Authentication and key management

CN122846115APending Publication Date: 2026-09-29NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610384741.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2026-03-26
Publication Date
2026-09-29

Smart Images

  • Figure CN122846115A_ABST
    Figure CN122846115A_ABST
Patent Text Reader

Abstract

The exemplary embodiments of this disclosure relate to authentication and key management. In one method, an apparatus receives a message from a network entity for establishing a Transport Layer Security (TLS) tunnel between the apparatus and the network entity. The apparatus determines first TLS information for establishing the TLS tunnel based on the message and a first session key used by the apparatus to protect the session between the apparatus and the network entity. The first session key is associated with a second session key used by the network entity to determine second TLS information for establishing the TLS tunnel. Therefore, a TLS tunnel can be established in a flexible and efficient manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various exemplary embodiments of this disclosure generally relate to the telecommunications domain, and particularly to methods, apparatuses, devices, and computer-readable storage media for authentication and key management. Background Technology

[0002] A communication network can serve as a facility that enables communication between two or more communication devices or provides communication devices with access to a data network. Mobile or wireless communication networks are an example of communication networks. Communication devices may be served by application servers.

[0003] Communication networks can operate according to standards such as those provided by the 3rd Generation Partnership Project (3GPP) or the European Telecommunications Standards Institute (ETSI). Examples of standards provided by 3GPP are the so-called 3GPP standards used for multiple generations of cellular technologies, such as those for 4G, 5G, and 6G technologies. Summary of the Invention

[0004] In a first aspect of this disclosure, an apparatus is provided. The apparatus includes at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: receive from a network entity a message for establishing a transport layer security (TLS) tunnel between the apparatus and the network entity; and determine first TLS information for establishing the TLS tunnel based on the message and a first session key for the apparatus to protect a session between the apparatus and the network entity, wherein the first session key is associated with a second session key for the network entity to determine second TLS information for establishing the TLS tunnel.

[0005] In a second aspect of this disclosure, a network entity is provided. The network entity includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the network entity to at least: send a message to a device for establishing a transport layer security (TLS) tunnel between the device and the network entity; and determine second TLS information for establishing the TLS tunnel based on the message and a second session key for the network entity to protect the session between the device and the network entity, wherein the second session key is associated with a first session key for the device to determine first TLS information for establishing the TLS tunnel.

[0006] In a third aspect of this disclosure, a method is provided. The method includes: receiving from a network entity a message for establishing a transport layer security (TLS) tunnel between a device and the network entity; and determining first TLS information for establishing the TLS tunnel based on the message and a first session key for the device to protect a session between the device and the network entity, wherein the first session key is associated with a second session key for the network entity to determine second TLS information for establishing the TLS tunnel.

[0007] In a fourth aspect of this disclosure, a method is provided. The method includes: sending a message to a device for establishing a transport layer security (TLS) tunnel between the device and a network entity; and determining second TLS information for establishing the TLS tunnel based on the message and a second session key used by the network entity to protect a session between the device and the network entity, wherein the second session key is associated with a first session key used by the device to determine first TLS information for establishing the TLS tunnel.

[0008] In a fifth aspect of this disclosure, an apparatus is provided. The apparatus includes components for receiving from a network entity a message for establishing a transport layer security (TLS) tunnel between the apparatus and the network entity; and components for determining first TLS information for establishing the TLS tunnel based on the message and a first session key for the apparatus to protect the session between the apparatus and the network entity, wherein the first session key is associated with a second session key for the network entity to determine second TLS information for establishing the TLS tunnel.

[0009] In a sixth aspect of this disclosure, a network entity is provided. The network entity includes components for sending a message to a device for establishing a transport layer security (TLS) tunnel between the device and the network entity; and components for determining second TLS information for establishing the TLS tunnel based on the message and a second session key for the network entity to protect the session between the device and the network entity, wherein the second session key is associated with a first session key used by the device to determine first TLS information for establishing the TLS tunnel.

[0010] In a seventh aspect of this disclosure, a non-transitory computer-readable medium is provided that includes instructions which, when executed by at least one processor of a device, cause the device to perform at least the method according to a third aspect.

[0011] In an eighth aspect of this disclosure, a non-transitory computer-readable medium is provided that includes instructions which, when executed by at least one processor of a device, cause the device to perform at least the method according to the fourth aspect.

[0012] It should be understood that the summary portion is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0013] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:

[0014] Figure 1A The illustration shows an example communication environment in which example embodiments of the present disclosure may be implemented;

[0015] Figure 1B The illustration shows an example communication environment in which example embodiments of the present disclosure may be implemented;

[0016] Figure 2 The diagram illustrates the signaling flow that yields the Authentication and Key Management (AKMA) anchor key used in the application;

[0017] Figure 3 The diagram illustrates the signaling flow for obtaining the AKMA application key;

[0018] Figure 4 The diagram illustrates the signaling flow for requesting the AKMA application key;

[0019] Figure 5 The diagram illustrates the signaling flow for authentication and key management according to some embodiments of this disclosure;

[0020] Figure 6 The illustration shows a flowchart of an authentication and key management process according to some embodiments of the present disclosure;

[0021] Figure 7 The illustration shows an example signaling flow for authentication and key management according to some embodiments of this disclosure;

[0022] Figure 8 The illustration shows a schematic diagram of an example key hierarchy structure according to some embodiments of the present disclosure;

[0023] Figure 9 The illustration shows a signaling flow of a Transport Layer Security (TLS) based protocol according to some embodiments of the present disclosure;

[0024] Figure 10 The illustration shows an example signaling flow of a TLS-based protocol according to some embodiments of the present disclosure;

[0025] Figure 11 The illustration shows a signaling flow of a TLS-based protocol according to some embodiments of the present disclosure;

[0026] Figure 12The illustration shows an example signaling flow of a TLS-based protocol according to some embodiments of the present disclosure;

[0027] Figure 13 The illustration shows an example signaling flow of a TLS-based protocol according to some embodiments of the present disclosure;

[0028] Figure 14 The illustration shows a flowchart of a method implemented at a device according to some exemplary embodiments of the present disclosure;

[0029] Figure 15 The illustration shows a flowchart of a method implemented at a network entity according to some example embodiments of the present disclosure;

[0030] Figure 16 The illustration shows a flowchart of a method implemented at a network entity according to some example embodiments of the present disclosure;

[0031] Figure 17 The illustration shows a flowchart of a method implemented at a device according to some exemplary embodiments of the present disclosure;

[0032] Figure 18 The illustration shows a flowchart of a method implemented at a network entity according to some example embodiments of the present disclosure;

[0033] Figure 19 The illustration shows a flowchart of a method implemented at a device according to some exemplary embodiments of the present disclosure;

[0034] Figure 20 The illustration shows a flowchart of a method implemented at a network entity according to some example embodiments of the present disclosure;

[0035] Figure 21 A simplified block diagram of a device suitable for implementing exemplary embodiments of the present disclosure is illustrated; and

[0036] Figure 22 A block diagram of an example computer-readable medium according to some example embodiments of the present disclosure is illustrated.

[0037] Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0038] The principles of this disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described for illustrative purposes only and to assist those skilled in the art in understanding and implementing this disclosure, and do not constitute any limitation on the scope of this disclosure. The embodiments described herein can be implemented in various ways other than those described below.

[0039] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0040] In this disclosure, references to "an embodiment," "embodiment," and "example embodiment," etc., indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment must include that particular feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Moreover, when a particular feature, structure, or characteristic is described in connection with an embodiment, those skilled in the art will understand that, whether explicitly described or not, combining it with other embodiments to affect such a feature, structure, or characteristic is within the knowledge of those skilled in the art.

[0041] It should be understood that although the terms "first," "second," etc., preceding the nouns(s) herein may be used to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and do not restrict the order of the nouns(s). For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0042] As used herein, “at least one of the following: ” and “at least one of the following: ” and similar wording (where the list of two or more elements is connected by “and” or “or”) means at least any one of these elements, or at least any two or more of these elements, or at least all of these elements.

[0043] As used herein, unless explicitly stated otherwise, “responding to A” does not mean that the step is performed immediately after “A” occurs, but rather that the step may include one or more intermediate steps.

[0044] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. The singular forms “a,” “an,” and “the” used herein also include the plural forms unless the context clearly indicates otherwise. Further understanding, the terms “comprises,” “comprising,” “has,” “having,” “includes,” and / or “including” as used herein specify the presence of the stated features, elements, and / or components, but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0045] As used in this application, the term "circuit system" may refer to one or more or all of the following: (a) Pure hardware circuit implementation (such as implementations only in analog and / or digital circuit systems), and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of (multiple) analog and / or digital hardware circuits and software / firmware, and (ii) Any part of a hardware processor (including multiple digital signal processors), software, and memory (multiple processors) having software, which work together to enable a device (such as a mobile phone or server) to perform various functions, and (c) (Multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or a portion thereof, which require software (e.g., firmware) to operate, but may be absent when operation is not required.

[0046] The definition of "circuit system" applies to all uses of the term in this application, including in any claim. As another example, as used in this application, the term "circuit system" also covers only hardware circuitry or a processor (or processors) or a portion of hardware circuitry or a processor and its accompanying software and / or firmware. For example, if applicable to a particular claim element, the term "circuit system" also covers baseband integrated circuits or processor integrated circuits for mobile devices, or similar integrated circuits in servers, cellular network devices, or other computing or network devices.

[0047] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-A Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in a communication network can be performed according to any suitable generation of communication protocol, including but not limited to first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G), 5.5G, sixth-generation (6G) communication protocols and / or any other currently known or future-developed protocols. Embodiments of this disclosure can be applied to various communication systems. Given the rapid development of communications, there will naturally be communication technologies and systems that can be used to embody future types of communication technologies and systems. This should not be construed as limiting the scope of this disclosure to the systems described above.

[0048] As used herein, the term "network device" refers to a node in a communication network through which terminal devices access the network and receive services. A network device can refer to a base station (BS) or access point (AP), such as a Node B (NodeB or NB), an evolved Node B (eNodeB or eNB), an NR NB (also known as a gNB), a Remote Radio Unit (RRU), a Radio Header (RH), a Remote Radio Header End (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low-power node (such as a femtosecond or picosecond), a non-terrestrial network (NTN), or a non-terrestrial network device (such as satellite network equipment, low Earth orbit (LEO) satellites and geostationary orbit (GEO) satellites, aircraft network equipment, etc.), depending on the terminology and technologies applied. In some example embodiments, the Radio Access Network (RAN) split architecture includes a centralized unit (CU) and a distributed unit (DU) at the IAB donor node. An IAB node includes: a mobile terminal (IAB-MT) portion that behaves as a UE to its parent node, and a DU portion of the IAB node that behaves as a base station to the next-hop IAB node.

[0049] The term "terminal device" refers to any terminal device capable of wireless communication. As an example and not a limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, Voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop mounted devices (LME), USB dongles, smart devices, wireless customer premises equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronics devices, commercially operated devices and / or industrial wireless networks, etc. The terminal device may also correspond to the mobile terminal (MT) portion of an IAB node (e.g., a relay node). In the following description, the terms "terminal device," "communication device," "terminal," "user equipment," and "UE" are used interchangeably.

[0050] As used herein, the terms “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” can refer to any resource used to perform communication, such as communication between a terminal device and a network device, including time-domain resources, frequency-domain resources, spatial-domain resources, code-domain resources, or any other combination of time-domain resources, frequency-domain resources, spatial-domain resources, and / or code-domain resources used to implement communication. In the following, unless explicitly stated otherwise, resources in both the frequency and time domains will be used as examples of transmission resources to describe some exemplary embodiments of this disclosure. It should be noted that the exemplary embodiments of this disclosure are equally applicable to other resources in other domains.

[0051] The core network functions described herein can be implemented as core network entities comprising a combination of hardware processing circuitry and software and / or firmware, including machine-readable instructions, or software comprising machine-readable instructions executable by at least one processor of the hardware processing circuitry of the device. A hardware processing circuitry includes at least one processor and at least one memory storing machine-readable instructions executable by at least one processor of the hardware processing circuitry. The processor includes any one or a combination of an accelerator, a microprocessor, the core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, a digital signal processor, a central processing unit, a graphics processing unit, and a tensor processing unit. The memory includes any or some combination of volatile or non-volatile memory (e.g., flash memory, cache, random access memory (RAM), and / or read-only memory (ROM)). The memory stores machine-readable instructions of the software and / or firmware for execution by at least one processor of the hardware processing circuitry. The machine-readable instructions are executable by at least one processor of the hardware processing circuitry to cause the hardware processing circuitry to perform the actions or operations of the methods described herein. For example, the session management function described in this paper can be implemented as a session management entity, and the session management policy control function described in this paper can be implemented as a session management policy control entity.

[0052] Figure 1A An example communication environment 100A is illustrated in which exemplary embodiments of the present disclosure may be implemented. Communication environment 100A relates to device 110, network entity 120, and network entity 130. Device 110 can communicate bidirectionally with network entity 120. Network entity 120 can communicate bidirectionally with network entity 130.

[0053] exist Figure 1A In the example, device 110 may include a terminal device (e.g., a UE). Network entity 120 may include network functions, such as application functions (AF). Network entity 130 may include additional network functions, such as the AKMA anchor function (AAnF).

[0054] It should be understood that Figure 1A The number of devices 110, network entity 120, and network entity 130 and their connections shown are for illustrative purposes only and do not represent any limitation. The communication environment 100A may include any suitable number of devices and / or equipment configured to implement the exemplary embodiments of this disclosure.

[0055] In the following description, for illustrative purposes, some example embodiments are described in which device 110 operates as a terminal device, network entity 120 includes network functions, and network entity 130 includes network functions. However, in some example embodiments, the operations described in connection with a terminal device may be implemented at a network device or other device, and the operations described in connection with a network device may be implemented at a terminal device or other device.

[0056] Figure 1B An example communication environment 100B is illustrated in which exemplary embodiments of the present disclosure may be implemented. Communication environment 100B relates to device 140 and network entity 150. Device 140 can communicate bidirectionally with network entity 150.

[0057] exist Figure 1B In the example, device 140 may include a terminal device (e.g., UE). Network entity 150 may include network functions, such as AF.

[0058] It should be understood that Figure 1B The number of devices 140 and network entities 150 and their connections shown are for illustrative purposes only and do not represent any limitation. The communication environment 100B may include any suitable number of devices and / or equipment configured to implement the exemplary embodiments of this disclosure.

[0059] In the following description, for illustrative purposes, some example embodiments are depicted in which device 140 operates as a terminal device and network entity 150 includes network functions. However, in some example embodiments, the operations described in connection with a terminal device may be implemented at a network device or other device, and vice versa.

[0060] Communication in communication environments 100A and 100B can be implemented according to any suitable communication protocol(s), including but not limited to cellular communication protocols, wireless LAN communication protocols such as IEEE 802.11, and / or any other protocols currently known or to be developed in the future. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple Input Multiple Output (MIMO), Orthogonal Frequency Division Multiplexing (OFDM), Discrete Fourier Transform Spread Spectrum OFDM (DFT-s-OFDM), and / or any other technologies currently known or to be developed in the future.

[0061] The study will investigate mechanisms for separate authentication of the UE to support AKMA functionality. For example, the 5G master authentication process performed during UE registration can be used to authenticate the UE for AKMA. If the 5G master authentication process is successfully executed, keys, such as those generated by the Authentication Server Function (AUSF), can be stored at both the AUSF and the UE.

[0062] refer to Figure 2 The diagram illustrates the process of deriving the AKMA anchor key (also referred to as "K" for discussion purposes). AKMA The signaling flow 200 may involve UE 201, Access and Mobility Management Function (AMF) 202, AUSF 203, Unified Data Management (UDM) Function 204 and AAnF 205.

[0063] like Figure 2 As shown, at point 2001, UE 201, AMF 202, and AMF 203 can perform the main authentication process. During the main authentication process, AMF 203 can interact with UDM 204 to obtain authentication information, such as subscription certificates (e.g., authentication and key negotiation (AKA) authentication vectors) and authentication methods. For example, at point 2010, AMF 203 can send a Nudm_UEAuthentication_Get request message to UDM 204 (e.g., based on a service operation). The Nudm_UEAuthentication_Get request message may include UE 201's Subscription Persistent Identifier (SUPI) and / or Subscription Hidden Identifier (SUCI).

[0064] Then, UDM 204 can send a Nudm_UEAuthentication_Get response message to AUSF 203 at point 2020. This message includes an indication (e.g., an AKMA indication) specifying whether an AKMA anchor key needs to be generated for UE 201. The Nudm_UEAuthentication_Get response message may also include the AKMA indication and the routing identifier (RID) of UE 201. Furthermore, the Nudm_UEAuthentication_Get response message may include an authentication vector. In some example implementations, this can be based on K... AUSF The AKMA temporary identifier (A-TID) is derived from the AKMA key identifier (A-KID).

[0065] If AUSF 203 receives an AKMA instruction from UDM 204, then after the main authentication process is successfully executed, AUSF 203 can store the key generated by AUSF 203 (also referred to as the "AUSF key" or "K key" for discussion purposes). AUSFThen, AUSF 203 can be based on K at 2032. AUSF Generate AKMA key K AKMA Furthermore, at 2034, A-KID is generated. Additionally, at 2034, AUSF 203 can determine A-KID based on the RID of UE 201 received from UDM 204.

[0066] After the main authentication process is successfully executed, K AUSF It can be stored at UE 201. UE 201 can generate K at 2031. AKMA At point 2033, UE 201 can initiate communication with AKMA application functions based on K... AUSF To generate an A-KID. An A-KID can identify the K of UE 201. AKMA The A-KID can be in Network Access Identifier (NAI) format, including a username portion and a domain portion. The username portion of the A-KID can include the RID of UE 201, and the domain portion of the A-KID can include the home network identifier.

[0067] AUSF 203 can choose AAnF 205 and send A-KID to AAnF 205. For example, at 2040, AUSF 203 can send a Naanf_AKMA_Anchorkey_Register request message to AAnF 205 (e.g., based on a service operation), which includes A-KID, K... AKMA And UE 201's SUPI. AAnF 205 can store A-KID, K AKMA And SUPI of UE 201.

[0068] In some example embodiments, after sending a Naanf_AKMA_Anchorkey_Register request message to AAnF 205, AUSF 203 may not store the A-KID and K. AKMA During the recertification process, AUSF 203 can generate a new A-KID and a new K. AKMA Then, AUSF 203 can send the new A-KID and the new K to AAnF 205. AKMA AAnF 205 can delete the A-KID and K stored in AAnF 205. AKMA It can also store new A-KIDs and new K. AKMA .

[0069] At 2050, AAnF 205 can send a Naanf_AKMA_Anchorkey_Register response message to AUSF 203 (e.g., based on service operations).

[0070] exist Figure 2 In the example, K AKMA It can be from K AUSF This is derived from the fact that K in A-KID... AKMA Both A-TID and K are based on the master authentication process and are obtained from K. AUSF Therefore, K AKMA A-KID can be updated through a new, successful master authentication process.

[0071] refer to Figure 3 The diagram illustrates the process of deriving the AKMA application key (also referred to as the "AF key" or "K key" for discussion purposes). AF The signaling flow 300 may involve UE 301, AUSF 302, AAnF 303, and Application Function (AF) 304. Figure 3 In the example, AF 304 can request the AKMA key from AAnF 303. Furthermore, AF 304 can be located within the operator's network.

[0072] Before communication between UE 301 and AF 304, UE 301 and AF 304 may need to know whether AKMA is used. In some example embodiments, UE 301 and AF 304 may be implicitly indicated to UE 301 whether AKMA is used. Alternatively, AF 304 may indicate to UE 301 whether AKMA is used.

[0073] At position 3001, master authentication and key authentication can be performed. AKMA Establishment process (e.g., Figure 2 (The process described in the text). UE 301 can initiate communication with AF 304 according to K. AUSF Generate K AKMA And A-KID.

[0074] At point 3010, UE 301 can initiate communication with AF 304 by sending an Application Session Establishment Request message to AF 304. The Application Session Establishment Request message may include A-KID. In some example implementations, UE 301 can derive KID before sending the Application Session Establishment Request message. AF Alternatively, UE 301 can derive K after sending the application session establishment request message. AF .

[0075] Upon receiving an application session establishment request message, if AF 304 does not have an activity context associated with A-KID, AF can select AAnF 303. At 3020, AF 304 can send a Naanf_AKMA_ApplicationKey_Get request message to AAnF 303, which includes the A-KID and the identifier of AF 304. The identifier of AF 304 may include the fully qualified domain name of AF 304 and the Ua identifier of the security protocol used by AF 304 and UE 301. Security protocol identifier.

[0076] AAnF 303 can determine whether it is allowed to provide services to AF 304 based on local policies or authorization information. Furthermore, AAnF 303 can communicate with the Network Repository Function (NRF) based on the AF 304's identifier and the policies used to determine whether services are permitted.

[0077] AAnF 303 can be based on the K identified by A-KID. AKMA The existence of AKMA is used to verify whether a subscriber (e.g., UE 301) is authorized to use AKMA. Specifically, if K is not present in AKMA 303... AKMA Then at 3040, AAnF 303 can send a Naanf_AKMA_ApplicationKey_Get response message to AF 304, which includes an indication of K AKMA Missing error indication. In this case, at 3050, AF 304 can send an application session establishment response message to UE 301, which includes a rejection indication of the application session establishment request and a failure indication indicating the reason for the failure.

[0078] If K exists in AAnF 303 AKMA And if the AF key or K AF If it is not stored in AAnF 303, then AAnF303 can be based on K at 3030. AKMA Derive K AF Then, at 3040, AAnF 303 can send a Naanf_AKMA_ApplicationKey_Get response message to AF 304, which includes the SUPI and K of UE 301. AF and K AF The expiration time. At 3050, AF 304 can send an application session establishment response message to UE 301, which includes the expiration time with K. AF The associated A-KID. The NEF403 can communicate with ANF in the carrier network.

[0079] In some cases, an AF (Automatic Firewall) can be located outside the operator's network. (See reference) Figure 4 The diagram illustrates signaling flow 400 requesting the AKMA application key in this scenario. Signaling flow 400 may involve... Figure 3 UE 301 and AAnF 303 in the example. Furthermore, Figure 4 This may involve Network Open Function (NEF) 403 and AF 404. In Figure 4 In the example, AF 404 can request the AKMA key from AAnF 303 via NEF 403. Furthermore, AF 404 can be located outside the operator's network.

[0080] In requesting UE 301's K from AAnF 303 AF Previously, for example, when UE 301 sent an application session establishment request message to AF 404, AF 404 could determine the Home Public Land Mobile Network (HPLMN) of UE 301 based on A-KID. AF 404 could then send an Nnef_AKMA_AFkey request message, including the identifier of AF 404 and A-KID, to AAnF 303 via NEF 403 (e.g., based on the NEF service API).

[0081] In some example implementations, the network architecture may not support the Common Application Programming Interface (API) framework for the 3GPP Northbound API (CAPIF). In this case, AF 404 can be configured with API endpoints for services. If the network architecture supports CAPIF, AF 404 can obtain service API information from the core CAPIF functionality via the availability of service API event notifications or service discovery response messages.

[0082] NEF 403 can determine whether AF 404 is authorized for the service. If AF 404 is authorized, request K AF Then NEF 403 can be found at 3030 and AAnF 303 can be selected for service.

[0083] At position 4030, NEF 403 can send a Naanf_AKMA_AFkey request message to AAnF 303 at position 3010, which includes the A-KID and the identifier of AF 404. AAnF 303 can determine the key based on the A-KID. AKMA Does it exist?

[0084] If K exists in AAnF 303 AKMA Then at position 4040, AAnF 303 can generate K. AFAnd send a Naanf_AKMA_AFkey response message to NEF 403, which includes SUPI and K of UE 301. AF and K AF The expiration time. In this case, at 4050, NEF 403 can send an Nnef_AKMA_AFkey response message to AF 404, which includes K AF and K AF The expiration time. Additionally, the Nnef_AKMA_AFkey response message may also include an external identifier for UE 301, such as the General Public Subscription Identifier (GPSI) of UE 301. The GPSI of UE 301 can be determined by NEF 403 based on the UE 301's SUPI using the Nudm_SubscriberDataManagement service according to the local policy in NEF 403.

[0085] If K does not exist in AAnF 303 AKMA Then at 4040, AAnF 303 can send a Naanf_AKMA_AFkey response message to NEF 403, which includes an indication of K AKMA Missing error indication. At 4050, NEF 403 can send an Nnef_AKMA_AFkey response message to AF 404, which includes an error indication.

[0086] Encryption algorithms can be used to protect confidential electronic information (such as emails, medical records, financial statements, etc.) from unauthorized viewing. They can also be used to defend against attacks that attempt to crack encryption using traditional computers. However, quantum computers may be able to break encryption algorithms, making electronic secrets easily discoverable.

[0087] To counter the threat posed by quantum computers to encryption algorithms, new encryption methods may be needed to defend against cyberattacks from both traditional and quantum computers. These new encryption methods could be termed post-quantum encryption algorithms or post-quantum algorithms.

[0088] Quantum computers can utilize the counterintuitive properties of quantum mechanics, which allow a single bit of data to act as both 0 and 1 simultaneously, enabling computations that might be difficult or impossible on conventional computers.

[0089] A sufficiently powerful quantum processor in a quantum computer can simultaneously sift through many potential solutions to a problem and quickly determine the correct answer, which may be difficult for a traditional computer.

[0090] For the AKMA process, the AKMA key (e.g., K) AFThis can be used for a long time between the UE and AF after many sessions. Traditional public-key algorithms used to derive AKMA keys may become obsolete and insecure because the assumption that the mathematical problems of traditional public-key algorithms that provide a reliable level of security are difficult to solve no longer applies to cryptography-related quantum computers (CRQC).

[0091] Neither traditional public-key algorithms nor post-quantum algorithms can be trusted to protect data throughout its required lifecycle. Post-quantum algorithms may face uncertainties in underlying mathematics, compliance issues, unknown vulnerabilities, or hardware and software implementation problems. Furthermore, post-quantum algorithms may not be mature enough to exclude cryptanalysis attacks and implementation errors.

[0092] Furthermore, symmetric-key algorithms are also susceptible to cryptanalysis attacks, although they may not be affected by asymmetric-key algorithms. Symmetric keys generated using pseudo-random number generators (PRNGs) may have lower entropy or randomness compared to those generated from quantum random number generators (QRNGs). Therefore, whether using manually shared pre-shared keys (PSKs) or quantum key distribution (QKD), key generation based on QRNGs may offer higher security. Thus, to provide an additional layer of quantum security against PRNG-generated symmetric keys, a hybrid approach of post-quantum pre-shared keys (PPKs) and QRNGs is necessary.

[0093] Embodiments of this disclosure present several solutions for authentication and key management. In one solution, a device sends a request to a network entity to establish a session between the device and the network entity. The request includes a public key associated with a private key used to determine a session key (also referred to as a "first session key" for the purposes of discussion) for protecting the session for the device. The public key is used to determine another session key (also referred to as a "second session key" for the purposes of discussion) for protecting the session for the network entity. The second session key and ciphertext information to be used to determine the first session key can be obtained by the network entity based on the public key. The network entity sends a response to the request to the device, the response including the ciphertext information. The first session key is determined by the device at least based on the ciphertext information and the private key.

[0094] In this way, the consistency between the first session key and the second session key can be ensured. This provides a flexible and efficient way to protect the session between the device and network entities.

[0095] In another solution, a digest of a session key (also referred to as the "first session key" for discussion purposes) is determined based on a first session key and an authentication management key. The first session key is used by the device to protect the session between the device and the network entity. The first session key is associated with another session key (also referred to as the "second session key" for discussion purposes) used by the network entity to protect the session. A session establishment request, including the digest information and the authentication management key, is sent from the device to the network entity. Verification of the digest information can be performed based on the authentication management key and the second session key.

[0096] In this way, the digest information can be used by network entities to authenticate the device in a flexible and efficient manner. This can improve the security of the session between the device and the network entity.

[0097] In another solution, a message is sent from the network entity to the device to establish a TLS tunnel (also referred to as a "TLS tunnel" for the purposes of discussion). Based on this message and a first session key used by the device to protect the session between the device and the network entity, TLS information (also referred to as "first TLS information" for the purposes of discussion) is determined for the device to establish the TLS tunnel. Further TLS information (also referred to as "second TLS information" for the network entity to establish the TLS tunnel) is determined based on this message and a second session key used by the network entity to protect the session. The first session key is associated with the second session key.

[0098] This method allows for the flexible and efficient establishment of TLS tunnels, ensuring consistency between the first and second TLS messages.

[0099] Several solutions of this disclosure have been briefly described. The principles and implementation of this disclosure will now be described in detail. Example embodiments of this disclosure will be described in detail below with reference to the accompanying drawings.

[0100] It should be understood that Figures 5 to 13 The sequence of actions shown is merely an example and not a limitation. Actions can be performed in any suitable manner. Reference Figures 5 to 13 The described example embodiments can be implemented individually or in any combination. For example, one or more example embodiments shown in a single figure can be combined with one or more example embodiments shown in one or more other figures.

[0101] also, Figures 5 to 13 The process described is merely an example and not a limitation. Figures 5 to 13 The process indicated by the dashed lines is optional and may be excluded from the process according to some exemplary embodiments of this disclosure.

[0102] refer to Figure 5The illustration depicts a signaling flow 500 for authentication and key management according to some embodiments of this disclosure. For discussion purposes, reference will be made to... Figure 1A Discuss signaling flow 500. Figure 5 Involving Figure 1A The device 110, network entity 120 and network entity 130.

[0103] In some example implementations, device 110 may be implemented as or include a terminal device, such as a UE. Network entity 120 may be implemented as or include a device implementing AF. Network entity 130 may be implemented as or include a device implementing ANF.

[0104] In operation, device 110 sends (501) a request to network entity 120 to establish a session between device 110 and network entity 120. This request includes a public key associated with a private key used to determine a first session key for protecting the session for device 110. The public key is used to determine a second session key for protecting the session for network entity 120. Accordingly, network entity 120 receives (502) the request from device 110. Furthermore, the request may also include an indication that the session will be protected by post-quantum computing (PQC). Therefore, network entity 120 may be instructed to use PQC-based methods for authentication and key management.

[0105] In some example embodiments, before sending (501) the request, device 110 may determine the public and private keys based on a key generation algorithm (e.g., a modular lattice-based key encapsulation mechanism (ML-KEM) KeyGen algorithm).

[0106] Network entity 120 obtains (503) ciphertext information and a second session key based on the public key. The ciphertext information will be used to determine the first session key. Specifically, network entity 120 may send (504) an additional request including the public key to network entity 130. Accordingly, network entity 130 receives (505) an additional request from network entity 120.

[0107] In some example embodiments, additional requests may include further instructions specifying that the session will be protected by PQC. In this way, network entity 130 may be instructed to use PQC-based methods for authentication and key management.

[0108] Upon receiving (505) an additional request, network entity 130 determines (506) the second session key and ciphertext information based at least on the public key. Specifically, network entity 130 may determine secret sharing information and ciphertext information based on the public key. In some example embodiments, secret sharing information may be applicable to PQC. Therefore, secret sharing information can be used to protect sessions from quantum computing-based attacks.

[0109] The secret-shared information determined by network entity 130 may be identical to additional secret-shared information determined at least based on a private key. This additional secret-shared information can be used to determine the first session key. In this way, consistency between the secret-shared information used to determine the second session key and the additional secret-shared information used to determine the first session key can be ensured.

[0110] Then, network entity 130 can determine the second session key based on at least one of the secret sharing information and the session identifier or application key. For example, network entity 130 can determine the second session key by using the session identifier, application key, and secret sharing information as input, based on a key derivation function (KDF). Therefore, network entity 130 can determine the second session key so that network entity 120 can obtain it.

[0111] In addition, network entity 130 can determine the application key. Alternatively or otherwise, the application key may already be stored in network entity 130.

[0112] Subsequently, network entity 130 sends (507) a response to another request to network entity 120. This response includes a second session key and encrypted information. Accordingly, network entity 120 can receive (508) this response from network entity 130. Furthermore, the response may also include the validity period of the second session key. Therefore, the validity period of the second session key can be indicated to network entity 120. This can improve the security of the session protected by the second session key.

[0113] Upon receiving (508) the response, network entity 120 sends (509) a further response to the request to device 110. The further response includes encrypted information. Accordingly, the device receives (510) the further response from network entity 120 and thus becomes aware of the encrypted information.

[0114] Based on the encrypted information and the private key, device 110 determines (511) a first session key. Specifically, device 110 may determine additional secret-shared information associated with device 110 based on the encrypted information and the private key. Then, device 110 may determine the first session key based on the additional secret-shared information and at least one of the session identifier or application key. In addition, device 110 may determine the application key. In this way, device 110 can determine the first session key based on the encrypted information received from the network entity. Therefore, the consistency between the first session key and the second session key can be ensured.

[0115] Subsequently, device 110 can communicate with network entity 120 via a session based on the first session key. Correspondingly, network entity 120 can communicate with device 110 via a session based on the second session key. In this way, communication between device 110 and network entity 120 can be protected in a flexible and efficient manner based on the first and second session keys.

[0116] Specifically, device 110 can encrypt data or messages based on a first session key before sending them to network entity 120. Upon receiving encrypted data or messages, network entity 120 can decrypt the data or messages based on a second session key. Alternatively, network entity 120 can encrypt data or messages based on the second session key before sending them to device 110. Upon receiving encrypted data or messages, device 110 can decrypt the data or messages based on the first session key.

[0117] In this way, the consistency between the first session key of device 110 and the second session key of network entity 120 is ensured. The session between device 110 and network entity 120 can be protected in a flexible and efficient manner.

[0118] refer to Figure 6 The illustration depicts a flowchart 600 of an authentication and key management process according to some embodiments of the present disclosure. (See also:) Figure 6 The example embodiments discussed may be referenced. Figure 5 The implementation of the example embodiment discussed. Flowchart 600 relates to the UE, AF, and AAnF. The UE can be... Figure 1A The implementation of device 110 in the AF. Figure 1A The implementation of network entity 120 in the example. AAnF can be... Figure 1A The implementation of network entity 130 in the example.

[0119] At point 601, the UE-AF AKMA procedure between the UE and the AF can begin. The AF can be an untrusted external AF or a trusted internal AF.

[0120] At point 602, it can be determined whether the UE supports PQC AKMA. If the UE does not support PQC AKMA, then at point 603, the UE and AF can perform the traditional AKMA procedure. In this case, at point 604, the same K can be used for all sessions between the UE and AF. AF Then, at point 611, the UE-AF AKMA procedure can end.

[0121] Alternatively, if the UE supports PQC AKMA, a 6G PQC AKMA procedure can be performed at point 605. At point 606, the UE can derive the PQC private key (also referred to as "pqc_sk" for the purposes of discussion) and the PQC public key (also referred to as "pqc_pk" for the purposes of discussion). Then, at point 607, the UE can send the PQC public key to the AF and request the AF to use PQC for the session between the UE and the AF; for example, the UE can request a PQC session key. The AF can then send the PQC public key to the AF.

[0122] At position 608, AAnF can use the received PQC public key to derive the PQC shared key (also referred to as "pqc_ss" for discussion purposes) and the PQC ciphertext (also referred to as "pqc_ct" for discussion purposes). Furthermore, AAnF can derive K. AF The session key (also referred to as the "PQC session key" for discussion purposes). Then, at 609, the ANF can send the PQC ciphertext to the UE via the AF. The UE can use the PQC ciphertext and the PQC private key to derive the PQC shared key.

[0123] Furthermore, at point 610, for a new session between the UE and AF, the UE can derive a new PQC session key. At point 611, the UE-AF AKMA procedure can end.

[0124] In this way, the UE-AF AKMA procedure can be performed flexibly. If the UE supports PQC AKMA, the session between the UE and AF can be protected from quantum computing-based attacks through the PQC session key.

[0125] refer to Figure 7 The illustration depicts an example signaling flow 700 for authentication and key management according to some embodiments of this disclosure. (Reference) Figure 7 The example embodiments discussed can be considered as references. Figure 5 The implementation of the example embodiments discussed. For the purposes of discussion, references will be made to... Figure 1A Discuss signaling flow 700.

[0126] Figure 7 This involves UE 701, AF 702, AAnF 703, and AUSF 704. UE 701 can be... Figure 1A The implementation of device 110 in the AF 702. Figure 1A The implementation of network entity 120 in the code. AAnF 703 can be... Figure 1A The implementation of network entity 130 in the example.

[0127] exist Figure 7In the example, UE 701 can communicate with AAnF 703 and AF 702 via AUSF 704. Before communication between UE 701 and AF 702, UE 701 and AF 702 may need to know whether AKMA is used. In some example embodiments, UE 701 and AF 702 may be implicitly indicated to UE 701 whether AKMA is used. Alternatively, AF 702 may indicate to UE 701 whether AKMA is used.

[0128] During operation, at point 7001, UE 701 and AAnF 703 can perform master authentication and K. AKMA The establishment process can be a prerequisite for AKMA. Before initiating communication between UE 701 and AF 702, UE 701 can establish a connection based on K... AUSF Generate K AKMA And A-KID.

[0129] At 7002, UE 701 uses a key generation algorithm (e.g., the kemKeyGen function) to generate the PQC public and private keys. The Key Encapsulation Mechanism (KEM) function can be used. Specifically, the ML-KEM.KeyGen algorithm can be used to generate the PQC public and private keys.

[0130] The ML-KEM.KeyGen algorithm can be used to generate encapsulation keys and corresponding decapsulation keys. The ML-KEM.KeyGen key generation algorithm accepts no input, internally generates randomness, and produces encapsulation and decapsulation keys. The encapsulation key can be a PQC public key (pqc_pk), and the decapsulation key can be a PQC private key (pqc_sk). The seed (d, 𝑧) generated in the ML-KEM.KeyGen algorithm can be stored for later expansion using the ML-KEM.KeyGen_internal function, as the seed can be used to compute the decapsulation key. The seed (d, 𝑧) can be sensitive data and is processed using the same protection measures as the decapsulation key.

[0131] Then, UE 701 initiates communication with AF 702. At 7003, UE 701 sends an application session establishment request message including pqc_pk to AF 702. The application session establishment request message may also include A-KID and an indication to use PQC for the session (e.g., session #1). Furthermore, UE 701 may derive K before or after sending the application session establishment request message. AF .

[0132] In some example embodiments, AF 702 can authorize the request from UE 701 at 7004. Then, if AF 702 does not have an activity context associated with A-KID, AF 702 can select AAnF 703. At 7005, AF 702 can send a Naanf_AKMA_ApplicationKey_Get request message to AAnF 703, which includes A-KID, the identifier of AF 702, pqc_pk, and additional indications that the session will be protected by PQC, etc.

[0133] The identifier of AF 702 may include the fully qualified domain name of AF 702 and the Ua identifier of the security protocol used by AF 702 and UE 701. Security protocol identifier.

[0134] Subsequently, AAnF 703 can determine whether it can provide services to AF 702 based on local policies or authorization information. Furthermore, AAnF 703 can communicate with the NRF based on AF 702's identifier to determine whether a service is permitted. If service to AF 702 is not permitted, AAnF 703 can refuse the service.

[0135] Alternatively, if the service is permitted, AAnF 703 can be based on the K identified by A-KID. AKMA The existence of K is used to verify whether a subscriber (e.g., UE 701) is authorized to use AKMA. Specifically, if K is not present in AAnF 703... AKMA Then at 7009, AAnF 703 can send a Naanf_AKMA_ApplicationKey_Get response message to AF 702, which includes an indication of K AKMA Missing error indication. In this case, at 7010, AF 702 can send an application session establishment response message to UE 701, which includes a rejection indication of the application session establishment request and a failure indication indicating the reason for the failure.

[0136] At 7006, AAnF 703 uses an encapsulation algorithm (e.g., the ML-KEM.Encaps algorithm) to derive the PQC shared secret pqc_ss and the PQC ciphertext pqc_ct based on the PQC public key pqc_pk.

[0137] The ML-KEM.Encaps algorithm can be used to generate a shared private key (e.g., pqc_ss) and associated ciphertext (e.g., pqc_ct) based on an encapsulation key (e.g., pqc_pk). The ML-KEM.Encaps encapsulation algorithm accepts the encapsulation key as input, internally generates randomness, and outputs the ciphertext and the shared private key.

[0138] Optionally, if K exists in AAnF 703 AKMA And if K AF If it is not stored in AAnF 703, then AAnF703 can be based on K at 7007. AKMA Derive K AF Based on K AKMA Derive K AF It can be part of a key hierarchy process, which may also include the derivation of the PQC session key.

[0139] refer to Figure 8 The illustration shows a schematic diagram 800 of an example key hierarchy structure according to some embodiments of the present disclosure. Figure 8 In the example, after a successful 6G master authentication process 801, a K can be generated. AUSF 802. Then, the mobile device (ME) and AUSF can be accessed from K. AUSF K is derived from 802 AKMA 803.

[0140] Subsequently, ME and AAnF can be obtained from K. AKMA K is derived from 803 AF 804. Then, ME and AAnF can be obtained from K. AF K is derived from 804 AF_PQC_SESSION#1 (For discussion purposes, also referred to as "PQC session key") 805, K AF_PQC_SESSION#2 806, K AF_PQC_SESSION#3 806, etc. Furthermore, AUSF and AAnF may be associated with HPLM.

[0141] In this way, the PQC session key can be derived from the AKMA key in a flexible and efficient manner. Furthermore, the PQC session key can be associated with a session identifier. Therefore, session security can be improved.

[0142] Back Figure 7 At 7008, AAnF 703 can be based on pqc_ss and K AF The PQC AF session key (also referred to as the "PQC session key" for discussion purposes) is derived based on pqc_ss and K. AFThe PQC session key can be derived based on the KDF. Specifically, when deriving the PQC session key, the parameters FC, P0, and L0 can be used as inputs to form the KDF.

[0143] exist Figure 7 In the example, parameter FC can be set to 0xWX, parameter P0 can be equal to the session identifier, and parameter L0 can be equal to the length of the session identifier. Furthermore, it can be based on K... AF And pqc_ss to determine the input key of KDF, for example by cascading K AF And pqc_ss. The identifier of AF can be used in KDF. In some example embodiments, the identifier of AF can be concatenated with the session identifier as input to KDF.

[0144] Subsequently, at 7009, AAnF 703 sends a Naanf_AKMA_ApplicationKey_Get response message to AF 702, which includes pqc_ct, UE 701's SUPI, PQC session key, and PQC session key expiration time. At 7010, AF 702 sends an application session establishment response message to UE 701, including pqc_ct.

[0145] At 7011, UE 701 can derive an additional pqc_ss based on pqc_ct and pqc_sk using a decapsulation algorithm (e.g., the ML-KEM.Decaps algorithm). The ML-KEM.Decaps algorithm can be used to generate a PQC shared private key (e.g., an additional pqc_ss) from the PQC ciphertext (e.g., pqc_ct).

[0146] The ML-KEM decapsulation algorithm ML-KEM.Decaps can accept a decapsulation key (e.g., pqc_sk) and ML-KEM ciphertext as input without any randomness, and outputs a shared private key.

[0147] Furthermore, UE 701 can derive K AF Then, UE 701 can be based on pqc_ss and K AF The additional PQC session key is then derived. Specifically, the derivation of the additional PQC session key can be the same as the derivation of the PQC session key performed by AAnF 703 at 7008, and therefore will not be repeated here.

[0148] Then, at 7012, UE 701 can use a different PQC session key to protect the session. Meanwhile, AF 702 can also use a PQC session key to protect the session. In some examples, the PQC session key is the same as another PQC session key. Therefore, UE 701 and AF 702 can use the same PQC session key to protect the same session.

[0149] It should be understood that session keys can be generated and / or applied on a per-session basis. In some example embodiments, a new PQC session key can be generated to protect the next session. In this case, the process corresponding to steps 7002 to 7012 can be repeated, and will not be described in detail here.

[0150] In this way, the consistency between the PQC session key of AF 702 and another PQC session key of UE 701 can be ensured in an efficient manner. This protects the session from quantum computing-based attacks.

[0151] refer to Figure 9 The illustration depicts a signaling flow 900 of a TLS-based protocol according to some embodiments of this disclosure. For discussion purposes, reference will be made to... Figure 1B Discuss signaling flow 900. Figure 9 Involving Figure 1B The device 140 and the network entity 150.

[0152] In some example implementations, device 140 may be implemented as or include a terminal device, such as a UE. Network entity 150 may be implemented as or include a device implementing AF.

[0153] In operation, device 140 determines (901) a digest of a session key (also referred to as the “first session key” for the purposes of discussion) based on a first session key and an authentication management key. The first session key is used by device 140 to protect the session between device 140 and network entity 150. The first session key is associated with another session key (also referred to as the “second session key” for the purposes of discussion) used by network entity 150 to protect the session.

[0154] In some example embodiments, the first session key may be determined based at least on ciphertext information and secret-shared information determined at least on the private key. The second session key may be determined based at least on ciphertext information and additional secret-shared information determined at least on the public key associated with the private key. Therefore, the first and second session keys can be determined in a flexible manner.

[0155] The public key can be sent from device 140 to network entity 150. Ciphertext information can be determined based on the public key. Ciphertext information can also be sent from network entity 150 to device 140. The secret sharing information is identical to any other secret sharing information. Therefore, the consistency between the first session key of device 140 and the second session key of network entity 150 can be ensured.

[0156] After determining the (901) digest information, device 140 sends (902) a request to establish a session to network entity 150. The request includes the digest information and the authentication management key. Accordingly, network entity 150 receives (903) the request from device 140.

[0157] In some example embodiments, network entity 150 can obtain the second session key based on the authentication management key. For example, network entity 150 can obtain the second session key from ANF. In this way, network entity 150 can access the second session key.

[0158] Subsequently, network entity 150 performs (904) digest information verification based on the authentication management key and the second session key. In some example embodiments, if the digest information verification is not successfully performed, network entity 150 may send an error message indicating that the verification failed to device 140. Therefore, communication between network entity 150 and device 140 can be protected from errors that lead to verification failure.

[0159] Alternatively, if the digest information verification is successfully performed, network entity 150 can communicate with device 140 via a session based on the second session key. In this case, device 140 can communicate with network entity 150 based on the first session key. Therefore, the communication between network entity 150 and device 140 can be protected by both the first and second session keys, thus improving communication security.

[0160] In this way, the digest information can be used by network entity 150 to authenticate device 140 in a flexible and efficient manner. This can improve the security of communication between device 140 and network entity 150.

[0161] refer to Figure 10 The illustration depicts an example signaling flow 1000 of a TLS-based protocol according to some embodiments of this disclosure. (Reference) Figure 10 The example embodiments discussed can be considered as references. Figure 9 The implementation of the example embodiments discussed. For the purposes of discussion, references will be made to... Figure 1B Discuss signaling flow 1000.

[0162] Figure 10This involves UE 1001 and AF 1002. UE 1001 can be... Figure 1B The implementation of device 140 in the AF 1002 can be... Figure 1B The implementation of network entity 150 in the UE 1001. In some example embodiments, UE 1001 may include a Universal Subscriber Identification Module (USIM), which includes a Hypertext Transfer Protocol Security (HTTPS) client. The USIM can be used to communicate with AF 1002. Additionally, UE 1001 may include an ME, which includes an HTTPS client.

[0163] exist Figure 10 In the example, AF 1002 could be an implementation of the Network Application Function (NAF) from the Generic Boot Architecture (GBA).

[0164] As shown in the figure, at position 1010, UE 1001 and AF 1002 can execute the AKMA procedure until K is obtained. AF At point 1011, a TLS tunnel can be established. At point 1012, AF 1002 can send the server public key certificate to UE 1001 for verification by UE 1001's HTTPS client. The server public key certificate can correspond to the fully qualified domain name (FQDN) of AF 1002. Alternatively, at point 1013, client certificate authentication as part of the TLS protocol can be omitted.

[0165] Then, at 1014, if UE 1001 supports AKMA with a TLS protocol, UE 1001 can add the constant string "3gpp-akma" to the HTTP header "User-Agent" as a product token. At 1015, if AF 1002 chooses AKMA to derive the key, AF 1002 can include the string "3GPP-bootstrapping-akma" in the WWW-Authenticate header field. Alternatively, if AF 1002 chooses between a GBA-based method (e.g., GBA_Digest) and AKMA-based keying, AF 1002 can choose AKMA instead of GBA_Digest.

[0166] Then, at 1016, after receiving a response message from AF 1002, UE 1001 can verify whether the FQDN in the domain attributes corresponds to the FQDN of AF 1002, which is used to establish the TLS tunnel. If the verification fails, UE 1001 can terminate the TLS tunnel between UE 1001 and AF 1002.

[0167] At point 1017, because AKMA is selected for keying, UE 1001 sends an Application Session Establishment Request to AF 1002, including an Authorization Header field. The Authorization Header field may include the A-KID and a digest calculation. The A-KID can be used as the username to insert the digest. The PQC session key can be used as the cipher in the digest calculation.

[0168] At point 1018, since AKMA is selected for input, AF 1002 uses an additional PQC session key to verify the value of the password attribute. This additional PQC session key is retrieved from AAnF using the A-KID received as the username attribute. If AF 1002 cannot obtain the additional PQC session key, AF 1002 can send an appropriate error message to UE 1001 that does not contain the domain attribute.

[0169] In this scenario, if AF 1002 successfully performs authentication, AF 1002 and UE 1001 can communicate using a TLS tunnel based on the PQC session key and an additional PQC session key.

[0170] In this way, AF 1002 can authenticate UE 1001 based on digest calculation, PQC session key, and additional PQC session key. Therefore, the security of the TLS tunnel can be improved.

[0171] refer to Figure 11 The illustration depicts a signaling flow 1100 of a TLS-based protocol according to some embodiments of the present disclosure. For discussion purposes, reference will be made to... Figure 1B Discuss signaling flow 1100. Figure 11 Involving Figure 1B The device 140 and the network entity 150.

[0172] In some example implementations, device 140 may be implemented as or include a terminal device, such as a UE. Network entity 150 may be implemented as or include a device implementing AF.

[0173] In operation, network entity 150 sends a message (1101) to device 140 to establish a TLS tunnel between device 140 and network entity 150. Accordingly, device 140 receives a message (1102) from network entity 150.

[0174] Based on the message and a session key (also referred to as the "first session key" for the purpose of discussion) used by device 140 to protect the session between device 140 and network entity 150, device 140 determines (1103) TLS information (also referred to as the "first TLS information") for establishing a TLS tunnel. Network entity 150 determines (1104) an additional session key (also referred to as the "second session key" for the purpose of discussion), which is used by network entity 150 to determine additional TLS information (also referred to as the "second TLS information") for establishing a TLS tunnel. The first session key is associated with the second session key.

[0175] In some example implementations, device 140 can establish a TLS tunnel based on the first TLS information. Network entity 150 can establish a TLS tunnel based on the second TLS information. Therefore, TLS tunnels can be established in a flexible and efficient manner.

[0176] In some example embodiments, the message may include cipher suite information. In this case, device 140 may determine the pre-master secret information (also referred to as "first pre-master secret information") as the first TLS information based on the cipher suite information and the first session key. Furthermore, device 140 may send an additional message to network entity 150, which includes an indication that the first session key is used to determine the first pre-master secret information. Therefore, network entity 150 may be instructed that the first session key is being used.

[0177] The network entity can determine additional pre-master secret information (also known as "second pre-master secret information") as the second TLS information based on the second session key and cipher suite information. In this way, the consistency of the first TLS information between device 140 and network entity 150 can be ensured.

[0178] Furthermore, the additional message may also include an authentication management key used by network entity 150 to determine the second session key. The second session key can be obtained by network entity 150 based on the authentication management key included in the additional message. For example, the second session key can be obtained from ANF. Therefore, network entity 150 can access the second session key.

[0179] Alternatively, the message may include key identification information. In this case, device 140 can determine the external key information (also referred to as "first external key information") as the first TLS information based on the key identification information and the first session key. Network entity 150 can determine additional external key information (also referred to as "second external key information") as the second TLS information based on the key identification information and the second session key. In this way, the consistency of the first TLS information between device 140 and network entity 150 can be ensured.

[0180] Furthermore, the first session key can be determined based at least on ciphertext information and secret shared information determined at least on the private key. The second session key can be determined based at least on ciphertext information and additional secret shared information determined at least on the public key associated with the private key. Therefore, the first and second session keys can be determined in a flexible and efficient manner.

[0181] The public key can be sent from device 140 to network entity 150. Ciphertext information can be determined based on the public key. Ciphertext information is sent from network entity 150 to device 140. Secret sharing information can be identical to other secret sharing information. Therefore, consistency between the first session key and the second session key can be ensured.

[0182] In this way, a TLS tunnel between device 140 and network entity 150 can be established in a flexible and efficient manner. Consistency between the first TLS information and the second TLS information can be ensured.

[0183] refer to Figure 12 The illustration depicts an example signaling flow 1200 of a TLS-based protocol according to some embodiments of the present disclosure. (Reference) Figure 12 The example embodiments discussed can be considered as references. Figure 11 The implementation of the example embodiments discussed. For the purposes of discussion, references will be made to... Figure 1B Discuss signaling flow 1200.

[0184] Figure 12 This involves UE 1201 and AF 1202. UE 1201 can be... Figure 1B The implementation of device 140 in the middle. AF 1202 can be Figure 1B The implementation of network entity 150 in the UE 1201. In some example embodiments, UE 1201 may include a USIM, which includes an HTTPS client. The USIM can be used to communicate with AF 1202. Additionally, UE 1201 may include an ME, which includes an HTTPS client.

[0185] exist Figure 12 In the example, AF 1202 could be an implementation of NAF from GBA. In operation, at 1210, UE1201 and AF 1202 can perform the AKMA procedure until K is obtained. AF Then, at 1211, UE 1201 can send a ClientHello message to AF 1202, which includes the AF hostname, an instruction to UE 1201 to support PSK-based TLS, and a cipher suite.

[0186] At 1212, AF 1202 can send a ServerHello message to UE 1201, which includes information about the selected cipher suite and a ServerKeyExchange message. The ServerKeyExchange message may include a PSK identification hint. The PSK identification hint may be the constant string "3GPP-AKMA", which indicates that AKMA-based keys are supported.

[0187] If AF 1202 indicates support for AKMA-based keys, UE 1201 can use keys generated by AKMA (even if AF 1202 also indicates support for GBA-based keys). For example, after receiving a ServerHello message, UE 1201 can derive the TLS pre-master secret from the PQC session key.

[0188] At 1213, UE 1201 sends a ClientKeyExchange message to AF 1202, which includes a PSK identifier. The PSK identifier includes the constant string "3GPP-AKMA" and A-KID. When selecting a key method, an AKMA-based key can take precedence over GBA_Digest.

[0189] Then, at 1214, AF 1202 uses A-KID to obtain an additional PQC session key from AAnF. AF 1202 can derive an additional TLS pre-master secret from the additional PQC session key. Subsequently, AF 1202 and UE 1201 can establish a TLS tunnel based on the TLS pre-master secret and the additional TLS pre-master secret.

[0190] In this way, AF 1202 and UE 1201 can authenticate each other in a flexible and efficient manner to establish a TLS tunnel. Therefore, the security of the TLS tunnel can be improved.

[0191] refer to Figure 13 The illustration depicts an example signaling flow 1300 of a TLS-based protocol according to some embodiments of the present disclosure. (Reference) Figure 13 The example embodiments discussed can be considered as references. Figure 11 The implementation of the example embodiments discussed. For the purposes of discussion, references will be made to... Figure 1B Discuss signaling flow 1300.

[0192] Figure 13 This involves UE 1301 and AF 1302. UE 1301 can be... Figure 1B The implementation of device 140 in the AF 1302 can be... Figure 1BThe implementation of network entity 150. In some example embodiments, UE 1301 may include a USIM, which includes an HTTPS client. The USIM can be used to communicate with AF 1302. Additionally, UE 1301 may include an ME, which includes an HTTPS client.

[0193] exist Figure 13 In the example, AF 1302 could be an implementation of NAF from GBA. In operation, at 1310, UE1301 and AF 1302 could perform the AKMA procedure until K is obtained. AF .

[0194] At 1311, UE 1301 can send a ClientHello message to AF 1302, which includes an A-KID and a prefix indicating a PSK identifier namespace including the constant string "3GPP-AKMA". The constant string "3GPP-AKMA" can be used to indicate that UE 1301 supports AKMA-based keys.

[0195] At 1312, if AF 1302 intends to establish a TLS tunnel using PSK authentication with an AKMA key, AF 1302 sends a ServerHello message to UE 1301, which includes an index of the selected PSK identifier, such as the index of the AKMA PSK identifier. UE 1301 then derives the TLS external PSK from the PQC session key, and AF 1302 derives another TLS external PSK from a different PQC session key.

[0196] Subsequently, UE 1301 and AF 1302 can establish a TLS tunnel based on an external TLS PSK and another external TLS PSK.

[0197] In this way, AF 1302 and UE 1301 can authenticate each other in a flexible and efficient manner to establish a TLS tunnel. Therefore, the security of the TLS tunnel can be improved.

[0198] Figure 14 A flowchart of an example method 1400 implemented at a device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1A The angle description method of the device 110 in the middle is 1400.

[0199] At block 1410, device 110 sends a request to a network entity to establish a session between the device and the network entity. This request may include a public key associated with a private key used to determine a first session key for protecting the session for the device, and the public key used to determine a second session key for protecting the session for the network entity.

[0200] At box 1420, device 110 receives a response to the request from the network entity. The response may include ciphertext information determined based on the public key.

[0201] At box 1430, device 110 determines the first session key based at least on the ciphertext information and the private key.

[0202] In some example embodiments, device 110 may perform communication with network entities via a session based on a first session key.

[0203] In some example embodiments, device 110 may determine secret shared information associated with the device based on ciphertext information and a private key; and determine a first session key based on the secret shared information and at least one of a session identifier or an application key.

[0204] In some example implementations, the secret-shared information may be the same as additional secret-shared information associated with a network entity. This additional secret-shared information may be determined based on a public key and may be used to determine a second session key.

[0205] In some example embodiments, secret sharing of information can be applied to post-quantum computing (PQC).

[0206] In some example embodiments, the request may also include an indication that the session will be protected by post-quantum computing (PQC).

[0207] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0208] Figure 15 A flowchart of an example method 1500 implemented at a network entity according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1A The perspective description method of network entity 120 in 1500.

[0209] At box 1510, network entity 120 receives a request from a device to establish a session between the device and the network entity. This request may include a public key associated with a private key used to determine a first session key for protecting the session for the device, and the public key used to determine a second session key for protecting the session for the network entity.

[0210] At box 1520, network entity 120 obtains ciphertext information and a second session key based on the public key. The ciphertext information will be used to determine the first session key.

[0211] At box 1530, network entity 120 sends a response to the request to the device, the response including encrypted information.

[0212] In some example embodiments, network entity 120 may communicate with the device via a session based on a second session key.

[0213] In some example embodiments, the request may also include an indication that the session will be protected by post-quantum computing (PQC).

[0214] In some example embodiments, network entity 120 may send an additional request, including a public key, to another network entity. Network entity 120 may receive an additional response to the additional request from the other network entity, the additional response including a second session key and password information.

[0215] In some example embodiments, the additional response may also include the validity period of the second session key.

[0216] In some example embodiments, additional requests may also include additional instructions that the session will be protected by post-quantum computing (PQC).

[0217] In some example embodiments, the apparatus may include a terminal device, the network entity may include a device that implements an application function (AF), and other network entities may include a device that implements an authentication and key management anchor function (AAnF) for applications.

[0218] Figure 16 A flowchart of an example method 1600 implemented at a network entity according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1A The perspective description method of network entity 130 in 1600.

[0219] At box 1610, network entity 130 receives a request from another network entity. This request may include a public key associated with a private key used to determine a first session key for protecting a session between the device and another network entity, and the public key is used to determine a second session key for protecting the session with the other network entity.

[0220] At box 1620, network entity 130 determines the second session key and ciphertext information based at least on the public key.

[0221] At box 1630, network entity 130 sends a response to the request to another network entity, the response including a second session key and ciphertext information.

[0222] In some example embodiments, network entity 130 may determine the secret shared information and ciphertext information based on the public key. Network entity 130 may determine a second session key based on the secret shared information and at least one of the session identifier or application key.

[0223] In some example embodiments, the secret-shared information may be the same as additional secret-shared information determined at least based on the private key, and the additional secret-shared information may be used to determine the first session key.

[0224] In some example embodiments, secret sharing of information can be applied to post-quantum computing (PQC).

[0225] In some example embodiments, the response may also include the validity period of the second session key.

[0226] In some example embodiments, the request may also include an indication that the session will be protected by post-quantum computing (PQC).

[0227] In some example embodiments, the apparatus may include a terminal device, the network entity may include a device that implements the Authentication and Key Management Anchor Function (AAnF) for an application, and other network entities may include a device that implements the Application Function (AF).

[0228] In some example embodiments, an apparatus capable of performing any of method 1400 (e.g., Figure 1A The device 110 may include components for performing the corresponding operations of method 1400. These components can be implemented in any suitable form. For example, the components can be implemented in a circuit system or a software module. The device can be implemented as... Figure 1A The device 110 in the middle may be included therein.

[0229] In some example embodiments, the apparatus may include components for sending a request to a network entity to establish a session between the apparatus and the network entity. The request may include a public key associated with a private key used to determine a first session key for protecting the session for the apparatus, and the public key is used to determine a second session key for protecting the session for the network entity. The apparatus may include components for receiving a response to the request from the network entity. The response may include ciphertext information determined based on the public key. The apparatus may include components for determining the first session key based at least on the ciphertext information and the private key.

[0230] In some example embodiments, the apparatus may further include a component for performing communication with a network entity via a session based on a first session key.

[0231] In some example embodiments, the device may further include: components for determining secret shared information associated with the device based on ciphertext information and a private key; and components for determining a first session key based on the secret shared information and at least one of a session identifier or an application key.

[0232] In some example implementations, the secret-shared information is identical to additional secret-shared information associated with the network entity. This additional secret-shared information may be determined based on the public key and may be used to determine the second session key.

[0233] In some example embodiments, secret sharing of information can be applied to post-quantum computing (PQC).

[0234] In some example embodiments, the request may also include an indication that the session will be protected by post-quantum computing (PQC).

[0235] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0236] In some example embodiments, a network entity capable of performing any of method 1500 (e.g., Figure 1A The network entity 120 in the diagram may include a component for performing the corresponding operation of method 1500. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The network entity can be implemented as... Figure 1A Network entity 120 may be included in it.

[0237] In some example embodiments, the network entity may include components for receiving a request from a device to establish a session between the device and the network entity. The request may include a public key associated with a private key used to determine a first session key for protecting the session for the device, and the public key is used to determine a second session key for protecting the session for the network entity. The network entity may include components for obtaining ciphertext information and the second session key based on the public key. The ciphertext information will be used to determine the first session key. The network entity may include components for sending a response to the request to the device, the response including the ciphertext information.

[0238] In some example embodiments, the network entity may further include a component for performing communication with the device via a session based on a second session key.

[0239] In some example embodiments, the request may also include an indication that the session will be protected by post-quantum computing (PQC).

[0240] In some example embodiments, the network entity may further include: a component for sending a further request, including a public key, to another network entity; and a component for receiving a further response to the further request from another network entity, the further response including a second session key and password information.

[0241] In some example embodiments, the additional response may also include the validity period of the second session key.

[0242] In some example embodiments, additional requests may also include additional instructions that the session will be protected by post-quantum computing (PQC).

[0243] In some example embodiments, the apparatus may include a terminal device, the network entity may include a device that implements an application function (AF), and other network entities may include a device that implements an authentication and key management anchor function (AAnF) for applications.

[0244] In some example embodiments, a network entity capable of performing any of method 1600 (e.g., Figure 1A The network entity 130 in the network entity may include a component for performing the corresponding operation of method 1600. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The network entity can be implemented as... Figure 1A Network entity 130 may be included in it.

[0245] In some example embodiments, a network entity may include components for receiving a request from another network entity. The request may include a public key associated with a private key used to determine a first session key for protecting a session between the device and another network entity, and the public key is used to determine a second session key for protecting the session with the other network entity. The network entity may include components for determining the second session key and encrypted information based at least on the public key; and components for sending a response to the request to the other network entity, the response including the second session key and encrypted information.

[0246] In some example embodiments, the network entity may further include: a component for determining secret shared information and ciphertext information based on a public key; and a component for determining a second session key based on the secret shared information and at least one of a session identifier or an application key.

[0247] In some example embodiments, the secret-shared information may be the same as additional secret-shared information determined at least based on the private key, and the additional secret-shared information may be used to determine the first session key.

[0248] In some example embodiments, secret sharing of information can be applied to post-quantum computing (PQC).

[0249] In some example embodiments, the response may also include the validity period of the second session key.

[0250] In some example embodiments, the request may also include an indication that the session will be protected by post-quantum computing (PQC).

[0251] In some example embodiments, the apparatus may include a terminal device, the network entity may include a device that implements the Authentication and Key Management Anchor Function (AAnF) for an application, and other network entities may include a device that implements the Application Function (AF).

[0252] Figure 17 A flowchart of an example method 1700 implemented at a device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1B The angle description method of the device 140 in the middle is 1700.

[0253] At block 1710, device 140 determines a digest of the first session key based on the first session key and the authentication management key. The first session key is used by the device to protect the session between the device and the network entity, and the first session key is associated with a second session key used by the network entity to protect the session.

[0254] At box 1720, device 140 sends a request to a network entity to establish a session. This request may include summary information and an authentication management key.

[0255] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0256] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0257] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0258] In some example embodiments, device 140 may receive an error message from a network entity indicating that the verification of the digest information was unsuccessful.

[0259] In some example embodiments, device 140 can perform communication with network entities via a session based on a first session key. Verification of the digest information may be successful.

[0260] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0261] Figure 18 A flowchart of an example method 1800 implemented at a network entity according to some example embodiments of the present disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1B The method for describing the network entity 150 from the perspective of 1800.

[0262] At box 1810, network entity 150 receives a request from the device to establish a session between the device and the network entity. This request may include an authentication management key and a digest of a first session key used by the device to protect the session, and the first session key may be associated with a second session key used by the network entity to protect the session.

[0263] At box 1820, network entity 150 performs verification of digest information based on the authentication management key and the second session key.

[0264] In some example implementations, network entity 150 obtains a second session key based on an authentication management key.

[0265] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0266] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0267] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0268] In some example embodiments, if the verification of the digest information is determined to have failed, the network entity 150 may send an error message indicating that the verification failed to the device.

[0269] In some example embodiments, once the verification of the determined digest information is successfully performed, the network entity 150 can communicate with the device via a session based on the second session key.

[0270] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0271] In some example embodiments, an apparatus capable of performing any of method 1700 (e.g., Figure 1B The device 140 may include components for performing the corresponding operations of method 1700. These components can be implemented in any suitable form. For example, the components can be implemented in a circuit system or a software module. The device can be implemented as... Figure 1B The device 140 is included therein.

[0272] In some example embodiments, the apparatus may include components for determining digest information of the first session key based on a first session key and an authentication management key. The first session key is used by the apparatus to protect a session between the apparatus and a network entity, and the first session key is associated with a second session key used by the network entity to protect the session. The apparatus may include components for sending a request to the network entity to establish a session. The request may include digest information and the authentication management key.

[0273] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0274] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0275] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0276] In some example embodiments, the apparatus may further include a component for receiving an error message from a network entity indicating that the verification of the digest information was unsuccessful.

[0277] In some example embodiments, the apparatus may further include components for performing communication with a network entity via a session based on a first session key. The verification of the digest information is successful.

[0278] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0279] In some example embodiments, a network entity capable of performing any of method 1800 (e.g., Figure 1BThe network entity 150 may include a component for performing the corresponding operation of method 1800. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The network entity can be implemented as... Figure 1B Network entity 150 may be included in it.

[0280] In some example embodiments, the network entity may include components for receiving a request from a device for establishing a session between the device and the network entity. The request may include a digest of an authentication management key and a first session key used by the device to protect the session, and the first session key is associated with a second session key used by the network entity to protect the session. The network entity may include components for performing verification of the digest information based on the authentication management key and the second session key.

[0281] In some example embodiments, the network entity may also include a component for obtaining a second session key based on the authentication management key.

[0282] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0283] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0284] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0285] In some example embodiments, the network entity may further include a component for sending an error message indicating that the verification failed, based on the determination that the verification of the digest information was not successfully performed.

[0286] In some example embodiments, the network entity may further include a component for communicating with the device via a session based on a second session key, provided that the verification of the determined digest information has been successfully performed.

[0287] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0288] Figure 19 A flowchart of an example method 1900 implemented at a device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1BThe angle description method of the device 140 in the 1900.

[0289] At box 1910, device 140 receives a message from a network entity for establishing a transport layer security (TLS) tunnel between the device and the network entity.

[0290] At box 1920, device 140 determines first TLS information for establishing a TLS tunnel based on the message and a first session key used by the device to protect the session between the device and the network entity. The first session key is associated with a second session key used by the network entity to determine second TLS information for establishing a TLS tunnel.

[0291] In some example embodiments, device 140 may establish a TLS tunnel based on first TLS information.

[0292] In some example embodiments, device 140 may determine the first premaster secret information as the first TLS information based on cipher suite information and the first session key.

[0293] In some example embodiments, device 140 may send additional messages to network entities, including instructions to use a first session key to determine first premaster secret information.

[0294] In some example embodiments, additional messages may also include an authentication management key that will be used by the network entity to determine the second session key.

[0295] In some example embodiments, device 140 may determine the first external key information as the first TLS information based on key identification information and the first session key.

[0296] In some example embodiments, the second TLS information may include at least one of a second pre-master secret information or a second external key information.

[0297] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0298] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information can be determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0299] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0300] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0301] Figure 20 A flowchart of an example method 2000 implemented at a network entity according to some example embodiments of this disclosure is shown. For discussion purposes, [the following will be discussed]. Figure 1B The method for describing network entities 150 from the perspective of 2000.

[0302] At box 2010, network entity 150 sends a message to the device for establishing a transport layer security (TLS) tunnel between the device and the network entity.

[0303] At box 2020, network entity 150 determines second TLS information for establishing a TLS tunnel based on the message and a second session key used by the network entity to protect the session between the device and the network entity. The second session key is associated with a first session key used by the device to determine first TLS information for establishing a TLS tunnel.

[0304] In some example embodiments, network entity 150 may establish a TLS tunnel based on second TLS information.

[0305] In some example embodiments, network entity 150 may receive additional messages from the device including an indication that a first session key is being used. Network entity 150 may determine pre-master secret information based on a second session key and cipher suite information.

[0306] In some example implementations, the second session key may be obtained based on an authentication management key included in a separate message.

[0307] In some example embodiments, the message may include key identification information, and network entity 150 may determine external key information based on the second session key and the key identification information.

[0308] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0309] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0310] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0311] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0312] In some example embodiments, an apparatus capable of performing any of method 1900 (e.g., Figure 1B The device 140 may include components for performing the corresponding operations of method 1900. These components can be implemented in any suitable form. For example, the components can be implemented in a circuit system or a software module. The device can be implemented as... Figure 1B The device 140 is included therein.

[0313] In some example embodiments, the apparatus may include components for receiving a message from a network entity for establishing a transport layer security (TLS) tunnel between the apparatus and the network entity; and components for determining first TLS information for establishing the TLS tunnel based on the message and a first session key used by the apparatus to protect the session between the apparatus and the network entity. The first session key is associated with a second session key used by the network entity to determine second TLS information for establishing the TLS tunnel.

[0314] In some example embodiments, the apparatus may further include a component for establishing a TLS tunnel based on the first TLS information.

[0315] In some example embodiments, the apparatus may further include a component for determining the first premaster secret information as the first TLS information based on cipher suite information and a first session key.

[0316] In some example embodiments, the apparatus may further include a component for sending an additional message to a network entity, the additional message including an indication that a first session key is used to determine first premaster secret information.

[0317] In some example embodiments, additional messages may also include an authentication management key to be used by the network entity to determine the second session key.

[0318] In some example embodiments, the apparatus may further include a component for determining first external key information as first TLS information based on key identification information and a first session key.

[0319] In some example embodiments, the second TLS information may include at least one of a second pre-master secret information or a second external key information.

[0320] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0321] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information can be determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0322] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0323] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0324] In some example embodiments, a network entity capable of performing any of method 2000 (e.g., Figure 1B The network entity 150 in the network entity may include a component for performing the corresponding operation of method 2000. This component can be implemented in any suitable form. For example, the component can be implemented in a circuit system or a software module. The network entity can be implemented as... Figure 1B Network entity 150 may be included in it.

[0325] In some example embodiments, the network entity may include components for sending a message to the device for establishing a transport layer security (TLS) tunnel between the device and the network entity; and components for determining second TLS information for establishing the TLS tunnel based on the message and a second session key used by the network entity to protect the session between the device and the network entity. The second session key is associated with a first session key used by the device to determine the first TLS information for establishing the TLS tunnel.

[0326] In some example embodiments, the network entity may further include a component for establishing a TLS tunnel based on second TLS information.

[0327] In some example embodiments, the network entity may further include: a component for receiving from the device an additional message including an indication that a first session key is being used; and a component for determining pre-master secret information based on a second session key and cipher suite information.

[0328] In some example implementations, the second session key may be obtained based on an authentication management key included in a separate message.

[0329] In some example embodiments, the message may include key identification information, and the network entity may include a component for determining external key information based on the second session key and the key identification information.

[0330] In some example embodiments, the first session key may be determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on the private key, and the second session key may be determined at least based on ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on the public key associated with the private key.

[0331] In some example embodiments, the public key can be sent from the device to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information can be sent from the network entity to the device.

[0332] In some example embodiments, the secret-shared information may be the same as other secret-shared information.

[0333] In some example embodiments, the apparatus may include a terminal device, and the network entity may include a device that implements an application function (AF).

[0334] Figure 21 This is a simplified block diagram of a device 2100 suitable for implementing exemplary embodiments of the present disclosure. The device 2100 can be provided to implement a communication device, for example, such as... Figure 1A The device 110, network entity 120, or network entity 130 shown, or as Figure 1B The device 140 or network entity 150 shown. As shown, device 2100 includes one or more processors 2110, one or more memories 2120 coupled to processor 2110, and one or more communication modules 2140 coupled to processor 2110.

[0335] Communication module 2140 is used for bidirectional communication. Communication module 2140 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface can represent any interface required for communication with other network elements. In some example embodiments, communication module 2140 may include at least one antenna.

[0336] Processor 2110 can be any type suitable for a local technology network, and by way of non-limiting example, can include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), and processor based on a multi-core processor architecture. Device 2100 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock synchronized with the main processor.

[0337] Memory 2120 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 2124, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disc (DVD), optical disc, laser disc, and other magnetic and / or optical storage devices. Examples of volatile memories include, but are not limited to, random access memory (RAM) 2122 and other volatile memories that do not persist during power outages.

[0338] Computer program 2130 includes computer-executable instructions that are executed by an associated processor 2110. The instructions of program 2130 may include instructions for performing operations / actions of some example embodiments of this disclosure. Program 2130 may be stored in memory, such as ROM 2124. Processor 2110 can perform any suitable actions and processes by loading program 2130 into RAM 2122.

[0339] Example embodiments of this disclosure can be implemented by program 2130, enabling device 2100 to execute reference... Figures 5 to 13 Any process discussed in this disclosure. Exemplary embodiments of this disclosure may also be implemented using hardware or a combination of software and hardware.

[0340] In some example embodiments, program 2130 may be tangibly contained in a computer-readable medium, which may be included in device 2100 (such as memory 2120) or other storage device accessible to device 2100. Device 2100 may load program 2130 from the computer-readable medium into RAM 2122 for execution. In some example embodiments, the computer-readable medium may include any type of non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. The term "non-transitory" as used herein refers to a limitation on the medium itself (i.e., tangible, not tactile), rather than a limitation on the persistence of data storage (e.g., RAM and ROM).

[0341] Figure 22 An example of a computer-readable medium 2200, which may be in the form of a CD, DVD, or other optical storage disc, is shown. A program 2130 is stored on the computer-readable medium 2200.

[0342] Generally, the various embodiments of this disclosure can be implemented using hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented using hardware, while others can be implemented using firmware or software that can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this disclosure are illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, as non-limiting examples, the blocks, apparatuses, systems, techniques, or methods described herein can be implemented using hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0343] Some exemplary embodiments of this disclosure also provide at least one computer program product tangibly stored on a computer-readable medium, such as a non-transitory computer-readable medium. The computer program product includes computer-executable instructions, such as instructions included in a program module, which execute in a device on a target physical or virtual processor to perform any of the methods described above. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform a particular task or implement a particular abstract data type. In various embodiments, the functionality of a program module can be combined or split among program modules as needed. The machine-executable instructions of a program module can execute within a local or distributed device. In a distributed device, a program module can reside on both local and remote storage media.

[0344] Program code used to perform the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0345] In the context of this disclosure, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.

[0346] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any suitable combination of the foregoing. More specific examples of computer-readable storage media will include electrical connections having one or more wires, portable computer floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0347] Furthermore, although operations are described in a specific order, this should not be construed as requiring the operations to be performed in the specific order shown or sequentially, or to perform all of the shown operations to obtain the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated otherwise, certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated otherwise, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0348] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features or actions described above are disclosed as exemplary forms of implementing the claims.

Claims

1. A device for communication, comprising: At least one processor; as well as At least one memory storing instructions, which, when executed by the at least one processor, cause the means to at least: Receive a message from a network entity for establishing a Transport Layer Security (TLS) tunnel between the device and the network entity; as well as Based on the message and a first session key used by the device to protect the session between the device and the network entity, first TLS information for establishing the TLS tunnel is determined, wherein the first session key is associated with a second session key used by the network entity to determine second TLS information for establishing the TLS tunnel.

2. The apparatus of claim 1, wherein the apparatus is configured to: The TLS tunnel is established based on the first TLS information.

3. The apparatus of claim 1 or 2, wherein the message includes cipher suite information, and the apparatus is configured to: Based on the cryptographic suite information and the first session key, the first pre-master secret information is determined to be the first TLS information.

4. The apparatus of claim 3, wherein the apparatus is configured to: Send an additional message to the network entity, the additional message including an indication that the first session key was used to determine the first premaster secret information.

5. The apparatus of claim 4, wherein the additional message further includes an authentication management key to be used by the network entity to determine the second session key.

6. The apparatus according to claim 1 or 2, wherein the message includes key identification information, and the apparatus is configured to: Based on the key identification information and the first session key, the first external key information is determined to be the first TLS information.

7. The apparatus according to any one of claims 3 to 6, wherein the second TLS information includes at least one of a second pre-master secret information or a second external key information.

8. The apparatus according to any one of claims 1 to 7, wherein the first session key is determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on a private key, the second session key is determined at least based on the ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on a public key associated with the private key.

9. The apparatus of claim 8, wherein the public key is sent from the apparatus to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information is sent from the network entity to the apparatus.

10. The apparatus according to claim 8 or 9, wherein the secret sharing information is the same as the additional secret sharing information.

11. The apparatus according to any one of claims 1 to 10, wherein the apparatus includes a terminal device, and the network entity includes a device that implements the application function AF.

12. A network entity, comprising: At least one processor; as well as At least one memory storing instructions, which, when executed by the at least one processor, cause the network entity to at least: Send a message to the device for establishing a Transport Layer Security (TLS) tunnel between the device and the network entity; as well as Based on the message and a second session key used by the network entity to protect the session between the device and the network entity, second TLS information for establishing the TLS tunnel is determined, wherein the second session key is associated with a first session key used by the device to determine first TLS information for establishing the TLS tunnel.

13. The network entity of claim 12, wherein the network entity is such that: The TLS tunnel is established based on the second TLS information.

14. The network entity according to claim 12 or 13, wherein the message includes cipher suite information, and the network entity is such that: Receive a further message from the device, the further message including an indication that the first session key has been used; and The pre-master secret information is determined based on the second session key and the cipher suite information.

15. The network entity of claim 14, wherein the second session key is obtained based on an authentication management key included in the additional message.

16. The network entity according to claim 12 or 13, wherein the message includes key identification information, and the network entity is configured to: The external key information is determined based on the second session key and the key identification information.

17. The network entity according to any one of claims 12 to 16, wherein the first session key is determined at least based on ciphertext information and secret sharing information, the secret sharing information being determined at least based on a private key, the second session key being determined at least based on the ciphertext information and additional secret sharing information, the additional secret sharing information being determined at least based on a public key associated with the private key.

18. The network entity of claim 17, wherein the public key is sent from the device to the network entity, the ciphertext information is determined based on the public key, and the ciphertext information is sent from the network entity to the device.

19. The network entity according to claim 17 or 18, wherein the secret sharing information is the same as the other secret sharing information.

20. The network entity according to any one of claims 12 to 19, wherein the means includes a terminal device, and the network entity includes a device that implements application function AF.

21. A method for communication, comprising: Receive a message from the network entity for establishing a Transport Layer Security (TLS) tunnel between the device and the network entity; as well as Based on the message and a first session key used by the device to protect the session between the device and the network entity, first TLS information for establishing the TLS tunnel is determined, wherein the first session key is associated with a second session key used by the network entity to determine second TLS information for establishing the TLS tunnel.

22. A method for communication, comprising: Send a message to the device to establish a Transport Layer Security (TLS) tunnel between the device and the network entity; as well as Based on the message and a second session key used by the network entity to protect the session between the device and the network entity, second TLS information for establishing the TLS tunnel is determined, wherein the second session key is associated with a first session key used by the device to determine first TLS information for establishing the TLS tunnel.

23. A device for communication, comprising: Components for receiving messages from a network entity for establishing a Transport Layer Security (TLS) tunnel between the device and the network entity; as well as A component for determining first TLS information for establishing the TLS tunnel based on the message and a first session key for protecting the session between the device and the network entity, wherein the first session key is associated with a second session key for the network entity to determine second TLS information for establishing the TLS tunnel.

24. A network entity, comprising: Components for sending messages to the device to establish a Transport Layer Security (TLS) tunnel between the device and the network entity; as well as A component for determining second TLS information for establishing the TLS tunnel based on the message and a second session key for protecting the session between the device and the network entity, wherein the second session key is associated with a first session key for the device to determine first TLS information for establishing the TLS tunnel.

25. A computer-readable medium comprising instructions that, when executed by at least one processor of a device, cause the device to perform the method according to claim 21 or 22.