining the UE ID, the application server can reuse it even without new requests from the application client. Generally, any approach / solution based on using long-term UE identifiers (which application servers can leverage to access services exposed by the network and associate with the network UE identifier) ​​is vulnerable to security / privacy breaches caused by compromised or malicious application servers.

[0055] The exemplary embodiments of this disclosure present a security mechanism to obtain the UE ID from the core network without using private UE information such as IP or MAC addresses, and to protect the NEF API from compromised or malicious application servers. This mechanism provides authentication and privacy protection for UE information provided by the UE (or EEC within the UE) to request the UE ID from the core network and prevents misuse of the requested UE ID. It protects the system from replay attacks because an application server that becomes aware of the UE ID cannot use it without permission. Some exemplary embodiments are described in the context of edge computing; however, it should be understood that the exemplary embodiments can be readily extrapolated, generalized, or applied to other contexts where application clients on the UE are consuming services provided by an application server, where the application server needs access to the northbound API as part of service delivery.

[0056] In some example embodiments, a temporary identifier associated with a Protocol Data Unit (PDU) session may be assigned to the UE (or EEC within the UE) and provided by the UE (or EEC) to the application server in place of an IP or MAC address for requesting the UE ID from the core network via the NEF. Figure 2 An example process 200 for generating a temporary identifier according to an example embodiment of this disclosure is shown.

[0057] refer to Figure 2 At 210, an application client (AC) 101 running on UE 102 can trigger a request for a temporary identifier to UE 102. For example, when AC 101 initiates communication with application server 103, AC 101 can request a new temporary identifier temp_ID from UE 102.

[0058] In response to a temporary identifier request, UE 102 may optionally obtain the application server or function identifier AF_ID of application client 101 at 212. The application server / function identifier AF_ID identifies the application server / function 103 that provides services to application client 101. In an example embodiment, UE 102 may initiate operation 212 proactively without being triggered by a temporary identifier request.

[0059] Optionally, UE 102 may generate a preliminary temporary identifier pre_temp_ID at 214. For example, UE 102 may generate a unique random value as the preliminary temporary identifier pre_temp_ID.

[0060] At 216, UE 102 may send a Protocol Data Unit (PDU) session establishment or modification request to Session Management Function (SMF) 104 to establish a new PDU session or modify an existing PDU session to support the services of application client 101. The PDU session establishment or modification request may include the application server / function identifier AF_ID of application client 101. If UE 102 has already generated a preliminary temporary identifier pre_temp_ID, the PDU session establishment or modification request may also include UE 102's preliminary temporary identifier pre_temp_ID. Since a PDU session can support multiple application services, in the example embodiment, UE 102 may send a list of ID pairs (pre_temp_ID, AF_ID) of the multiple application services that the PDU session is intended to support in the PDU session request.

[0061] If the received PDU session request does not include the preliminary temporary identifier pre_temp_ID generated at UE 102, then instead, SMF 104 may generate the preliminary temporary identifier pre_temp_ID at 218. For example, SMF 104 may generate a network-internal random unique value as the preliminary temporary identifier pre_temp_ID for the PDU session. In the example embodiment, operation 218 may be omitted regardless of whether the received PDU session request includes the preliminary temporary identifier pre_temp_ID.

[0062] In response to a PDU session establishment or modification request, SMF 104 can establish a new PDU session or modify an existing PDU session to support the application services of application client 101. At 220, SMF 104 can store PDU session information in Unified Data Management Function (UDM) 106 by sending PDU session information to UDM 106 via a Nudm_UECM_Registration request for a new PDU session or a Nudm_UECM_Update request for a modified PDU session. The PDU session information may include a preliminary temporary identifier pre_temp_ID generated at UE 102 or a preliminary temporary identifier pre_temp_ID generated at SMF 104, and an application server / function identifier AF_ID. If neither UE 102 nor SMF 104 generates a preliminary temporary identifier pre_temp_ID, the PDU session information sent to UDM 106 may only include the application server / function identifier AF_ID.

[0063] Upon receiving PDU session information, UDM 106 can generate a temporary identifier temp_ID for the PDU session and UE 102 at 222. The temporary identifier temp_ID may contain information identifying the UDM 106's UDM group identifier. In one example, the temporary identifier temp_ID may contain the UDM 106's UDM group identifier. If the received PDU session information includes a preliminary temporary identifier pre_temp_ID generated at UE 102 or SMF 104, UDM 106 can generate the temporary identifier temp_ID based on pre_temp_ID. For example, UDM 106 can generate the temporary identifier temp_ID by combining the preliminary temporary identifier pre_temp_ID with information identifying the UDM 106's UDM group identifier. If the received PDU session information does not include a preliminary temporary identifier pre_temp_ID, UDM 106 may first generate a preliminary temporary identifier pre_temp_ID, such as a random unique value within the network, and then combine the generated preliminary temporary identifier pre_temp_ID with information identifying the UDM group identifier of UDM 106 to generate a temporary identifier temp_ID. In one example, temp_ID may include a combination of pre_temp_ID and UDM group ID. UDM 106 may store the temporary identifier temp_ID used for PDU sessions and UE 102 in a unified data repository (UDR). In one example embodiment, UDM 106 may store a mapping in the UDR of the temporary identifier temp_ID, the identifier UE_ID of UE 102, and optionally, the application server / function identifier AF_ID. UE_ID may be the subscription permanent identifier (SUPI) of UE 102.

[0064] Then, UDM 106 can send a temporary identifier temp_ID to SMF 104 at position 224. For example, UDM 106 can send the temporary identifier temp_ID to SMF 104 in a Nudm_UECM_Registration / Update response message.

[0065] At position 226, SMF 104 may send a temporary identifier temp_ID to UE 102 in a PDU session establishment / modification accept message. In the example embodiment, SMF 104 may use any other message to transmit the temporary identifier temp_ID to UE 102. For example, SMF 104 may send the temporary identifier temp_ID to UE 102 in an Extended Protocol Configuration Options (ePCO) message.

[0066] At 228, UE 102 may send a temporary identifier temp_ID to application client 101 in a temporary identifier response message. Application client 101 can then use the temporary identifier temp_ID to initiate communication with application server 103, as described below.

[0067] In process 200, the temporary identifier temp_ID of UE 102 associated with the PDU session supporting the service of application client 101 can be partially generated at UE 102 or SMF 104, or fully generated at UDM 106. This prevents potential attacks in the event that application client 101 is malicious or compromised. Furthermore, the optional use of the application server / function identifier AF_ID further enhances security, as the temporary identifier temp_ID is generated based on AF_ID, and multiple applications can be transmitted within the same PDU session.

[0068] Figure 3 A process 300 for providing application services to UE 102 or application client 101 in UE 102 according to an example embodiment of this disclosure is illustrated. A temporary identifier temp_ID generated in process 200 may be used in process 300.

[0069] See Figure 3 At point 310, UE 102 or application client 101 in UE 102 may send an application service request to application server 103. The application service request may include a temporary identifier temp_ID of UE 102 associated with a PDU session supporting the application service.

[0070] Upon receiving an application service request, application server 103 may request an authorization token from authorization server 107 at point 312. In an example embodiment, application server 103 may send an authorization token request to authorization server 107 and receive an authorization token response containing the token from authorization server 107. The token may contain the application server / function identifier AF_ID of application server 103. It should be understood that the token request and response messages are described as examples only, and alternatively, any other method of authenticating and authorizing application server 103 may be performed prior to Network Exposure Function (NEF) 105 at point 312.

[0071] At 314, application server 103 may send a request for the identifier of UE 102 to NEF 105. In an example embodiment, application server 103 may request the UE ID via the Nnef_UEId_Get service operation. The request message may contain a temporary identifier temp_ID instead of the IP or MAC address of UE 102. Optionally, the request may also include a token obtained at 312.

[0072] Upon receiving a UE ID request containing a temporary identifier temp_ID, NEF 105 can determine the UDM 106 at 316 based on the information identifying the UDM group identifier in the temporary identifier temp_ID to obtain the UE ID.

[0073] Then, NEF 105 can obtain the UE ID from UDM 106 based on the temporary identifier temp_ID. For example, at 318, NEF 105 can send a UE ID retrieval request containing the temporary identifier temp_ID to UDM 106, and at 320 receive a UE ID retrieval response containing the identifier UE_ID of UE 102. UDM 106 can determine the UE_ID corresponding to the received temporary identifier temp_ID, such as SUPI, and send the UE_ID to NEF 105 in the retrieval response message. Optionally, the retrieval response message may also include the application server / function identifier AF_ID corresponding to the temporary identifier temp_ID. NEF 105 can verify the AF_ID received from UDM 106 at 321 by comparing the AF_ID received from UDM 106 with the AF_ID received from application server 103 (e.g., the AF_ID contained in a token received from application server 03). If the two AF_IDs match, NEF 105 can proceed to the next step using the received UE_ID. If the two AF_IDs do not match, NEF 105 can send a request-reject message containing a rejection reason to application server 103. Application server 103 can forward the request-reject message to UE 102 or application client 101 in UE 102. In response to this message, application client 101 or UE 102 can re-trigger procedure 200 to create a temporary identifier temp_ID corresponding to the application server / function identifier AF_ID of application server 103.

[0074] Having verified the validity of the AF_ID received from UDM 106 at point 321, NEF 105 can obtain the application-specific UE identifier AF_UE_ID from UDM 102 based on UE_ID and AF_ID. In an example embodiment, UDM 106 can request the application-specific UE identifier AF_UE_ID via the Nudm_SDM_Get service operation. NEF 105 can send a Nudm_SDM_Get request message containing UE_ID and AF_ID to UDM 106 at point 322, and receive a Nudm_SDM_Get response message containing AF_UE_ID, such as the General Public Subscription Identifier (GPSI) of UE 102, at point 324.

[0075] At 326, NEF 105 can send the application-specific UE identifier AF_UE_ID to application server 103 in the UE ID response message.

[0076] At 328, application server 103 may request an authorization token from authorization server 107. Operation 328 may be similar to operation 312 described above, and repeated descriptions are omitted here. Alternatively, at 328, any other method for authenticating and authorizing application server 103 may be performed prior to NEF 105.

[0077] At 330, application server 103 may send a UE information request containing AF_UE_ID to NEF 105. For example, application server 103 may request the UE location via NEF location service operation. The request message may also include an authorization token obtained at 328.

[0078] If the token successfully authenticates and authorizes application server 103, or application server 103 obtains authentication and authorization in any other way, NEF 105 can obtain the requested UE information from the corresponding network function or node based on AF_UE_ID, and return the UE information to application server 103 in a response message at 332. For example, NEF 105 can obtain the UE location from the Location Management Function (LMF) and return the UE location to application server 103.

[0079] Using the UE information, the application server 103 can determine the service data for the UE 102 or the application client 101, and send an application service response message to the UE 102 or the application client 101 at 334.

[0080] In process 300, instead of private UE information such as IP or MAC addresses, a temporary identifier temp_ID for UE 102 is used to obtain UE information from the core network, such as the required location. This prevents sensitive private UE information from being exposed to and misused by third-party applications, thereby protecting the system from replay attacks.

[0081] Figure 4 A process 300a according to an example embodiment of this disclosure is shown. Process 300a is a variation of the process 300 described above, and may include the same operations as those in process 300. Only descriptions of the different operations in process 300a will now be given.

[0082] refer to Figure 4 After receiving the application-specific UE identifier AF_UE_ID from UMD 106 at point 324, NEF 105 can select one or more access control policies (also known as security policies), such as role-based access control (RBAC) policies, for AF_UE_ID at point 325. These access control policies can strengthen control over multiple attributes of AF_UE_ID, such as expiration time, usage, and range. NEF 105 can store a mapping between AF_UE_ID (e.g., GPSI), the selected access control policy, and optionally, the UE ID (e.g., SUPI). This mapping can be stored locally at NEF 105 or in UMD / UDR.

[0083] Then, when NEF 105 receives a UE information request containing AF_UE_ID from application server 103 at 330, NEF 105 can verify whether the AF_UE_ID contained in the UE information request conforms to the access control policy. If AF_UE_ID conforms to the access control policy, NEF 105 can proceed to obtain the requested UE information using AF_UE_ID and send the UE information to application server 103 in a UE information response message. If AF_UE_ID violates one or more access control policies, NEF 105 can send a UE information request rejection message (not shown) containing the rejection reason to application server 103, and application server 103 can forward the request rejection message containing the rejection reason to UE 102 or application client 101. Then, UE 102 or application client 101 can restart process 300a to select an access control policy for AF_UE_ID.

[0084] In process 300a, access control policies provide flexible and fine-grained control over AF_UE_ID. By introducing access control policies targeting AF_UE_ID, NEF 105 prevents the abuse of AF_UE_ID by malicious or compromised application servers and protects the system from replay attacks that may exist in the current API workflow due to the relative static nature of UE_ID and AF_UE_ID. This further improves system security.

[0085] Figure 5 A process 400 according to an example embodiment of this disclosure is illustrated. In the example embodiment, the initial caller of the API is identified using the Authentication and Key Management for Applications (AKMA) protocol and the AKMA key identifier A-KID. The A-KID is an application-specific identifier derived from a long-term symmetric pre-shared key between the UE and the network, and it is used by the AKMA protocol to identify the application function / server in an untrusted scenario. The A-KID may be sent from the UE along with the application service request. The edge application / enabler server, as another untrusted application function (AF) connected to the NEF, will then use the AKMA protocol to request an external UE ID from the NEF.

[0086] refer to Figure 5 As a prerequisite, a main authentication process is performed at 402 to authenticate UE 102 during network registration, followed by an AKMA key derivation process 404 to generate a key, which includes, for example, the root key K. AUSF Anchor key K AKMA and K AKMA The AKMA key identifier A-KID is used. The Authentication Server Function (AUSF) 109 is responsible for key generation. Then, at 406, the AKMA Anchoring Function (AAnF) 108 creates and maintains the UE AKMA context, including SUPI, GPSI, and K for secure communication between the UE 102 and the application server / function 103. AKMA And A-KID.

[0087] At 410, UE 102 or application client (AC) 101 in UE 102 may send an application service request containing the AKMA key identifier A-KID to application server 103.

[0088] Upon receiving an application service request containing A-KID, application server 103 can send A-KID to AAnF 108 via NEF 105 to request the KAMA application key K associated with A-KID from AAnF 108. AFMore specifically, application server 103 can request the AKMA application key K by sending an Nnef_AKMA_ApplicationKey_Get request message including A-KID to NEF 105 at 412. AF Optionally, K AF The request message may also include the application server / function identifier AF_ID and authorization token of application server 103. If application server 103 is authorized by NEF 105 to request K... AF Then NEF 105 can discover and select AAnF 108 for application server 103, and request the AKMA application key K by sending a Naanf_AKMA_ApplicationKey_Get request message including A-KID, optional, and AF_ID to AAnF 108 at 414. AF AAnF 108 can compute the AKMA application key K. AF Its expiration date is based on A-KID or K. AF Obtain the SUPI (i.e., UE_ID) of UE 102, and then send a K-value to NEF 105 at position 416. AF The expiration time and SUPI response message. In an example embodiment, AAnF 108 can K AF The calculation is bound to the application session identifier, so that the calculated K AF This is different for each application session. It prevents K from being interrupted after the application session between UE 102 and application server 103 ends. AF It was reused.

[0089] At 418, NEF 105 can convert the SUPI received from UE 102 from AAnF 108 into GPSI (External ID). In an example embodiment, NEF 105 can communicate with UDM 106 (such as...) Figure 2-4 The NEF 105 interacts with the application server 103 via the Nudm_SDM_Get service operation to obtain the GPSI (i.e., AF_UE_ID). The service request may include the SUPI and at least one of the following: application port ID, machine type communication (MTC) vendor information, or AF_ID. Then, at 420, the NEF 105 may send the GPSI, K... AF And its expiration date.

[0090] At 422, application server 103 may request an authorization token from authorization server 107. In an example embodiment, application server 103 may send an authorization token request to authorization server 107 and receive an authorization token response containing the token from authorization server 107. The token may contain the application server / function identifier AF_ID of application server 103. It should be understood that the token request and response messages are described as examples, and any other methods for authenticating and authorizing application server 103 may be used prior to NEF 105.

[0091] At position 424, application server 103 can send to NEF 105 a data packet containing GPSI (i.e., AF_UE_ID), optional location, and K. AF UE information requests for tokens. For example, application server 103 can request the UE's location via NEF location service operation. If the K is verified... AF If a token is received, NEF 105 can obtain the requested UE information from the corresponding network function or node based on GPSI, and return the UE information to application server 103 in a response message at 426. For example, NEF 105 can obtain the UE location from the Location Management Function (LMF) and return the UE location to application server 103.

[0092] Using the UE information, the application server 103 can determine the service data for the UE 102 or the application client 101, and send an application service response message to the UE 102 or the application client 101 at 428.

[0093] In process 400, A-KID is reused to obtain the application-specific UE identifier from AAnF 108 via AKMA operation. This also protects the system from replay attacks by preventing sensitive privacy-preserving UE information, such as IP or MAC addresses, from being exposed and misused by third-party applications. Furthermore, the overall process is simplified because process 200 for generating the temporary identifier temp_ID is not required.

[0094] Figure 6 A process 400a according to an example embodiment of this disclosure is shown. Process 400a is a variation of process 400 described above, and it may include the same operations as those in process 400. Only descriptions of the different operations in process 400a will now be given.

[0095] refer to Figure 6After NEF 105 converts UE 102's SUPI to GPSI at position 418, NEF 105 can select one or more access control policies (also known as security policies), such as role-based access control (RBAC) policies, for the GPSI at position 419. These access control policies can strengthen control over multiple attributes of the GPSI, such as expiration time, usage, and range. NEF 105 can store a mapping between the GPSI, the selected access control policy, and optionally, the UE ID (e.g., SUPI). This mapping can be stored locally in NEF 105 or in the UDM / UDR.

[0096] Then, when NEF 105 receives from application server 103 at 424 the data containing GPSI, optional location, and K... AF When a UE requests UE information using a token, NEF 105 can verify whether the GPSI contained in the UE information request conforms to the access control policy. If the GPSI conforms to the access control policy, NEF 105 can use the GPSI to obtain the requested UE information and send the UE information to application server 103 in a UE information response message. If the GPSI violates one or more access control policies, NEF 105 can send a UE information request rejection message (not shown) containing the rejection reason to application server 103, and application server 103 can forward the request rejection message containing the rejection reason to UE 102 or application client 101. Then, UE 102 or application client 101 can restart process 400a to select an access control policy for the GPSI.

[0097] In process 400a, the access control policy provides flexible and fine-grained control over the GPSI of UE 102. By introducing an access control policy for GPSI, NEF 105 prevents malicious or compromised application servers from abusing GPSI and protects the system from replay attacks that may occur in the current API workflow due to the relative static nature of UE_ID and AF_UE_ID. This further improves system security.

[0098] Figure 7 A process 500 according to an example embodiment of this disclosure is shown. Process 500 includes some operations similar to those in process 300, and such operations will be described below in a simplified manner.

[0099] refer to Figure 7 At point 510, UE 102 or application client 101 may send an application service request containing a temporary identifier temp_ID to application server 103. For example, the temporary identifier temp_ID can be found in the previous section regarding... Figure 2 The discussion process was generated in 200.

[0100] Upon receiving an application service request, application server 103 may obtain an authorization token from authorization server 107 at point 512, for example, by sending an authorization token request to authorization server 107 and receiving an authorization token response containing the token from authorization server 107. The token may contain the application server / function identifier AF_ID of application server 103. It should be understood that at point 512, any other method for authenticating and authorizing application server 103 prior to NEF 105 may be used instead.

[0101] At point 514, application server 103 may send a UE information request to NEF 105 containing a temporary identifier temp_ID, optionally, and a token. For example, application server 103 may request the UE location via NEF location service operation. Instead of the application-specific UE identifier AF_UE_ID or GPSI, the temporary identifier temp_ID is used in the request message to obtain the UE location. The token contains the application server / function identifier AF_ID of application server 103, or the request message may directly include AF_ID.

[0102] If the token successfully authenticates and authorizes application server 103, NEF 105 can determine UDM 106 at 516 based on the information identifying the UDM group identifier in the temporary identifier temp_ID to obtain the UE ID of UE 102. Then, at 518, NEF 105 can send a UE identifier retrieval request containing the temporary identifier temp_ID to UDM 106. In response to the request, UDM 106 can obtain the UE ID, such as SUPI, based on the temporary identifier temp_ID and send the UE ID to NEF 105 in a UE ID retrieval response message at 520. Optionally, the retrieval response message may also include the application server / function identifier AF_ID corresponding to the temporary identifier temp_ID. NEF 105 can verify the AF_ID received from UDM 106 at 521 by comparing the AF_ID received from UDM 106 with the AF_ID received from application server 103 (e.g., the AF_ID contained in the token received from application server 103). If the two AF_IDs match, NEF 105 can proceed to the next step using the received UE_ID. If the two AF_IDs do not match, NEF 105 can send a request-reject message containing a rejection reason to application server 103. Application server 103 can forward the request-reject message to UE 102 or application client 101. In response to the message, application client 101 or UE 102 can re-trigger process 200 to create a temporary identifier temp_ID corresponding to the application server / function identifier AF_ID of application server 103.

[0103] Having verified the validity of the AF_ID received from UDM 106 at point 521, NEF 105 can obtain the requested UE information from the corresponding network function or node based on the UE_ID, optionally and AF_ID, at point 522, and return the UE information to application server 103 in a response message at point 524. For example, NEF 105 can obtain the UE location from the Location Management Function (LMF) and return the UE location to application server 103.

[0104] Using the UE information, the application server 103 can determine the service data for the UE 102 or the application client 101, and send an application service response message to the UE 102 or the application client 101 at 526.

[0105] Process 500 reduces the number of API calls required to obtain services. When an application service request containing a temporary identifier temp_ID is received, the application server 103 does not need to obtain the UE ID first. Instead, the application server 103 can directly use the temporary identifier temp_ID to obtain the service. This eliminates the need to expose the UE ID to the application server or any other intermediate server that does not need to obtain the desired service, thereby preventing replay attacks that may occur in the current API workflow due to the relative static nature of the UE ID or SUPI, or even the application-specific UE ID or GPSI.

[0106] Figure 8 A process 600 according to an example embodiment of this disclosure is illustrated. Process 600 is similar to process 500 in that the temporary identifier (A-KID in process 600) is directly used to obtain UE information, but the acquisition of the UE ID based on the temporary identifier is omitted. The difference is that the AKMA feature is utilized in process 600.

[0107] refer to Figure 8 At 610, UE 102 or application client (AC) 101 may send an application service request containing the AKMA key identifier A-KID to application server 103.

[0108] Upon receiving an application service request containing an A-KID, application server 103 may obtain an authorization token from authorization server 107 at 612, for example, by sending an authorization token request to authorization server 107 and receiving an authorization token response containing the token from authorization server 107. The token may contain the application server / function identifier AF_ID of application server 103. It should be understood that at 612, any other method for authenticating and authorizing application server 103 prior to NEF 105 may be used instead.

[0109] At 614, application server 103 may send a UE information request to NEF 105 containing A-KID, optional location, AF_ID, and token. For example, application server 103 may request the UE location via NEF location service operation. Instead of applying the application-specific UE identifier AF_UE_ID or GPSI, A-KID is used in the request message to obtain the UE location.

[0110] If the token is successfully authenticated and the application server 103 is authorized, NEF 105 can discover and select AAnF 108 for the application server 103, and request the AKMA application key K by sending a Naanf_AKMA_ApplicationKey_Get request message including A-KID, optional, and AF_ID to AAnF 108 at 616.AF In response to this request, AAnF108 can compute the AKMA application key K. AF and its expiration date, based on A-KID or K AF Obtain the SUPI (i.e., UE_ID) of UE 102, and then send a K-value to NEF 105 at position 618. AF The expiration time and SUPI response message. In the example embodiment, AAnF108 can K AF The calculation is bound to the application session identifier, so that the calculated K AF This is different for each application session. It prevents K from being interrupted after the application session between UE 102 and application server 103 ends. AF It was reused.

[0111] After receiving the SUPI from AAnF 108, NEF 105 can obtain the requested UE information from the corresponding network function or node based on the SUPI, optionally and AF_ID at 620, and return the UE information to application server 103 in a response message at 622. For example, NEF 105 can obtain the UE location from the Location Management Function (LMF) and return the UE location to application server 103.

[0112] Using the UE information, the application server 103 can determine the service data for the UE 102 or the application client 101, and send an application service response message to the UE 102 or the application client 101 at 624.

[0113] Process 600 reduces the number of API calls required to obtain services because when an application service request containing an A-KID is received, the application server 103 does not need to first obtain the UE ID. Instead, the application server 103 can directly use the A-KID to obtain the service. This eliminates the need to expose the UE ID to the application server or any other intermediate server that does not need to obtain the desired service, and thus prevents replay attacks that could occur in the current API workflow due to the relative static nature of the UE ID or SUPI, or even application-specific UE ID or GPSI. By reusing the A-KID, process 600 also eliminates the need for a dedicated temporary identifier and simplifies the overall process because process 200 for generating the dedicated temporary identifier is not required.

[0114] The above has been referred to Figure 2-8Example embodiments of processes 200, 300, 300a, 400, 400a, 500, and 600 are described. Each of the SMF 104, NEF 105, UDM 106, Authorization Server 107, AAnF 108, and ASUF 109 involved in processes 200-600 can be implemented as a network function (NF) or as a network entity / device for performing said function. Each of the UE 102, Application Server 103, and Network Functions / Entities / Devices 104-109 can be implemented to include multiple components, modules, devices, or elements for performing related operations in processes 200-600. These multiple components, modules, devices, or elements can be implemented in various ways, including but not limited to, software, hardware, firmware, or any combination thereof.

[0115] Figure 9A , 9B Figures 9C and 9C respectively illustrate internal blocks of terminal device 700, core network device 800, and application server device 900 according to exemplary embodiments of the present disclosure. In the exemplary embodiment, terminal device 700 may be implemented as UE 102 as described above, core network device 800 may be implemented as one or more of network functions / entities / devices 104-109 as described above, and application server device 900 may be implemented as application server 103 as described above.

[0116] refer to Figure 9A The terminal device 700 may include one or more processors 710, one or more memories 720, and one or more transceivers 730 interconnected via one or more buses 740. Each of the one or more transceivers 730 may include a receiver and a transmitter connected to one or more antennas 750. The terminal device 700 may wirelessly communicate with a base station (not shown) via one or more antennas 750. The one or more memories 720 may include instructions 722, which, when executed by the one or more processors 710, cause the terminal device 700 to perform operations related to UE 102 as described above.

[0117] refer to Figure 9B The core network device 800 may include one or more processors 810, one or more memories 820, and one or more network interfaces 830 interconnected via one or more buses 840. The one or more network interfaces 830 provide wired or wireless communication links through which the core network device 800 can communicate with other network devices, entities, nodes, functions, or components. For example, the core network device 800 may communicate with the service terminal device 700 via a backhaul link. Figure 9AThe core network device 800 communicates with a base station (not shown). One or more memories 820 may include instructions 822, which, when executed by one or more processors 810, cause the core network device 800 to perform operations as described above in relation to one or more of the network functions / entities / devices 104-109.

[0118] refer to Figure 9C The application server device 900 may include one or more processors 910, one or more memories 920, and one or more network interfaces 930 interconnected via one or more buses 940. The one or more network interfaces 930 may provide wired or wireless communication links through which the application server device 900 may communicate with other terminals or network devices, entities, nodes, functions, or elements. The one or more memories 920 may include instructions 922, which, when executed by the one or more processors 910, enable the application server device 900 to perform the operations described above related to the application server 103.

[0119] The aforementioned processors 710, 810, and 910 can be any suitable type for a local technology network and may include one or more of the following: general-purpose processors, special-purpose processors, microprocessors, digital signal processors (DSPs), one or more processors in a processor-based multi-core processor architecture, and special-purpose processors, such as processors developed based on field-programmable gate arrays (FPGAs) and application-specific integrated circuits (ASICs). The aforementioned processors 710, 810, and 910 may be configured to control other elements of the terminal / core network / application server equipment and operate in conjunction with them to implement the processes described above.

[0120] One or more memories 720, 820, and 920 may comprise at least one storage medium of various forms, such as transient and / or non-transient memory. The transient memory may include, but is not limited to, random access memory (RAM) or cache. The non-transient memory may include, but is not limited to, read-only memory (ROM), hard disk, flash memory, etc. The term "non-transient" as used herein refers to a limitation on the medium itself (i.e., tangible, not tactile), rather than a limitation on the persistence of data storage (e.g., RAM versus ROM). Furthermore, one or more memories 720, 820, and 920 may include, but are not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof.

[0121] It should be understood that the blocks in the figures can be implemented in various ways, including software, hardware, firmware, or any combination thereof. In some embodiments, one or more blocks / operations may be implemented using software and / or firmware (e.g., machine-executable instructions stored in a storage medium). In addition to, or in lieu of, machine-executable instructions, some or all of the blocks in the figures may be implemented at least partially by one or more hardware logic components. For example, but not limited to, exemplary types of hardware logic components that may be used include field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SOCs), complex programmable logic devices (CPLDs), etc.

[0122] Some exemplary embodiments also provide a computer program including instructions that, when executed by one or more processors, cause a device or apparatus to perform the processes described above. The program instructions for performing the processes of the exemplary embodiments can be written in any combination of one or more programming languages. The program instructions can be provided to one or more processors or controllers of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor or controller, the program instructions cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program instructions can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0123] Some exemplary embodiments also provide a computer program product or a computer-readable medium in which one or more program instructions are stored. The computer-readable medium can be any tangible medium that may contain or store a program used by or associated with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media may include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination thereof. More specific examples of the machine-readable storage medium will include electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0124] As used herein, “at least one of the following: a list of two or more elements” and “at least one of the following: a list of two or more elements” and similar wording (where the list of two or more elements is connected by “and” or “or”) refers to at least any one element, or at least any two or more elements, or all elements.

[0125] Furthermore, while the operations are described in a specific order, this should not be construed as requiring such operations to be performed in the specific order or sequence shown, or requiring all of the operations shown to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0126] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the subject matter defined in the appended claims is not limited to the specific features or actions described above. Rather, the specific features and actions discussed above are disclosed as examples of implementing the claims.

Claims

1. An application client comprising instructions for executing at least the following: Sending an application service request to the application server, the application service request including a temporary identifier of the user device on which the application client is running; and Receive application service response from the application server.

2. The application client as described in claim 1, further comprising instructions for executing at least the following: Send a temporary identifier request to the user equipment; and Receive a temporary identifier response including the temporary identifier from the user equipment.

3. A user equipment, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following: Send an application service request to the application server, the application service request including at least one of the following: A temporary identifier of the user equipment associated with a protocol data unit session supporting the application service, or AKMA key identifiers for application authentication and key management; and Receive application service response from the application server.

4. The user equipment as claimed in claim 3, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following: Send a Protocol Data Unit (PDU) session request to the session management function entity to establish or modify a PDU session that supports the application service. as well as Receive a message including the temporary identifier from the session management function entity.

5. The user equipment as claimed in claim 4, wherein, The temporary identifier is received in the protocol data unit session establishment or modification response message or extended protocol configuration option message from the session management function entity.

6. The user equipment as claimed in claim 4 or 5, wherein, The protocol data unit session request is triggered by a temporary identifier request from an application client running on the user equipment, and the temporary identifier is sent to the application client in a temporary identifier response.

7. The user equipment as described in any one of claims 4-6, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the user equipment to perform at least the following: Generate initial temporary identifiers; and Provide the initial temporary identifier to the session management function entity.

8. The user equipment as described in any one of claims 4-7, wherein, The protocol data unit session request also includes an application function identifier.

9. An application server, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the application server to execute at least the following: Receive an application service request from the user equipment, the application service request including a temporary identifier of the user equipment associated with a protocol data unit session supporting the application service; Send a User Equipment Identifier Request, including the temporary identifier, to the Network Exposure Function Entity; Receive a User Equipment Identifier Response, including an Application-Specific User Equipment Identifier, from the Network Exposure Function Entity; Send a user equipment information request, including the application-specific user equipment identifier, to the network exposure function entity; Receive a user equipment information response, including the requested user equipment information, from the network exposure function entity; and Send an application service response to the user equipment.

10. The application server as described in claim 9, wherein, The user equipment information is the location of the user equipment.

11. A session management function entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the session management function entity to perform at least the following: Receive Protocol Data Unit Session Request from User Equipment; Send information about the protocol data unit session associated with the protocol data unit session request to the unified data management function entity; Receive a temporary identifier associated with the protocol data unit session from the unified data management function entity; as well as Send a message including the temporary identifier to the user equipment.

12. The session management function entity as described in claim 11, wherein, The temporary identifier is sent to the user equipment in the Protocol Data Unit Session Establishment or Modification Response Message or Extended Protocol Configuration Options Message.

13. The session management function entity as described in claim 11 or 12, wherein, The protocol data unit session request includes a preliminary temporary identifier, and the session management function entity includes the preliminary temporary identifier in the protocol data unit session information sent to the unified data management function entity.

14. The session management function entity as described in any one of claims 11-13, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the session management function entity to perform at least the following: Generate an initial temporary identifier; as well as Provide the initial temporary identifier to the unified data management function entity.

15. A network exposure functional entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: Receive a User Equipment Identifier Request, which includes a temporary identifier for the user equipment, from the application server; The user equipment identifier is obtained from the unified data management function entity based on the temporary identifier; Based on the user equipment identifier and application function identifier, obtain the application-specific user equipment identifier from the unified data management function entity; as well as Send a User Device Identifier (MPI) response, including the application-specific MPI, to the application server.

16. The network exposure functional entity as described in claim 15, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: Based on the information of the unified data management group identifier contained in the temporary identifier, the unified data management function entity is determined to obtain the user equipment identifier.

17. The network exposure functional entity as described in claim 15 or 16, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: The application function identifier obtained from the unified data management entity along with the user equipment identifier is verified by comparing it with the application function identifier received in the user equipment identifier request from the application server.

18. The network exposure functional entity as described in any one of claims 15-17, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: After obtaining the application-specific user device identifier from the unified data management function entity, an access control policy is selected for the application-specific user device identifier; Receive a user device information request, including the application-specific user device identifier, from the application server; Verify whether the application-specific user equipment identifier included in the user equipment information request conforms to the access control policy; as well as Send a user device information response, including the requested user device information, to the application server.

19. A unified data management functional entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the unified data management function entity to perform at least the following: Receive information about the protocol data unit session from the session management function entity; Generate a temporary identifier for the protocol data unit session, the temporary identifier containing information identifying a unified data management group identifier associated with the unified data management function entity; A mapping between the temporary identifier and the user equipment identifier is stored in the unified data repository functional entity, wherein the user equipment identifier represents the user equipment associated with the protocol data unit session; as well as Send the temporary identifier to the session management function entity.

20. The unified data management functional entity as described in claim 19, wherein, The protocol data unit session information received from the session management function entity includes a preliminary temporary identifier, and the unified data management function entity generates the temporary identifier based on the preliminary temporary identifier.

21. A unified data management functional entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the unified data management function entity to perform at least the following: Receive a User Equipment Identifier Acquisition Request containing a temporary identifier of the User Equipment from the Network Exposure Function Entity; Sending a User Equipment Identifier (UEI) to the Network Exposure Function Entity to obtain a response, the UEI response including the UEI mapped to the temporary identifier; Receive an application-specific user equipment identifier retrieval request containing the user equipment identifier and the application function identifier from the network exposure function entity; as well as Sending an application-specific user equipment identifier (APDI) to the network exposure function entity to obtain a response, wherein the ADI response includes an application-specific user equipment identifier corresponding to the user equipment identifier and the application function identifier.

22. An application server, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the application server to execute at least the following: Receive application service requests from user equipment, including AKMA key identifiers for application authentication and key management; Send an application key request, including the AKMA key identifier, to the network exposure function entity; Receive an application key response from the network exposure function entity, the application key response including an application key for the application server and a generic public subscription identifier for the user device; Send a user equipment information request, including the general public subscription identifier, to the network exposure function entity; Receive a user equipment information response, including the requested user equipment information, from the network exposure function entity; and Send an application service response to the user equipment.

23. A network exposure functional entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: Receive an application key request from the application server, the application key request including an AKMA key identifier for application authentication and key management; Based on the AKMA key identifier, obtain the application key and subscription permanent identifier for the application server from the AKMA anchoring function entity; Convert the subscription permanent identifier to a general public subscription identifier; Send an application key response to the application server, the application key response including the application key for the application server and the general public subscription identifier; Receive a user device information request including the general public subscription identifier from the application server; as well as Send a user device information response to the application server.

24. The network exposure functional entity as described in claim 23, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: After converting the subscription persistent identifier to the general public subscription identifier, an access control policy is selected for the general public subscription identifier; and In response to a user equipment information request received from the application server that includes the general public subscription identifier, the system verifies whether the general public subscription identifier included in the user equipment information request conforms to the access control policy.

25. An application server, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the application server to execute at least the following: Receive an application service request from the user equipment, the application service request including at least one of the user equipment's temporary identifier or the AKMA key identifier for application authentication and key management; Send a user equipment information request to the network exposure function entity, including at least one of the temporary identifier and the AKMA key identifier; Receive a user equipment information response, including the requested user equipment information, from the network exposure function entity; as well as Send an application service response to the user equipment.

26. The application server as described in claim 25, wherein, If the application service request received from the user equipment includes the AKMA key identifier, the user equipment information request sent to the network exposure function entity includes the AKMA key identifier and the application function identifier.

27. A network exposure functional entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: Receive a user device information request from the application server, including a temporary identifier for the user device. The user equipment identifier is obtained from the unified data management function entity based on the temporary identifier; The requested user equipment information is obtained based on the user equipment identifier. as well as Send a user device information response to the application server.

28. The network exposure functional entity as described in claim 27, wherein, The at least one memory also stores instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: The application function identifier obtained from the unified data management entity along with the user equipment identifier is verified by comparing it with the application function identifier received in the user equipment identifier request from the application server.

29. A network exposure functional entity, comprising: At least one processor; as well as At least one memory storing instructions that, when executed by the at least one processor, cause the network-exposed functional entity to perform at least the following: Receive user equipment information request from application server, the user equipment information request including AKMA key identifier for application authentication and key management; The subscription permanent identifier is obtained from the AKMA anchoring function entity based on the AKMA key identifier; The requested user device information is obtained based on the subscription permanent identifier; as well as Send a user device information response to the application server.

30. A method comprising: The application client sends an application service request to the application server, the application service request including a temporary identifier of the user device on which the application client is running; as well as Receive application service response from the application server.

31. The method of claim 30, further comprising: Send a temporary identifier request to the user equipment; as well as Receive a temporary identifier response including the temporary identifier from the user equipment.

32. A method comprising: Send an application service request to the application server, the application service request including at least one of the following: A temporary identifier of the user device associated with the Protocol Data Unit session supporting the application service, or AKMA key identifiers for application authentication and key management; and Receive application service response from the application server.

33. The method of claim 32, further comprising: Send a Protocol Data Unit (PDU) session request to the session management function entity to establish or modify a PDU session that supports the application service. as well as Receive a message including the temporary identifier from the session management function entity.

34. The method of claim 33, wherein, The temporary identifier is received in the protocol data unit session establishment or modification response message or extended protocol configuration option message from the session management function entity.

35. The method of claim 33 or 34, wherein, The protocol data unit session request is triggered by a temporary identifier request from an application client running on the user equipment, and the temporary identifier is sent to the application client in a temporary identifier response.

36. The method according to any one of claims 33-35, further comprising: Generate an initial temporary identifier; as well as Provide the initial temporary identifier to the session management function entity.

37. The method according to any one of claims 33-36, wherein, The protocol data unit session request also includes an application function identifier.

38. A method comprising: Receive an application service request from the user equipment, the application service request including a temporary identifier of the user equipment associated with a protocol data unit session supporting the application service; Send a User Equipment Identifier Request, including the temporary identifier, to the Network Exposure Function Entity; Receive a User Equipment Identifier Response, including an Application-Specific User Equipment Identifier, from the Network Exposure Function Entity; Send a user equipment information request, including the application-specific user equipment identifier, to the network exposure function entity; Receive a user equipment information response, including the requested user equipment information, from the network exposure function entity; and Send an application service response to the user equipment.

39. The method of claim 38, wherein, The user equipment information is the location of the user equipment.

40. A method comprising: Receive Protocol Data Unit Session Request from User Equipment; Send information about the protocol data unit session associated with the protocol data unit session request to the unified data management function entity; Receive a temporary identifier associated with the protocol data unit session from the unified data management function entity; as well as Send a message including the temporary identifier to the user equipment.

41. The method of claim 40, wherein, The temporary identifier is sent to the user equipment in the Protocol Data Unit Session Establishment or Modification Response Message or Extended Protocol Configuration Options Message.

42. The method of claim 40 or 41, wherein, The protocol data unit session request includes a preliminary temporary identifier, and the preliminary temporary identifier is included in the protocol data unit session information sent to the unified data management function entity.

43. The method according to any one of claims 40-42, further comprising: Generate an initial temporary identifier; as well as Send the initial temporary identifier to the unified data management function entity.

44. A method comprising: Receive a User Equipment Identifier Request, which includes a temporary identifier for the user equipment, from the application server; The user equipment identifier is obtained from the unified data management function entity based on the temporary identifier; Based on the user equipment identifier and application function identifier, obtain the application-specific user equipment identifier from the unified data management function entity; as well as Send a User Device Identifier (MPI) response, including the application-specific MPI, to the application server.

45. The method of claim 44, further comprising: The unified data management function entity is determined based on the information of the unified data management group identifier contained in the temporary identifier to obtain the user equipment identifier.

46. ​​The method of claim 44 or 45, further comprising: The application function identifier obtained from the unified data management entity along with the user equipment identifier is verified by comparing it with the application function identifier received in the user equipment identifier request from the application server.

47. The method of any one of claims 44 to 46, further comprising: After obtaining the application-specific user device identifier from the unified data management function entity, an access control policy is selected for the application-specific user device identifier; Receive a user device information request, including the application-specific user device identifier, from the application server; Verify whether the application-specific user equipment identifier included in the user equipment information request conforms to the access control policy; as well as Send a user device information response, including the requested user device information, to the application server.

48. A method comprising: Receive information about the protocol data unit session from the session management function entity; Generate a temporary identifier for the protocol data unit session, the temporary identifier containing information identifying a unified data management group identifier associated with a unified data management function entity; A mapping between the temporary identifier and the user equipment identifier is stored in the unified data repository functional entity, wherein the user equipment identifier represents the user equipment associated with the protocol data unit session; as well as Send the temporary identifier to the session management function entity.

49. The method of claim 48, wherein, The protocol data unit session information received from the session management function entity includes a preliminary temporary identifier, and the temporary identifier is generated based on the preliminary temporary identifier.

50. A method comprising: Receive a User Equipment Identifier Acquisition Request containing a temporary identifier of the User Equipment from the Network Exposure Function Entity; Sending a User Equipment Identifier (UEI) to the Network Exposure Function Entity to obtain a response, the UEI response including the UEI mapped to the temporary identifier; Receive an application-specific user equipment identifier retrieval request containing the user equipment identifier and the application function identifier from the network exposure function entity; as well as Sending an application-specific user equipment identifier (APDI) response to the network exposure function entity, the ADI response including an application-specific user equipment identifier corresponding to the user equipment identifier and the application function identifier.

51. A method comprising: Receive application service requests from user equipment, including AKMA key identifiers for application authentication and key management; Send an application key request, including the AKMA key identifier, to the network exposure function entity; Receive an application key response from the network exposure function entity, the application key response including an application key for the application server and a generic public subscription identifier for the user equipment; Send a user equipment information request, including the general public subscription identifier, to the network exposure function entity; Receive a user equipment information response, including the requested user equipment information, from the network exposure function entity; and Send an application service response to the user equipment.

52. A method comprising: Receive an application key request from the application server, including an AKMA key identifier for application authentication and key management; Based on the AKMA key identifier, obtain the application key and subscription permanent identifier for the application server from the AKMA anchoring function entity; Convert the subscription permanent identifier to a general public subscription identifier; Send an application key response to the application server, the application key response including the application key for the application server and the general public subscription identifier; Receive a user device information request including the general public subscription identifier from the application server; as well as Send a user device information response to the application server.

53. The method of claim 52, further comprising: After converting the subscription persistent identifier into the general public subscription identifier, select an access control policy for the general public subscription identifier; as well as In response to a user equipment information request received from the application server that includes the general public subscription identifier, the system verifies whether the general public subscription identifier included in the user equipment information request conforms to the access control policy.

54. A method comprising: Receive an application service request from the user equipment, the application service request including at least one of the user equipment's temporary identifier or the AKMA key identifier for application authentication and key management; Send a user equipment information request to the network exposure function entity, including at least one of the temporary identifier and the AKMA key identifier; Receive a user equipment information response, including the requested user equipment information, from the network exposure function entity; as well as Send an application service response to the user equipment.

55. The method of claim 54, wherein, If the application service request received from the user equipment includes the AKMA key identifier, the user equipment information request sent to the network exposure function entity includes the AKMA key identifier and the application function identifier.

56. A method comprising: Receive a user device information request from the application server, including a temporary identifier for the user device. The user equipment identifier is obtained from the unified data management function entity based on the temporary identifier; The requested user equipment information is obtained based on the user equipment identifier; as well as Send a user device information response to the application server.

57. The method of claim 56, further comprising: The application function identifier obtained from the unified data management entity along with the user equipment identifier is verified by comparing it with the application function identifier received in the user equipment identifier request from the application server.

58. A method comprising: Receive user equipment information request from application server, the user equipment information request including AKMA key identifier for application authentication and key management; The subscription permanent identifier is obtained from the AKMA anchoring function entity based on the AKMA key identifier; The requested user device information is obtained based on the subscription permanent identifier; as well as Send a user device information response to the application server.

59. An apparatus for a user equipment, comprising means for performing the method of any one of claims 30-37.

60. An apparatus for an application server, comprising means for performing the method of any one of claims 38-39, 51, 54-55.

61. An apparatus for a session management functional entity, comprising means for performing the method of any one of claims 40-43.

62. An apparatus for exposing a network functional entity, comprising means for performing the method of any one of claims 44-47, 52-53, 56-58.

63. An apparatus for a unified data management functional entity, comprising means for performing the method of any one of claims 48-50.

64. A computer-readable medium comprising instructions that, when executed by means for a user equipment, cause the user equipment to perform at least the method of any one of claims 30-37.

65. A computer-readable medium comprising instructions that, when executed by means for an application server, cause the application server to perform at least the method of any one of claims 38-39, 51, and 54-55.

66. A computer-readable medium comprising instructions that, when executed by means for a session management functional entity, cause the session management functional entity to perform at least the method of any one of claims 40-43.

67. A computer-readable medium comprising instructions that, when executed by means for a network exposure function entity, cause the network exposure function entity to perform at least the method of any one of claims 44-47, 52-53, and 56-58.

68. A computer-readable medium comprising instructions that, when executed by means for a unified data management functional entity, cause the unified data management functional entity to perform at least the method of any one of claims 48-50.