Communication Method, Communication Device, Communication Machine, and Computer Storage Medium

The proposed communication method addresses the limitations of AKMA processing in roaming scenarios by enabling the AKMA Anchor Function to manage and provide keys in visited networks, thus enhancing key management efficiency and reducing costs.

JP2025519829AActive Publication Date: 2025-06-26CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024574772
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-06-20
Filing Date
2023-06-15
Publication Date
2025-06-26
Estimated Expiration
2043-06-15

AI Technical Summary

Technical Problem

Current AKMA processing is limited to the user equipment's home network and lacks an effective solution for roaming scenarios, leading to increased management costs and service delays.

Method used

A communication method that involves the AKMA Anchor Function (AAnF) receiving messages from the Application Function (AF) to obtain and provide the key K AF, even in visited networks, through a proxy function in the visited Public Land Mobile Network (VPLMN).

Benefits of technology

This solution enables efficient AKMA key management for user equipment in roaming scenarios, reducing interaction and management costs between the AF and home networks while maintaining service integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025519829000001_ABST
    Figure 2025519829000001_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a communication method, a communication device, a communication apparatus, and a computer storage medium. The method includes: a step in which an Application Authentication and Key Management (AKMA) Anchor Function (AAnF) receives a first message sent from an Application Function (AF) or receives a first message sent from the AF via a first device, where the first message is for obtaining a key; and a step in which, when the AAnF checks that it can provide a service to the AF, the AAnF sends a second message to the AF or sends a second message to the AF via the first device, where the second message includes at least a key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a communication method, a communication device, a communication apparatus, and a computer storage medium.

[0002] (Cross-reference to related applications) This application claims the priority of a Chinese patent application with an application number of No. 202210701088.4, filed with the China National Intellectual Property Administration on June 20, 2022, and all of its content is incorporated herein by reference.

Background Art

[0003] Currently, the processing process of application authentication and key management (AKMA) is only applicable when the user equipment (UE) is in its home network. When the UE roams to a visited network (i.e., the roaming scenario), there is currently no effective solution.

Summary of the Invention

Problems to be Solved by the Invention

[0004] Embodiments of this application provide a communication method, a communication device, a communication apparatus, and a computer storage medium.

Means for Solving the Problems

[0005] The technical solution of the embodiments of this application is realized as follows.

[0006] In a first aspect, embodiments of this application provide a communication method, and the method includes The step of the AKMA Anchor Function (AAnF) receiving the first message sent from the Application Function (AF) or receiving the first message sent from the AF via the first device, wherein the first message is for obtaining the key K AF and, When the AAnF checks that it can provide services to the AF, the step of sending a second message to the AF or sending a second message to the AF via the first device, wherein the second message includes at least the key K AF and, including.

[0007] In some alternative embodiments of the present application, the AAnF is located in the Home Public Land Mobile Network (HPLMN, abbreviated as the home network), and / or the first device is located in the Visit Public Land Mobile Network (VPLMN, abbreviated as the visited network), and / or the AF is located in the VPLMN.

[0008] In some alternative embodiments of the present application, the first message includes an AKMA-Key Identifier (A-KID) and / or an identifier of the AF.

[0009] In some alternative embodiments of the present application, the communication method further includes the step of the AAnF deriving the key K AKMA based on the AKMA anchor key (K AF ).

[0010] In some alternative embodiments of the present application, the second message is the validity time information of the key K AF and, Subscription Permanent Identifier (SUPI), further includes at least one of Generic Public Subscription Identifier (GPSI).

[0011] In some alternative embodiments of the present application, the communication method further includes the step of the AAnF receiving a third message sent from an Authentication Server Function (AUSF), the third message is for registering a key, and the third message includes at least one of A-KID, K AKMA , SUPI, and roaming information of the terminal.

[0012] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0013] In some alternative embodiments of the present application, the roaming information of the terminal is obtained by the AUSF from Unified Data Management (UDM).

[0014] In some alternative embodiments of the present application, the roaming information of the terminal obtained by the AUSF from UDM is the roaming information of the terminal associated with the terminal SUPI.

[0015] In some alternative embodiments of the present application, after receiving the first message, the communication method further includes the step of the AAnF obtaining roaming information of the terminal from UDM, and the roaming information of the terminal is related to the terminal corresponding to the A-KID in the first message.

[0016] In some alternative embodiments of the present application, the step of the AAnF checking whether it can provide services to the AF includes the step of the AAnF checking whether it can provide services to the AF based on the roaming information of the terminal.

[0017] In a second aspect, the embodiment of the present application further provides a communication method, and the method includes: a step in which a first device receives a first message sent from an AF and sends the first message to an AAnF, where the first message is for obtaining a key K AF ; and when the AAnF can provide services to the AF, a step in which the first device receives a second message sent from the AAnF and sends the second message to the AF, where the second message includes at least the key K AF .

[0018] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0019] In some alternative embodiments of the present application, the first message includes an A-KID and / or an identifier of the AF.

[0020] In some alternative embodiments of the present application, the second message further includes at least one of the validity time information of the key K AF , SUPI, and GPSI.

[0021] In a third aspect, the embodiment of the present application further provides a communication method, and the method includes: a step in which a first device receives a first message sent from an AF, where the first message is for obtaining a key K AF ; and When it is checked that the first device can provide services to the AF, a step of transmitting a second message to the AF, where the second message includes at least the key K AF and, steps.

[0022] In some alternative embodiments of the present application, the first message includes an A-KID and / or an identifier of the AF.

[0023] In some alternative embodiments of the present application, the communication method further includes a step in which the first device receives first information transmitted from the AAnF, and the first information includes AKMA context information.

[0024] In some alternative embodiments of the present application, the first information includes at least one of an A-KID, an AKMA anchor key (K AKMA ), and a SUPI.

[0025] In some alternative embodiments of the present application, the communication method further includes a step in which the first device derives the key K AKMA based on AF .

[0026] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0027] In a fourth aspect, an embodiment of the present application further provides a communication method, which further includes a step in which the AAnF transmits first information to a first device, and the first information includes AKMA context information.

[0028] In some alternative embodiments of the present application, the first information includes at least one of an A-KID, an AKMA anchor key (K AKMA ), and a SUPI.

[0029] In some alternative embodiments of the present application, the communication method further includes the step of the AAnF receiving a third message sent from the AUSF, where the third message is for registering a key, and the third message includes at least one of an A-KID, K AKMA , a SUPI, and roaming information of the terminal.

[0030] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0031] In some alternative embodiments of the present application, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0032] In some alternative embodiments of the present application, the roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI.

[0033] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN.

[0034] In a fifth aspect, an embodiment of the present application further provides a communication method, the method including: a step of an AF sending a first message to a first device or an AAnF, where the first message is for obtaining a key K AF ; and when the first device or the AAnF checks that it can provide a service to the AF, a step of the AF receiving a second message sent from the first device or the AAnF, where the second message includes at least the key K AF .

[0035] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0036] In some alternative embodiments of the present application, the first message includes an AKMA key identifier (A-KID) and / or an identifier of the AF.

[0037] In some alternative embodiments of the present application, the second message further includes at least one of the validity time information of the key K AF , the SUPI, and the GPSI.

[0038] In a sixth aspect, an embodiment of the present application further provides a communication method, and the method includes a step in which the AUSF obtains authentication-related information from the UDM, and the authentication-related information includes at least one of third indication information indicating that it is necessary to generate AKMA key material for the terminal, fourth indication information indicating that it is not necessary to generate AKMA key material for the terminal, routing identifier (RID) information of the terminal, and roaming information of the terminal.

[0039] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0040] In some alternative embodiments of the present application, the communication method further includes a step in which the AUSF sends a third message to the AAnF, the third message is for registering a key, and the third message includes at least one of an A-KID, K AKMA , the SUPI, and the roaming information of the terminal.

[0041] In a seventh aspect, an embodiment of the present application further provides a communication method, and the method includes The step where the UDM sends authentication-related information to the AUSF is included, and the authentication-related information includes at least one of the third indication information indicating that it is necessary to generate the AKMA key material for the terminal, the fourth indication information indicating that it is not necessary to generate the AKMA key material for the terminal, the RID information of the terminal, and the roaming information of the terminal.

[0042] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of the first indication information indicating that the terminal is in a roaming state, the second indication information indicating that the terminal is not in a roaming state, the roaming destination information, the contract information at the roaming destination of the terminal, and the policy information at the roaming destination of the terminal.

[0043] In some alternative embodiments of the present application, the communication method further includes the step where the UDM receives the fourth message sent from the AAnF, where the fourth message is for requesting the roaming information of the terminal, and the step where the UDM sends the fifth message to the AAnF, where the fifth message includes the roaming information of the terminal.

[0044] In the eighth aspect, the embodiment of the present application further provides a communication device applicable to the AAnF, and the device includes a first communication unit and a first processing unit. The first communication unit is configured to receive the first message sent from the AF or receive the first message sent from the AF via the first device, and the first message is for obtaining the key K AF thereof. The first processing unit is configured to check whether it can provide services to the AF. When the first processing unit checks that it can provide services to the AF, the first communication unit is further configured to send the second message to the AF or send the second message to the AF via the first device, and the second message includes at least the key K AF thereof.

[0045] In the ninth aspect, the embodiment of the present application further provides a communication device applied to a first device, the device comprising a first receiving unit and a first transmitting unit, the first receiving unit is configured to receive a first message transmitted from an AF and transmit the first message to an AAnF, the first message being for obtaining a key K AF ; the first transmitting unit is configured to receive a second message transmitted from the AAnF and transmit the second message to the AF when the AAnF can provide a service to the AF, the second message including at least the key K AF ;

[0046] In the tenth aspect, the embodiment of the present application further provides a communication device applied to a first device, the device comprising a second communication unit and a second processing unit, the second communication unit is configured to receive a first message transmitted from an AF, the first message being for obtaining a key K AF ; the second processing unit is configured to check whether the AF can provide a service; the second communication unit is further configured to transmit a second message to the AF when the second processing unit checks that the AF can provide a service, the second message including at least the key K AF ;

[0047] In the eleventh aspect, the embodiment of the present application further provides a communication device applied to an AAnF, the device comprising a second transmitting unit, the second transmitting unit being configured to transmit first information to a first device, the first information including AKMA context information.

[0048] In the twelfth aspect, the embodiment of the present application further provides a communication device applied to an AF, the device comprising a third transmitting unit and a third receiving unit, The third transmitting unit is configured to transmit a first message to the first device or the AAnF, and the first message is for obtaining the key K AF and is so on. The third receiving unit is configured to receive a second message transmitted from the first device or the AAnF when the first device or the AAnF checks that it can provide a service to the AF, and the second message includes at least the key K AF and so on.

[0049] In a 13th aspect, an embodiment of the present application further provides a communication device applicable to an AUSF, the device includes a fourth receiving unit, the fourth receiving unit is configured to obtain authentication-related information from a UDM, and the authentication-related information includes at least one of third indication information indicating that it is necessary to generate an AKMA key material for a terminal, fourth indication information indicating that it is not necessary to generate an AKMA key material for the terminal, RID information of the terminal, and roaming information of the terminal.

[0050] In a 14th aspect, an embodiment of the present application further provides a communication device applicable to a UDM, the device includes a fifth transmitting unit, the fifth transmitting unit is configured to transmit authentication-related information to an AUSF, and the authentication-related information includes at least one of third indication information indicating that it is necessary to generate an AKMA key material for a terminal, fourth indication information indicating that it is not necessary to generate an AKMA key material for the terminal, RID information of the terminal, and roaming information of the terminal.

[0051] In a 15th aspect, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, and when the program is executed by a processor, it realizes the steps of the communication method according to any one of the first to seventh aspects of the embodiments of the present application.

[0052] In the 16th aspect, an embodiment of the present application further provides a communication device, which includes a memory, a processor, and a computer program stored in the memory and executable by the processor. When the processor executes the program, it executes the steps of the communication method according to any one of the 1st to 7th aspects of the embodiment of the present application.

Advantages of the Invention

[0053] According to the communication method, communication device, communication equipment, and computer storage medium provided by the embodiments of the present application, on the one hand, the method includes the step that AAnF receives the first message sent from AF or receives the first message sent from AF via the first device, where the first message is for obtaining the key K AF ; and when AAnF checks that it can provide services to AF, it sends a second message to AF or sends a second message to AF via the first device, where the second message includes at least the key K AF . Through the above interaction process, the AKMA service for the terminal to roam in the visited network is realized.

[0054] On the other hand, the first device receives the first message sent from AF, where the first message is for obtaining the key K AF ; and when the first device checks that it can provide services to AF, it sends a second message to AF, where the second message includes at least the key K AF . In this embodiment, a first device for managing and storing the AKMA key material obtained from the home network is introduced into the network architecture to provide the AKMA key service to the visited terminal and AF, thereby reducing the interaction and management costs between AF and each home network.

Brief Description of the Drawings

[0055]

Figure 1

Figure 2

Figure 3

Figure 4a

Figure 4b

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

DETAILED DESCRIPTION OF THE INVENTION

[0056] Hereinafter, the present application will be described in more detail with reference to the drawings and specific embodiments.

[0057] The technical solutions in the embodiments of the present application can be applied to various communication systems, such as Global System of Mobile communication (GSM), Long Term Evolution (LTE) system, or 5G system. Optionally, the 5G system or 5G network can also be referred to as a New Radio (NR) system or NR network.

[0058] Exemplarily, the communication system to which the embodiments of the present application are applied may include network devices and terminal devices (which may also be referred to as terminals, communication terminals, etc.). The network device may be a device that communicates with the terminal device. Here, the network device can provide communication coverage within a certain area and communicate with terminals located within this area. Optionally, the network device may be a base station in each communication system, for example, an evolved Node B (eNB) in the LTE system, or a base station (gNB) in the 5G system or NR system.

[0059] In addition, in the embodiments of the present application, a device equipped with a communication function in a network / system may be referred to as a communication device. The communication device may include network devices and terminals equipped with a communication function. The network devices and terminals may be the above-mentioned specific devices, which will not be repeatedly described here. The communication device may further include other devices in the communication system, such as other network entities such as network controllers and mobile management entities, but the embodiments of the present application do not limit these.

[0060] Note that the terms "system" and "network" in this specification are always used interchangeably in this specification. The term "and / or" in this specification only describes the association relationship of the associated objects and indicates that three relationships may exist. For example, A and / or B can represent three cases: when A exists independently, when both A and B exist, and when B exists independently. Also, the symbol " / " in this specification usually indicates that the relationship between the associated objects before and after is an "or" relationship.

[0061] The terms "first", "second", etc. in the specification and claims of the present application do not limit a specific order or sequence, but are used to distinguish similar objects. Note that since the data used in this way can be exchanged when appropriate, the embodiments of the present application described in this specification can be implemented in an order other than those illustrated or described in this specification. Furthermore, the terms "include" and "have" and their variants are intended to be non-exclusive inclusion. For example, a process, method, system, product, or device incorporating a series of steps or units need not be limited to those explicitly listed, but may include other things not explicitly listed or specific to those processes, methods, products, or devices.

[0062] Before describing the embodiments of the present application in detail, first, the related technology of AKMA will be briefly described.

[0063] Figure 1 is a schematic diagram of the AKMA network architecture. As shown in Figure 1, the core network elements of the AKMA network architecture mainly include AAnF, AF, AUSF, etc. Here, AAnF is an anchor function deployed within the home operator (or home network). AAnF stores the AKMA anchor key (K AKMA ) for the AKMA service. After the 5G master authentication between the UE and the AUSF is successfully completed, the AUSF sends this key to the AAnF. At the same time, the AAnF also generates the key K AF for use between the UE and the AF and maintains the AKMA context of the UE.

[0064] The AF with the AKMA service can request the AKMA application key K AF from the AAnF via the AKMA key identifier (A-KID). The AF can obtain the key K AF after obtaining the authentication and authorization of the operator's network.

[0065] The AUSF provides the UE identifier and AKMA key material, such as A-KID and K AKMA , etc. to the AAnF.

[0066] Currently, the network architecture and response processing process in the AKMA roaming scenario have not been proposed. However, based on the AKMA network architecture shown in Figure 1, every time the UE roams to the visited network, if the AF is also an application function that contracts with the visited network, it is assumed that the architecture of the AKMA service will be as shown in Figure 2. In such a network architecture, on the one hand, for the same AF, it provides application services to UEs belonging to multiple Public Land Mobile Networks (PLMNs). These UEs roam to the visited PLMN (VPLMN) where the AF is located. When the UE uses the AKMA service, the AF provides the AKMA key material (K AFThis means that in order to obtain (such as) these UEs' home PLMN (HPLMN), it is necessary to interact with the HPLMN. Here, the HPLMN can also be called the home network or the destination network, and the VPLMN can also be called the visited network or the visited destination network.

[0067] On the other hand, in the case of the same UE, it may contract with a plurality of AFs and AKMA services at the visited destination where it is located. This means that when the UE uses the AKMA service, in order to obtain the AKMA key material, these AFs need to interact with the HPLMN where the UE is located.

[0068] The problems faced in this way are as follows. 1) The AF needs to interact with a plurality of HPLMNs to obtain the AKMA key material. That is, the AF needs to contract with a plurality of HPLMNs and the corresponding AKMA roaming protocol, increasing the management cost of the AF. 2) When the UE interacts with the AF and uses the AKMA service, the AF needs to interact with the HPLMN to obtain the key material, increasing the delay of the AKMA service.

[0069] FIG. 3 is a schematic diagram of a system architecture to which the communication method of the embodiment of the present application is applied, and FIGS. 4a and 4b are schematic diagrams of models of system architectures to which the communication method of the embodiment of the present application is applied, respectively. Referring to FIGS. 3, 4a, and 4b, in the embodiment of the present application, a first device arranged in the VPLMN is added, and its functions include at least the following. 1) Function as a proxy between the visited AF (vAF) and the home AAnF (HAAnF). 2) Address the home network corresponding to the UE and the HAAnF, and establish secure communication with the HAAnF. 3) Verify the legitimacy of the vAF and authorize the AKMA key material required by the vAF.

[0070] In each embodiment of the present application, the first device has a plurality of realizable embodiments, and the first device may be referred to as, for example, a proxy, proxy function, proxy network element, network element, proxy, proxy function, proxy NF, network function (NF: Network Function), etc., and may be a device having at least one of a proxy function, a management function, a transmission function, a key management function, a key storage function, and a key distribution function. The first device may be provided with only the above network function, or may be provided with other network functions, that is, the above network function and other network functions may be provided together.

[0071] When actually arranged or realized, the first device may be provided together with other network elements within the VPLMN, or the logical function may be realized by other network elements. Exemplarily, when the AKMA service is arranged in the VPLMN, the proxy function is the AAnF of the VPLMN. When the AKMA service is not arranged in the VPLMN, the proxy function may be an independent network element, or may be provided together with the NEF, UPF or other network elements of the VPLMN, or the logical function of the proxy function may be realized by other network elements.

[0072] In addition, the first device may be an optional function, and the VPLMN may arrange the first device as needed. For example, in the VPLMN, there are a plurality of locally arranged AFs that use the AKMA service provided by the HPLMN. To facilitate management and contracting, the VPLMN may proxy the interaction between these AFs and the AANF of the HPLMN to obtain the AKMA key by selecting to locally arrange the first device, or when the AF arranged in the VPLMN provides services to UEs of a plurality of HPLMNs and uses the AKMA service, the VPLMN may proxy the interaction between this AF and the AAnF of the HPLMN of these UEs to obtain the AKMA key by selecting to locally arrange the first device.

[0073] When the AF is a third - party AF, as shown in Figure 4b, the AF interacts with the first device or the AAnF via the Network Exposure Function (NEF).

[0074] Based at least on the above - mentioned network architecture, the following embodiments of the present application are proposed.

[0075] The embodiments of the present application provide a communication method. Figure 5 is a flowchart 1 of the communication method of the embodiments of the present application. As shown in Figure 5, the method includes the following steps.

[0076] In step 101, the AAnF receives the first message sent from the AF, or receives the first message sent from the AF via the first device. The first message is for obtaining the key K AF thereof.

[0077] In step 102, when the AAnF checks that it can provide services to the AF, it sends a second message to the AF, or sends a second message to the AF via the first device. The second message includes at least the key K AF therein.

[0078] In some alternative embodiments, the AAnF is located in the Home Public Land Mobile Network (HPLMN), and / or the first device is located in the Visited Public Land Mobile Network (VPLMN), and / or the AF is located in the VPLMN.

[0079] Exemplarily, this embodiment is applicable to the AKMA roaming scenario. For example, when the UE roams in the visited network, the AF is also an application function contracted with the visited network, and when the UE uses the AKMA service, the AF needs to obtain AKMA key materials such as the key K AF The AAnF of the home network receives, from the AF, the key KAF When receiving a first message for obtaining AF and checking that the service can be provided to the AF, at least key K AF is included in the second message and sent to the AF.

[0080] In one embodiment, when the first device is arranged, the first device addresses the home network and AAnF corresponding to the UE, and establishes secure communication with the AAnF. As a result, the first message is transmitted to the AAnF via the first device. Correspondingly, the second message is transmitted to the AF via the first device. In another embodiment, when the first device is not arranged, the AF can search for the AAnF of the home network corresponding to the UE and establish secure communication with the AAnF. The AF can directly transmit the first message to the AAnF. Correspondingly, the AAnF directly transmits the second message to the AF. Optionally, the AF can send a query message to the Network Repository Function (NRF) to obtain related information of the AAnF (such as the address of the AAnF), and further transmit the first message based on the obtained related information of the AAnF.

[0081] In some alternative embodiments, the first message includes an A-KID and / or an identifier of the AF.

[0082] In some alternative embodiments, the communication method further includes the step of the AAnF deriving the key K AKMA based on AKMA . AF

[0083] In this embodiment, during or after the authentication process between the terminal (or UE) and the AUSF, the AUSF transmits the AKMA anchor key (K AKMA ) to the AAnF. The AAnF is a function within the home operator (or home network) and stores K AKMA for the AKMA service. After receiving the first message, the AAnF derives the key K AKMA based on AKMA . AF ​can be derived, and the key K AF may also be referred to as an application key.

[0084] In some alternative embodiments, the second message further includes at least one of the validity time information of the key K the key K AF , SUPI, and GPSI.

[0085] In this embodiment, the validity time information of the key K AF represents the validity period of the key K AF or the expiration time of the key K AF or may be displayed as the expiration time of the key K AF .

[0086] In some alternative embodiments of the present application, the communication method further includes a step in which the AAnF receives a third message sent from the AUSF, the third message is for registering a key, and the third message includes at least one of an A-KID, K AKMA , SUPI, and roaming information of the terminal.

[0087] In this embodiment, after receiving the third message, the AAnF registers the key. Optionally, the communication method further includes a step in which the AAnF sends a response message of the third message to the AUSF.

[0088] In some alternative embodiments, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0089] In this embodiment, when the terminal is not in a roaming state, that is, when the terminal is within the home network, the roaming information of the terminal may include second indication information indicating that the terminal is not in a roaming state. When the terminal is in a roaming state, that is, when the terminal is within the visited network, the roaming information of the terminal may include at least one of the following: first indication information indicating that the terminal is in a roaming state, roaming destination information, subscription information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0090] Here, the roaming destination information may be information indicating the roaming destination network (or visited network), for example, the roaming destination network name / identifier, etc., for example, the service network name (SN name: Service Network name).

[0091] Specifically, the above-mentioned subscription information of the terminal at the roaming destination may include, for example, a service subscription list between the terminal and the roaming destination, a subscription policy between the terminal and the roaming destination, etc.

[0092] Specifically, the above-mentioned policy information of the terminal at the roaming destination may include, for example, whether the home network permits the use of the AKMA service by the terminal at the visited destination, whether the visited network permits the use of the AKMA service by the terminal, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, the legitimate monitoring policy of the visited network, etc.

[0093] In some alternative embodiments, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0094] Optionally, the roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI.

[0095] In some alternative embodiments of the present application, after receiving the first message, the communication method further includes a step in which the AAnF obtains roaming information of the terminal from the UDM, and the roaming information of the terminal is related to the terminal corresponding to the A-KID in the first message.

[0096] In this embodiment, after receiving the first message, the AAnF can search for the SUPI of the corresponding terminal based on the A-KID in the first message, and use the SUPI to obtain the roaming information of the corresponding terminal from the UDM.

[0097] In some alternative embodiments, the step in which the AAnF checks whether it can provide services to the AF includes a step in which the AAnF checks whether it can provide services to the AF based on the identifier of the AF.

[0098] In some other alternative embodiments, the step in which the AAnF checks whether it can provide services to the AF includes a step in which the AAnF checks whether it can provide services to the AF based on the roaming information of the terminal.

[0099] In this embodiment, the AAnF can further combine with the roaming information of the terminal (for example, contract information at the roaming destination of the terminal and / or policy information at the roaming destination of the terminal) based on the identifier of the AF to check whether it can provide services to the AF.

[0100] Based on the above embodiments, the embodiments of the present application further provide a communication method. FIG. 6 is a flowchart 2 of the communication method of the embodiments of the present application. As shown in FIG. 6, the method includes the following steps.

[0101] In step 201, the first device receives a first message sent from the AF, and sends the first message to the AAnF. The first message is for obtaining key K AF for this purpose.

[0102] In step 202, when the AAnF can provide services to the AF, the first device receives a second message sent from the AAnF, and sends the second message to the AF. The second message includes at least the key K AF .

[0103] In some alternative embodiments, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0104] In this embodiment, the first device, as a proxy function or proxy device located in the visited network, has a proxy function between the visited AF and the home AAnF. After receiving the first message sent from the AF, by addressing the corresponding home AAnF, the first device sends the first message to the AAnF. When the AAnF can provide services to the AF, the first device receives a second message sent from the AAnF and sends the second message to the AF.

[0105] In some alternative embodiments, the first message includes an A-KID and / or an identifier of the AF.

[0106] In this embodiment, the A-KID is used as an AKMA key identifier. After receiving the first message, the first device can search for an identifier of the corresponding terminal, such as SUPI, based on the A-KID in the first message. Furthermore, based on the identifier of the terminal, the first device can search for and determine information (identifier and / or address of the AAnF) of the corresponding home AAnF.

[0107] In some alternative embodiments, the second message further includes at least one of the validity time information of the key K AF , SUPI, and GPSI.

[0108] In this embodiment, the validity time information of the key K AF is the validity time information of the key K AFThe validity period, or the key K AF represents the expiration time, or the key K AF may be indicated as "expiration time".

[0109] The embodiments of the present application further provide a communication method. FIG. 7 is a flowchart 3 of the communication method according to the embodiments of the present application. As shown in FIG. 7, the method includes the following steps.

[0110] In step 301, the first device receives a first message sent from the AF, and the first message is for obtaining the key K AF .

[0111] In step 302, if the first device checks that it can provide services to the AF, the first device sends a second message to the AF, and the second message includes at least the key K AF .

[0112] In some alternative embodiments, the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0113] Exemplarily, this embodiment is applicable to the AKMA roaming scenario. For example, when the UE roams in the visited network and the AF is also the application function of the visited network contract, and the UE uses the AKMA service, the AF needs to obtain AKMA key materials such as the key K AF . The first device, as a proxy function or proxy device arranged in the visited network, has the function of verifying the legitimacy of the AF and authorizing the AKMA key materials required by the AF.

[0114] In some alternative embodiments, the first message includes the A-KID and / or the identifier of the AF.

[0115] In this embodiment, the first device can check whether it can provide services to the AF based on the identifier of the AF. If it is determined that it can provide services to the AF, the key KAF Permit sending to AF.

[0116] Optionally, when the first device determines that there is no key K AF the communication method further includes a step in which the first device derives the key K AKMA based on K AF .

[0117] In this embodiment, the first device, as a proxy between the destination AF and the home destination AAnF, pre-gets and stores K AKMA from AAnF, and when it checks that it can provide services to the AF, it derives the key K AKMA based on the pre-obtained K AF .

[0118] In some alternative embodiments, the communication method further includes a step in which the first device receives first information sent from AAnF, and the first information includes AKMA context information.

[0119] In this embodiment, the step in which the first device receives first information sent from AAnF includes several feasible embodiments. As one embodiment, the first device sends a request message to AAnF, and the request message is for requesting AKMA context information, and the first device receives the first information sent from AAnF. As another embodiment, the first device receives the first information actively pushed by AAnF. In the above second embodiment, in the embodiments of the present application, the time order in which the first device receives the first information actively pushed by AAnF and receives the first message sent from AF is not limited.

[0120] In some alternative embodiments, the first information includes at least one of A-KID, K AKMA , and SUPI.

[0121] Optionally, the AAnF is located in the HPLMN.

[0122] Based on the above embodiments, the embodiments of the present application further provide a communication method. FIG. 8 is a flowchart 4 of the communication method according to the embodiments of the present application. As shown in FIG. 8, the method includes the following steps.

[0123] In step 401, the AAnF sends first information to the first device, and the first information includes AKMA context information.

[0124] In some alternative embodiments, the first information includes at least one of A-KID, K AKMA , and SUPI.

[0125] In this embodiment, the step of the AAnF sending the first information to the first device includes several possible implementation forms. As another embodiment, the AAnF receives a request message sent by the first device, and the request message is for requesting AKMA context information. The AAnF sends the first information to the first device based on the request message. As another embodiment, the AAnF actively pushes the first information to the first device.

[0126] In this embodiment, after the key registration is completed, the AAnF adopts any of the above embodiments to send the AKMA context information to the first device.

[0127] In some alternative embodiments, the communication method further includes the step of the AAnF receiving a third message sent by the AUSF, and the third message is for registering a key. The third message includes at least one of A-KID, K AKMA , SUPI, and terminal roaming information.

[0128] In this embodiment, the above key registration process is a key registration process started by the AUSF for the AAnF. The AUSF uses the terminal identifier information (such as SUPI) and AKMA key material (A-KID, K AKMASend information such as (etc.) to AAnF, and optionally, AUSF can also provide the roaming information of the terminal to AAnF.

[0129] Optionally, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0130] In this embodiment, when the terminal is not in a roaming state, that is, when the terminal is within the home network, the roaming information of the terminal may include second indication information indicating that the terminal is not in a roaming state. When the terminal is in a roaming state, that is, when the terminal is within the visited network, the roaming information of the terminal may include at least one of first indication information indicating that the terminal is in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0131] Here, the roaming destination information may be information indicating the roaming destination network (or visited network), for example, it may be the roaming destination network name / identifier, for example, the SN name.

[0132] Specifically, the contract information of the terminal at the above-mentioned roaming destination may include a service contract list between the terminal and the roaming destination, a contract policy between the terminal and the roaming destination, etc.

[0133] Specifically, the policy information of the terminal at the above-mentioned roaming destination may include whether the home network permits the use of the AKMA service at the visited destination of the terminal, whether the visited network permits the use of the AKMA service of the terminal, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, the legitimate monitoring policy of the visited network, etc.

[0134] In some alternative embodiments, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0135] Optionally, the roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI.

[0136] In some alternative embodiments, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN.

[0137] Based on the above embodiments, the embodiments of the present application further provide a communication method. FIG. 9 is a flowchart 5 of the communication method of the embodiments of the present application. As shown in FIG. 9, the method includes the following steps.

[0138] In step 501, the AF sends a first message to the first device or the AAnF, and the first message is for obtaining the key K AF .

[0139] In step 502, if the first device or the AAnF checks that it can provide services to the AF, the AF receives a second message sent from the first device or the AAnF, and the second message includes at least the key K AF .

[0140] In some alternative embodiments, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0141] In some alternative embodiments, the first message includes the A-KID and / or the identifier of the AF.

[0142] In some alternative embodiments, the second message further includes at least one of the validity time information of the key K AF , the SUPI, and the GPSI.

[0143] In this embodiment, the key K AF 's validity time information represents the validity period of key K AF or the expiration time of key K AF or may be expressed as the expiration time of key K AF expiration time.

[0144] Embodiments of the present application further provide a communication method. FIG. 10 is a flowchart 6 of the communication method according to an embodiment of the present application. As shown in FIG. 10, the method includes the following steps.

[0145] In step 601, the AUSF obtains authentication-related information from the UDM, and the authentication-related information includes at least one of the third indication information indicating that it is necessary to generate AKMA key material for the terminal, the fourth indication information indicating that it is not necessary to generate AKMA key material for the terminal, the routing identifier (RID: Router ID) information of the terminal, and the roaming information of the terminal.

[0146] In this embodiment, both the AUSF and the UDM are located in the home public land mobile network (HPLMN). In the authentication process between the terminal and the AUSF, the AUSF sends an authentication request associated with the terminal to the UDM, and the authentication request may include a terminal identifier. The UDM performs a check based on the terminal identifier in the authentication request, determines the authentication-related information (or authentication information) of the terminal, and can send the authentication-related information to the AUSF via an authentication response.

[0147] In this embodiment, the AUSF can determine that it is necessary to generate AKMA key material for the terminal based on the above third indication information. For example, derive K AUSF to K AKMA and A-KID. Alternatively, the AUSF can determine that it is not necessary to generate AKMA key material for the terminal based on the fourth indication information.

[0148] Here, optionally, the terminal identifier may be a SUPI and / or a Subscription Concealed Identifier (SUCI).

[0149] In some alternative embodiments, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0150] In this embodiment, when the terminal is not in a roaming state, that is, when the terminal is within the home network, the roaming information of the terminal may include second indication information indicating that the terminal is not in a roaming state. When the terminal is in a roaming state, that is, when the terminal is within the visited network, the roaming information of the terminal may include at least one of first indication information indicating that the terminal is in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0151] Here, the roaming destination information may be information indicating the roaming destination network (or visited network), for example, the roaming destination network name / identifier, etc., for example, it may be the SN name.

[0152] Specifically, the contract information of the terminal at the above-mentioned roaming destination may include, for example, a service contract list between the terminal and the roaming destination, a contract policy between the terminal and the roaming destination, etc.

[0153] Specifically, the policy information at the roaming destination of the above terminal may include whether the home network permits the use of the AKMA service at the visited destination of the terminal, whether the visited network permits the use of the AKMA service by the terminal, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, the legitimate monitoring policy of the visited network, and the like.

[0154] In some alternative embodiments, the communication method further includes a step in which the AUSF sends a third message to the AAnF, the third message is for registering a key, and the third message A-KID, K AKMA , SUPI, and at least one of the roaming information of the terminal.

[0155] Based on the above embodiments, the embodiments of the present application further provide a communication method. FIG. 11 is a flowchart 7 of the communication method of the embodiments of the present application. As shown in FIG. 11, the method includes the following steps.

[0156] In step 701, the UDM sends authentication-related information to the AUSF, and the authentication-related information includes at least one of third indication information indicating that it is necessary to generate AKMA key material for the terminal, fourth indication information indicating that it is not necessary to generate AKMA key material for the terminal, RID information of the terminal, and roaming information of the terminal.

[0157] In this embodiment, both the AUSF and the UDM are located in the home public land mobile network (HPLMN). In the authentication process between the terminal and the AUSF, the AUSF sends an authentication request associated with the terminal to the UDM. The authentication request may include a terminal identifier. The UDM performs a check based on the terminal identifier in the authentication request, determines the authentication-related information (or authentication information) of the terminal, and can send the authentication-related information to the AUSF via an authentication response.

[0158] Here, optionally, the terminal identifier may be a SUPI and / or a SUCI.

[0159] In some alternative embodiments, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0160] In this embodiment, when the terminal is not in a roaming state, that is, when the terminal is within the home network, the roaming information of the terminal may include second indication information indicating that the terminal is not in a roaming state. When the terminal is in a roaming state, that is, when the terminal is within the visited network, the roaming information of the terminal may include at least one of first indication information indicating that the terminal is in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0161] Here, the roaming destination information may be information indicating the roaming destination network (or visited network), for example, the roaming destination network name / identifier, etc., for example, it may be the SN name.

[0162] Specifically, the contract information of the terminal at the above-mentioned roaming destination may include a service contract list between the terminal and the roaming destination, a contract policy between the terminal and the roaming destination, etc.

[0163] Specifically, the policy information of the terminal at the above-mentioned roaming destination may include whether the home network permits the use of the AKMA service at the visited destination of the terminal, whether the visited network permits the use of the AKMA service of the terminal, the service protocol between the home network and the visited network, the legitimate monitoring policy of the home network, the legitimate monitoring policy of the visited network, etc.

[0164] In some alternative embodiments, the communication method further includes the steps of: the UDM receiving a fourth message sent from the AAnF, where the fourth message is for requesting roaming information of the terminal; and the UDM sending a fifth message to the AAnF, where the fifth message includes the roaming information of the terminal.

[0165] Hereinafter, with reference to specific examples, the communication method of the embodiments of the present application will be described in detail.

[0166] Regarding Example 1 FIG. 12 is an interaction flowchart 1 of the communication method of the embodiments of the present application. As shown in FIG. 12, the method includes the following steps.

[0167] In step 801, in the master authentication process between the UE and the AUSF, the AUSF sends a UE authentication request to the UDM, and the UE authentication request may include a UE identifier.

[0168] Here, the UE identifier may include a SUPI and / or a SUCI.

[0169] In step 802, the UDM sends a UE authentication response to the AUSF, and the UE authentication response may include a subscription certificate (e.g., an AKA authentication vector) and an authentication method.

[0170] Here, the UDM sends an AKMA indication (AKMA Ind) to the AUSF (i.e., indicating whether the AUSF needs to generate AKMA key material for the UE, e.g., an A-KID and a K AKMAIn addition to returning the RID information of the UE (including etc.), the roaming information of the UE (i.e., the roaming information of the terminal), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc. can also be carried.

[0171] In step 803, based on the AKMA instruction received from the UDM, after the master authentication process is successfully completed, the AUSF derives the keys K AUSF from K AKMA and the A-KID. Correspondingly, the UE derives the keys K AUSF from K AKMA and the A-KID.

[0172] In step 804, the AUSF addresses the AAnF of the home network and sends a key registration request to the AAnF. The request message can carry the A-KID, K AKMA , and the SUPI of the UE. The roaming information of the UE (i.e., the roaming information of the terminal), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc. can also be carried.

[0173] In step 805, the AAnF sends a key registration response to the AUSF.

[0174] In step 806, the UE establishes communication with the AF. The UE sends an Application Session Establishment Request to the AF, and the request message may include the A-KID.

[0175] In step 807a, when the first device is located within the visited network and there is no AKMA context associated with the A-KID in the AF, the AF addresses the first device located locally according to the local configuration or policy, or according to the policy obtained from other network elements (such as the NRF), and sends a key acquisition request to the first device. After receiving the key acquisition request, the first device sends the key acquisition request to the AAnF, and the request message can carry the A-KID and the identifier of the AF (AF ID).

[0176] In step 807b, when the first device is not located within the visited network and there is no AKMA context associated with the A-KID in the AF, the AF selects to address the AAnF of the home network according to the local configuration or policy, or according to the policy obtained from other network elements (such as the NRF), and sends a key acquisition request to the AAnF, and the request message can carry the A-KID and the identifier of the AF (AF ID).

[0177] In step 808, if there is no key K AF in AAnF, the AKMA application key (K AKMA ) is derived based on K AF .

[0178] In step 809a, when the first device is located within the visited network, the AAnF sends a key acquisition response to the first device. After receiving the key acquisition response, the first device sends the key acquisition response to the AF, and the response message can carry the key K AF , the validity time information (such as the life cycle) of the key K AF , and the SUPI.

[0179] In step 809b, when the first device is not located within the visited network, the AAnF sends a key acquisition response to the AF, and the response message can carry the key K AF , the key K AFIt can carry the validity time information (such as the life cycle) and the SUPI.

[0180] In this example, the AAnF checks whether it can provide services to the AF using the AF ID according to the configured local policy or according to the authorization information or policy provided by the NRF, or combines the AF ID with the roaming information of the UE (for example, the contract information at the roaming destination of the UE and / or the policy information at the roaming destination of the UE) to check whether the AAnF can provide services to the AF. If it is determined that services can be provided to the AF, the processes in step 808 and subsequent steps are executed. Otherwise, the AAnF rejects the execution of the processes in step 808 and subsequent steps.

[0181] In step 810, the AF sends an Application Session Establishment Response to the UE.

[0182] Regarding Example 2 FIG. 13 is an interaction flowchart 2 of the communication method according to the embodiment of the present application. As shown in FIG. 13, the method includes the following steps.

[0183] In step 901, in the master authentication process between the UE and the AUSF, the AUSF sends a UE authentication request to the UDM, and the UE authentication request may include a UE identifier.

[0184] Here, the UE identifier may include the SUPI and / or the SUCI.

[0185] In step 902, the UDM sends a UE authentication response to the AUSF, and the UE authentication response may include a subscription certificate (for example, an AKA authentication vector) and an authentication method.

[0186] Here, in addition to the UDM returning the AKMA instruction (AKMA Ind) to the AUSF (i.e., instructing the AUSF whether it needs to generate AKMA key material for the UE, for example, including A-KID and K AKMA etc.) and the RID information of the UE, the roaming information of the UE (i.e., the roaming information of the terminal), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc. can also be carried.

[0187] In step 903, based on the AKMA instruction received from the UDM, after the master authentication process is successfully completed, the AUSF derives keys K AUSF from K AKMA and A-KID. Correspondingly, the UE derives keys K AUSF from K AKMA and A-KID.

[0188] In step 904, the AUSF addresses the AAnF of the home network and sends a key registration request to the AAnF. The request message can carry A-KID, K AKMA , and the SUPI of the UE. The roaming information of the UE (i.e., the roaming information of the terminal), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc. can also be carried.

[0189] In step 905, the AAnF sends a key registration response to the AUSF.

[0190] In step 906, the AAnF sends the AKMA context information of the UE to the first device according to the local policy. The AKMA context information includes A-KID, K AKMAincluding etc.

[0191] Here, step 906 may be completed before step 905, or may be executed simultaneously with step 905.

[0192] In step 907, the UE establishes communication with the AF, and the UE sends an Application Session Establishment Request to the AF, and the request message may include an A-KID.

[0193] In step 908, if there is no AKMA context associated with the A-KID in the AKMA AF, the AF addresses a first device located locally according to a local configuration or policy, or according to a policy obtained from another network element (such as the NRF), and sends a key acquisition request to the first device, and the request message can carry the A-KID and the identifier of the AF (AF ID).

[0194] In step 909, the first device checks whether it can provide services to the AF using the AF ID according to the configured local policy, or according to the authorization information or policy provided by the NRF. If it is determined that services can be provided to the AF, the subsequent process is executed, otherwise, the first device rejects the execution of the subsequent process. If the first device does not have the key K AF , K AKMA is used to derive the AKMA application key (K AF ).

[0195] In step 910, the first device sends a key acquisition response to the AF, and the response message can carry the key K AF , the validity time information (such as the life cycle) of the key K AF , and the SUPI.

[0196] In step 911, AF sends an Application Session Establishment Response to the UE.

[0197] Regarding Example 3 FIG. 14 is an interaction flowchart 3 of the communication method according to the embodiment of the present application. As shown in FIG. 14, the method includes the following steps.

[0198] In step 1001, in the master authentication process between the UE and the AUSF, the AUSF sends a UE authentication request to the UDM, and the UE authentication request may include a UE identifier.

[0199] Here, the UE identifier may include a SUPI and / or a SUCI.

[0200] In step 1002, the UDM sends a UE authentication response to the AUSF, and the UE authentication response may include a subscription certificate (for example, an AKA authentication vector) and an authentication method.

[0201] Here, in addition to returning an AKMA indication (AKMA Ind) (that is, indicating whether the AUSF needs to generate AKMA key material for the UE, for example, including an A-KID and a K AKMA etc.) and the RID information of the UE to the AUSF, the UDM can also carry the roaming information of the UE (that is, the roaming information of the terminal), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc.

[0202] In step 1003, based on the AKMA indication received from the UDM, after the master authentication process is successfully completed, the AUSF derives keys K AUSF from K AKMA and the A-KID. Correspondingly, the UE derives the key KAUSF from K AKMA and derive A-KID.

[0203] In step 1004, the AUSF addresses the AAnF of the home network, sends a key registration request to the AAnF, and the request message can carry the A-KID, K AKMA , and the SUPI of the UE, and can also carry the roaming information of the UE (i.e., the roaming information of the terminal), for example, the first indication information indicating that the UE is in a roaming state, the second indication information indicating that the UE is not in a roaming state, the roaming destination information (such as the identifier or name of the roaming destination), the contract information of the UE at the roaming destination, the policy information of the UE at the roaming destination, etc.

[0204] In step 1005, the AAnF sends a key registration response to the AUSF.

[0205] In step 1006, the UE establishes communication with the AF, and the UE sends an Application Session Establishment Request to the AF, and the request message may include the A-KID.

[0206] In step 1007a, when a first device is deployed in the visited network and there is no AKMA context associated with the A-KID in the AF, the AF addresses the locally deployed first device according to the local configuration or policy, or according to the policy obtained from other network elements (such as the NRF), sends a key acquisition request to the first device, and after receiving the key acquisition request, the first device sends the key acquisition request to the AAnF, and the request message can carry the A-KID and the identifier of the AF (AF ID).

[0207] In step 1007b, when the first device is not located within the visited network and there is no AKMA context associated with the A-KID in the AF, the AF selects to address the AAnF of the home network according to the local configuration or policy, or according to the policy obtained from other network elements (such as the NRF), sends a key acquisition request to the AAnF, and the request message can carry the A-KID and the identifier (AF ID) of the AF.

[0208] In steps 1008 to 1009, after receiving the key acquisition request, the AAnF sends a roaming information acquisition request to the UDM. The request message may include the SUPI. The UDM queries and obtains the roaming information of the corresponding UE (i.e., the roaming information of the terminal) based on the SUPI, and sends a roaming information acquisition response to the AAnF. The response message includes the roaming information of the UE (i.e., the roaming information of the terminal).

[0209] Here, the roaming information of the UE (i.e., the roaming information of the terminal) may include first indication information indicating that the UE is in a roaming state, second indication information indicating that the UE is not in a roaming state, roaming destination information (such as the identifier or name of the roaming destination), subscription information of the UE at the roaming destination, policy information of the UE at the roaming destination, and the like.

[0210] In step 1010, when there is no key K AF for the AAnF, the AKMA application key (K AKMA ) is derived based on K AF .

[0211] In step 1011a, when the first device is located within the visited network, the AAnF sends a key acquisition response to the first device. After receiving the key acquisition response, the first device sends the key acquisition response to the AF. The response message can carry the key K AF , the validity time information (such as the life cycle) of the key K AF , and the SUPI.

[0212] In step 1011b, if the first device is not located within the visited network, the AAnF sends a key acquisition response to the AF, and the response message can carry the key K AF the key K AF valid time information (such as life cycle) and the SUPI.

[0213] In this example, the AAnF checks whether it can provide services to the AF using the AF ID according to the configured local policy or according to the authorization information or policy provided by the NRF, or combines the AF ID with the roaming information of the UE (for example, the contract information at the roaming destination of the UE and / or the policy information at the roaming destination of the UE) to check whether the AAnF can provide services to the AF. If it is determined that services can be provided to the AF, the processes from step 1010 and subsequent are executed. Otherwise, the AAnF rejects the execution of the processes from step 1010 and subsequent.

[0214] In step 1012, the AF sends an Application Session Establishment Response to the UE.

[0215] Based on the above embodiments, the embodiments of the present application further provide a communication device applicable to the AAnF. FIG. 15 is a schematic diagram 1 showing the configuration of the communication device according to the embodiments of the present application. As shown in FIG. 15, the device includes a first communication unit 11 and a first processing unit 12. The first communication unit 11 is configured to receive a first message sent from an Application Function (AF) or receive a first message sent from the AF via a first device, and the first message is for obtaining the key K AF and the first processing unit 12 is configured to check whether services can be provided to the AF. When the first communication unit 11 further checks that the first processing unit 12 can provide services to the AF, it is configured to transmit a second message to the AF or transmit a second message to the AF via the first device, and the second message includes at least the key K AF is included.

[0216] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0217] In some alternative embodiments of the present application, the first message includes an A-KID and / or an identifier of the AF.

[0218] In some alternative embodiments of the present application, the first processing unit 12 is further configured to derive the key K AKMA based on K AF is configured to be derived.

[0219] In some alternative embodiments of the present application, the second message further includes at least one of the validity time information of the key K AF , SUPI, and GPSI.

[0220] In some alternative embodiments of the present application, the first communication unit 11 is further configured to receive a third message transmitted from the AUSF, the third message is for registering a key, and the third message includes at least one of an A-KID, K AKMA , SUPI, and roaming information of the terminal.

[0221] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0222] In some alternative embodiments of the present application, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0223] In some alternative embodiments of the present application, the roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI.

[0224] In some alternative embodiments of the present application, the first communication unit 11 is further configured to obtain the roaming information of the terminal from the UDM after receiving the first message, and the roaming information of the terminal is related to the terminal corresponding to the A-KID in the first message.

[0225] In some alternative embodiments of the present application, the first processing unit 12 is configured to check whether the AF can be provided with services based on the roaming information of the terminal.

[0226] In an embodiment of the present application, the first processing unit 12 in the communication device can be realized by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU), or a field-programmable gate array (FPGA) in actual applications. The first communication unit 11 in the communication device can be realized by combining a communication assembly (including a basic communication kit, an operating system, a communication module, a standardized interface, and a protocol, etc.) and a transceiver antenna in actual applications.

[0227] The embodiment of the present application further provides a communication device applied to a first device. FIG. 16 is a schematic diagram 2 showing the configuration of the communication device according to the embodiment of the present application. As shown in FIG. 16, the device includes a first receiving unit 21 and a first transmitting unit 22. The first receiving unit 21 is configured to receive a first message transmitted from the AF and transmit the first message to the AAnF. The first message is for obtaining the key K AF and when the AAnF can provide services to the AF, the first transmitting unit 22 is configured to receive a second message transmitted from the AAnF and transmit the second message to the AF. The second message includes at least the key K AF .

[0228] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0229] In some alternative embodiments of the present application, the first message includes the A-KID and / or the identifier of the AF.

[0230] In some alternative embodiments of the present application, the second message further includes at least one of the validity time information of the key K AF , the SUPI, and the GPSI.

[0231] In the embodiments of the present application, the first receiving unit 21 and the first transmitting unit 22 in the communication device can be realized by being combined with a communication assembly (including a basic communication kit, an operating system, a communication module, a standardized interface, a protocol, etc.) and a transceiver antenna in actual applications.

[0232] The embodiments of the present application further provide a communication device applied to the first device. FIG. 17 is a schematic diagram 3 showing the configuration of the communication device according to the embodiment of the present application. As shown in FIG. 17, the device includes a second communication unit 31 and a second processing unit 32 The second communication unit 31 is configured to receive a first message transmitted from the AF. The first message is for obtaining the key K AF and The second processing unit 32 is configured to check whether it can provide services to the AF. The second communication unit 31 is further configured to transmit a second message to the AF when the second processing unit 32 checks that it can provide services to the AF. The second message includes at least the key K. AF including.

[0233] In some alternative embodiments of the present application, the first message includes an A-KID and / or an identifier of the AF.

[0234] In some alternative embodiments of the present application, the second communication unit 31 is further configured to receive first information transmitted from the AAnF, and the first information includes AKMA context information.

[0235] In some alternative embodiments of the present application, the first information includes at least one of an A-KID, K. AKMA , and at least one of SUPI.

[0236] In some alternative embodiments of the present application, the second processing unit 32 is further configured to derive the key K based on K. AKMA to derive the key K. AF configured.

[0237] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0238] In an embodiment of the present application, the second processing unit 32 in the communication device can be realized by a CPU, a DSP, an MCU or an FPGA in actual applications, and the second communication unit 31 in the communication device can be realized by combining a communication assembly (including a basic communication kit, an operating system, a communication module, a standardized interface and protocol, etc.) and a transceiver antenna in actual applications.

[0239] Embodiments of the present application further provide a communication device applicable to AAnF. FIG. 18 is a schematic diagram 4 showing the configuration of the communication device according to the embodiment of the present application. As shown in FIG. 18, the device includes a second transmission unit 41, and the second transmission unit 41 is configured to transmit first information to a first device, and the first information includes AKMA context information.

[0240] In some alternative embodiments of the present application, the first information includes at least one of A-KID, K AKMA , and SUPI.

[0241] In some alternative embodiments of the present application, the communication device further includes a second reception unit 42, and the second reception unit 42 is configured to receive a third message transmitted from the AUSF. The third message is for registering a key, and the third message includes at least one of A-KID, K AKMA , SUPI, and roaming information of the terminal.

[0242] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0243] In some alternative embodiments of the present application, the roaming information of the terminal is obtained by the AUSF from the UDM.

[0244] In some alternative embodiments of the present application, the roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI.

[0245] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN.

[0246] In the embodiments of the present application, the second receiving unit 42 and the second transmitting unit 41 in the communication device can be implemented by being combined with a communication assembly (including a basic communication kit, an operating system, a communication module, a standardized interface and protocol, etc.) and a transceiver antenna in actual applications.

[0247] The embodiments of the present application further provide a communication device applicable to the AF. FIG. 19 is a schematic diagram 5 showing the configuration of the communication device according to the embodiments of the present application. As shown in FIG. 19, the device includes a third transmitting unit 51 and a third receiving unit 52. The third transmitting unit 51 is configured to transmit a first message to a first device or an AAnF, and the first message is for obtaining a key K AF The third receiving unit 52 is configured to receive a second message transmitted from the first device or the AAnF when the first device or the AAnF checks that it can provide services to the AF, and the second message includes at least the key K AF

[0248] In some alternative embodiments of the present application, the AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN.

[0249] In some alternative embodiments of the present application, the first message includes an A-KID and / or an identifier of the AF.

[0250] In some alternative embodiments of the present application, the second message further includes at least one of the validity time information of the key K AF , SUPI, and GPSI.

[0251] ​​In the embodiments of the present application, the third receiving unit 52 and the third transmitting unit 51 in the communication device can be implemented by being combined with a communication assembly (including a basic communication kit, an operating system, a communication module, a standardized interface, a protocol, etc.) and a transceiver antenna in actual applications.

[0252] The embodiments of the present application further provide a communication device applicable to the AUSF. FIG. 20 is a schematic diagram 6 showing the configuration of the communication device according to the embodiments of the present application. As shown in FIG. 20, the device includes a fourth receiving unit 61, and the fourth receiving unit 61 is configured to obtain authentication-related information from the UDM. The authentication-related information includes at least one of third indication information indicating that the terminal needs to generate AKMA key material, fourth indication information indicating that the terminal does not need to generate AKMA key material, RID information of the terminal, and roaming information of the terminal.

[0253] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0254] In some alternative embodiments of the present application, the communication device further includes a fourth transmitting unit 62, and the fourth transmitting unit 62 is configured to transmit a third message to the AAnF. The third message is for key registration, and the third message includes at least one of A-KID, K AKMA , SUPI, and the roaming information of the terminal.

[0255] In the embodiments of the present application, the fourth receiving unit 61 and the fourth transmitting unit 62 in the communication device can be implemented by being combined with a communication assembly (including a basic communication kit, an operating system, a communication module, a standardized interface, a protocol, etc.) and a transceiver antenna in actual applications.

[0256] The embodiment of the present application further provides a communication device applied to the UDM. FIG. 21 is a schematic diagram 7 showing the configuration of the communication device according to the embodiment of the present application. As shown in FIG. 21, the device includes a fifth transmission unit 71, and the fifth transmission unit 71 is configured to transmit authentication-related information to the AUSF. The authentication-related information includes at least one of third indication information indicating that the terminal needs to generate AKMA key material, fourth indication information indicating that the terminal does not need to generate AKMA key material, RID information of the terminal, and roaming information of the terminal.

[0257] In some alternative embodiments of the present application, the roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination.

[0258] In some alternative embodiments of the present application, the communication device further includes a fifth reception unit 72. The fifth reception unit 72 is configured to receive a fourth message transmitted from the AAnF, where the fourth message is for requesting the roaming information of the terminal, and the step of the UDM transmitting a fifth message to the AAnF, where the fifth message includes the roaming information of the terminal.

[0259] In the embodiment of the present application, the fifth reception unit 72 and the fifth transmission unit 71 in the communication device can be realized by being combined with a communication assembly (including a basic communication kit, an operating system, a communication module, a standardized interface, and a protocol, etc.) and a transceiver antenna in actual application.

[0260] It should be noted that when the communication device provided by the above embodiments conducts communication, only the division of the above program modules is taken as an example for description. However, in actual applications, the above processing may be assigned to different program modules as needed and completed. That is, the internal structure of the device can be divided into different program modules to complete all or part of the above processing. In addition, the communication device provided by the above embodiments belongs to the same concept as the embodiments of the communication method. For the specific implementation process, reference can be made to the embodiments of the method, and the description will not be repeated here.

[0261] The embodiments of the present application further provide a communication device, which may be, for example, an AAnF, a first device, an AF, an AUSF, or a UDM. FIG. 22 is a schematic diagram showing the hardware configuration of the communication device according to the embodiments of the present application. As shown in FIG. 22, the communication device includes a memory 82, a processor 81, and a computer program stored in the memory 82 and executable by the processor 81. When the processor 81 executes the program, it realizes the steps of the communication method applicable to the AAnF according to the embodiments of the present application, or the steps of the communication method applicable to the first device according to the embodiments of the present application, or the steps of the communication method applicable to the AF according to the embodiments of the present application, or the steps of the communication method applicable to the AUSF according to the embodiments of the present application, or the steps of the communication method applicable to the UDM according to the embodiments of the present application.

[0262] Optionally, the communication device may further include one or more network interfaces 83. Here, each component in the communication device is coupled via a bus system 84. It can be understood that the bus system 84 realizes the connection and communication between these components. The bus system 84 includes a power bus, a control bus, and a status signal bus in addition to a data bus. However, for the sake of clarity in the description, in FIG. 22, all various buses are represented as the bus system 84.

[0263] Understandably, the memory 82 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Here, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM (registered trademark)), a flash memory, a magnetic memory, a compact disc, or a compact disc read-only memory (CD-ROM). The magnetic memory may be a magnetic disk memory or a magnetic tape memory. The volatile memory may be a random access memory (RAM) used as an external cache.By way of illustration and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), sync link dynamic random access memory (SLDRAM), direct rambus random access memory (DRRAM), and the like. The memory 82 described in the embodiments of the present application is intended to include these and any other suitable types of memory, but is not limited thereto.

[0264] The above method disclosed in the embodiments of the present application may be applied to the processor 81 or may be implemented by the processor 81. The processor 81 may be an integrated circuit chip with signal processing functions. In the implementation process, each step of the above method may be completed by the integrated logic circuit of the hardware in the processor 81 or instructions in the form of software. The above processor 81 may be a general-purpose processor, DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 81 can implement or execute each method, step, and logic block diagram disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of the present application may be directly executed by the hardware decoding processor or may be executed by a combination of hardware and software modules in the decoding processor. The software module may be arranged in a storage medium, and the storage medium is arranged in the memory 82. The processor 81 reads the information stored in the memory 82 and combines it with its hardware to complete the steps of the above method.

[0265] In an exemplary embodiment, the communication device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic elements to execute the above method.

[0266] In an exemplary embodiment, the embodiment of the present application further provides a computer-readable storage medium such as a memory 82 including a computer program, and when the computer program is executed by a processor 81 of a communication device, the steps of the above method can be completed. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic memory, optical disk, or CD-ROM, or may be various devices including one or any combination of the above memories.

[0267] The embodiment of the present application further provides a computer-readable storage medium storing a computer program, and when the program is executed by a processor, the steps of the communication method applicable to AAnF according to the embodiment of the present application, or the steps of the communication method applicable to the first device according to the embodiment of the present application, or the steps of the communication method applicable to AF according to the embodiment of the present application, or the steps of the communication method applicable to AUSF according to the embodiment of the present application, or the steps of the communication method applicable to UDM according to the embodiment of the present application are realized.

[0268] The methods disclosed in some method embodiments provided in the present application can be arbitrarily combined without conflict to obtain new method embodiments.

[0269] The features disclosed in some product embodiments provided in the present application can be arbitrarily combined without conflict to obtain new product embodiments.

[0270] The features disclosed in some method or device embodiments provided in the present application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.

[0271] In some embodiments provided in the present application, the disclosed devices and methods can be implemented in other ways. The embodiments of the devices described above are merely exemplary. For example, the division of the said units is only a division of logical functions. In actual implementation, there may be other division methods. For example, a plurality of units or components may be combined, integrated into another system, some features may be ignored, or not executed. Furthermore, the mutual connection, direct connection, or communication connection between each component shown or described may be an indirect connection or communication connection through some interfaces, devices, or units, and may be in electrical, mechanical, or other forms.

[0272] The units described as the separation members may or may not be physically separated. The members shown as units may or may not be physical units. They may be arranged in one place or dispersed in a plurality of network units. According to actual needs, some or all of the units can be selected to achieve the purpose of the technical solution of this embodiment.

[0273] In addition, each functional unit in each embodiment of the present invention may all be integrated into one second processing unit, each unit may be used individually as one unit, or two or more units may be integrated into one unit. The integrated unit can be embodied in the form of hardware or in the form of a combination of hardware and software functional units.

[0274] Those skilled in the art will appreciate that all or some of the steps of the above method embodiments can be completed by hardware related to program instructions. The program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above method embodiments are executed. The storage medium includes various media that can store program codes, such as removable storage, ROM, RAM, magnetic memory, or optical disks.

[0275] Alternatively, when the above integrated unit of the present application is implemented in the form of software function modules and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the essential part of the technical solution of the embodiments of the present application, that is, the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in one storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The above storage medium includes various media that can store program codes such as removable storage, ROM, RAM, magnetic memory, or optical disks.

[0276] The above content is only an embodiment of the present application, and the protection scope of the present application is not limited thereto. Within the technical scope disclosed in the present application, all deformations or substitutions that can be easily conceived by those skilled in the art should be included within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A communication method, The step in which the Application Authentication and Key Management (AKMA) Anchor Function (AAnF) receives a first message sent from an Application Function (AF) or receives a first message sent from the AF via a first device, wherein the first message is for obtaining a key K AF and, step When it is checked that the AAnF can provide services to the AF, a step of transmitting a second message to the AF or transmitting a second message to the AF via the first device, wherein the second message includes at least the key K AF and a communication method including the step.

2. wherein the AAnF is located in a home network (HPLMN), and / or the first device is located in a visited network (VPLMN), and / or the AF is located in a visited network (VPLMN), The communication method according to claim 1.

3. The first message includes an AKMA key identifier (A-KID) and / or an identifier of the AF, The communication method according to claim 1.

4. The communication method, wherein the AAnF is an AKMA anchor key K AKMA deriving the key K based on AF further comprising the step of The communication method according to claim 1.

5. The second message, the key K AF valid time information of subscription permanent identifier (SUPI), further includes at least one of a general public subscription identifier (GPSI), The communication method according to claim 1.

6. The communication method, further includes the step of receiving a third message sent by an authentication server function (AUSF) by the AAnF, the third message is for registering a key, and the third message, A-KID, AKMA anchor key K AKMA , including at least one of SUPIs and roaming information of the terminal The communication method according to any one of claims 1 to 5.

7. The roaming information of the terminal, includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination, The communication method according to claim 6.

8. The roaming information of the terminal is obtained by the AUSF from an integrated data management (UDM), The communication method according to claim 6.

9. The roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI, The communication method according to claim 8.

10. After receiving the first message, the communication method, further includes the step of the AAnF obtaining roaming information of the terminal from the UDM, and the roaming information of the terminal is related to the terminal corresponding to the A-KID in the first message, The communication method according to claim 3.

11. The step of the AAnF checking whether it can provide a service to the AF, includes the step of the AAnF checking whether it can provide a service to the AF based on the roaming information of the terminal, The communication method according to any one of claims 6 to 10.

12. A communication method, The step in which the first device receives the first message transmitted from the AF and transmits the first message to the AAnF, wherein the first message is for obtaining the key K AF and the step; When the AAnF can provide services to the AF, the first device receives a second message sent from the AAnF and transmits the second message to the AF, where the second message includes at least the key K AF and a step, and a communication method including the same.

13. The AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN. The communication method according to claim 12.

14. The first message includes an AKMA key identifier (A-KID) and / or an identifier of the AF. The communication method according to claim 12.

15. The second message the key K AF valid time information of subscription permanent identifier (SUPI), further includes at least one of a general public subscription identifier (GPSI). The communication method according to claim 12.

16. A communication method, The step of the first device receiving the first message transmitted from the AF, wherein the first message is for obtaining the key K AF and, a step When it is checked that the first device can provide services to the AF, a step of transmitting a second message to the AF, where the second message includes at least the key K AF and a communication method including the step.

17. The first message includes an A-KID and / or an identifier of the AF. The communication method according to claim 16.

18. The communication method further includes a step in which the first device receives first information sent from the AAnF, and the first information includes AKMA context information. The communication method according to claim 16.

19. The first information includes at least one of A-KID, AKMA anchor key K AKMA , and SUPI The communication method according to claim 18.

20. The communication method The first machine is based on the AKMA anchor key K AKMA to derive the key K AF further comprising the step of: The communication method according to claim 19.

21. The AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN. The communication method according to claim 18.

22. A communication method, further includes a step in which the AAnF sends first information to the first device, and the first information includes AKMA context information, a communication method.

23. The first information includes at least one of A-KID, AKMA anchor key K AKMA , and SUPI The communication method according to claim 22.

24. The communication method further includes a step in which the AAnF receives a third message sent from the AUSF, the third message is for registering a key, and the third message A-KID, AKMA anchor key K AKMA , SUP, including at least one of the roaming information of the terminal The communication method according to claim 22.

25. The roaming information of the terminal includes at least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and policy information of the terminal at the roaming destination. The communication method according to claim 24.

26. The roaming information of the terminal is obtained by the AUSF from the UDM. The communication method according to claim 25.

27. The roaming information of the terminal obtained by the AUSF from the UDM is the roaming information of the terminal associated with the terminal SUPI. The communication method according to claim 26.

28. The AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, The communication method according to claim 22.

29. A communication method, The step in which AF transmits a first message to the first device or AAnF, wherein the first message is for obtaining the key K AF and the step; When it is checked that the first device or the AAnF can provide services to the AF, a step of the AF receiving a second message transmitted from the first device or the AAnF, where the second message includes at least the key K AF and a communication method including the step.

30. The AAnF is located in the HPLMN, and / or the first device is located in the VPLMN, and / or the AF is located in the VPLMN, The communication method according to claim 29.

31. The first message includes an AKMA key identifier (A-KID) and / or an identifier of the AF, The communication method according to claim 29.

32. The second message, The key K AF valid time information of, A subscription permanent identifier (SUPI), Further includes at least one of a general public subscription identifier (GPSI), The communication method according to claim 29.

33. A communication method, Including the step that the AUSF obtains authentication-related information from the unified data management (UDM), and the authentication-related information includes A third instruction information indicating that it is necessary to generate an AKMA key material for the terminal, a fourth instruction information indicating that it is not necessary to generate an AKMA key material for the terminal, the routing identifier (RID) information of the terminal, and at least one of the roaming information of the terminal.

34. The roaming information of the terminal is The first instruction information indicating that the terminal is in a roaming state, the second instruction information indicating that the terminal is not in a roaming state, roaming destination information, contract information of the terminal at the roaming destination, and at least one of policy information of the terminal at the roaming destination. The communication method according to claim 33.

35. The communication method further includes The step that the AUSF sends a third message to the AAnF, and the third message is for registering a key, and the third message A-KID, AKMA anchor key K AKMA , SUP, including at least one of the roaming information of the terminal The communication method according to claim 33.

36. A communication method, Including the step that the UDM sends authentication-related information to the AUSF, and the authentication-related information includes A third instruction information indicating that it is necessary to generate an AKMA key material for the terminal, a fourth instruction information indicating that it is not necessary to generate an AKMA key material for the terminal, the RID information of the terminal, and at least one of the roaming information of the terminal.

37. The roaming information of the terminal is At least one of first indication information indicating that the terminal is in a roaming state, second indication information indicating that the terminal is not in a roaming state, roaming destination information, contract information at the roaming destination of the terminal, and policy information at the roaming destination of the terminal. The communication method according to claim 36.

38. The communication method is as follows: A step in which the UDM receives a fourth message transmitted from the AAnF, wherein the fourth message is for requesting roaming information of the terminal. A step in which the UDM transmits a fifth message to the AAnF, wherein the fifth message includes the roaming information of the terminal. The method further includes this step. The communication method according to claim 36 or 37.

39. A communication device applied to the AAnF, comprising a first communication unit and a first processing unit. The first communication unit is configured to receive a first message transmitted from an application function (AF) or receive a first message transmitted from the AF via a first device, and the first message is for obtaining a key K AF and is as follows The first processing unit is configured to check whether the AF can be provided with services. When the first communication unit further checks that the first processing unit can provide services to the AF, it is configured to send a second message to the AF or send a second message to the AF via the first device, and the second message includes at least the key K AF A communication device including

40. A communication device applied to a first device, comprising a first receiving unit and a first transmitting unit. The first receiving unit is configured to receive a first message transmitted from AF and transmit the first message to AAnF, and the first message is for obtaining a key K AF and is used for this purpose The first transmission unit is configured to receive a second message transmitted from the AAnF and transmit the second message to the AF when the AAnF can provide a service to the AF, and the second message includes at least the key K AF A communication device including the same.

41. A communication device applied to a first device, comprising a second communication unit and a second processing unit. The second communication unit is configured to receive a first message transmitted from the AF, and the first message is for obtaining the key K AF and is as follows The second processing unit is configured to check whether the AF can be provided with services. When the second communication unit further checks that the second processing unit can provide a service to the AF, it is configured to transmit a second message to the AF, and the second message includes at least the key K AF A communication device including

42. A communication device applied to the AAnF, comprising a second transmitting unit. The second transmitting unit is configured to transmit first information to a first device, and the first information includes AKMA context information.

43. A communication device applied to the AF, comprising a third transmitting unit and a third receiving unit. The third transmission unit is configured to transmit a first message to the first device or the AAnF, and the first message is for obtaining the key K AF and is as follows When the third receiving unit checks that the first device or the AAnF can provide a service to the AF, the third receiving unit is configured to receive a second message transmitted from the first device or the AAnF, and the second message includes at least a key K AF A communication device including

44. A communication device applied to the AUSF, comprising a fourth receiving unit. The fourth receiving unit is configured to obtain authentication-related information from the UDM, and the authentication-related information is A communication device including at least one of third indication information indicating that it is necessary to generate an AKMA key material for the terminal, fourth indication information indicating that it is not necessary to generate an AKMA key material for the terminal, RID information of the terminal, and roaming information of the terminal.

45. A communication device applied to the UDM, comprising a fifth transmitting unit. The fifth transmitting unit is configured to transmit authentication-related information to the AUSF, and the authentication-related information is A communication device including at least one of third instruction information indicating that it is necessary to generate an AKMA key material for a terminal, fourth instruction information indicating that it is not necessary to generate an AKMA key material for the terminal, RID information of the terminal, and roaming information of the terminal.

46. A computer-readable storage medium storing a computer program, wherein when the program is executed by a processor, it realizes the steps of the method according to any one of claims 1 to 11, or the steps of the method according to any one of claims 12 to 15, or the steps of the method according to any one of claims 16 to 21, or the steps of the method according to any one of claims 22 to 28, or the steps of the method according to any one of claims 29 to 32, or the steps of the method according to any one of claims 33 to 35, or the steps of the method according to any one of claims 36 to 38.

47. A communication device, comprising a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein when the processor executes the program, it realizes the steps of the method according to any one of claims 1 to 11, or the steps of the method according to any one of claims 12 to 15, or the steps of the method according to any one of claims 16 to 21, or the steps of the method according to any one of claims 22 to 28, or the steps of the method according to any one of claims 29 to 32, or the steps of the method according to any one of claims 33 to 35, or the steps of the method according to any one of claims 36 to 38.