System and method for key generation in an authentication and key management unit for applications (AKMA)

JP2024525633A5Active Publication Date: 2025-07-10SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024500575
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-07-08
Filing Date
2022-07-07
Publication Date
2025-07-10
Estimated Expiration
2042-07-07

AI Technical Summary

Technical Problem

The existing 5G mobile communication systems face challenges in efficiently managing Authentication and Key Management Authority (AKMA) keys, leading to issues such as delayed key refreshes, computational overhead, and key synchronization problems, which affect the usability and security of applications.

Method used

A method and system for generating new AKMA keys and AF keys without requiring primary authentication, utilizing Unified Data Management (UDM) and Authentication Server Function (AUSF) to manage key refresh parameters, ensuring synchronized key management across user equipment and application functions.

Benefits of technology

This approach enables efficient and timely key refreshes, reduces computational burden, and prevents key synchronization issues, thereby enhancing the usability and security of applications in wireless networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The present disclosure relates to 5G or 6G communication systems to support higher data transmission rates. The present disclosure provides a system and method for key refresh in an authentication and key management unit (AKMA) for applications. The proposed method is AF If expires soon, K can be refreshed by requesting a refresh parameter from the network. AKMA The aim of the proposed method is to support refresh. AF If expires soon, K can be refreshed by requesting a refresh parameter from the network. AF The proposed method also uses a specific mechanism to provide refresh parameters to the AUSF, AAnF, and UE as part of the AKMA refresh procedure or as part of the UPU procedure. Furthermore, the proposed method supports AKMA key refresh while limiting the impact on AKMA services in 5G systems. The proposed method is also used to support a mechanism for solving the key synchronization problem on the user equipment (UE) side, the AF, and the network side.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates generally to authentication in wireless networks, and more particularly to a system and method for key generation in an Authentication and Key Management for Applications (AKMA). [Background technology]

[0002] 5G mobile communication technology defines a wide frequency band to enable high transmission rates and new services, and can be implemented not only in "sub-6GHz" bands such as 3.5GHz, but also in "above-6GHz" bands called mmWave, including 28GHz and 39GHz. Also, in order to achieve a transmission rate 50 times faster than 5G mobile communication technology and ultra-low latency that is one-tenth of that of 5G mobile communication technology, it is being considered to implement 6G mobile communication technology (called the Beyond 5G system) in the terahertz band (e.g., 95GHz to 3THz band).

[0003] In the early stages of 5G mobile communications development, to meet the service support and requirements associated with eMBB (enhanced Mobile Broadband), URLLC (Ultra Reliable Low Latency Communications), and mMTC (massive Machine-Type Communications), standardization is underway on beamforming and massive MIMO to reduce propagation path loss and increase propagation transmission distance in mmWave, supporting neurology (e.g., multiple operating subcarrier spacing) for efficient utilization of mmWave resources and dynamic operation of slotted formats, initial access techniques for multi-beam transmission and wideband support, definition and operation of BandWidth Part (BWP), new channel coding methods such as Low Density Parity Check (LDPC) codes for large-capacity data transmission and polar codes for reliable control information transmission, L2 pre-processing, and network slicing to provide dedicated networks specialized for specific services.

[0004] Discussions are currently underway on improvements and performance enhancements to the initial 5G mobile communications technology in terms of the services that will be supported by 5G mobile communications technology. Physical layer standardization is underway for technologies such as Vehicle-to-Everything (V2X), which supports autonomous vehicles' driving decisions based on information on the vehicle's location and status transmitted by the autonomous vehicles and improves user convenience; New Radio Unlicensed (NR-U), which aims to operate systems in unlicensed bands in accordance with various regulatory requirements; NR UE power saving; and Non-Terrestrial Network (NTN), which provides coverage in areas where communication with terrestrial networks is not possible and is direct UE-satellite communication for positioning.

[0005] In addition, standardization of radio interface architecture / protocols related to technologies such as Industrial Internet of Things (IIOT) to support new services through linkage and integration with other industries, Integrated Access and Backhaul (IAB) to provide nodes for expanding network service areas by supporting wireless backhaul links and access links in an integrated manner, mobility improvement including conditional handover and Dual Active Protocol Stack (DAPS) handover, and two-stage random access (two-stage RACH for NR) to simplify random access procedures is underway. In addition, standardization of system architecture / services related to 5G basic architecture (e.g., service-based architecture or service-based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies and Mobile Edge Computing (MEC) for receiving services based on UE location is underway.

[0006] As 5G mobile communication systems are commercialized, an exponentially increasing number of connected devices will be connected to the communication network, and it is expected that the functions and performance of 5G mobile communication systems and the integrated operation of connected devices will be required accordingly. For this reason, new research is planned to be conducted on artificial intelligence (AI) and machine learning (ML), AI service support, metabus service support, and drone communication to efficiently support Augmented Reality (AR), Virtual Reality (VR), Mixed Reality (MR), etc., in conjunction with 5G performance improvement and complexity reduction.

[0007] In addition, the development of such 5G mobile communication systems will serve as a foundation for developing 6G mobile communication technologies, including multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO) to improve the coverage of terahertz band signals, array antennas and large-scale antennas, and metamaterial-based lenses and antennas, new waveforms to provide terahertz band coverage for high-dimensional spatial multiplexing technologies using Orbital Angular Momentum (OAM) and Reconfigurable Intelligent Surface (RIS), full-duplex technology to improve the frequency efficiency of 6G mobile communication technologies and improve system networks, AI-based communication technologies to realize system optimization by utilizing satellites and artificial intelligence (AI) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technologies to realize services with a level of complexity that exceeds the limits of UE operating capabilities by utilizing ultra-high performance communication and computing resources.

[0008] 3rd Generation Partnership Project (3GPP) Rel-16 introduces a new feature known as Authentication and Key Management for Applications (AKMA) based on 3GPP user credentials in 5G. AKMA leverages the user's Authentication and Key Management (AKA) credentials to bootstrap security between a User Equipment (UE) and an Application Function (AF) so that the UE can securely exchange data with the AF.

[0009] According to 3GPP, as described in TS 33.535, a first authentication is performed to obtain the AKMA key (K AKMA ) to refresh or generate a new AKMA key, AKMA When generating, press the AF key (K AF ) or refresh your K AF However, K AF is K AFIt is associated with a timer that indicates the validity period of K. AF When the validity period of K expires, the AF can deny the UE access to the AF. AF Upon expiration of the AUSF key (K AUSF ) is changed, the UE AUSF The user can then retry accessing the AF using a new A-KID (AKMA Key Identity) derived from the AF.

[0010] Therefore, K AF will be set to K until a new primary authentication occurs. AF Therefore, the user cannot refresh K immediately after the validity period of K expires. AF After the expiration of the period, the application may not be usable until a new primary authentication procedure occurs (which requires authentication with AKMA). However, AF is K AF must be refreshed as needed by applications that depend on the AKMA key and the AF key, and therefore a mechanism is required for the AKMA service to request the network to provide refresh parameters for refreshing the AKMA key and the AF key. AF Performing a first authentication every time a user creates a new Kerberos server requires a lot of effort, as it is a computationally intensive approach that consumes a lot of memory.

[0011] According to 3GPP TS 33.535 AF can be refreshed through Ua*, depending on whether the Ua* protocol supports such functionality, and also whether the operator or application can refresh K through Ua*. AFIt may be intentionally undesirable to implement refresh, but rather rely on the network verifying the AKMA every time. If key refresh is supported by the Ua* protocol, it will be performed independently regardless of the number of times, which creates issues with misuse of subscription credentials in 5G systems and lawful interception that are part of regulatory requirements in certain regions.

[0012] In this scenario, the UE and AAnF AF With AF, old K AF While the AF has the key or derives a new key based on the Ua* protocol, the UE does not know that it should derive a new key and use the latest key. In such cases, key synchronization problems may occur, mainly due to misalignment and non-coordination of contexts derived from different entities.

[0013] It would therefore be desirable to overcome these and other deficiencies, or at least provide a useful alternative. Summary of the Invention [Problem to be solved by the invention]

[0014] The main objective of the present embodiment is to provide a new Authentication and Key Management (AKMA) key generation method for applications in wireless networks.

[0015] Another object of the present embodiment is to provide a system for generating at least one new Authentication and Key Management (AKMA) key for an application in a wireless network.

[0016] Another object of the present embodiment is to provide an application key (K A ) by requesting the network to provide refresh parameters to the UE when the application key (K AFThe present invention provides a system and method for refreshing a file.

[0017] Another object of the present embodiment is to provide a system and method for avoiding key synchronization issues when keys are refreshed on the UE or network side.

[0018] Furthermore, the proposed method is used to support a mechanism for solving the key synchronization problem at the user equipment (UE) side. [Means for solving the problem]

[0019] Accordingly, the present embodiment provides a method performed by a Unified Data Management (UDM) in a wireless network to generate new Authentication and Key Management (AKMA) keys for an application. The method includes receiving, by the UDM, a first request from an AKMA Anchor Function (AAnF) in the wireless network, where the first request includes an AKMA refresh request indication and a Subscription Permanent Identifier (SUPI) associated with a user equipment (UE) in the wireless network, the first request indicating a request to generate new AKMA keys for establishing communication between the user equipment (UE) and at least one Application Function (AF) in the wireless network. The method further includes receiving, by the UDM, AKMA refresh parameters (AKMA) based on the received first request. RP The method includes a step of generating, by the UDM, the generated AKMA refresh parameter (AKMA) together with the at least one SUPI to generate at least one new AKMA key. RP ) to an Authentication Server Function (AUSF) in the wireless network.

[0020] Accordingly, the present embodiment provides a method for generating a new Authentication and Key Management (AKMA) key for an application by an Authentication Server Function (AUSF) in a wireless network. The method includes receiving, by the AUSF, a first request from a Unified Data Manager (UDM) in the wireless network, where the first request includes an AKMA refresh parameter (AKMA RP The first request includes a first request, a second request, a subscription permanent identifier (SUPI) associated with a user equipment (UE) in a wireless network, and at least one subscription permanent identifier (SUPI) associated with the user equipment (UE) in the wireless network, the first request indicating a request to generate at least one new AKMA key for establishing communication between the UE and at least one application function (AF) in the wireless network. The method further includes generating, by the AUSF, the at least one new AKMA key and an associated new AKMA key identifier based on the received first request. The method further includes transmitting, by the AUSF, the generated at least one new AKMA key to an AKMA anchor function (AAnF) in the wireless network, where the AAnF is associated with the at least one AF.

[0021] Accordingly, the present embodiment provides a method for generating new Authentication and Key Management (AKMA) keys for an application by a user equipment (UE) in a wireless network. The method includes receiving a first request by the user equipment (UE) from a Unified Data Manager (UDM) in the wireless network, where the first request includes an Authentication and Key Management (AKMA) refresh parameter (AKMA) for the application. RP), where the first request indicates a request for generating at least one new AKMA key for establishing communication between a user equipment (UE) and at least one application function (AF) in the wireless network. The method further includes generating, by the user equipment (UE), at least one new AKMA key and an associated new AKMA key identifier based on the received first request. The method further includes transmitting, by the user equipment (UE), a second request based on the generated at least one new AKMA key, where the second request is an application session establishment request for establishing communication between the user equipment (UE) and at least one application function (AF).

[0022] This and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following description, while indicating preferred embodiments and many specific details thereof, is given by way of example and not by way of limitation. Many changes and modifications can be made within the scope of the present embodiments, and the embodiments herein include all such modifications. Effect of the Invention

[0023] The embodiments of the present disclosure provide a method and apparatus for refreshing AKMA and AF keys without performing primary authentication.

[0024] The embodiments of the present disclosure provide a method and apparatus for avoiding key synchronization issues by defining how the AKMA Key ID indicates a refreshed key.

[0025] The method is illustrated in the accompanying drawings, in which like reference characters designate corresponding parts in the various drawings throughout. Embodiments herein will be better understood from the following description with reference to the drawings, in which: [Brief description of the drawings]

[0026] [Figure 1] 1 is a diagram illustrating a sequence flow scenario of a method for establishing communication between a user equipment (UE) and an application function (AF) according to the prior art; [Diagram 2] 1 is a block diagram of a network entity for generating a new AKMA key and a new AF key according to an embodiment as disclosed herein. [Diagram 3] FIG. 2 is a block diagram of a user terminal for generating a new AKMA key and a new AF key according to an embodiment disclosed in the present application. [Figure 4A] 1 is a flowchart illustrating various operations performed by a network entity to generate a new AKMA key and a new AF key, according to an embodiment as disclosed herein. [Figure 4B] 1 is a flowchart illustrating various operations performed by a network entity to generate a new AKMA key and a new AF key, according to an embodiment as disclosed herein. [Figure 4C] 1 is a flowchart illustrating various operations performed by a UE to generate a new AKMA key and a new AF key in accordance with embodiments disclosed herein. [Diagram 5] 1 is an exemplary sequential flow chart illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein. [Figure 6] 11 is another exemplary sequential flow chart illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein. [Figure 7] 11 is another exemplary sequential flow chart illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein. [Figure 8]11 is another exemplary sequential flow chart illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein. [Figure 9] 4 is an exemplary sequential flow chart illustrating the generation of a new AF key according to an embodiment as disclosed herein. [Figure 10] 1 is an exemplary sequential flow chart illustrating timer-based generation of a new AKMA key according to an embodiment as disclosed herein. [Figure 11] 1 is an exemplary sequential flow chart illustrating timer-based generation of a new AF key according to an embodiment as disclosed herein. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0027] The embodiments of the present specification and various features and advantageous details thereof will be more fully described with reference to the non-limiting embodiments shown in the accompanying drawings and described in detail in the following description. Descriptions of well-known components and processing techniques are omitted so as not to unnecessarily obscure the embodiments of the present specification. Furthermore, the various embodiments described herein are not necessarily mutually exclusive, since some embodiments can be combined with one or more other embodiments to form new embodiments. The term "or" used in this application refers to non-exclusive unless otherwise indicated. The examples used in this application are intended to facilitate understanding of how the embodiments of the present specification may be implemented and further enable those skilled in the art to implement the embodiments of the present specification. Thus, the examples should not be interpreted as limiting the scope of the embodiments of the present specification.

[0028] As is conventional in the art, the embodiments may be described and illustrated in terms of described functions or blocks performing functions. These blocks, which may be referred to herein as units, modules, or the like, may be physically embodied by analog or digital circuits, such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, and the like, and may be optionally driven by firmware. The circuits may be embodied, for example, in one or more semiconductor chips, or on a substrate support, such as a printed circuit board. The circuits constituting a block may be embodied by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuits), or by a combination of dedicated hardware performing some functions of the block and a processor performing other functions of the block. Each block of the embodiments may be physically separated into two or more interacting separate blocks without departing from the scope of the present invention. Similarly, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the present invention.

[0029] It should be understood that the accompanying drawings are used to help easily understand various technical features, and the embodiments presented in the present application are not limited by the accompanying drawings. Therefore, the present disclosure should be interpreted as extending to any modifications, equivalents, and alternatives in addition to those specifically specified in the accompanying drawings. In the present application, terms such as first and second may be used to describe various elements, but these elements should not be limited by these terms. These terms are usually used only to distinguish one element from another element.

[0030] The terms "electronic device," "user equipment," and "UE" have the same meaning and are used interchangeably throughout this document.

[0031] Accordingly, the present embodiment provides a method for generating a new Authentication and Key Management (AKMA) key for an application by an Authentication Server Function (AUSF) in a wireless network. The method includes receiving, by the AUSF, a first request from a Unified Data Manager (UDM) in the wireless network, where the first request includes an AKMA refresh parameter (AKMA RP The method further includes a step of generating, by the AUSF, the at least one new AKMA key and an associated new AKMA key identifier based on the received first request, and at least one subscription permanent identifier (SUPI) associated with at least one user equipment (UE) in the wireless network, the first request indicating a request to generate at least one new AKMA key for establishing communication between the at least one user equipment (UE) and at least one application function (AF) in the wireless network. The method further includes a step of transmitting, by the AUSF, the generated at least one new AKMA key to an AKMA anchor function (AAnF) in the wireless network, where the AAnF is associated with the at least one AF.

[0032] In the conventional method and system, the AF key (K AF ) cannot be refreshed immediately after its validity period expires until a new primary authentication occurs. This is because the user AF This means that after the expiration of the AKMA (which may occur after a very long period of time), the application may not be usable until a new primary authentication procedure occurs (which requires authentication with the AKMA). AF is K AF Therefore, a mechanism is required for the AKMA service to request the network to provide refresh parameters for refreshing the AKMA and AF keys. AFPerforming the primary authentication every time a new AF key needs to be created is a heavy approach and requires a large effort. Unlike conventional methods and systems, in the present disclosure, a new AF key is generated without the need to perform the primary authentication.

[0033] Referring now to the drawings, and particularly to Figures 1-11, in which like reference characters indicate corresponding features consistently throughout the views, a preferred embodiment is illustrated.

[0034] FIG. 1 is a diagram illustrating a sequence flow scenario of a method for establishing communication between a user equipment (UE) and an application function (AF) according to the prior art. As shown in FIG. 1, in step 110, the UE 102 initiates a network access authentication procedure by requesting the AUSF 104 to register the UE 102 for AKMA service. In step 112, once the network access authentication procedure is completed, the UE 102 receives an AUSF key (K AUSF Similarly, in step 114, the AUSF 104 further generates an AUSF key (K AUSF In step 116, the UE 102 generates the generated K AUSF Based on AKMA key (K AKMA ) 116. Then, the UE 102 derives K AKMA Use the AF key (K AF Similarly, in step 118, the AUSF 104 derives the generated K AUSF Based on K AKMA Derive K AKMA Once A-KID1 is derived, in step 120, the AUSF 104 sends a key response to the AAnF 106. In step 122, the UE 102 initiates an application session establishment request using A-KID1 (112). In step 124, the AF 108 will send a key request to the AANF 106 upon receiving the application session establishment request from the UE 102. In step 126, the AAnF 10 derives K using A-KID1. AF In step 128, the AAnF 106 derives (126)AF Upon generation of K, the AF 108 sends a key response to the AF 108. In step 130, the AF 108 sends an initial provisioning response to the UE 102 that includes the counter AF. AF When the validity of A-KID expires, in steps 132 and 134, when the UE 102 sends an initial provisioning request using the previous A-KID1, the AF 108 will AF In step 136, the AF 108 is unable to provide application access to the UE 102 and so rejects the request because the new K for the AF is not valid. AF AKMA cannot be generated until the next primary authentication is performed according to the conventional method. Thus, the UE 102 may not be able to use applications that require AKMA services from the AF 108.

[0035] 2 is a block diagram of a network entity 200 for generating new AKMA keys and new AF keys according to an embodiment as disclosed herein. In one embodiment, network entity 200 includes memory 210, processor 220, communicator 230, AKMA refresh parameter generator 240, AKMA key generator 250, AKMA key identifier generator 260, and AF key generator 280. In one embodiment, network entity 200 includes AMF 201, AUSF 202, UDM 203, AAnF 204, and AF 205 (not shown in FIG. 2). In other embodiments, network entity 200 may be one of AMF 201, AUSF 202, UDM 203, AAnF 204, and AF 205.

[0036] The memory 210 further stores instructions executed by the processor 220. The memory 210 may include a non-volatile storage element. Examples of such non-volatile storage elements may include a magnetic hard disk, an optical disk, a floppy disk, a flash memory, or a form of electrically programmable memory (EPROM) or a form of electrically erasable and programmable memory (EEPROM). Furthermore, the memory 210 may be considered a non-transitory storage medium in some examples. The term "non-transitory" may refer to the storage medium not being embodied as a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted as the memory 210 being non-moving. In some examples, the memory 210 may be configured to store a larger amount of information than a memory. In certain examples, the non-transitory storage medium may store data that can be changed over time (e.g., in a random access memory (RAM) or cache). In one embodiment, the memory 210 may be an internal storage unit, an external storage unit of the network entity 200, a cloud storage, or any other type of external storage.

[0037] Processor 220 is in communication with memory 210, communicator 230, AKMA refresh parameter generator 240, AKMA key generator 250, AKMA key identifier generator 260, and AF key generator 270. Processor 220 is configured to execute instructions stored in memory 210 to perform various processes. Communicator 230 is configured to communicate internally between external devices and internal hardware components over one or more networks.

[0038] In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameter (AKMA RP ) is generated. RPmay be generated by one of the AUSF 202, the UDM 203, and the AAnF 204 based on a received AKMA refresh display request. RP is a random (RAND) value, a counter AKMA , and a counter AF It may be a value.

[0039] In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA The AKMA key generator 250 generates the AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 102, into a key distribution function (KDF), as shown in Equation 1. [Number 1] K AKMA '=KDF(SUPI,K AUSF ,“AKMA”,AKMA RP )

[0040] In one embodiment, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates an AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300 (102). In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (KAUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2. [Number 2] A-TID'=KDF(“A-TID”,K AUSF ,AKMA RP ,SUPI)

[0041] In one embodiment, the AF key generator 270 generates a new Application Function (AF) key. The AF key generator 270 generates an AKMA key (K AKMA ), an identifier of at least one AF (AF-ID), and AKMA refresh parameters (AKMA RP In one embodiment, the AF key generator 280 generates a new Application Function (AF) key based on the AKMA key (K AKMA ), an identifier of at least one AF (AF-ID), and AKMA refresh parameters (AKMA RP ) into the KDF as shown in Equation 3 to generate a new Application Function (AF) key (K AF ) [Number 3] K AF '=KDF(K AKMA, AF-ID,AKMA RP )

[0042] 2 illustrates various hardware components of the network entity 200, it should be understood that other embodiments are not so limited. In other embodiments, the network entity 200 may include fewer or more components. Furthermore, the labels or names of the components are used for illustrative purposes only and do not limit the scope of the invention. One or more components performing the same or substantially similar functions may be combined together to generate a new AKMA key and a new AF key for establishing communications between the UE 102 and the AF 205 in the wireless network.

[0043] 3 shows a block diagram of a UE 300 for generating a new AKMA key and a new AF key according to an embodiment as disclosed herein. In one embodiment, the user equipment 300 includes a memory 310, a processor 320, a communicator 330, an AKMA key generator 340, an AKMA key identifier generator 350, and an AF key generator 360.

[0044] The memory 310 further stores instructions executed by the processor 320. The memory 310 may include a non-volatile storage element. Examples of such non-volatile storage elements may include a magnetic hard disk, an optical disk, a floppy disk, a flash memory, or a form of electrically programmable memory (EPROM) or a form of electrically erasable and programmable memory (EEPROM). Furthermore, the memory 310 may be considered a non-transitory storage medium in some examples. The term "non-transitory" may refer to the storage medium not being embodied as a carrier wave or a propagated signal. However, the term "non-transitory" should not be interpreted as the memory 310 being non-moving. In some examples, the memory 310 may be configured to store a larger amount of information than a memory. In certain examples, the non-transitory storage medium may store data that can be changed over time (e.g., in a random access memory (RAM) or cache). In one embodiment, the memory 310 may be an internal storage unit, an external storage unit of the network entity 300, a cloud storage, or any other type of external storage.

[0045] Processor 320 is in communication with memory 310, communicator 330, AKMA key generator 340, AKMA key identifier generator 350, and AF key generator 380. Processor 320 is configured to execute instructions stored in memory 310 to perform various processes. Communicator 330 is configured to communicate internally between external devices and internal hardware components over one or more networks.

[0046] In one embodiment, AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 360 generates the AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300, into a key distribution function KDF as shown in Equation 1.

[0047] In one embodiment, AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 370 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 370 generates an AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 370 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0048] In one embodiment, the AF key generator 360 generates a new application function key (K AF The AF key generator 360 generates a new AKMA key (K AKMA '), the AF205 identifier (AF-ID), and the AKMA refresh parameters (AKMA RP ) based on the new application feature key (K AF In one embodiment, the AF key generator 360 generates a new AKMA key (K AKMA'), at least one AF identifier (AF-ID), and AKMA refresh parameters (AKMA RP ) into the KDF as shown in Equation 3 to obtain a new application function key (K AF ').

[0049] 3 illustrates various hardware components of the user terminal 300, it should be understood that other embodiments are not so limited. In other embodiments, the user terminal 300 may include fewer or more components. Furthermore, the labels or names of the components are used for illustrative purposes only and do not limit the scope of the invention. One or more components performing the same or substantially similar functions may be combined together to generate new AKMA keys and new AF keys for establishing communications between the UE 300 and the application function 205 in a wireless network.

[0050] 4A and 4B are flow charts illustrating various operations performed by network entity 200 to generate new AKMA keys and new AF keys according to embodiments as disclosed herein.

[0051] At 402, the method includes receiving, by the UDM 203, an AKMA refresh request from the AAnF 204. In one embodiment, the AKMA refresh request received from the AAnF 204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user equipment (UE) 300.

[0052] At block 404, the method includes generating, by the UDM 203, an AKMA refresh parameter based on the received AKMA refresh request. In one embodiment, the AKMA refresh parameter generator 240 generates an AKMA refresh parameter (AKMA RP ) is generated. RPmay be generated by one of the AUSF 202, the UDM 203, and the AAnF 204 based on a received AKMA refresh display request. RP is a random (RAND) value, a counter AKMA , and a counter AF It may be at least one of the values.

[0053] In block 406, the method includes, by the UDM 203, updating the AKMA refresh parameter (AKMA RP ) to the AUSF 202. In one embodiment, the UDM 203 transmits an AKMA refresh parameter (AKMA RP ) to AUSF202.

[0054] At block 408, the method proceeds to generate a new AKMA key (K AKMA In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA The AKMA key generator 250 generates the AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates an AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0055] At block 410, the method includes transmitting, by the AUSF 202, an AKMA response to the UDM 203. In one embodiment, the AUSF 202 transmits an AKMA refresh response to the UDM 203. The AKMA refresh response includes an acknowledgment response to the AKMA refresh request received from the UDM 203. The AKMA refresh response further includes an AKMA MAC-I. AUSF and counter AKMA Includes.

[0056] At block 412, the method includes sending, by the AUSF 202, an AKMA anchor key registration request refresh response to the AAnF 204. In one embodiment, the AUSF 202 sends the AKMA anchor key registration request refresh response to the AAnF 204. In one embodiment, the AKMA anchor key registration request refresh response includes the new AKMA key (K AKMA'), at least one SUPI associated with the UE 300, and a new AKMA key identifier (A-KID').

[0057] At block 414, the method includes sending, by the UDM 203, the notification to the UE 300 through the AMF 201. In one embodiment, the UDM 203 sends the notification to the UE 300 through the AMF 201. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0058] At block 416, the method includes receiving, by the UDM 203, the acknowledgement from the UE 300 through the AMF 201. In one embodiment, the UDM 203 receives the acknowledgement from the UE 300.

[0059] FIG. 4C is a flow chart illustrating various operations performed by UE 300 to generate a new AKMA key and a new AF key according to an embodiment as disclosed herein.

[0060] At block 452, the method includes receiving, by the UE 300, the notification from the UDM 203. In one embodiment, the UE 300 receives the notification from the UDM 203. In one embodiment, the UE 300 receives the notification from the UDM 203 through the AMF 201. The notification is received via an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0061] At block 454, the method includes generating, by the UE 300, a new AKMA key and an associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 340 generates the AKMA, AUSF key (K AUSF), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 370 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 370 generates an AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0062] At 456, the method includes sending, by the UE 300, the acknowledgement to the UDM 203. In one embodiment, the UE 300 sends the acknowledgement to the UDM 203 through the AMF 201.

[0063] At 458, the method includes sending, by the UE 300, an application session establishment request to the AF 205. In one embodiment, the UE 300 sends the application session establishment request to the AF 205 based on the new AKMA key identifier (A-KID').

[0064] FIG. 5 is an exemplary sequential flow diagram illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein.

[0065] At 510, the UE 300 performs a primary authentication with the network entity by registering with the UDM 203. After performing the primary authentication, the UE 300 and the AUSF 202 exchange an AUSF key (K AUSF ) will be derived.

[0066] In 515, the UE 300 and the AF 205 are K AKMA and K AF is generated.

[0067] At 520, the AAnF 204 sends an AKMA refresh request to the UDM 203. In one embodiment, the AKMA refresh request received from the AAnF 204 includes an AKMA refresh indicator and at least one SUPI associated with the UE 300.

[0068] At 525, the UDM 203 generates AKMA refresh parameters based on the received AKMA refresh request. In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameters (AKMA RP ) is generated. RP may be generated by one of the AUSF 202, the UDM 203, and the AAnF 204 based on a received AKMA refresh display request. RP is a random (RAND) value, a counterAKMA , and a counter AF It may be at least one of the values.

[0069] At 530, the UDM 203 transmits the AKMA refresh parameters to the AUSF 202. In one embodiment, the UDM 203 transmits the AKMA refresh parameters (AKMA RP ) to AUSF202.

[0070] 535, AUSF202 uses the new AKMA key (K AKMA In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA The AKMA key generator 250 generates the AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is the AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), “AKMA”, and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID′). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID′) to generate a new AKMA key identifier (A-KID′). The AKMA key identifier generator 260 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0071] At 540, the AUSF 202 sends an AKMA response to the UDM 203. In one embodiment, the AUSF 202 sends an AKMA refresh response to the UDM 203. The AKMA refresh response includes an acknowledgment to the AKMA refresh request received from the UDM 203. The AKMA refresh response further includes an AKMA MAC-I. AUSF and counter AKMA Includes.

[0072] In 545, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AAnF 204. In one embodiment, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AAnF 204. In one embodiment, the AKMA anchor key registration request refresh response includes the new AKMA key (K AKMA '), at least one SUPI associated with the UE 300, and a new AKMA key identifier (A-KID').

[0073] At 550, the UDM 203 sends a notification to the AMF 201. In one embodiment, the UDM 203 sends a notification to the AMF 201. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0074] At 555, the AMF 201 sends a notification to the UE 300. In one embodiment, the AMF 201 sends a notification to the UE 300. The notification includes the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0075] At 560, the UE 300 generates a new AKMA key and an associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 340 generates the AUSF key (K AUSF ), “AKMA”, AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, AKMA key identifier generator 370 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300, into the key distribution function as shown in Equation 2 to generate a new AKMA temporary identifier (A-TID').

[0076] At 565, the UE 300 sends an acknowledgement to the AMF 201. In one embodiment, the UE 300 sends an acknowledgement to the AMF 201.

[0077] At 570, the AMF 201 sends an acknowledgement to the UDM 203. In one embodiment, the AMF 201 sends an acknowledgement to the UDM 203.

[0078] At 575, the UE 300 sends an application session establishment request to the AF 205. In one embodiment, the UE 300 sends the application session establishment request to the AF 205 based on the new AKMA key identifier (A-KID').

[0079] FIG. 6 is an exemplary sequential flow diagram illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein.

[0080] At 610, the UE 300 performs a primary authentication with the network entity by registering with the UDM 203. After performing the primary authentication, the UE 300 and the AUSF 202 exchange an AUSF key (K AUSF ) will be derived.

[0081] In 615, the UE 300 and the AF 205 are AKMA and K AF Generate.

[0082] At 620, the AAnF 204 sends an AKMA refresh request to the UDM 203. In one embodiment, the AKMA refresh request received from the AAnF 204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user equipment (UE).

[0083] At 625, the UDM 203 generates AKMA refresh parameters based on the received AKMA refresh request. In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameters (AKMA RP) is generated. RP may be generated by one of the AUSF 202, the UDM 203, and the AAnF 204 based on a received AKMA refresh display request. RP is a random (RAND) value, a counter AKMA , and a counter AF It may be at least one of the values.

[0084] At 630, the UDM 203 transmits the AKMA refresh parameters to the AUSF 202. In one embodiment, the UDM 203 transmits the AKMA refresh parameters (AKMA RP ) to AUSF202.

[0085] In the 635, the AUSF202 uses the new AKMA key (K AKMA In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA The AKMA key generator 250 generates the AUSF key (K AUSF ), “AKMA”, AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. Additionally, in another embodiment, AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates an AUSF key (K AUSF), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0086] At 640, the AUSF 202 sends an AKMA response to the UDM 203. In one embodiment, the AUSF 202 sends an AKMA refresh response to the UDM 203. The AKMA refresh response includes an acknowledgment for the AKMA refresh request received from the UDM 203. The AKMA refresh response further includes an AKMA MAC-I. AUSF and counter AKMA Includes:

[0087] At 645, the UDM 203 sends a notification to the AMF 201. In one embodiment, the UDM 203 sends a notification to the AMF 201. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0088] At 650, the AMF 201 sends a notification to the UE 300. In one embodiment, the AMF 201 sends a notification to the UE 300. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0089] At 655, the UE 300 generates a new AKMA key and an associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA’ The AKMA key generator 340 generates the AUSF key (K AUSF ), “AKMA”, AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0090] At 660, the UE 300 sends an acknowledgement to the AMF 201. In one embodiment, the UE 300 sends an acknowledgement to the AMF 201.

[0091] At 665, the UDM 203 sends the refresh information to the AUSF 202. In one embodiment, the UDM 203 sends the refresh information to the AUSF 202, including an acknowledgement for receiving the acknowledgement from the AMF 201.

[0092] At 670, the AMF 201 sends an acknowledgement to the UDM 203. In one embodiment, the AMF 201 sends an acknowledgement to the UDM 203.

[0093] At 675, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AANF 204. In one embodiment, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AANF 204. In one embodiment, the AKMA anchor key registration request refresh response includes the new AKMA key (K AKMA '), at least one SUPI associated with the UE 300, and a new AKMA key identifier (A-KID').

[0094] At 680, the UE 300 sends an application session establishment request to the AF 205. In one embodiment, the UE 300 sends the application session establishment request to the AF 205 based on the new AKMA key identifier (A-KID').

[0095] FIG. 7 is an exemplary sequential flow diagram illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein.

[0096] At 710, the UE 300 performs a primary authentication with the network entity by registering with the UDM 203. After performing the primary authentication, the UE 300 and the AUSF 202 exchange an AUSF key (K AUSF ) will be derived.

[0097] In 715, UE300 and AF205 are K AKMA and K AFGenerate.

[0098] At 720, the AAnF 204 sends an AKMA refresh request to the UDM 203. In one embodiment, the AKMA refresh request received from the AAnF 204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user equipment (UE).

[0099] At 725, the UDM 203 sends an AKMA refresh request to the AUSF 202. In one embodiment, the UDM 203 sends the AKMA refresh request to the AUSF 202 with at least one SUPI associated with the UE 300.

[0100] At 730, the AUSF202 determines the AKMA refresh parameter (AKMA RP ), new AKMA key (K AKMA In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameters (AKMA RP In one embodiment, AKMA RP is a random (RAND) value, a counter AKMA , and a counter AF In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA The AKMA key generator 250 generates a new AKMA key (K AKMA '), AUSF key (K AUSF ), “AKMA”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0101] At 735, the AUSF 202 sends an AKMA response to the UDM 203. In one embodiment, the AUSF 202 sends an AKMA refresh response to the UDM 203. The AKMA refresh response includes an acknowledgment to the AKMA refresh request received from the UDM 203. The AKMA refresh response further includes the AKMA MAC-I. AUSF and counter AKMA Including 。

[0102] At 740, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AANF 204. In one embodiment, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AANF 204. In one embodiment, the AKMA anchor key registration request refresh response includes the new AKMA key (K AKMA '), at least one SUPI associated with the UE 300, and a new AKMA key identifier (A-KID').

[0103] At 745, the UDM 203 sends a notification to the AMF 201. In one embodiment, the UDM 203 sends a notification to the AMF 201. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0104] At 750, the AMF 201 sends a notification to the UE 300. In one embodiment, the AMF 201 sends a notification to the UE 300. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0105] At 755, the UE 300 generates a new AKMA key and an associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 340 generates the AUSF key (K AUSF ), “AKMA”, AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates an AUSF key (K AUSF), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0106] At 760, the UE 300 sends an acknowledgement to the AMF 201. In one embodiment, the UE 300 sends an acknowledgement to the AMF 201.

[0107] At 765, the AMF 201 sends an acknowledgement to the UDM 203. In one embodiment, the AMF 201 sends an acknowledgement to the UDM 203.

[0108] At 770, the UE 300 sends an application session establishment request to the AF 205. In one embodiment, the UE 300 sends the application session establishment request to the AF 205 based on the new AKMA key identifier (A-KID').

[0109] FIG. 8 is another exemplary sequential flow diagram illustrating the generation of a new AKMA key and an associated AKMA key identifier according to an embodiment as disclosed herein.

[0110] At 810, the UE 300 performs a primary authentication with the network entity by registering with the UDM 203. After performing the primary authentication, the UE 300 and the AUSF 202 exchange an AUSF key (K AUSF ) will be derived.

[0111] In 815, the UE300 and AF205 are K AKMAand K AF Generate.

[0112] At 820, the AAnF 204 generates the AKMA refresh parameters. In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameters (AKMA RP In one embodiment, AKMA RP is a random (RAND) value, a counter AKMA , and a counter AF It may be at least one of the values.

[0113] At 825, the AAnF 204 sends an AKMA refresh request to the UDM 203. In one embodiment, the AKMA refresh request received from the AAnF 204 includes AKMA refresh parameters and at least one SUPI associated with at least one user equipment (UE).

[0114] At 830, the UDM 203 transmits the AKMA refresh parameters to the AUSF 202. In one embodiment, the UDM 203 transmits the AKMA refresh parameters (AKMA RP ) to AUSF202.

[0115] In the 835, the AUSF202 uses the new AKMA key (K AKMA In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA The AKMA key generator 250 generates the AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is "AKMA", AUSF key (K AUSF), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. In yet another embodiment, AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 260 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the key distribution function as shown in Equation 2 to generate a new AKMA temporary identifier (A-TID').

[0116] At 840, the AUSF 202 sends an AKMA response to the UDM 203. In one embodiment, the AUSF 202 sends an AKMA refresh response to the UDM 203. The AKMA refresh response includes an acknowledgment to the AKMA refresh request received from the UDM 203. The AKMA refresh response further includes an AKMA MAC-I. AUSF and counter AKMA Includes.

[0117] At 845, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AANF 204. In one embodiment, the AUSF 202 sends an AKMA anchor key registration request refresh response to the AANF 204. In one embodiment, the AKMA anchor key registration request refresh response includes the new AKMA key (K AKMA'), at least one SUPI associated with the UE 300, and a new AKMA key identifier (A-KID').

[0118] At 850, the UDM 203 sends a notification to the AMF 201. In one embodiment, the UDM 203 sends a notification to the AMF 201. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0119] At 855, the AMF 201 sends a notification to the UE 300. In one embodiment, the AMF 201 sends a notification to the UE 300. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0120] At 860, the UE 300 generates a new AKMA key and an associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 340 generates the AUSF key (K AUSF ), “AKMA”, AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP), and at least one SUPI associated with UE 300, into the KDF as shown in Equation 1. Additionally, in another embodiment, AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). AKMA key identifier generator 350 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with the UE 300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE 300, into the KDF to generate a new AKMA temporary identifier (A-TID′) as shown in Equation 2.

[0121] At 865, the UE 300 sends an acknowledgement to the AMF 201. In one embodiment, the UE 300 sends an acknowledgement to the AMF 201.

[0122] At 870, the AMF 201 sends an acknowledgement to the UDM 203. In one embodiment, the AMF 201 sends an acknowledgement to the UDM 203.

[0123] At 875, the UE 300 sends an application session establishment request to the AF 205. In one embodiment, the UE 300 sends the application session establishment request to the AF 205 based on the new AKMA key identifier (A-KID').

[0124] FIG. 9 is an exemplary sequential flow diagram illustrating the generation of a new AF key according to an embodiment as disclosed herein.

[0125] At 910, the UE 300 performs a primary authentication with the network entity by registering with the UDM 203. After performing the primary authentication, the UE 300 and the AUSF 202 exchange an AUSF key (K AUSF ) will be derived.

[0126] In accordance with TS 33.535, the UE300 and AF205 are AKMA and K AF Generate.

[0127] At 920, the AAnF 204 sends an AKMA refresh request to the UDM 203. In one embodiment, the AKMA refresh request received from the AAnF 204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user equipment (UE).

[0128] At 925, the UDM203 generates a new K based on the AKMA refresh request received from the AAnF. AF Trigger a refresh.

[0129] At 930, the UDM 203 sends an AKMA refresh request to the AUSF 202. In one embodiment, the AKMA refresh request received from the AUSF 202 includes an AKMA refresh indicator and at least one SUPI associated with at least one user equipment (UE).

[0130] At 935, the UDM 203 generates AKMA refresh parameters based on the received AKMA refresh request. In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameters (AKMA RP In one embodiment, AKMA RP is a random (RAND) value, a counter AKMA , and a counter AF It may be at least one of the values.

[0131] At 940, the AUSF 202 sends an AKMA response to the UDM 203. In one embodiment, the AUSF 202 sends an AKMA refresh response to the UDM 203. The AKMA refresh response includes an acknowledgment to the AKMA refresh request received from the UDM 203. The AKMA refresh response further includes an AKMA MAC-I. AUSF and counter AKMA Includes.

[0132] At 945, the UDM 203 sends an AKMA refresh response to the AAnF 204. In one embodiment, the AKMA refresh response includes an AKMA refresh parameter (AKMA RP ).

[0133] In the 950, the AAnF204 implements a new AF key (K AF )

[0134] At 955, the UDM 203 sends a notification to the AMF 201. In one embodiment, the UDM 203 sends a notification to the AMF 201. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0135] At 960, the AMF 201 sends a notification to the UE 300. In one embodiment, the AMF 201 sends a notification to the UE 300. The notification includes an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and a counter AKMA Includes at least one of the following:

[0136] At 965, the UE 300 generates a new AF key based on the received notification.

[0137] At 970, the UE 300 sends an acknowledgement to the AMF 201. In one embodiment, the UE 300 sends an acknowledgement to the AMF 201.

[0138] At 975, the AMF 201 sends an acknowledgement to the UDM 203. In one embodiment, the AMF 201 sends an acknowledgement to the UDM 203.

[0139] FIG. 10 is an exemplary sequential flow diagram illustrating timer-based generation of a new AKMA key according to an embodiment as disclosed herein.

[0140] At 1010, the UE 300 performs a first authentication with the network entity by registering with the AAnF 204. After performing the first authentication, the UE 300 and the AUSF 202 exchange an AUSF key (K AUSF ) will be derived.

[0141] At 1015, the UE 300 sends an application session establishment request to the AF 205. In one embodiment, the UE 300 sends the application session establishment request to the AF based on the AKMA key identifier (A-KID).

[0142] 1020, AF205, K AF When the timer associated with expires, AF is determined to be invalid.

[0143] 1025, AF205 has a new AF key (K AF ') Send the request to AAnF204.

[0144] In the 1030, the AAnF204 has a new AF key (K AF ) is K AF If the request is not available in the AAnF 204 along with the current timer value, it sends a request rejection to the AF 205.

[0145] At 1035, the AF 205 sends a rejection message to the UE 300 according to the current timer value.

[0146] 1040, AAnF204 is a new AKMA key (K AKMA ') to trigger the

[0147] At 1045 , the AAnF 204 sends a refresh parameter request to the UDM 203 .

[0148] 1050, UDM203 uses AKMA refresh parameters (AKMA RP ) and generate the generated AKMA RP along with an AKMA refresh response as an acknowledgment to the AUSF 202.

[0149] At 1055, upon receiving the AKMA refresh parameters from the UDM 203, the AUSF 202 transmits an AKMA refresh response.

[0150] In 1060, the UDM203 was produced with a new timer associated with it. RP to UE300.

[0151] 1065, UE300 supports new AKMA keys (K AKMA ').

[0152] 1070, AUSF202 supports new AKMA keys (K AKMA ').

[0153] At 1075, the AUSF 202 sends an AKMA anchor key registration request to the AANF 204. In one embodiment, the AKMA anchor key registration request is AKMA ' is included.

[0154] At 1080, the AAnF 204 sends an AKMA anchor key registration request to the AUSF 202. In one embodiment, the AKMA anchor key registration response is AKMA’ Includes an acknowledgment for

[0155] FIG. 11 is an exemplary sequential flow diagram illustrating timer-based generation of a new AF key according to an embodiment as disclosed herein.

[0156] At 1110, the UE 300 performs a first authentication with a network entity by registering with the AAnF 203. After performing the first authentication, the UE 300 and the AUSF 202 exchange an AUSF key (K AUSF ) will be derived.

[0157] At 1115, the UE 300 sends an application session establishment request to the AF 205. In one embodiment, the UE 300 sends the application session establishment request to the AF 205 based on the AKMA key identifier (A-KID).

[0158] At 1120, AF205 is K AF When the timer associated with expires, AF is determined to be invalid.

[0159] 1125, AF205 has a new AF key (K AF ') Send the request to AAnF204.

[0160] In 1130, AAnF204 has a new AF key (K AF ) is K AF If the request is not available in the AAnF 204 along with the current timer value, it sends a request rejection to the AF 205.

[0161] At 1135, the AF 205 sends a rejection message to the UE 300 according to the current timer value.

[0162] 1140, AAnF204 has a new AF key (K AF ') to trigger the

[0163] At 1145 , the AAnF 204 sends a refresh parameter request to the UDM 203 .

[0164] 1150, UDM203 uses AKMA refresh parameters (AKMA RP ) and generate the generated AKMA RP along with an AKMA refresh response as an acknowledgment to the AUSF 204.

[0165] In 1155, the UDM203 was produced by AKMA along with a new timer associated with it. RP to UE300.

[0166] 1160, UE300 has a new AF key (K AF ').

[0167] 1165, AAnF204 has a new AF key (K AF ').

[0168] The above description of the specific embodiment fully reveals the general characteristics of the embodiments of the present application so that others can easily modify and / or adapt for various applications such as the specific embodiment by applying current knowledge without departing from the general concept, and therefore such adaptation and modification should and are intended to be understood within the meaning and range of equivalents of the disclosed embodiment. It should be understood that the words or terms used in the present application are for the purpose of description and not for the purpose of limitation. Thus, although the embodiments of the present application are described in terms of the preferred embodiment, those skilled in the art will recognize that the embodiments of the present application can be modified and implemented within the scope of the embodiments described in the present application. [Explanation of symbols]

[0169] 200 Network Entities 205 Application Functions 210 Memory 220 Processor 230 Communication Device 240 AKMA Refresh Parameter Generator 250 AKMA Key Generator 260 AKMA Key Identifier Generator 270 AF Key Generator 280 AF Key Generator 300 User terminals 310 Memory 320 Processor 330 Communication Device 340 AKMA Key Generator 350 AKMA Key Identifier Generator 360 AF Key Generator 370 AKMA Key Identifier Generator 380 AF Key Generator

Claims

1. A method performed by an integrated data management unit (UDM) in a wireless network to generate at least one new authentication and key management unit (AKMA) key for an application, comprising: Receiving, by an AKMA anchor function unit (AAnF), a first request, wherein the first request includes an AKMA refresh request indication and a subscription permanent identifier (SUPI) associated with at least one user equipment (UE); Generating at least one AKMA refresh parameter (AKMA RP ) based on the received first request; Sending the at least one generated AKMA to an authentication server function (AUSF) to generate the at least one new AKMA key RP A method comprising the step of:

2. The method according to claim 1, further comprising receiving, from the AUSF, at least one response message when the AUSF generates the at least one new AKMA key.

3. Transmitting the at least one generated AKMA to at least one user terminal via an Access and Mobility Management Function (AMF). RP The method according to claim 1, further comprising the step of transmitting.

4. The method according to claim 1, wherein the at least one new AKMA key is associated with a new AKMA key identifier.

5. A method for generating at least one new authentication and key management unit (AKMA) key for an application by an authentication server function unit (AUSF) in a wireless network, comprising: Receiving a response message from an integrated data management unit (UDM), the response message including at least one AKMA refresh parameter (AKMA RP ) and a subscription permanent identifier (SUPI) associated with at least one user equipment (UE). Generating, based on the received response message, the at least one new AKMA key and a new AKMA key identifier (A-KID'); Transmitting the generated at least one new AKMA key to an AKMA anchor function unit (AAnF).

6. The method according to claim 5, further comprising transmitting, to the UDM, at least one confirmation response when the at least one new AKMA key is generated. **Claim 7**: By inputting at least one of the AUSF keys (K AUSF ), the AKMA, the AKMA RP or at least one of at least one SUPIs into a key derivation function (KDF), generating K AKMA '; and K AUSF , an AKMA temporary identifier (A-TID), AKMA RP , or generating a new AKMA temporary identifier (A-TID') by inputting at least one of at least one SUPIs into the KDF; The method according to claim 5, further comprising generating the new AKMA key identifier (A-KID') based on the new AKMA temporary identifier (A-TID').

8. A method for generating at least one new authentication and key management part (AKMA) key for an application by a user equipment (UE) in a wireless network, the method comprising receiving, from an integrated data management part (UDM), authentication and key management part (AKMA) refresh parameters (AKMA RP ) for generating at least one new AKMA key for the application; Generating, based on the received refresh parameter (AKMA RP), the at least one new AKMA key and an associated new AKMA key identifier (A-KID'); Transmitting, to at least one AF (application function), a second request based on the generated at least one new AKMA key, wherein the second request is an application session establishment request for establishing communication between the UE and the at least one AF.

9. The method according to claim 8, comprising the step of sending at least one confirmation response to the UDM in response to generating the at least one new AKMA key.

10. The method according to claim 8, wherein the at least one new AKMA key generated is associated with the A-KID'.

11. An integrated data management unit (UDM) in a wireless network for generating at least one new authentication and key management unit (AKMA) key for an application, A communicator, Including a processor connected to the communicator, The processor, Receives a first request from an AKMA anchor function unit (AAnF), the first request including an AKMA refresh request instruction and a subscription permanent identifier (SUPI) associated with at least one user equipment (UE), Generate at least one AKMA refresh parameter (AKMA RP ) based on the received first request, The UDM is configured to send the at least one generated AKMA to an authentication server function (AUSF) to generate the at least one new AKMA key. RP ​

12. The processor, The UDM is further configured to receive at least one response message from the AUSF when the AUSF generates the at least one new AKMA key.

13. An authentication server function unit (AUSF) in a wireless network for generating at least one new authentication and key management unit (AKMA) key for an application, A communicator, Including a processor connected to the communicator, The processor, Receive a response message from the Unified Data Management Unit (UDM), where the response message includes an AKMA refresh parameter (AKMA RP ) and a Subscription Permanent Identifier (SUPI) associated with at least one User Equipment (UE). Generates the at least one new AKMA key and a new AKMA key identifier (A-KID') based on the received response message, The AUSF is configured to send the generated at least one new AKMA key to an AKMA anchor function unit (AAnF).

14. The processor, The AUSF according to claim 13 is further configured to send at least one confirmation response to the UDM when generating the at least one new AKMA key.

15. A user equipment (UE) in a wireless network for generating at least one new authentication and key management unit (AKMA) key for an application, A communicator, Including a processor connected to the communicator, The processor, Authentication and Key Management Department (AKMA) refresh parameters (AKMA RP ) for an application to generate at least one new AKMA key from the Unified Data Management Department (UDM) Generates the at least one new AKMA key and an associated new AKMA key identifier (A-KID') based on the received refresh parameter (AKMA RP), At least one AF (application function) is configured to send a second request based on the at least one newly generated AKMA key, The second request is an application session establishment request for establishing communication between the UE and at least one AF, user equipment (UE).