Method of a communication terminal, communication terminal, method of a core network device, and core network device

The method addresses the ambiguity in synchronizing Kausf information between UE and the network by exchanging authentication messages to ensure secure key agreement in 5G systems.

JP7683613B2Active Publication Date: 2025-05-27NEC CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022575866
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-10-16
Filing Date
2021-10-12
Publication Date
2025-05-27
Estimated Expiration
2041-10-12

AI Technical Summary

Technical Problem

The authentication and key agreement procedures in 5G systems remain ambiguous, particularly in synchronizing Kausf information between user equipment (UE) and the network, which is crucial for secure operations.

Method used

The proposed method involves a communication terminal and a core network device exchanging authentication request and response messages to calculate and verify security keys, ensuring synchronization of the latest Kausf for various security procedures.

Benefits of technology

This approach ensures that the UE and the network use the same Kausf in security procedures, enhancing security synchronization and maintaining service integrity in 5G systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007683613000002
    Figure 0007683613000002
  • Figure 0007683613000003
    Figure 0007683613000003
  • Figure 0007683613000004
    Figure 0007683613000004
Patent Text Reader

Abstract

This document exposes procedures for configuring the latest security keys in the UE and network. Specifically, it defines various methods for establishing the latest Kausf in the UE and network, and ensures that the UE and network use the same Kausf for various security procedures.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to wireless electrical communication, and in particular, in embodiments, to the handling of security keys during an authentication procedure.

Background Art

[0002] The purpose of the primary authentication and key agreement procedure is to enable mutual authentication between the UE and the network, and to provide keying material that can be used between the UE and the network in subsequent security procedures, as defined in Non-Patent Document 5. A plurality of keys (K AUSF , K SEAF , and K AMF ) are generated after the successful completion of the authentication procedure.

[0003] Two methods of the primary authentication and key agreement procedure are defined. a) EAP-based primary authentication and key agreement procedure b) 5G AKA-based primary authentication and key agreement procedure

[0004] The UE and the AMF need to support both the EAP-based primary authentication and key agreement procedure and the 5G AKA-based primary authentication and key agreement procedure. If the authentication procedure fails in the network, the AMF returns an Authentication Reject message to the UE.

[0005] FIG. 1 shows the start of the authentication procedure and the selection of the authentication method. The UDM selects the authentication method to be applied to the UE.

[0006] Figure 2 shows the primary authentication and key agreement procedures based on 5G AKA.

[0007] K created at the UE and AUSF AUSF ( Kausf) is used for the Steering of roaming (SoR) procedure defined in Non-Patent Document 5 and for the update of UE parameter(s) via the UDM control plane procedure security mechanism.

[0008] Figure 3 shows the procedure for steering the UE in the Visited Public land mobile network (VPLMN) during registration. In that roaming steering procedure, Kausf is used to derive SoR-MAC-Iausf at the UE and AUSF. When the UE receives SOR-MAC-Iausf from the network, it calculates SoR-MAC-Iausf and compares the calculated SoR-MAC-Iausf with the SOR-MAC-Iausf received from the network. If the SOR-MAC-Iausfs match at the UE, the UE determines that it has passed the security check for SoR transmission, and the UE stores a steering list, that is, a list of preferred PLMN / access technology combinations, in the UE.

[0009] Figure 4 shows the procedure for providing a list of preferred PLMN / access technology combinations after registration.

[0010] In the update of UE parameter(s) via the UDM control plane procedure, when the UE receives UPU-MAC-Iausf from the network, the UE calculates the UPU-MAC-Iausf and compares the calculated UPU-MAC-Iausf with the UPU-MAC-Iausf received from the network. If the UPU-MAC-Iausfs match in the UE, the UE determines that the UE parameter transmission by the update of UE parameter(s) via the UDM control plane procedure is secure and stores the UE parameters sent by the UDM in the UE.

[0011] Furthermore, Kasuf is also used for the generation of the AKMA (Authentication and Key Agreement for Applications) key. When the UE is registered with two different PLMNs (for example, one via 3GPP (registered trademark) access and the other via non-3GPP access), the UE and the AUSF store only the latest Kausf. This latest Kausf is used in various security procedures of the UE and the network.

Prior Art Documents

Non-Patent Documents

[0012]

Non-Patent Document 1

Non-Patent Document 2

Non-Patent Document 3

Non-Patent Document 4

[0013] The authentication and key agreement procedures defined in Non-Patent Document 5 remain ambiguous. As mentioned in the background, Kausf information is used in various security procedures. Therefore, the synchronization of Kausf information between the UE and the network is very important for 5GS. If Kausf is not synchronized between the UE and the network, although security is very important and thus not violated, 5GS should not provide services on 5GS. [Means for Solving the Problems]

[0014] In a first aspect of the present disclosure, a method of a communication terminal includes receiving an authentication request message from a first core network device, calculating a first security key and a first authentication response, returning the first authentication response to the first core network device in an authentication response message, and receiving a NAS message from the first core network device.

[0015] In a second aspect of the present disclosure, a method of a first core network device includes transmitting a first authentication request message for starting authentication with a communication terminal to a second core network device; transmitting a second authentication request message to the communication terminal; receiving a first authentication response in a first authentication response message from the communication terminal; receiving a second authentication response message corresponding to the first authentication request message from the second core network device; and transmitting a NAS message to the communication terminal for replacing a second security key with a first security key calculated by the communication terminal.

[0016] In a third aspect of the present disclosure, a method of a first core network device includes transmitting a first authentication request message for starting authentication with a communication terminal to a second core network device; transmitting a second authentication request message to the communication terminal; receiving a first authentication response in a first authentication response message from the communication terminal; receiving a second authentication response message corresponding to the first authentication request message from the second core network device; and transmitting a NAS message to the communication terminal. When the NAS message selects information indicating null encryption and a null encryption algorithm, the first security key is not stored in the communication terminal, and the communication terminal sets a session related to an emergency session.

[0017] In a fourth aspect of the present disclosure, a communication terminal includes means for receiving an authentication request message from a first core network device; means for calculating a first security key and a first authentication response; means for returning the first authentication response to the first core network device in an authentication response message; and means for receiving a NAS message from the first core network device.

[0018] In a fifth aspect of the present disclosure, the first core network device includes means for transmitting a first authentication request message for starting authentication with a communication terminal to a second core network device, means for transmitting a second authentication request message to the communication terminal, means for receiving a first authentication response in a second authentication response message from the communication terminal, means for receiving an authentication response message corresponding to the first authentication request message from the second core network device, and means for transmitting a NAS message for replacing a second security key with a first security key calculated by the communication terminal to the communication terminal.

[0019] In a sixth aspect of the present disclosure, the first core network device includes means for transmitting a first authentication request message for starting authentication with a communication terminal to a second core network device, means for transmitting a second authentication request message to the communication terminal, means for receiving a first authentication response in a first authentication response message from the communication terminal, means for receiving a second authentication response message corresponding to the first authentication request message from the second core network device, and means for transmitting a NAS message to the communication terminal. When the NAS message selects information indicating null encryption and a null encryption algorithm, the first security key is not stored in the communication terminal, and the communication terminal sets a session related to an emergency session.

Brief Description of the Drawings

[0020]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

DETAILED DESCRIPTION OF THE INVENTION

[0021] The present disclosure provides procedures for establishing the latest security keys in a UE and a network. Specifically, the procedures define various methods for establishing the latest Kausf in a UE and a network, and enable the UE and the network to use the same Kausf in various security procedures. To further clarify the advantages and features of the present disclosure, a more specific description of the present disclosure will continue by referring to its specific embodiments shown in the accompanying drawings. It should be recognized that these figures show only typical embodiments of the disclosure and, accordingly, should not be considered as limiting the scope. The present disclosure is described and explained with additional specificity and detail together with the accompanying drawings.

[0022] Furthermore, those skilled in the art will understand that the elements in the figures are illustrated for simplicity and may not necessarily be drawn to scale. Additionally, with respect to the configuration of the device, one or more components of the device may be represented in the figures by conventional symbols, and the figures can only show the specific details appropriate for understanding the embodiments of the present disclosure. Therefore, the figures do not obscure the details that will be readily apparent to those skilled in the art who have the advantage of the description herein.

[0023] For the purpose of facilitating an understanding of the principles of the present disclosure, reference is made herein to the embodiments shown in the figures and specific language is used to describe them. Nevertheless, it will be understood that no limitation of the scope of the present disclosure is thereby intended. Alternative and further modifications in the illustrated systems, as well as further applications of the principles of the disclosure that are typical for those skilled in the art, should be construed as being within the scope of the present disclosure.

[0024] The terms "comprises", "comprising", or other variations thereof are intended to cover non-exclusive inclusion. A process or method that includes a list of steps does not include only those steps but may also include other steps that are not explicitly listed or inherent in such a process or method. Similarly, one or more devices, entities, sub-systems, elements, structures, or components that begin with "comprises... a" do not, without more constraints, preclude the presence of other devices, other sub-systems, other elements, other structures, other components, additional devices, additional sub-systems, additional elements, additional structures, or additional components. Throughout this specification, the phrases "in one embodiment", "in another embodiment", and similar language do not necessarily all refer to the same embodiment, but may.

[0025] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. The systems, methods, and examples provided herein are merely illustrative and not intended to be limiting.

[0026] In the following specification and claims, numerous terms are referenced, and these terms are defined to have the following meanings. The singular forms "a", "an", and "the" include plural references unless the context clearly dictates otherwise.

[0027] As used herein, data is meaningful information, and since information represents values resulting from parameters, information is associated with data and knowledge. Further, knowledge means the understanding of abstract or concrete concepts. Note that the example of this system has been simplified to facilitate the description of the disclosed subject matter and is not intended to limit the scope of this disclosure. In addition to or instead of the system, other devices, systems, and configurations can be used to implement the embodiments disclosed herein, and all such embodiments are contemplated as being within the scope of this disclosure.

[0028] <Example 1 of problem description> This problem description 1 is applicable to 5G AKA-based primary authentication and key agreement procedures.

[0029] When the UE has already successfully registered with the PLMN, a valid Kausf is derived in the UE and the AUSF (Authentication Server Function). The network can initiate the authentication procedure at any time according to Non-Patent Document 5. When the UE receives an Authentication Request message containing a 5G authentication vector (5G SE AV), it authenticates the network by verifying the received AUTN (Authentication token). If the verification of the AUTN is successful, the UE creates a new Kausf and RES*, and sends an Authentication Response containing RES* to the network. At this point, the UE has two Kausfs, the old Kausf and the new Kausf. Based on the verification of RES* at the AMF (Access and Mobility Management Function) or the AUSF, the authentication of the UE in the network may succeed or fail. If the authentication procedure is successful, the network does not send a NAS message to the UE. Therefore, without an explicit message received from the network, the UE does not know when the new Kausf will become effective and when the new Kausf can be used in various procedures (e.g., steering of roaming security mechanisms and updating of UE parameters via the UDM control plane procedure security mechanism).

[0030] <Example 2 of problem description> This problem description 2 applies to both the EAP-based mutual authentication and key agreement procedure and the 5G AKA-based mutual authentication and key agreement procedure. When the UE has already successfully registered with the PLMN, a valid Kausf has been derived in the UE and the AUSF. The network can initiate the authentication procedure at any time according to Non-Patent Document 5. During the authentication procedure, a radio link failure may occur between the UE and the network, and the authentication procedure may be interrupted. For example, if the AMF detects a radio link failure before receiving the authentication response message, it will abort the authentication procedure. In such a scenario, the UE and the network are not synchronized with respect to the latest Kausf used by the UE and the network. In some cases, the UE has multiple Kausfs (old Kausf and new Kausf), and it is not clear which Kausf the network will use in various security procedures (e.g., steering of roaming security mechanisms and updating of UE parameters via the UDM control plane procedure security mechanism) that require Kausf.

[0031] <Overview> The latest Kausf created in the following embodiments is used in the following security procedures (security mechanisms). i) Steering of the roaming security mechanism for calculating SoR-MAC-Iausf and SoR-MAC-Iue in the UE and the AUSF, as defined in Non-Patent Document 5. ii) Update of UE parameters via the UDM control plane procedure security mechanism for calculating UPU-MAC-Iausf and UPU-MAC-Iue in the UE and the AUSF, as defined in Non-Patent Document 5. iii) Deriving the AKMA key, as defined in Non-Patent Document 5.

[0032] In the following embodiments, if the UE sets the new Kausf (new Kausf) as the latest Kausf (latest Kausf), the UE shall initialize CounterSoR or CounterUPU to 0x00 0x00. When derived, the UE does not initialize CounterSoR or CounterUPU to 0x00 0x00, but initializes them when the new Kausf becomes the latest or valid. In the following embodiments, when the new Kausf becomes valid in the UE and the AUSF, this means that the new Kausf is the latest Kausf.

[0033] The embodiments defined for 5G AKA are also applicable to EAP-AKA, and vice versa. Also, in the following embodiments, "AMF" may be interpreted as "SEAF (Security Anchor Functionality)". Also, in the following embodiments, "UDM" may be interpreted as "ARPF (Authentication credential Repository and Processing Function)". Note that the following embodiments are applicable not only to 5GS but also to communication methods other than 5GS.

[0034] If the security check fails in the Steering of roaming (SoR) procedure or the UE Parameters Update (UPU) procedure, the UE shall include the Kausf used in the security verification procedure of the SoR procedure or the UPU procedure in a NAS message (e.g., a registration complete message to the AMF or a UL NAS transport message) and notify the AMF of it. The AMF shall transfer this Kausf to the UDM. In this case, the UDM has two options, and the comparison of the Kausf is performed either by the UDM or the AUDF. - Option 1 UDM performs the comparison of Kausf. That is, UDM obtains Kausf used in the SoR procedure or UPU procedure from the AUSF. Then, UDM compares the Kausf received from the UE with the Kausf received from the AUSF used in the SoR procedure or UPU procedure. - Option 2 AUSF performs the comparison of Kausf. That is, UDM transfers the Kausf received from the AMF to the AUSF. Next, AUSF compares the Kausf received from the UDM with the latest Kausf used in the SOR procedure or UPU procedure. Next, AUSF notifies the UDM of the comparison result. If the Kausf received for the UE is different from the Kausf stored in the AUSF, the UDM starts a new authentication procedure for that UE. In one example, when the UDM receives a signal from the AMF for the UE, the UDM requests the AMF to start a new authentication procedure. Or, the UDM may request the AMF to start a re-registration procedure for that UE. In this case, the AMF executes a new authentication procedure during the registration procedure. When the authentication procedure is successful, the latest Kausf is synchronized between the UE and the network.

[0035] <First Embodiment (Solution 1)> The UE starts a timer, and after the expiration of the timer, if the UE has not received an authentication rejection message, the new Kausf becomes valid.

[0036] This embodiment is applicable to both the 5G AKA-based primary authentication and key agreement procedure and the EAP-based primary authentication and key agreement procedure. Figure 5 shows the procedure for establishing the latest Kausf for the UE based on the UE's timer. Hereinafter, the detailed processing of the embodiment will be described.

[0037] 0. The UE is successfully registered with a PLMN, and in the UE and the network, Kausf is created. That is, the UE and the network each have (or maintain or keep or store) Kausf. If the UE is not yet registered with any PLMN, the UE does not have a valid Kausf.

[0038] 1. The network (e.g., AMF) initiates a 5G AKA-based primary authentication and key agreement procedure or an EAP-based primary authentication and key agreement procedure, and sends an authentication request message to the UE. The AUSF holds the new Kausf received from the UDM during the authentication procedure and the old Kausf (created in step 0).

[0039] 2. The UE verifies the AUTN parameter received in the authentication request message as defined in Non-Patent Document 6. When the verification of the AUTN parameter is successful, the UE calculates (or creates or generates) a new Kausf (or new Kausf parameters) based on the parameters received in the authentication request message and the USIM parameters defined in Non-Patent Document 5. The UE has both the old Kausf created in step 0 and the new Kausf created in this step.

[0040] 3. The UE sends an authentication response message containing *RES to the network.

[0041] 4. The UE starts timer T1 and stores both the old Kausf and the new Kausf. While timer T1 is running, the UE may consider the old Kausf as the latest Kausf and use the old Kausf in the security system that uses Kausf, or the UE may consider the new Kausf as the latest Kausf and use the new Kausf in the security system that uses Kausf. For example, the UE starts timer T1 either at the same time as transmitting an authentication response message containing *RES or after transmitting an authentication response message containing *RES. That is, the cause of start of the time T1 is the transmission of an authentication response message containing *RES.

[0042] 5. In the 5G AKA-based primary authentication and key agreement procedure, upon receiving an authentication response message containing RES*, the AMF and the AUSF verify HRES* and RES* respectively, as defined in Non-Patent Document 5. When the verification of HRES* and RES* is successful, the AMF and the AUSF consider that Kausf has succeeded, and the AUSF starts using the new Kausf created at the AUSF. In this case, Case 1, i.e., Step 6a, is performed after Step 5.

[0043] If the verification of HRES* or RES* fails at the AMF or the AUSF, the AMF transmits a Registration Reject message. The AUSF treats the old Kausf as valid with the latest Kausf and uses it in the security mechanism that uses Kausf. In this case, Case 2, i.e., Step 6b and Step 7b, are performed after Step 5. In the case of the EAP-based primary authentication and key agreement procedure, Case 3, i.e., Step 6c and Step 7c, are performed after Step 5.

[0044] 6a. If the UE does not receive an authentication rejection message and timer T1 expires, the UE shall consider that the 5G AKA-based primary authentication and key agreement procedure has succeeded, delete the old Kausf, set the new Kausf as the latest valid Kausf, and use the new Kausf in the security mechanism that uses Kausf.

[0045] 6b. The UE receives an authentication rejection message from the AMF during the operation of timer T1.

[0046] 7b. The UE stops timer T1, deletes the new Kausf, uses the old Kausf, and treats the old Kausf as the valid one with the latest Kausf.

[0047] 6c. The UE receives a NAS message from the AMF during the operation of timer T1. The NAS message contains either EAP success or EAP failure.

[0048] 7c. The UE stops timer T1. If the UE receives EAP success in step 6c, it deletes the old Kausf, uses the new Kausf, and treats the new Kausf as the valid one with the latest Kausf. If the UE receives EAP failure in step 6c, it deletes the new Kausf, uses the old Kausf, and treats the old Kausf as the valid one with the latest Kausf.

[0049] In one example, a radio link failure occurs and the radio link failure is detected by the UE at any step while timer T1 is running (for example, the NG-RAN indicates to the UE that the UE radio contact has been lost while the next N1 NAS signaling connection is being established or after the next N1 NAS signaling connection has been established). In this case, the UE shall restart timer T1 when the N1 NAS signaling connection is established. Timer T1 shall start with the remaining value or the original value. In this case, while the N1 NAS signaling connection is being established, if the first NAS procedure is rejected due to a failure in the authentication procedure (e.g., Registration Reject with cause #3 (illegal UE), or Service Reject with cause #3 (illegal UE)), the UE deletes the new Kausf, treats the old Kausf as valid with the latest Kausf, and uses the old Kausf in the security mechanism that uses the subsequent Kausf.

[0050] In one example, if a radio link failure occurs and the radio link failure is detected by the network (e.g., AMF) immediately after the network sends an authentication rejection message, the network may send the authentication rejection message to the UE again. For example, the NG-RAN indicates to the AMF that the UE radio contact has been lost through an NGAP message.

[0051] In one example, the UE may not hold (or maintain, keep, store, or have) the old Kausf. For example, when the UE is first powered on, or before the UE starts the first registration procedure, the UE may not hold the old Kausf.

[0052] In this case, all situations of the embodiment where the old Kausf becomes effective mean that the UE does not have a valid Kausf. For example, "the UE deletes the new Kausf, treats the old Kausf as valid with the latest Kausf, and uses the old Kausf in the subsequent security mechanism using Kausf" in this embodiment means that "the UE must delete the new Kausf, and the UE does not have a valid Kausf". In this case, the UE may start the registration procedure after deleting the new Kausf. For example, "(the UE) deletes the old Kausf, sets the new Kausf as the latest valid Kausf, and uses the new Kausf in the security mechanism involving Kausf" in this embodiment means that "(the UE) sets the new Kausf as the latest valid Kausf and uses the new Kausf in the security mechanism involving Kausf".

[0053] <Modification Example of the First Embodiment> While the timer T1 is running, the UE maintains both the old Kausf and the new Kausf and treats them as valid with the latest Kausf. The UE shall use the old Kausf and the new Kausf in the security mechanism involving Kausf. If the security mechanism is passed using either of these keys, the UE shall treat that key as the latest and valid key and delete the other key. For example, if the security mechanism is passed using the old Kausf, the UE shall treat the old Kausf as the latest and valid and delete the new Kausf. Further, for example, if the security mechanism is passed using the new Kausf, the UE shall treat the new Kausf as the latest and valid and delete the old Kausf.

[0054] <Second Embodiment (Solution 2)> When the authentication procedure is successful at the AMF, the AMF sends the authentication result.

[0055] This embodiment is applicable to 5G AKA-based primary authentication and key agreement procedures. FIG. 6 shows a procedure for establishing the latest Kausf between a UE and a network using explicit NAS signaling. The detailed processing of the embodiment will be described below. The UE and the AUSF each have (or maintain, keep, store) an old Kausf.

[0056] 1. In the registration procedure as a trigger for 5G AKA-based primary authentication and key agreement procedures, the UE sends a registration request message including a first information element (IE), and this first information element indicates that the UE supports receiving an acknowledgement message (e.g., authentication result) sent by the network in a successful authentication procedure. The transmission of this capability is optional in the registration request message, that is, this capability may be transmitted in other existing NAS messages (e.g., authentication response) or in a new NAS message during any NAS procedure. The registration procedure may be an initial registration procedure or a periodic registration or mobility registration procedure. The network (e.g., AMF) stores this capability of the UE.

[0057] 2. The AMF sends a UE Authentication and Authorization request to the AUSF / UDM to start 5G AKA-based primary authentication and key agreement procedures.

[0058] 3. The UDM generates an AV (authentication vector). Next, a new Kausf is created in the AUSF. At this point, the AUSF maintains both the old Kausf and the new Kausf.

[0059] 4. The AUSF / UDM sends the UE Authentication and Authorization response to the AMF.

[0060] 5. The AMF sends an Authentication Request message to the UE. The Authentication Request message may include the network capability for sending a NAS acknowledgement message when the 5G AKA-based primary authentication and key agreement procedure is successfully completed. Upon receiving the Authentication Request message, the UE stores this capability. The sending of this capability is optional in the Authentication Request message. That is, this capability may be sent in other existing NAS messages (e.g., Registration Accept) or in a new NAS message during any NAS procedure. For example, if the UE indicates to the AMF that it supports receiving a NAS acknowledgement message sent from the network when the 5G AKA-based primary authentication and key agreement procedure is successful, the AMF sends an Authentication Request message to the UE.

[0061] 6. Upon receiving the Authentication Request message, the UE verifies the AUTN as defined in Non-Patent Document 6. If the verification of the AUTN is successful, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the latest Kausf created before this step) and the new Kausf. The UE continues to use the old Kausf as the most recent and valid Kausf in security procedures related to Kausf. If it has been previously shown that the network supports the transmission of a confirmation response message (e.g., authentication result) upon successful completion of the authentication procedure, the UE waits for a NAS acknowledgement message and does not use a new Kausf in subsequent security procedures related to Kausf until a NAS acknowledgement message indicating successful completion of the authentication procedure is received.

[0062] 7. The UE sends an Authentication Response message containing RES* to the AMF.

[0063] 8. The AMF performs a comparison between HRES* and HXRES*.

[0064] 9. If the verification of HRES* at the AMF is successful, the AMF sends a UE Authentication and Authorization request to the AUSF / UDM.

[0065] 10. The AUSF performs a comparison between RES* and XRES*.

[0066] 11. If the verification of RES* at the AUSF is successful, the AUSF considers the new Kausf valid and deletes the old Kausf. The AUSF then begins to use the new Kausf as the most recent and valid Kausf in subsequent security procedures related to Kausf.

[0067] 12. The AUSF / UDM sends a UE Authentication and Authorization response to the AMF.

[0068] 13. When the UE indicates to the AMF that it supports receiving the NAS acknowledgement message sent from the network when the 5G AKA-based primary authentication and key agreement procedure is successful, the AMF sends an existing NAS message or a new NAS message indicating the success of the 5G AKA-based primary authentication and key agreement procedure. Otherwise, the AMF does not send a NAS acknowledgement message indicating the success of the 5G AKA-based primary authentication and key agreement procedure. For example, the AMF sends the UE an authentication result indicating the success of the 5G AKA-based primary authentication and key agreement procedure.

[0069] 14. Upon receiving the NAS acknowledgement message, the UE deletes the old Kausf and begins to use the new Kausf as the latest and valid Kausf in the security procedures related to Kausf.

[0070] In one example, the UE may not need to hold (or maintain, keep, store, or have) the old Kausf. For example, when the UE is first powered on or before the UE starts the first registration procedure, the UE may not hold the old Kausf.

[0071] For example, "the UE deletes the old Kausf and begins to use the new Kausf as the latest and valid Kausf in the security procedures related to Kausf" in this embodiment means "the UE begins to use the new Kausf as the latest and valid Kausf in the security procedures related to Kausf".

[0072] <Modification Example 1 of the Second Embodiment> After step 14, the UE may send an Authentication Acknowledgment message to the AMF to indicate to the AMF a successful UE authentication procedure. When the AMF receives the authentication acknowledgment message from the UE, the AMF confirms that the UE authentication procedure has been successful, and the AMF sends a UE Authentication and Authorization notify indicating that the UE authentication procedure has been successful to the AUSF / UDM. When the AUSF / UDM receives the UE Authentication and Authorization notify indicating the success of the UE authentication procedure, it considers the new Kausf valid and deletes the old Kausf. The AUSF then begins to use the new Kausf as the latest and valid Kausf in subsequent security procedures related to Kausf. In this variation, step 11 is not performed by the AUSF, that is, the AUSF does not consider the new Kausf valid in step 11.

[0073] In one example, when the AMF sends an existing NAS message or a new NAS message in step 13, it starts a timer T3 to wait for the authentication acknowledgment message sent from the UE. If the timer T3 expires, the AMF may re - send the existing NAS message or the new NAS message indicating the success of the 5G AKA - based primary authentication and key agreement procedure shown in step 13.

[0074] In one example, the UE and the network execute a plurality of steps defined in the second embodiment without exchanging and checking the function of receiving the authentication result or sending the authentication result message.

[0075] <Variation 2 of the Second Embodiment> If the UE has a PDU session for emergency services or has established a PDU session for emergency services, and after the UE has sent an authentication response message, the UE receives a security mode command message with null encryption and a null ciphering algorithm (NIA 0 and NEA 0), the UE does not consider the Kausf created during the authentication procedure as the latest one, that is, in the security procedures related to Kausf, the UE does not use Kausf. The UE may delete Kausf. In one example, after the PDU session related to emergency services is released / deactivated, or after the UE enters the 5GMM DEREGISTERED state, the UE deletes Kausf.

[0076] In one example, if the authentication result indicates a failure of the authentication procedure and the UE receives a security mode command message, the UE invalidates the Kausf created during the latest authentication procedure. If the UE has an old Kausf that is being used in the security procedure, the UE continues to use that Kausf in the security procedure. This procedure is applicable to both 5G AKA and EAP AKA, or other authentication methods used in 5GS.

[0077] <The Third Embodiment (Solution 3)> The UE starts the procedure to establish the latest Kausf.

[0078] This embodiment is applicable to both 5G AKA-based primary authentication and key agreement procedures, and EAP-based primary authentication and key agreement procedures. Figure 7 shows the procedure for creating the latest Kausf in the UE and the network. The detailed processing of the embodiment will be described below.

[0079] 0. The UE is successfully registered with a PLMN, and Kausf is created between the UE and the network. That is, the UE and the network each have (or maintain or keep or store) Kausf. If the UE is not yet registered with any PLMN, the UE does not have a valid Kausf.

[0080] 1. The network (e.g., AMF) initiates a 5G AKA-based mutual authentication and key agreement procedure or an EAP-based mutual authentication and key agreement procedure, and sends an Authentication Request message to the UE. The AUSF stores the new Kausf received from the UDM during the authentication procedure and the old Kausf (created in step 0). The Authentication Request message may include the network function that receives the First NAS message in step 7 if the UE detects a radio link failure during the 5G AKA-based mutual authentication and key agreement procedure and during the EAP-based mutual authentication and key agreement procedure. When receiving the Authentication Request message, the UE stores this function. The transmission of this function is optional in the Authentication Request message, that is, this function may be transmitted in other existing NAS messages (e.g., Registration Accept) or in a new NAS message during any NAS procedure.

[0081] 2. The UE verifies the AUTN parameter received in the Authentication Request message as defined in Non-Patent Document 6. When the verification of the AUTN parameter is successful, the UE calculates (or creates or generates) a new Kausf (or new Kausf parameters) based on the parameters received in the Authentication Request message and the USIM parameters defined in Non-Patent Document 5. The UE has both the old Kausf created in step 0 and the new Kausf created in this step.

[0082] 3. The UE sends an authentication response message containing *RES to the network.

[0083] 4. The UE stores both the old Kausf and the new Kausf created in step 2.

[0084] 5. The network performs a 5G AKA-based primary authentication and key agreement procedure or an EAP-based primary authentication and key agreement procedure based on the selection by the UDM.

[0085] 6. In the 5G AKA-based primary authentication and key agreement procedure, upon receiving an authentication response message containing RES*, the AMF and the AUSF verify HRES* and RES* respectively, as defined in Non-Patent Document 5. When the verification of HRES* and RES* is successful, the AMF and the AUSF consider Kausf to be successful, and the AUSF starts using the new Kausf created by the AUSF. In this case, the AMF sends an authentication result message indicating the success of the 5G AKA-based primary authentication and key agreement procedure to the UE. If the verification of HRES* or RES* fails in the AMF or the AUSF, the AMF sends a Registration Reject message to the UE. In the EAP-based primary authentication and key agreement procedure, the AMF sends a NAS message to the UE. Note that the AMF may send multiple NAS messages to the UE during the EAP-based primary authentication and key agreement procedure. In this step, due to a radio link failure between the network and the UE, the authentication result message or the authentication reject message or the NAS message may be lost.

[0086] 7. If the UE detects a radio link failure during the 5G AKA-based initial authentication and key agreement procedure or the EAP-based initial authentication and key agreement procedure, the UE shall send a First NAS message to the AMF during the establishment of the next N1 NAS signaling connection. For example, when the UE sends an authentication response, it starts a timer. If it does not receive an authentication result message or an authentication rejection message or a NAS message in step 6 and the timer expires, it detects a radio link failure.

[0087] For example, during the establishment of the next N1 NAS signaling connection, the NG-RAN may indicate to the UE that a radio link failure has occurred before the UE sends the First NAS message to the AMF. The First NAS message can be a new NAS message or an existing NAS message (for example, a registration request message when the registration procedure is started, or a service request message when the service request procedure is started). The First NAS message shall include an Information Element (IE) indicating to the AMF that the UE has not completed the 5G AKA-based initial authentication and key agreement procedure or the EAP-based initial authentication and key agreement procedure. That is, if the 5G AKA-based initial authentication and key agreement procedure has been performed, neither an authentication result message nor an authentication rejection message has been received yet. If the EAP-based initial authentication and key agreement procedure has been executed, the NAS message carrying the next EAP message of the EAP-based initial authentication and key agreement procedure has not been received yet. The UE may include the ngKSI (5G Key Set Identifier) in the First NAS message. Upon receiving the First NAS message, the AMF shall execute either case 1 (step 8a) or case 2 (step 8b).

[0088] After step 4, when the N1 NAS signaling connection establishment procedure is performed and the UE receives a security mode command message containing an ngKSI that matches the ngKSI associated with the new Kausf, the UE deletes the old Kausf, sets the new Kausf as the latest and valid Kausf, and starts using the latest Kausf. The UE can make this decision because the ngKSI in the security mode command message received from the AMF can serve as evidence that the AMF holds the new Kausf as the latest and valid Kausf.

[0089] 8a. The AMF starts a new authentication procedure. When the authentication procedure is successfully completed, the UE and the AUSF start using the latest Kausf created during the authentication procedure.

[0090] 8b. The AMF sends a second NAS message to the UE. The second NAS message can be a NAS message that contains the message from step 6, i.e., an authentication result message, an authentication rejection message, or an EAP message. The second NAS message can be a DL NAS transport message, a Registration Accept message, or a Service Accept message that contains the results of the last executed EAP-based mutual authentication and key agreement procedure. When the AMF receives an ngKSI from the UE in step 7, the AMF sends the results of the EAP-based mutual authentication and key agreement procedure corresponding to the received ngKSI.

[0091] 9. In the 5G AKA-based primary authentication and key agreement procedure, when the UE receives an authentication result message as the second NAS message, the UE deletes the old Kasuf, sets the new Kasuf as the latest and valid Kasuf, and starts using the new Kasuf in subsequent security procedures related to Kasuf. When the UE receives an authentication rejection message as the second NAS message, the UE deletes the new Kausf and continues to use the old Kausf as the latest and valid Kausf in the security procedures related to Kausf.

[0092] In the EAP-based primary authentication and key agreement procedure, when the UE receives the second NAS message containing the authentication result (EAP message), and the EAP authentication result contains an EAP failure message, the UE deletes the new Kausf and continues to use the old Kausf as the latest and valid Kausf in the security procedures related to Kausf. When the authentication result contains EAP success, the UE deletes the old Kasuf, sets the new Kasuf as the latest and valid Kasuf, and starts using the new Kasuf in subsequent security procedures related to Kasuf. When the second message contains ngKSI, the UE uses the received ngKSI to find the relevant Kausf in the UE. The UE uses the found Kausf as the latest and valid Kausf in the subsequent security procedures related to Kausf.

[0093] In one example, the UE may not have (or maintain, keep, or hold) the old Kausf. For example, when the UE is first powered on or before the UE starts the first registration procedure, the UE may not have the old Kausf. In this case, all situations of the embodiment where the old Kausf becomes valid mean that the UE does not have a valid Kausf. For example, in this embodiment, "the UE deletes the new Kausf and continues to use the old Kausf as the latest and valid Kausf in the security procedures related to Kausf" means that "the UE deletes the new Kausf and the UE does not have a valid Kausf". In this case, the UE may start the registration procedure after deleting the new Kausf. For example, in this embodiment, "the UE deletes the old Kausf, sets the new Kausf as the latest and valid Kausf, and starts using the latest Kausf" means that "the UE sets the new Kausf as the latest and valid Kausf and starts using the latest Kausf".

[0094] <Variant 1 of the Third Embodiment> In step 7 of this embodiment, the UE includes the list of Kausf maintained by the UE (for example, the old Kausf or the new Kausf). The AMF verifies which Kausf in the list is being used by the AUSF. Next, the AMF returns the matching Kausf used by the AUSF to the UE in the second NAS message. The UE sets the received Kausf as the latest and valid Kausf and starts using it in subsequent security mechanisms that require Kausf. In one example, if the UE does not include the list of Kausf, the AMF obtains the latest Kausf from the AUSF and sends this Kausf to the UE in the second NAS message. In one example, the UE and the AMF or AUSF maintain the association between Kausf and ngKSI. The UE sends the list of ngKSI associated with the Kausf it holds in the first NAS message in step 7. The network (AMF or AUSF) matches the received ngKSI with the ngKSI of the latest Kausf. The AMF returns the matched ngKSI used by the AUSF to the UE. The UE regards the Kausf associated with the received ngKSI as the latest and valid Kausf and starts to use it in the security procedures that require Kausf. If the ngKSI list is not sent in the first NAS message, the AMF sends the ngKSI of the latest Kausf used by the AUSF in the second NAS message. When receiving the second NAS message, the UE regards the Kausf corresponding to the ngKSI as the latest and valid Kausf.

[0095] <Modification Example 2 of the Third Embodiment> In this embodiment, the radio link failure detected by the UE is considered as a trigger for sending the first NAS message to the AMF. As a modification of this trigger, when the UE sends an authentication response message to the AMF, the UE may start timer T1 as described in the first embodiment. When timer T1 expires, the UE may regard the expiration of this timer as a trigger for sending the first NAS message to the AMF. Therefore, when the timer T1 expires, the UE sends the first NAS message to the AMF. When receiving the second message, the UE stops timer T1.

[0096] <Fourth Embodiment (Solution 4)> This embodiment is applicable to both the 5G AKA-based primary authentication and key agreement procedure and the EAP-based primary authentication and key agreement procedure.

[0097] In the first, second, and third embodiments, when the UE receives steering of roaming information in a Registration accept message or a Configuration Update Command message while having multiple Kausfs, the UE performs a security check on the steering of roaming using each Kausf. If the security check is passed using a Kausf, the UE designates that Kausf as the latest and valid Kausf, and then starts using that Kausf in security procedures that require a Kausf. The UE performs the same processing as in the UE Parameters Update procedure. For example, when the UE performs a security check for a security procedure or security mechanism (e.g., steering of roaming or UE Parameters Update procedure), and the UE has two Kausfs (e.g., an old Kausf and a new Kausf), and the security check is passed (or completed successfully) using the old Kausf, the UE designates the old Kausf as the latest and valid Kausf, starts using the old Kausf in subsequent security procedures that require a Kausf, and may delete the new Kausf. Also, when the UE performs a security check and the UE has two Kausfs (e.g., an old Kausf and a new Kausf), and the security check is passed using the new Kausf, the UE designates the new Kausf as the latest and valid Kausf, starts using the new Kausf in subsequent security procedures that require a Kausf, and may delete the old Kausf.

[0098] Furthermore, for example, if the UE performs a security check and the UE has two Kausfs, first, the UE may perform the security check using one of the two Kausfs. If the UE passes the security check using one Kausf, the UE may set that one Kausf as the latest and valid Kausf, start using that one Kausf in subsequent security procedures that require a Kausf, and delete the other Kausf. If the UE fails the security check using one Kausf, the UE may perform the security check using the other of the two Kausfs. If the UE passes the security check using that other Kausf, the UE may set that other Kausf as the latest and valid Kausf, start using that other Kausf in subsequent security procedures that require a Kausf, and delete that one Kausf.

[0099] In one example, the UE may not hold (or maintain, keep, store, or have) an old Kausf. For example, when the UE is first powered on or before the UE starts the first registration procedure, the UE may not hold an old Kausf.

[0100] In this case, while the UE has one Kausf and has not received an authentication result message, the UE receives steering of roaming information in a Registration accept message or a Configuration Update Command message, and the UE performs a security check on the steering of roaming using that Kausf. If the UE passes the security check using that Kausf, the UE may set that Kausf as the latest and valid Kausf and start using that Kausf in subsequent security procedures that require a Kausf.

[0101] <Fifth Embodiment (Solution 5)> When a radio link failure is detected by the AMF while the AMF is waiting for an authentication response message, the authentication request message is retransmitted.

[0102] This embodiment is applicable to both 5G AKA-based mutual authentication and key agreement procedures and EAP-based mutual authentication and key agreement procedures. FIG. 8 shows a procedure for creating the latest Kausf at the UE and the network. The detailed processing of the embodiment will be described below. The UE and the AUSF each have (or maintain or store) an old Kausf.

[0103] 1. In a registration procedure that triggers the UE authentication procedure, the UE transmits a registration request message including a first information element (IE) indicating that the UE supports repeated reception of authentication-related messages (e.g., authentication result, authentication rejection, DL NAS transport message) transmitted from the network during the UE authentication procedure to the network. The transmission of this function is optional in the registration request message, that is, this function can be transmitted in other existing NAS messages or new NAS messages during any NAS procedure. The registration procedure can be an initial registration procedure, or a periodic registration or mobility registration procedure. The network (e.g., the AMF) stores this UE capability.

[0104] 2. The AMF transmits a UE Authentication and Authorization request to the AUSF / UDM to initiate a 5G AKA-based mutual authentication and key agreement procedure, or an EAP-based mutual authentication and key agreement procedure.

[0105] 3. The UDM generates the AV. Next, at the AUSF, a new Kausf is created. The AUSF maintains both the old Kausf and the new Kausf at this point.

[0106] 4. The AUSF / UDM sends the UE Authentication and Authorization response to the AMF.

[0107] 5. The AMF sends an Authentication Request message to the UE. The Authentication Request message may include a network function that repeatedly sends authentication-related messages (e.g., authentication result, authentication rejection, DL NAS transport message) in case authentication-related messages are lost between the UE and the AMF. When the UE receives the Authentication Request message, it stores this function. The transmission of this function is optional in the Authentication Request message, i.e., this function can be sent in other existing NAS messages (e.g., Registration Accept or a new NAS message during any NAS procedure).

[0108] 6. The AMF starts timer T2. For example, when the AMF sends the Authentication Request message in step 5 or after the AMF sends the Authentication Request message in step 5, the AMF starts timer T2. That is, the cause of starting timer 2 is the transmission of the Authentication Request message in step 5. Timer T2 can be a new timer or an existing timer. T2 can be T3560.

[0109] 7. When the UE receives the authentication request message, it verifies the AUTN as defined in Non-Patent Document 6. If the verification of the AUTN is successful, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the latest Kausf created before this step) and the new Kausf. The UE continues to use the old Kausf as the latest and valid Kausf in the security procedures related to Kausf. As previously shown, when the network supports repeatedly sending authentication-related messages (e.g., authentication result, authentication rejection, DL NAS transport message), the UE processes them once but can process repeated authentication-related messages.

[0110] 8. The UE sends an authentication response message containing RES* to the AMF. However, this message is lost and cannot reach the AMF. For example, due to a radio link failure, the authentication response message is lost and cannot reach the AMF.

[0111] 9. Timer T2 expires at the AMF.

[0112] 10. When Timer T2 expires, the AMF sends the authentication-related message that was already sent in step 5 to the UE. In one example, if the AMF detects a radio link failure while Timer T2 is running, the AMF immediately stops Timer T2 upon detecting the radio link failure and sends the authentication request message to the UE. That is, the AMF does not wait for the expiration of Timer T2. For example, the NG-RAN indicates to the AMF via an NGAP message that the UE radio contact has been lost, and the AMF detects a radio link failure based on the NGAP message. Also, for example, if the AMF detects a radio link failure, the AMF may leave Timer T2 running, and then, when Timer T2 expires, the AMF may send the authentication-related message that was already sent in step 5 to the UE.

[0113] 11. When the UE receives an authentication request message, it verifies the AUTN as defined in Non-Patent Document 6. If the verification of the AUTN is successful, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the latest Kausf created before this step) and the new Kausf. The UE continues to use the old Kausf as the latest and valid Kausf in the security procedures related to Kausf.

[0114] 12. The UE sends an authentication response message containing RES* to the AMF.

[0115] 13. The network executes the UE authentication procedure.

[0116] 14. When the verification of HRES* and RES* is successful at the AMF and AUSF respectively, the AMF sends an authentication result message to the UE.

[0117] 15. When receiving the authentication result message, the UE deletes the old Kausf and starts using the new Kausf as the latest and valid Kausf in the security procedures related to Kausf.

[0118] In one example, the UE may not hold (or maintain or keep or store or have) the old Kausf. For example, when the UE is first powered on or before it starts the first registration procedure, the UE may not hold the old Kausf. In this case, for example, in this embodiment, "the UE deletes the old Kausf and starts using the new Kausf as the latest and valid Kausf in the security procedures related to Kausf" means "the UE starts using the new Kausf as the latest and valid Kausf in the security procedures related to Kausf".

[0119] <Variant of the Fifth Embodiment> This embodiment discloses that an authentication request message is repeatedly sent by the AMF for the expiration of timer T2.

[0120] As an example, the mechanism by which this message is repeatedly sent for the expiration of timer T2 can be used for EAP-based mutual authentication and key agreement procedures. During the EAP-based mutual authentication and key agreement procedures, since there are multiple NAS messages communicated between the UE and the AMF, in this embodiment, any authentication-related NAS message from the AMF to the UE can be used for NAS message retransmission, that is, the NAS message including the EAP message in step 5 can be repeatedly sent by the AMF when timer T2 expires in step 10.

[0121] <Sixth Embodiment (Solution 6)> Before receiving the authentication response message, when the AMF detects a radio link failure, it starts a new authentication procedure.

[0122] This embodiment is applicable to both 5G AKA-based mutual authentication and key agreement procedures and EAP-based mutual authentication and key agreement procedures. FIG. 9 shows the procedure for creating the latest Kausf in the UE and the network.

[0123] Hereinafter, the detailed processing of the embodiment will be described. The UE and the AUSF each have (or maintain or store) an old Kausf.

[0124] 1. In the registration procedure that triggers the UE authentication procedure, the UE sends a Registration Request message to the network, including a first Information Element (IE) indicating that the UE supports repeatedly receiving authentication-related messages (e.g., authentication result, authentication rejection, DL NAS transfer message) sent from the network during the UE authentication procedure. The transmission of this function is optional in the registration request, that is, this function can be transmitted in other existing NAS messages or new NAS messages during any NAS procedure. The registration procedure can be an initial registration procedure, or a periodic registration or mobility registration procedure. The network (e.g., AMF) stores this UE function.

[0125] 2. The AMF sends a UE Authentication and Authorization request to the AUSF / UDM to initiate a 5G AKA-based primary authentication and key agreement procedure, or an EAP-based primary authentication and key agreement procedure.

[0126] 3. The UDM generates the AV. Next, in the AUSF, a new Kausf is created. At this point, the AUSF maintains both the old Kausf and the new Kausf.

[0127] 4. The AUSF / UDM sends a UE Authentication and Authorization response to the AMF.

[0128] 5. The AMF sends an Authentication Request message to the UE. The Authentication Request message may include a network function for repeatedly sending authentication-related messages (e.g., authentication result, authentication rejection, DL NAS transport message) in case authentication-related messages are lost between the UE and the AMF. When the UE receives the Authentication Request message, it stores this function. The transmission of this function is optional in the Authentication Request message, i.e., this function can be sent in other existing NAS messages (e.g., Registration Accept) or in a new NAS message during any NAS procedure.

[0129] 6. The AMF starts timer T2. For example, when the AMF sends the Authentication Request message in step 5 or after the AMF sends the Authentication Request message in step 5, the AMF starts timer T2. That is, the cause of starting timer T2 is the transmission of the Authentication Request message in step 5.

[0130] 7. When the UE receives the Authentication Request message, it verifies the AUTN defined in Non-Patent Document 6. If the verification of the AUTN is successful, the UE calculates (or creates or generates) a new Kausf and RES*. The UE stores both the old Kausf (the latest Kausf created before this step) and the new Kausf. The UE continues to use the old Kausf as the latest and valid Kausf in security procedures related to Kausf.

[0131] If it was previously shown that the network supports repeatedly sending authentication-related messages (e.g., authentication result, authentication rejection, DL NAS transport message), the UE processes it once but can process repeatedly received authentication-related messages.

[0132] 8. The UE sends an authentication response message containing RES* to the AMF. However, this message is lost and cannot reach the AMF. For example, the authentication response message is lost due to a radio link failure and cannot reach the AMF.

[0133] 9. The timer T2 expires at the AMF.

[0134] 10. When the timer T2 expires, the AMF starts a new authentication procedure by sending a UE authentication and authorization request to the AUSF / UDM as shown in step 2 of FIG. 9. When the UE authentication procedure between the UE and the network is successfully completed, the UE and the AUSF begin to use the Kasuf created during this new authentication procedure for the security procedures related to Kausf. In one example, if the AMF detects a radio link failure while the timer T2 is running, the AMF starts a new authentication procedure. In this case, the AMF stops the timer T2 and immediately sends a UE authentication and authorization request to the AUSF / UDM as shown in step 2 of FIG. 9, that is, the AMF does not wait for the expiration of the timer T2. For example, the NG-RAN indicates to the AMF via an NGAP message that the UE radio contact has been lost, and the AMF detects a radio link failure based on the NGAP message. Further, for example, if the AMF detects a radio link failure, the AMF may leave the timer T2 running, and then, when the timer T2 expires, the AMF sends an Authentication and Authorization request to the AUSF / UDM as shown in step 2 of FIG. 9.

[0135] 14. In one example, the UE may not hold the old Kausf. For example, when the UE is first powered on or before the UE starts the first registration procedure, the UE may not hold the old Kausf. The above process in this embodiment is also applicable to this example.

[0136] <User Equipment (UE)> FIG. 10 shows a block diagram illustrating the main components (1000) of a UE. As shown in the figure, the UE 1000 includes a transceiver circuit 1002 operable to transmit and receive signals with nodes connected via one or more antennas 1001. Although not necessarily shown in FIG. 10, of course, the UE has all the normal functions of a conventional mobile device (such as a user interface), which can be provided by any one or any combination of hardware, software, firmware as required. The software may be pre-installed in the memory and / or downloaded via a telecommunications network or from a removable data storage device (RMD).

[0137] The controller 1004 controls the operation of the UE according to the software stored in the memory 1005. The software includes, among other things, an operating system and a communication control module having at least a transceiver control module. The communication control module (using the transceiver control sub-module) is responsible for the processing (generation / transmission / reception) of signaling and uplink / downlink data packets between the UE and other nodes, and the other nodes are, for example, base stations / (R)AN nodes, MME, AMF (and other core network nodes), etc. Such signaling may include, for example, properly formatted signaling messages related to connection establishment and maintenance (e.g., RRC connection establishment message, and other RRC messages), NAS messages such as periodic location update related messages (e.g., tracking area update, paging area update, location area update), etc. Such signaling may also include, for example, broadcast information in the reception case (e.g., Master Information, System information).

[0138] <(R)AN node> FIG. 11 is a block diagram showing the main components of an exemplary (R)AN node 1100, which is, for example, a base station (referred to as "eNB" in LTE and "gNB" in 5G). As shown in the figure, the (R)AN node operates to transmit and receive signals to and from a UE connected via one or more antennas 1101 and to transmit and receive signals to and from other network nodes (directly or indirectly) via a network interface 1103, and includes a transceiver circuit 1102. A controller 1104 controls the operation of the (R)AN node according to software stored in a memory 1105. The software may be pre-installed in the memory and / or may be downloaded, for example, via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system and a communications control module having at least a transceiver control module.

[0139] The communications control module (using a transceiver control sub-module) is responsible for processing (generating / transmitting / receiving) signaling between the (R)AN node and other nodes (e.g., directly or indirectly), and the other nodes include a UE, an MME, an AMF, etc. The signaling may include, for example, properly formatted signaling messages related to radio connection and location procedures (for a specific UE), particularly those related to connection establishment and maintenance, such as RRC connection establishment and other RRC messages, periodic location update related messages (e.g., tracking area update, paging area update, location area update), S1 AP messages, and NG AP messages (i.e., messages at the N2 reference point), etc. Such signaling may include, for example, broadcast information (e.g., master information, system information, etc.) in the case of transmission.

[0140] The controller is also configured (by software or hardware) to process related tasks such as UE mobility estimate and / or moving trajectory estimation when implemented.

[0141] <amf> Figure 12 is a block diagram showing the main components of the AMF 1200. The AMF is included in the 5GC (5G core network). As shown in the figure, the AMF 1200 includes a transceiver circuit 1201 operable to transmit and receive signals with other nodes (including UEs) via a network interface 1204. A controller 1202 controls the operation of the AMF 1200 according to software stored in a memory 1203. The software may be pre-installed in the memory 1203 and / or downloaded, for example, via a telecommunications network or from a removable data storage device (RMD). The software includes, among other things, an operating system and a communications control module having at least a transceiver control module.

[0142] The communications control module (using a transceiver control sub-module) is responsible for processing (generating / sending / receiving) signaling between the AMF and other nodes (such as directly or indirectly), and the other nodes are, for example, UEs, base stations / (R)AN nodes (such as, "gNB" or "eNB"), etc. Such signaling may include, for example, appropriately formatted signaling messages related to the procedures described herein, such as NG AP messages (i.e., messages at the N2 reference point) for conveying NAS messages between the UE and the like.

[0143] The user equipment (or, "UE", "mobile station", "mobile device", or "wireless device") in the present disclosure is an entity connected to a network via a wireless interface. Note that the UE in this specification is not limited to a dedicated communication device, and as described later, it can be applied to any device having a communication function as the UE described in this specification.

[0144] The terms "User Equipment" or "UE", "Mobile Station", "Mobile Device", and "Wireless Device" as used in 3GPP are generally intended to be synonymous with each other and include stand-alone mobile stations such as terminals, cell phones, smartphones, tablets, cellular IoT devices, IoT devices, and machinery. It will be understood that the terms "UE" and "Wireless Device" also include devices that remain stationary for long periods of time.

[0145] A UE may be, for example, an item of equipment for production or manufacturing and / or an item of energy-related machinery (e.g., boilers; engines; turbines; solar panels; wind turbines; hydroelectric generators; thermal power generators; nuclear power plants; batteries; nuclear systems and / or related equipment; heavy electrical equipment; pumps including vacuum pumps; compressors; fans; blowers; hydraulic equipment; pneumatic equipment; metalworking machinery; manipulators; robots and their application systems; tools; molds or dies; rolls; conveying equipment; lifting equipment; material handling systems; textile machinery; sewing machines; printing and / or related equipment; paper processing machinery; chemical machinery; mining and / or construction machinery, and / or related facilities; machinery and / or implements for agriculture, forestry, and fishery; safety and / or environmental protection equipment; tractors; precision bearings; chains; gears; power transmission equipment; lubrication equipment; valves; pipe joints; etc.), and / or an application system of any of the above equipment or machinery. A UE may be, for example, an item of conveying equipment (e.g., transportation equipment such as rolling stocks; automobiles; motorcycles; bicycles; trains; buses; carts; rickshaws; ships, other vessels; aircraft; rockets; satellites; drones; balloons, etc.).

[0146] The UE may be an item of an information and communication device (for example, an information and communication device such as an electronic computer and related devices; communication and related devices; electronic components, etc.). The UE may be, for example, an item of a refrigerator, a refrigerator application product, a commodity and / or a service industry device, a vending machine, an automatic service machine, an office machine or device, an electronic device for consumers (for example, the following electronic devices for consumers: audio devices; video devices; speakers; radios; televisions; microwave ovens; rice cookers; coffee machines; dishwashers; washing machines; dryers; electric fans or related devices; vacuum cleaners, etc.).

[0147] The UE may be, for example, an electric application system or device (for example, the following electric application systems or devices: X-ray systems; particle accelerators; radioisotope devices; acoustic devices; electromagnetic application devices; electronic application devices, etc.).

[0148] The UE may be, for example, an electronic lamp, a lighting fixture, a measuring instrument, an analyzer, a tester, or a surveying or sensing device (for example, the following surveying or sensing devices: smoke alarms; human alarm sensors; motion sensors; wireless tags, etc.), a wristwatch or clock, a laboratory device, an optical device, a medical device and / or system, a weapon, an item of a blade, a hand tool, etc.

[0149] The UE may be, for example, a wireless portable information terminal or related device (for example, something like a wireless card or module designed to be attached to another electronic device (for example, a personal computer, an electrical measuring instrument) or designed to be inserted into another electronic device).

[0150] The UE can be part of a device or system that uses various wired and / or wireless communication technologies to provide the applications, services, and solutions described below with respect to the "Internet of Things (IoT)". Internet of Things devices (or "things" Internet) may comprise appropriate electronic devices, software, sensors, network connections, etc., and these devices can collect and exchange data with each other and with other communication devices. IoT devices can comprise automated devices that follow software instructions stored in internal memory. IoT devices may operate without the need for human monitoring or operation. IoT devices may also be stationary and / or inactive for long periods of time. IoT devices can generally be implemented as part of a fixed installation. IoT devices may also be incorporated into non-fixed devices (e.g., vehicles) or attached to animals or persons to be monitored or tracked.

[0151] It will be understood that IoT technology can be implemented in any communication device that can be connected to a communication network to send and receive data, whether controlled by human input or by software instructions stored in memory.

[0152] It will be understood that IoT devices may also be referred to as machine type communication (MTC) devices or machine-to-machine (M2M) communication devices or narrowband IoT UEs (NB-IoT UEs). It will be understood that the UE can support one or more IoT or MTC applications. Some examples of MTC applications are shown in the following table (Source: 3GPP TS 22.368 V 13.1.0, Annex B, the content of which is incorporated herein by reference). This list is not exhaustive and is intended to show some examples of machine type communication applications.

[0153]

Table 1

[0154] Applications, services, and solutions can include MVNO (Mobile Virtual Network Operator) services, emergency wireless communication systems, PBX (Private Branch eXchange) systems, PHS / digital cordless communication systems, POS (Point of Sale) systems, advertise calling systems, MBMS (Multimedia Broadcast Multicast Service), V2X (Vehicle to Everything) systems, train wireless systems, location-based services, disaster / emergency wireless communication services, community services, video streaming services, femtocell application services, VoLTE (Voice over LTE) services, charging services, radio on-demand services, roaming services, activity monitoring services, telecommunications carrier / communication NW selection services, function-limited services, PoC (Proof of Concept) services, personal information management services, ad hoc network / DTN (Delay Tolerant Networking) services, and the like. Also, the above-described UE categories are merely application examples of the technical ideas and embodiments described in this specification. Of course, these technical ideas and embodiments are not limited to the above-described UEs, and various modifications are possible.

[0155] Although the present disclosure has been particularly shown and described with reference to its exemplary embodiments, the present disclosure is not limited to these embodiments. It will be understood by those skilled in the art that various changes in form and detail can be made without departing from the spirit and scope of the disclosure as defined by this specification. For example, the above embodiments are not limited to 5GS and are also applicable to communication systems other than 5GS.

[0156] Some or all of the above embodiments may be described as follows, but are not limited thereto.

[0157] (Appendix 1) A method for a user equipment (UE) to store a first key, comprising: calculating a second key; sending an authentication response message; starting a timer based on the sending of the authentication response message; when the UE does not receive an authentication rejection message and the timer expires, deleting the first key; when the UE does not receive an authentication rejection message and the timer expires, enabling the second key; when the UE receives the authentication rejection message while the timer is running, deleting the second key; when the UE receives the authentication rejection message while the timer is running, enabling the first key; A method comprising the above.

[0158] (Appendix 2) When the timer is running and a predetermined process is being performed, further comprising using the first key and the second key for the predetermined process. The method according to Appendix 1.

[0159] (Appendix 3) When the security check of the predetermined process passes by using the second key, deleting the first key; When the security check passes by using the second key, enabling the second key; When the security check passes by using the first key, deleting the second key; When the security check passes by using the first key, enabling the first key; A method comprising the above. The method described in Supplementary Note 2.

[0160] (Supplementary Note 4) A method for a user equipment (UE), transmitting first information indicating that the UE supports receiving a message to a network device, calculating a first key, receiving second information indicating that the network device supports transmitting the message from the network device, calculating a second key, transmitting an authentication response message, when the UE supports receiving the message, receiving the message, when the message is received, deleting the first key, when the message is received, enabling the second key, A method including the above.

[0161] (Supplementary Note 5) A method for a network device, receiving first information indicating that a user equipment (UE) supports receiving a message from the UE, transmitting second information indicating that the network device supports transmitting the message to the UE, receiving an authentication response message, when the UE supports receiving the message, transmitting a message indicating the validity of the key, A method including the above.

[0162] (Supplementary Note 6) A user equipment (UE) storing a first key, means for calculating a second key, means for transmitting an authentication response message, means for starting a timer based on the transmission of the authentication response message, means for deleting the first key when the UE does not receive an authentication rejection message and the timer expires; means for enabling the second key when the UE does not receive an authentication rejection message and the timer expires; means for deleting the second key when the UE receives the authentication rejection message while the timer is running; means for enabling the first key when the UE receives the authentication rejection message while the timer is running; A UE comprising the above.

[0163] (Appendix 7) further comprising means for using the first key and the second key for the predetermined process when the timer is running and the predetermined process is being performed; The UE according to Appendix 6.

[0164] (Appendix 8) means for deleting the first key when the security check of the predetermined process is passed by using the second key; means for enabling the second key when the security check is passed by using the second key; means for deleting the second key when the security check is passed by using the first key; means for enabling the first key when the security check is passed by using the first key; comprising the above; The UE according to Appendix 7.

[0165] (Appendix 9) A user equipment (UE), means for transmitting first information indicating that the UE supports receiving messages to a network device; means for calculating a first key; Means for receiving, from the network device, second information indicating that the network device supports transmitting the message; Means for calculating a second key; Means for transmitting an authentication response message; Means for receiving the message if the UE supports receiving the message; Means for deleting the first key when the message is received; Means for enabling the second key when the message is received; A UE comprising the above.

[0166] (Appendix 10) A network device, comprising: Means for receiving, from the UE, first information indicating that the user equipment (UE) supports receiving a message; Means for transmitting, to the UE, second information indicating that the network device supports transmitting the message; Means for receiving an authentication response message; Means for transmitting a message indicating the validity of a key if the UE supports receiving the message; A network device comprising the above.

[0167] (Appendix 11) A method for a user equipment (UE), comprising: Calculating a key; Transmitting an authentication response message; Starting a timer based on the transmission of the authentication response message; Enabling the key if the UE does not receive an authentication rejection message and the timer expires; Deleting the key if the UE receives the authentication rejection message while the timer is running; A method comprising the above.

[0168] (Appendix 12) When the timer is running and a predetermined process is being performed, further including using the key for the predetermined process. The method according to Supplementary Note 11.

[0169] (Supplementary Note 13) When the security check of the predetermined process fails by using the key, deleting the key; When the security check is passed by using the key, validating the key; Further including. The method according to Supplementary Note 12.

[0170] (Supplementary Note 14) A method for a user equipment (UE), Transmitting first information indicating that the UE supports receiving a message to a network device; Calculating a key; Receiving second information indicating that the network device supports transmitting the message from the network device; Transmitting an authentication response message; When the UE supports receiving the message, receiving the message; When the message is received, validating the key; A method including.

[0171] (Supplementary Note 15) A user equipment (UE), Means for calculating a key; Means for transmitting an authentication response message; Means for starting a timer based on the transmission of the authentication response message; Means for validating the key when the UE does not receive an authentication rejection message and the timer expires; Means for deleting the key when the UE receives the authentication rejection message while the timer is running. A UE comprising

[0172] (Appendix 16) When the timer is running and a predetermined process is being performed, further comprising means for using the key for the predetermined process The UE according to Appendix 15

[0173] (Appendix 17) When the security check of the predetermined process fails by using the key, means for deleting the key When the security check is passed by using the key, means for enabling the key Further comprising The UE according to Appendix 16

[0174] (Appendix 18) A user equipment (UE) comprising Means for transmitting first information indicating that the UE supports receiving a message to a network device Means for calculating a key Means for receiving second information indicating that the network device supports transmitting the message from the network device Means for transmitting an authentication response message When the UE supports receiving the message, means for receiving the message When the message is received, means for enabling the key A UE comprising

[0175] (Appendix 19) A method for a user equipment (UE) to store a first key, comprising Calculating a second key during an authentication procedure Transmitting an authentication response message Detecting a radio link failure When the wireless link failure is detected, sending a message indicating that the authentication procedure has not been completed; executing the authentication procedure; When the authentication procedure is completed, deleting the first key; When the authentication procedure is completed, enabling the second key; A method including the above.

[0176] (Appendix 20) A method for a user equipment (UE) storing a first key, comprising: calculating a second key during an authentication procedure; sending an authentication response message; detecting a wireless link failure; When the wireless link failure is detected, sending a first message indicating that the authentication procedure has not been completed; receiving a second message indicating whether the first key or the second key is valid; When the second message indicates that the second key is valid, deleting the first key; When the second message indicates that the second key is valid, enabling the second key; When the second message indicates that the first key is valid, deleting the second key; When the second message indicates that the first key is valid, enabling the first key; A method including the above.

[0177] (Appendix 21) The first message includes a list including the first key and the second key, The method further includes: when the first message includes the list, receiving a third message indicating whether the first key or the second key is valid; when the third message indicates that the second key is valid, deleting the first key; When the third message indicates that the second key is valid, enabling the second key, and When the third message indicates that the first key is valid, deleting the second key, and When the third message indicates that the first key is valid, enabling the first key, and further comprising the method according to Appendix 20.

[0178] (Appendix 22) The first message includes a list containing first information related to the first key and second information related to the second key, The method includes when the first message includes the list, receiving a third message indicating the first information or the second information, and when the third message indicates the second information, deleting the first key, and when the third message indicates the second information, enabling the second key, and when the third message indicates the first information, deleting the second key, and when the third message indicates the first information, enabling the first key, and the method according to Appendix 20.

[0179] (Appendix 23) A method for a user equipment (UE) to store a first key, comprising calculating a second key during a first authentication procedure, and sending an authentication response message, and starting a timer based on the sending of the authentication response message, and when the timer expires, sending a first message indicating that the first authentication procedure is not completed, and performing a second authentication procedure, and when the second authentication procedure is completed, deleting the first key, When the second authentication procedure is completed, enabling the second key, and A method including.

[0180] (Appendix 24) A method of an Access and Mobility Management Function (AMF), comprising: Performing a first authentication procedure, and Receiving a message indicating that the first authentication procedure has not been completed, and When the message is received, performing a second authentication procedure to indicate the validity of the key, and A method including.

[0181] (Appendix 25) A method of an Access and Mobility Management Function (AMF), comprising: Performing a procedure for authentication, and During the procedure, transmitting a first message indicating the validity of the key, and Receiving a second message indicating that the procedure has not been completed, and When the second message is received, transmitting the first message, and A method including.

[0182] (Appendix 26) A method of a User Equipment (UE) for storing a first key, comprising: Calculating a second key, and Performing a first process based on the first key, and When the first process based on the first key is completed, enabling the first key, and When the first process based on the first key is completed, deleting the second key, and Performing a second process based on the second key, and When the second process based on the second key is completed, enabling the second key, and When the second process based on the second key is completed, deleting the first key, and A method including.

[0183] (Appendix 27) A method for a user equipment (UE) to store a first key, comprising: Receiving a first authentication request message; Calculating a second key; Receiving a second authentication request message; Sending an authentication response message; Receiving a message indicating the validity of the second key; If the message is received, enabling the second key; If the message is received, deleting the first key; A method comprising the above steps.

[0184] (Appendix 28) A method for an access and mobility management function (AMF), comprising: Sending a first authentication request message; Starting a timer based on the sending of the first authentication request message; If the timer expires, sending a second authentication request message; Receiving an authentication response message; Sending a message indicating the validity of a key; A method comprising the above steps.

[0185] (Appendix 29) Detecting a radio link failure; If the radio link failure is detected while the timer is running, sending the second authentication request message; Further comprising the above steps, The method according to Appendix 28.

[0186] (Appendix 30) A method for a user equipment (UE) to store a first key, comprising: During a first authentication procedure, receiving a first authentication request message; Calculating a second key; Execute the second authentication procedure, and When the second authentication procedure is completed, enable a third key, and including The third key is created in the second authentication procedure Method

[0187] (Appendix 31) A method for an Access and Mobility Management Function (AMF), comprising During a first authentication procedure, sending a first authentication request message, and Based on the sending of the first authentication request message, starting a timer, and When the timer expires, executing a second authentication procedure to indicate the validity of a key, and A method including

[0188] (Appendix 32) A user equipment (UE) for storing a first key, comprising Means for calculating a second key during an authentication procedure, and Means for sending an authentication response message, and Means for detecting a radio link failure, and When the radio link failure is detected, means for sending a message indicating that the authentication procedure is not completed, and Means for executing the authentication procedure, and When the authentication procedure is completed, means for deleting the first key, and When the authentication procedure is completed, means for enabling the second key, and A UE comprising

[0189] (Appendix 33) A user equipment (UE) for storing a first key, comprising Means for calculating a second key during an authentication procedure, and Means for sending an authentication response message, and Means for detecting a radio link failure, and means for transmitting a first message indicating that the authentication procedure has not been completed when the wireless link failure is detected; means for receiving a second message indicating whether the first key or the second key is valid; means for deleting the first key when the second message indicates that the second key is valid; means for enabling the second key when the second message indicates that the second key is valid; means for deleting the second key when the second message indicates that the first key is valid; means for enabling the first key when the second message indicates that the first key is valid; A UE comprising:

[0190] (Appendix 34) The first message includes a list including the first key and the second key, The UE means for receiving a third message indicating whether the first key or the second key is valid when the first message includes the list; means for deleting the first key when the third message indicates that the second key is valid; means for enabling the second key when the third message indicates that the second key is valid; means for deleting the second key when the third message indicates that the first key is valid; means for enabling the first key when the third message indicates that the first key is valid; comprising the UE according to Appendix 33.

[0191] (Appendix 35) The first message includes a list including first information related to the first key and second information related to the second key, The UE means for receiving a third message indicating the first information or the second information when the first message includes the list; means for deleting the first key when the third message indicates the second information; means for enabling the second key when the third message indicates the second information; means for deleting the second key when the third message indicates the first information; means for enabling the first key when the third message indicates the first information; comprising; the UE according to Appendix 33.

[0192] (Appendix 36) A user equipment (UE) for storing a first key, means for calculating a second key during a first authentication procedure; means for transmitting an authentication response message; means for starting a timer based on the transmission of the authentication response message; means for transmitting a first message indicating that the first authentication procedure is not completed when the timer expires; means for executing a second authentication procedure; means for deleting the first key when the second authentication procedure is completed; means for enabling the second key when the second authentication procedure is completed; A UE comprising.

[0193] (Appendix 37) An access and mobility management function (AMF), means for executing a first authentication procedure; means for receiving a message indicating that the first authentication procedure is not completed; means for executing a second authentication procedure to indicate the validity of the key when the message is received; An AMF comprising.

[0194] (Appendix 38) An access and mobility management function (AMF) comprising: means for performing procedures for authentication; means for transmitting a first message indicating the validity of a key during said procedures; means for receiving a second message indicating that said procedures are not complete; means for transmitting said first message when said second message is received; The AMF.

[0195] (Appendix 39) A user equipment (UE) for storing a first key, comprising: means for calculating a second key; means for performing a first process based on said first key; means for validating said first key when said first process based on said first key is completed; means for deleting said second key when said first process based on said first key is completed; means for performing a second process based on said second key; means for validating said second key when said second process based on said second key is completed; means for deleting said first key when said second process based on said second key is completed; The UE.

[0196] (Appendix 40) A user equipment (UE) for storing a first key, comprising: means for receiving a first authentication request message; means for calculating a second key; means for receiving a second authentication request message; means for transmitting an authentication response message; means for receiving a message indicating the validity of said second key; means for validating said second key when said message is received; means for deleting said first key when said message is received; A UE comprising

[0197] (Appendix 41) An access and mobility management function (AMF) comprising Means for sending a first authentication request message Means for starting a timer based on the sending of the first authentication request message Means for sending a second authentication request message when the timer expires Means for receiving an authentication response message Means for sending a message indicating the validity of a key An AMF comprising

[0198] (Appendix 42) Means for detecting a radio link failure Means for sending the second authentication request message when the radio link failure is detected while the timer is running The AMF according to Appendix 41, further comprising

[0199] (Appendix 43) A user equipment (UE) for storing a first key, comprising Means for receiving a first authentication request message during a first authentication procedure Means for calculating a second key Means for executing a second authentication procedure Means for enabling a third key when the second authentication procedure is completed Comprising The third key is created in the second authentication procedure A UE

[0200] (Appendix 44) An access and mobility management function (AMF) comprising Means for sending a first authentication request message during a first authentication procedure Means for starting a timer based on the sending of the first authentication request message means for executing a second authentication procedure to indicate the validity of the key when the timer expires; An AMF comprising the same.

[0201] (Appendix 45) A method for a user equipment (UE), comprising: calculating a key during an authentication procedure; sending an authentication response message; detecting a radio link failure; when the radio link failure is detected, sending a first message indicating that the authentication procedure is not completed; executing the authentication procedure; when the authentication procedure is completed, validating the key; A method including the above.

[0202] (Appendix 46) A method for a user equipment (UE), comprising: calculating a key during an authentication procedure; sending an authentication response message; detecting a radio link failure; when the radio link failure is detected, sending a first message indicating that the authentication procedure is not completed; receiving a second message indicating whether the key is valid; when the second message indicates that the key is not valid, deleting the key; when the second message indicates that the key is valid, validating the key; A method including the above.

[0203] (Appendix 47) The first message includes the key, The method further includes: when the first message includes the key, receiving a third message indicating whether the key is valid; If the third message indicates that the key is not valid, deleting the key; If the third message indicates that the key is valid, enabling the key; further comprising the method according to appendix 46.

[0204] (Appendix 48) The first message includes information related to the key, The method receiving a third message for indicating the information; if the third message does not indicate the information, deleting the key; if the third message indicates the information, enabling the key; further comprising the method according to appendix 46.

[0205] (Appendix 49) A method for a user equipment (UE), calculating a first key during a first authentication procedure; sending an authentication response message; starting a timer based on the sending of the authentication response message; if the timer expires, sending a first message indicating that the first authentication procedure is not completed; executing a second authentication procedure; if the second authentication procedure is completed, enabling a second key; including wherein the second key is created in the second authentication procedure, method.

[0206] (Appendix 50) A method for a user equipment (UE), calculating a key; executing a process based on the key; if the process based on the key is completed, enabling the key; When the process based on the key is completed, deleting the key; A method including

[0207] (Appendix 51) A method of a user equipment (UE), comprising: Receiving a first authentication request message; Calculating a key; Sending a first authentication response message; Receiving a second authentication request message; Sending a second authentication response message; Receiving a message indicating the validity of the key; When the message is received, validating the key; A method including

[0208] (Appendix 52) A method of a user equipment (UE), comprising: During a first authentication procedure, receiving a first authentication request message; Calculating a first key; Performing a second authentication procedure; When the second authentication procedure is completed, validating a second key; Including The second key is created in the second authentication procedure; A method

[0209] (Appendix 53) A user equipment (UE), comprising: Means for calculating a key during an authentication procedure; Means for sending an authentication response message; Means for detecting a radio link failure; When the radio link failure is detected, means for sending a first message indicating that the authentication procedure is not completed; Means for performing the authentication procedure; When the authentication procedure is completed, means for validating the key; A UE comprising

[0210] (Appendix 54) A user equipment (UE) means for calculating a key during an authentication procedure; sending an authentication response message; means for detecting a radio link failure; means for sending a first message indicating that the authentication procedure is not completed when the radio link failure is detected; means for receiving a second message indicating whether the key is valid; means for deleting the key if the second message indicates that the key is not valid; means for enabling the key if the second message indicates that the key is valid; A UE comprising

[0211] (Appendix 55) The first message includes the key, The UE means for receiving a third message indicating whether the key is valid when the first message includes the key; means for deleting the key if the third message indicates that the key is not valid; means for enabling the key if the third message indicates that the key is valid; further comprising the UE according to Appendix 54.

[0212] (Appendix 56) The first message includes information related to the key, The UE means for receiving a third message for indicating the information; means for deleting the key if the third message does not indicate the information; means for enabling the key if the third message indicates the information; further comprising The UE described in Supplementary Note 54.

[0213] (Supplementary Note 57) A user equipment (UE), means for calculating a first key during a first authentication procedure; means for transmitting an authentication response message; means for starting a timer based on the transmission of the authentication response message; means for transmitting a first message indicating that the first authentication procedure is not completed when the timer expires; means for executing a second authentication procedure; means for validating a second key when the second authentication procedure is completed; comprising the second key is created in the second authentication procedure, UE.

[0214] (Supplementary Note 58) A user equipment (UE), means for calculating a key; means for executing a process based on the key; means for validating the key when the process based on the key is completed; means for deleting the key when the process based on the key is completed; UE comprising.

[0215] (Supplementary Note 59) A user equipment (UE), means for receiving a first authentication request message; means for calculating a key; means for transmitting a first authentication response message; means for receiving a second authentication request message; means for transmitting a second authentication response message; means for receiving a message indicating the validity of the key; means for validating the key when the message is received; UE comprising.

[0216] (Appendix 60) A user equipment (UE) comprising: means for receiving a first authentication request message during a first authentication procedure; means for calculating a first key; means for performing a second authentication procedure; means for enabling a second key when the second authentication procedure is completed; comprising: wherein the second key is created in the second authentication procedure; UE.

[0217] All or part of the embodiments disclosed above can be described as follows, but are not limited thereto.

[0218] 3GPP TS 33.501 v16.4.0

[0219] 6.1.2 Initiation of authentication and selection of authentication method The initiation of primary authentication is shown in Figure 6.1.2-1 (see Figure 13 of this specification). The SEAF may initiate authentication with the UE during any procedure for establishing a signalling connection with the UE according to the SEAF's policy. The UE shall use the SUCI or 5G-GUTI in the Registration Request. If the UE supports the reception of an Authentication Result message, the UE shall include a capability indicating support for the reception of authentication results. The SEAF shall invoke the Nausf_UEAuthentication service by sending an Nausf_UEAuthentication_Authenticate Request message to the AUSF each time the SEAF attempts to initiate authentication. The Nausf_UEAuthentication_Authenticate Request message shall include any of the following: - The SUCI defined in the current specification, or - The SUPI defined in TS 23.501 [2]. When the SEAF re - authenticates the UE with a valid 5G - GUTI, the SEAF shall include the SUPI in the Nausf_UEAuthentication_Authenticate Request message. Otherwise, the SUCI shall be included in the Nausf_UEAuthentication_Authenticate Request. The SUPI / SUCI structure is part of the stage 3 protocol design. The Nausf_UEAuthentication_Authenticate Request shall further include the following. - The serving network name defined in clause 6.1.1.4 of this document. Note 2: The local policy for selecting the authentication method does not have to be UE - specific and can be the same for all UEs.

[0220] Upon receiving the Nausf_UEAuthentication_Authenticate Request message, the AUSF shall verify that the requesting SEAF in the serving network has the right to use the serving network name in the Nausf_UEAuthentication_Authenticate Request by comparing the serving network name with the expected serving network name. The AUSF shall temporarily store the received serving network name. If the serving network is not authorized to use that serving network name, the AUSF shall respond with "serving network not authorized" in the Nausf_UEAuthentication_Authenticate Response. The Nudm_UEAuthentication_Get Request sent from the AUSF to the UDM contains the following information. - SUCI or SUPI; - Serving network name; Upon receiving the Nudm_UEAuthentication_Get Request, if the UDM has received an SUCI, it shall call the SIDF. Before the UDM processes the request, the SIDF shall de-conceal the SUCI to obtain the SUPI. The UDM / ARPF selects an authentication method based on the SUPI. Note 3: The Nudm_UEAuthentication_Get Response, which is a response to the Nudm_UEAuthentication_Get Request, and the Nausf_UEAuthentication_Authenticate Response message, which is a response to the Nausf_UEAuthentication_Authenticate Request message, are described as part of the authentication procedure in subclause 6.1.3.

[0221] 3GPP TS 33.501 v16.4.0

[0222] 6.1.3.2.0 5G AKA 5G AKA enhances EPS AKA

[10] by providing the home network with proof of successful authentication of the UE from the visited network. That proof is sent in the Authentication Confirmation message from the visited network. The selection of the use of 5G AKA is described in subclause 6.1.2 of this document. Note 1: 5G AKA does not support requiring multiple 5G AVs, nor does it support the SEAF pre-fetching of 5G AVs from the home network for future use. Figure 6.1.3.2-1: 5G AKA Authentication Procedure (see Figure 14 of this specification)

[0223] The 5G AKA authentication procedure operates as follows. Also, refer to Figure 6.1.3.2-1 (see Figure 14 of this specification). 1. For each Nudm_Authenticate_Get Request, the UDM / ARPF shall create a 5G HE AV. The UDM / ARPF shall do this by generating an AV with the authentication management field (AMF: Authentication Management Field) separation bit set to '1' as defined in TS 33.102 [9]. Next, the UDM / ARPF shall derive K AUSF (according to Annex A.2) and calculate XRES* (according to Annex A.4). Finally, the UDM / ARPF shall create a 5G HE AV from RAND, AUTN, XRES*, and K AUSF .

[0224] 2. Then, the UDM shall return the 5G HE AV to the AUSF, along with an indication that the 5G HE AV is to be used for 5G AKA in the Nudm_UEAuthentication_Get Response. If the SUCI is included in the Nudm_UEAuthentication_Get Request, the UDM shall include the SUPI in the Nudm_UEAuthentication_Get Response after decrypting the SUCI by the SIDF. If the subscriber has an AKMA subscription, the UDM shall include an AKMA indication in the Nudm_UEAuthentication_Get Response.

[0225] 3. The AUSF shall temporarily hold XRES* together with the received SUCI or SUPI.

[0226] 4. Thereafter, the AUSF shall calculate HXRES* (according to Annex A.5) from XRES*, and calculate K AUSF from K SEAF (according to Annex A.6), and in the 5G HE AV, replace XRES* with HXRES*, and replace K AUSF with K SEAF to generate 5G AV from the 5G HE AV received from the UDM / ARPF.

[0227] 5. Thereafter, the AUSF shall remove KSEAF and return the 5G SE AV (RAND, AUTN, HXRES*) to the SEAF in the Nausf_UEAuthentication_Authenticate Response.

[0228] 6. The SEAF shall send RAND and AUTN to the UE in the NAS message Authentication Request. This message shall include the ngKSI used by the UE and the AMF to identify K AMF and the partial native security context created if the authentication is successful. This message shall also include the ABBA parameter. The SEAF shall set the ABBA parameter defined in Annex A.7.1. The ME shall transfer the RAND and AUTN received in the NAS message Authentication Request to the USIM. Note 2: The ABBA parameter is included to enable bidding down protection of security features.

[0229] 7. When receiving RAND and AUTN, the USIM verifies the freshness of the received values by checking whether the AUTN can be accepted as described in TS 33.102 [9]. In that case, the USIM calculates the response RES. The USIM returns RES, CK, and IK to the ME. If the USIM calculates Kc (i.e., GPRS Kc) from CK and IK using the conversion function c3 described in TS 33.102 [9] and transmits it to the ME, the ME shall ignore such GPRS Kc and shall not store GPRS Kc in the USIM or the ME. The ME shall calculate RES* from RES in accordance with Annex A.4. The ME shall calculate K from CK||IK in accordance with Section A.2. The ME shall calculate K from K in accordance with Section A.6. The ME accessing 5G shall confirm during authentication that the "separation bit" in the AMF field of the AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of the AUTN. AUSF shall be calculated. The ME shall calculate K from K in accordance with Section A.6. AUSF from K SEAF shall be calculated. The ME accessing 5G shall confirm during authentication that the "separation bit" in the AMF field of the AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of the AUTN. Note 3: This separation bit in the AMF field of the AUTN cannot be used for operator-specific purposes as described in Annex F of TS 33.102 [9].

[0230] 8. The UE returns RES* to the SEAF in the NAS message Authentication Response.

[0231] 9. Subsequently, the SEAF calculates HRES* from RES* in accordance with Annex A.5, and the SEAF compares HRES* with HXRES*. If they match, the SEAF shall consider the authentication to be successful from the perspective of the serving network. Otherwise, the SEAF shall proceed as described in Section 6.1.3.2.2. If the SEAF does not reach the UE and does not receive RES*, the SEAF shall consider the authentication to have failed and indicate the failure to the AUSF.

[0232] 10. SEAF shall send the RES* received from the UE to the AUSF in the Nausf_UEAuthentication_Authenticate Request message.

[0233] 11. When the AUSF receives the Nausf_UEAuthentication_Authenticate Request message containing RES* as an authentication confirmation, it may check whether the expiration date of the 5G AV has passed. If the expiration date of the 5G AV has passed, the AUSF may consider the authentication to have failed from the perspective of the home network. If the authentication is successful, the AUSF shall hold K AUSF . The AUSF shall compare the received RES* with the held XRES*. If RES* and XRES* are equal, the AUSF shall consider the authentication to have been successful from the perspective of the home network. The AUSF shall notify the UDM of the authentication result (see Section 6.1.4 of this document for cooperation with authentication confirmation).

[0234] 12. The AUSF shall indicate to the SEAF in the Nausf_UEAuthentication_Authenticate Response whether the authentication has been successful from the perspective of the home network. If the authentication is successful, K SEAF shall be sent to the SEAF in the Nausf_UEAuthentication_Authenticate Response. If the AUSF receives the SUCI from the SEAF in the authentication request (see Section 6.1.2 of this document) and the authentication is successful, the AUSF shall also include the SUPI in the Nausf_UEAuthentication_Authenticate Response message.

[0235] If the authentication is successful, the key K received in the Nausf_UEAuthentication_Authenticate Response message SEAF Shall be the anchor key in the sense of the key hierarchy defined in clause 6.2 of this document. Thereafter, SEAF shall, in accordance with Annex A.7, derive K SEAF , the ABBA parameter and the SUPI from K AMF . SEAF shall provide ngKSI and K AMF to the AMF.

[0236] If the SUCI is used for this authentication, after SEAF receives the Nausf_UEAuthentication_Authenticate Response message including K SEAF and the SUPI, SEAF shall provide only ngKSI and K AMF to the AMF, and the communication service shall not be provided to the UE until the SUPI is recognized by the serving network. The further procedures taken by the AUSF after the authentication procedure are described in clause 6.1.4 of this document.

[0237] 3GPP TS 33.501

[0238] 6.1.3.2.0 5G AKA 5G AKA enhances EPS AKA

[10] by providing the home network with proof of the normal authentication of the UE from the visited network. This proof is sent by the visited network in the Authentication Confirmation message.

[0239] The selection of the use of 5G AKA is described in clause 6.1.2 of this document. Note 1: 5G AKA does not support the requirements of multiple 5G AVs, and SEAF does not pre-fetch 5G AVs from the home network for future use.

[0240] Figure 6.1.3.2-1: 5G AKA authentication procedure (see Figure 15 of this specification) The 5G AKA authentication procedure operates as follows. Also, refer to Figure 6.1.3.2-1 (see Figure 15 in this specification).

[0241] 1. For each Nudm_Authenticate_Get Request, the UDM / ARPF shall create a 5G HE AV. The UDM / ARPF shall do this by generating an AV with the separation bit of the authentication management field (AMF: Authentication Management Field) set to '1' as defined in TS 33.102 [9]. Next, the UDM / ARPF shall derive K AUSF (according to Annex A.2) and calculate XRES* (according to Annex A.4). Finally, the UDM / ARPF shall create a 5G HE AV from RAND, AUTN, XRES*, and K AUSF .

[0242] 2. Then, the UDM shall return the 5G HE AV to the AUSF, together with an indication that the 5G HE AV is to be used for 5G AKA in the Nudm_UEAuthentication_Get Response. If the SUCI is included in the Nudm_UEAuthentication_Get Request, the UDM shall include the SUPI in the Nudm_UEAuthentication_Get Response after decrypting the SUCI by the SIDF. If the subscriber has an AKMA subscription, the UDM shall include an AKMA indication in the Nudm_UEAuthentication_Get Response.

[0243] 3. The AUSF shall temporarily hold XRES* together with the received SUCI or SUPI.

[0244] 4. Then, the AUSF shall calculate HXRES* (according to Annex A.5) from XRES* and K AUSF from K SEAF Calculate according to (Annex A.6), and in 5G HE AV, replace XRES* with HXRES*, and K AUSF Replace K SEAF with K

[0245] 5. Then, the AUSF removes KSEAF and returns 5G SE AV (RAND, AUTN, HXRES*) to the SEAF in the Nausf_UEAuthentication_Authenticate Response.

[0246] 6. The SEAF sends RAND and AUTN to the UE in the NAS message Authentication Request. This message shall include the ngKSI used by the UE and the AMF to identify K AMF and the partial native security context created when authentication is successful. This message shall also include the ABBA parameter. The SEAF shall set the ABBA parameter defined in Annex A.7.1. The ME shall transfer the RAND and AUTN received in the NAS message Authentication Request to the USIM. Note 2: The ABBA parameter is included to enable bidding down protection of security features.

[0247] 7. When receiving RAND and AUTN, the USIM verifies the freshness of the received values by checking whether the AUTN can be accepted as described in TS 33.102 [9]. In that case, the USIM calculates the response RES. The USIM returns RES, CK, and IK to the ME. If the USIM calculates Kc (i.e., GPRS Kc) from CK and IK using the conversion function c3 described in TS 33.102 [9] and sends it to the ME, the ME shall ignore such GPRS Kc and shall not store GPRS Kc in the USIM or the ME. The ME shall calculate RES* from RES in accordance with Annex A.4. The ME shall calculate K from CK||IK in accordance with Section A.2. The ME shall calculate K from K in accordance with Section A.6. The ME accessing 5G shall confirm during authentication that the "separation bit" in the AMF field of AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of AUTN. AUSF shall be calculated. The ME shall calculate K from K in accordance with Section A.6. The ME accessing 5G shall confirm during authentication that the "separation bit" in the AMF field of AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of AUTN. AUSF from K SEAF shall be calculated. The ME accessing 5G shall confirm during authentication that the "separation bit" in the AMF field of AUTN is set to 1. The "separation bit" is bit 0 of the AMF field of AUTN. Note 3: This separation bit in the AMF field of AUTN cannot be used for operator-specific purposes as described in TS 33.102 [9], Annex F.

[0248] 8. The UE returns RES* to the SEAF in the NAS message Authentication Response. The UE shall start timer T. While timer T is running, the K created in step 7 shall not be regarded as the latest K, and K shall not be used in security-related procedures related to K. If timer T expires and the UE does not receive a NAS message such as Authentication Reject indicating that the authentication procedure has failed, the UE shall set that K as the latest K, and in subsequent security procedures related to K, that K AUSF shall not be regarded as the latest K AUSF and K AUSF shall not be used in security-related procedures related to K AUSF . If timer T expires and the UE does not receive a NAS message such as Authentication Reject indicating that the authentication procedure has failed, the UE shall set that K as the latest K, and in subsequent security procedures related to K, that K AUSF shall be set as the latest K AUSF and in subsequent security procedures related to K AUSF , that K AUSF It is assumed to be used. If the UE encounters a radio link failure before the timer expires, the UE shall stop the timer and the UE shall not use the KAUSF. When the next NAS signaling connection is successfully established, the UE shall start using K AUSF and set K AUSF to the latest K AUSF . If the establishment of the next NAS signaling connection fails due to the failure of the last authentication procedure (for example, when the UE receives a NAS message indicating the failure of the authentication procedure from the AMF (5GMM cause#3 illegal UE)), the UE shall consider K AUSF as invalid and the UE shall delete K AUSF .

[0249] 9. Then, the SEAF shall calculate HRES* from RES* in accordance with Annex A.5, and the SEAF shall compare HRES* with HXRES*. If they match, the SEAF shall consider the authentication as successful from the perspective of the serving network. Otherwise, the SEAF shall proceed as described in paragraph 6.1.3.2.2. If the SEAF fails to reach the UE and does not receive RES*, the SEAF shall consider the authentication as failed and indicate the failure to the AUSF.

[0250] 10. The SEAF shall send the RES* received from the UE to the AUSF in the Nausf_UEAuthentication_Authenticate Request message.

[0251] 11. When the AUSF receives the Nausf_UEAuthentication_Authenticate Request message containing RES* as an authentication confirmation, it may check whether the expiration date of the 5G AV has passed. If the expiration date of the 5G AV has passed, the AUSF may consider the authentication as failed from the perspective of the home network. If the authentication is successful, the AUSF shall use K AUSF It is assumed to be retained. The AUSF shall compare the received RES* with the retained XRES*. If RES* and XRES* are equal, the AUSF shall consider the authentication to be successful from the perspective of the home network. The AUSF shall notify the UDM of the authentication result (see clause 6.1.4 of this document for the coordination with authentication confirmation).

[0252] 12. The AUSF shall indicate to the SEAF in the Nausf_UEAuthentication_Authenticate Response whether the authentication has been successful from the perspective of the home network. If the authentication is successful, K SEAF shall be sent to the SEAF in the Nausf_UEAuthentication_Authenticate Response. If the AUSF receives the SUCI from the SEAF in the authentication request (see clause 6.1.2 of this document) and the authentication is successful, the AUSF shall also include the SUPI in the Nausf_UEAuthentication_Authenticate Response message.

[0253] If the authentication is successful, the key K received in the Nausf_UEAuthentication_Authenticate Response message SEAF shall be the anchor key in the sense of the key hierarchy defined in clause 6.2 of this document. Thereafter, the SEAF shall derive K SEAF , the ABBA parameter and the SUPI from K AMF shall be derived. The SEAF shall provide ngKSI and K AMF to the AMF.

[0254] If the SUCI is used for this authentication, after receiving the Nausf_UEAuthentication_Authenticate Response message containing K SEAF and the SUPI, the SEAF shall provide ngKSI and K AMF The communication service is not provided to the UE until only SUPI is provided and recognized by the serving network. The further procedures taken by the AUSF after the authentication procedure are described in section 6.1.4 of this document.

[0255] 3GPP TS 24.501

[0256] 5.4.1.3.7 Abnormal cases a) Lower layer failure. If a lower layer failure is detected before the AUTHENTICATION RESPONSE message is received, the network shall continue to run timer T3560 if it is running.

[0257] b) Expiry of timer T3560. When the first expiry of timer T3560 occurs, the network shall retransmit the authentication request message, reset and start timer T3560. This retransmission shall be repeated 4 times, i.e., when the 5th expiry of timer T3560 occurs, the network shall abort the 5G AKA-based mutual authentication and key agreement procedure and the ongoing 5GMM-specific procedure, and release the N1 NAS signaling connection.

[0258] c) Authentication failure (5GMM cause #20 "MAC failure"). The UE shall send an AUTHENTICATION FAILURE message due to 5GMM cause #20 "MAC failure" in accordance with item 5.4.1.3.6 to the network and start timer T3520 (see the example in Figure 5.4.1.3.7.1). Further, the UE shall stop the retransmission timers in operation (e.g., T3510, T3517, T3521). When receiving the AUTHENTICATION FAILURE message with 5GMM cause #20 "MAC failure" from the UE for the first time, the network may start the identification procedure described in item 5.4.3. This is to enable the network to obtain the SUCI from the UE. Thereafter, the network may verify that the 5G-GUTI first used in the 5G authentication challenge corresponds to the correct SUPI. When receiving an IDENTITY REQUEST message from the network, the UE shall proceed with the processing as defined in item 5.4.3.3. Note 1: Also, when receiving an AUTHENTICATION FAILURE message with 5GMM cause #20 "MAC failure" from the UE, the network may terminate the 5G AKA-based primary authentication and key agreement procedure (see item 5.4.1.3.5).

[0259] If the mapping of the 5G-GUTI to the SUPI in the network is incorrect, the network shall respond by sending a new AUTHENTICATION REQUEST message to the UE. When the UE receives a new AUTHENTICATION REQUEST message from the network, if the timer T3520 is running, it shall stop it and process the 5G challenge information as normal. If the mapping of the 5G-GUTI to the SUPI in the network is correct, the network shall end the 5G AKA-based mutual authentication and key agreement procedure by sending an AUTHENTICATION REJECT message (see subclause 5.4.1.3.5).

[0260] If the UE successfully authenticates to the network (i.e., it receives an AUTHENTICATION REQUEST message containing a valid SQN and MAC), the UE shall send an AUTHENTICATION RESPONSE message to the network and, if a retransmission timer (e.g., T3510, T3517, T3521) was running and was stopped when the first failed AUTHENTICATION REQUEST message was received, start the retransmission timer (e.g., T3510, T3517, T3521).

[0261] If the UE receives a second AUTHENTICATION REQUEST message and is unable to resolve the MAC value, the UE shall either repeat the procedure as defined in item c of this subclause from the start or, if the message contains a UMTS authentication challenge, follow the procedure as defined in item d. If the SQN is invalid, the UE shall proceed as defined in item f.

[0262] Figure 5.4.1.3.7.1: Authentication failure during the 5G AKA-based mutual authentication and key agreement procedure (see Figure 16 of this application).

[0263] d) Authentication failure (5GMM cause #26 "non-5G authentication unacceptable"). The UE shall send an AUTHENTICATION FAILURE message with 5GMM cause #26 "non-5G authentication unacceptable" to the network and start timer T3520 (see the example in Figure 5.4.1.3.7.1). Further, the UE shall stop the ongoing retransmission timers (e.g., T3510, T3517, T3521). Upon first receiving an AUTHENTICATION FAILURE message from the UE with 5GMM cause #26 "non-5G authentication unacceptable", the network may start the identification procedure described in subclause 5.4.3. This is to enable the network to obtain the SUCI from the UE. Thereafter, the network may verify that the 5G-GUTI first used in the 5G authentication challenge corresponds to the correct SUPI. Upon receiving an IDENTITY REQUEST message from the network, the UE shall proceed with the processing as specified in subclause 5.4.3.3. Note 2: Upon receiving an AUTHENTICATION FAILURE message from the UE with 5GMM cause #26 "non-5G authentication unacceptable", the network may terminate the 5G AKA-based primary authentication and key agreement procedure (see subclause 5.4.1.3.5).

[0264] If the mapping of the 5G-GUTI to the SUPI in the network is incorrect, the network shall respond by sending a new AUTHENTICATION REQUEST message to the UE. When receiving a new AUTHENTICATION REQUEST message from the network, the UE shall stop timer T3520 if it is running and process the 5G challenge information as normal. If the mapping of the 5G-GUTI to the SUPI in the network is correct, the network shall end the 5G AKA-based initial authentication and key agreement authentication procedure by sending an AUTHENTICATION REJECT message (see subclause 5.4.1.3.5). If the network is successfully authenticated (i.e., an AUTHENTICATION REQUEST message containing a valid 5G authentication challenge is received), the UE shall send an AUTHENTICATION RESPONSE message to the network and, if a retransmission timer (e.g., T3510, T3517, T3521) was running and was stopped when the first failed AUTHENTICATION REQUEST message was received, start the retransmission timer (e.g., T3510, T3517, T3521).

[0265] e) Authentication failure (5GMM cause #71 "ngKSI already in use"). The UE sends an AUTHENTICATION FAILURE message with 5GMM cause #71 "ngKSI already in use" to the network and starts timer T3520 (see the example in Figure 5.4.1.3.7.1). Further, the UE stops the ongoing retransmission timers (e.g., T3510, T3517, T3521). When receiving for the first time an AUTHENTICATION FAILURE message with 5GMM cause #71 "ngKSI already in use" from the UE, the network performs the necessary actions to select a new ngKSI and sends the same 5G authentication challenge to the UE. Note 3: When receiving an AUTHENTICATION FAILURE message with 5GMM cause #71 "ngKSI already in use" from the UE, the network may restart the 5G AKA-based mutual authentication and key agreement procedure (see subclause 5.4.1.3.2). When receiving a new AUTHENTICATION REQUEST message from the network, the UE stops timer T3520 if it is running and processes the 5G challenge information as normal. If the network is successfully authenticated (when an AUTHENTICATION REQUEST message containing a valid ngKSI, SQN, and MAC is received), the UE sends an AUTHENTICATION RESPONSE message to the network and, if the retransmission timers (e.g., T3510, T3517, T3521) are running and were stopped when receiving the first failed AUTHENTICATION REQUEST message, starts the retransmission timers (e.g., T3510, T3517, T3521).

[0266] f) Authentication failure (5GMM cause #21 "synch failure"). The UE sends an AUTHENTICATION FAILURE message with 5GMM cause #21 "synch failure" to the network and starts timer T3520 (see the example in Figure 5.4.1.3.7.1). Further, the UE stops the ongoing retransmission timers (e.g., T3510, T3517, T3521). When receiving the AUTHENTICATION FAILURE message with 5GMM cause #21 "synch failure" from the UE for the first time, the network performs resynchronization using the AUTS parameter returned from the authentication failure parameter IE within the AUTHENTICATION FAILURE message. In the resynchronization procedure, the AMF needs to delete all unused authentication vectors for its SUPI and obtain new vectors from the UDM / AUSF. When the resynchronization is completed, the network shall start the 5G AKA-based mutual authentication and key agreement procedure. When receiving the AUTHENTICATION REQUEST message, the UE stops timer T3520 if it is running.

[0267] Note 4: When receiving two consecutive AUTHENTICATION FAILURE messages with 5GMM cause #21 "synch failure" from the UE, the network may terminate the 5G AKA-based mutual authentication and key agreement procedure by sending an AUTHENTICATION REJECT message.

[0268] If the network is successfully verified while T3520 is running (if a new AUTHENTICATION REQUEST message containing a valid SQN and MAC is received), the UE shall send the AUTHENTICATION REQUEST message to the network and, if the retransmission timer (e.g., T3510, T3517, T3521) is running and was stopped when the first failed AUTHENTICATION REQUEST message was received, start the retransmission timer (e.g., T3510, T3517, T3521). Upon receiving an AUTHENTICATION REJECT message, the UE shall perform the actions specified in subclause 5.4.1.3.5.

[0269] g) Network failing the authentication check. If the UE determines that the network has failed the authentication check, it shall request the RRC to locally release the RRC connection and treat the active cell as barred (see 3GPP TS 38.304

[28] ). If the retransmission timer (e.g., T3510, T3517, T3521) is running and was stopped when the first AUTHENTICATION REQUEST message containing the incorrect authentication challenge data that caused the authentication failure was received, the retransmission timer (e.g., T3510, T3517, T3521) shall be started.

[0270] h) Transmission failure of an AUTHENTICATION RESPONSE message or an AUTHENTICATION FAILURE message indication from the lower layer (when the 5G AKA-based primary authentication and key agreement procedure is triggered by the registration procedure for mobility and periodic registration update). If timer T3520 is running, the UE shall stop it and restart the registration procedures for mobility and periodic registration updates.

[0271] i) Transmission failure of an AUTHENTICATION RESPONSE message or an AUTHENTICATION FAILURE message indication accompanied by a TAI change from the lower layer (when the 5G AKA-based mutual authentication and key agreement procedure is triggered by a service request procedure). If timer T3520 is running, the UE shall stop it. If the current TAI is not included in the TAI list, the 5G AKA-based mutual authentication and key agreement procedure shall be aborted and the registration procedures for mobility and periodic registration updates shall be started. If the current TAI is still part of the TAI list, the method of re-executing the ongoing procedure that triggered the 5G AKA-based mutual authentication and key agreement procedure is left to the UE implementation.

[0272] j) Transmission failure of an AUTHENTICATION RESPONSE message or an AUTHENTICATION FAILURE message indication without a TAI change from the lower layer (when the authentication procedure is triggered by a service request procedure). If timer T3520 is running, the UE shall stop it. The method of re-executing the ongoing procedure that triggered the 5G AKA-based mutual authentication and key agreement procedure depends on the UE implementation.

[0273] k) Lower layers indication of non-delivered NAS PDU due to handover. If the AMF handover within the AMF causes the AUTHENTICATION REQUEST message not to be delivered and the target TA is included in the TAI list, when the AMF handover within the AMF is successfully completed, the AMF shall re - send the AUTHENTICATION REQUEST message. If the failure of the handover procedure is reported by the lower layer and there is an N1 NAS signaling connection, the AMF shall re - send the AUTHENTICATION REQUEST message.

[0274] l) Change of cell into a new tracking area. If a change of cell to a new tracking area not in the TAI list occurs before the AUTHENTICATION RESPONSE message is sent, the UE may abort the transmission of the AUTHENTICATION RESPONSE message to the network and continue with the start of the registration procedure for mobility and periodic registration as described in sub - clause 5.5.1.3.2.

[0275] Regarding items c, d, e, and f, whether the UE is registered for emergency services: When the timer is running and the UE enters the 5GMM - IDLE mode, for example, upon detection of a lower layer failure, release of the N1 NAS signaling connection, or as a result of an inter - system change from the N1 mode in 5GMM - CONNECTED mode to the S1 mode, the UE shall stop the timer T3520.

[0276] If any of the following occurs, the UE shall determine that the network has failed the authentication check or that the authentication is not legitimate and proceed with the processing as described in item g above. - The timer T3520 expires, or - The UE detects any combination of 5G authentication failures. 5G authentication failures include 5GMM causes #20 "MAC failure", #21 "synch failure", #26 "non-5G authentication unacceptable", #71 "ngKSI already in use" between three consecutive authentication challenges. If a 5G authentication challenge that caused a second or third 5G authentication failure is received by the UE while the timer T3520 started after the previous 5G authentication failure is running, the 5G authentication challenges are considered consecutive.

[0277] For items c, d, e, and f: Depending on local requirements regarding emergency services or operator preference, if the UE has an established emergency PDU session or is establishing an emergency PDU session, the AMF does not need to follow the procedures defined for authentication failures as defined in the current subclause. The AMF may respond to the AUTHENTICATION FAILURE message by selecting the "null integrity protection algorithm" 5G-IA0 and the "null ciphering algorithm" 5G-EA0 to initiate the security mode control procedure, or may interrupt the 5G AKA-based mutual authentication and key agreement procedure and continue to use the current security context (if any). If there are non-emergency PDU sessions, the AMF shall release all non-emergency PDU sessions by initiating the PDU session release procedure. If there is an ongoing PDU session establishment procedure, the AMF shall release all non-emergency PDU sessions upon completion of the PDU session establishment procedure. The network shall operate as if the UE were registered for emergency services.

[0278] If the UE is establishing or attempting to establish an emergency PDU session and sends an AUTHENTICATION FAILURE message with a 5GMM cause suitable for these cases (#20, #21, #26, or #71) to the AMF and receives a SECURITY MODE COMMAND message before the timer T3520 times out, the UE shall consider that the network has successfully passed the authentication check and shall stop the timer T3520 and execute the security mode control procedure respectively.

[0279] When the timer T3520 expires, if the UE is establishing or attempting to establish an emergency PDU session, the UE shall not consider that the network has failed the authentication check and shall not operate as described in item g. Instead, the UE shall continue to use the current security context (if any) and shall release all non-emergency PDU sessions (if any) by initiating the PDU session release procedure requested by the UE. If there is an ongoing PDU session establishment procedure, the UE shall release all non-emergency PDU sessions upon completion of the PDU session establishment procedure. The UE shall start the retransmission timers (e.g., T3510, T3517, T3521) in the following cases. - When the UE receives an AUTHENTICATION REQUEST message and detects an authentication failure and those timers are running and stopped. - When the procedures related to these timers have not been completed yet. The UE shall act as if it were registered for emergency services.

[0280] <Abbreviation> For the purposes of this document, Non-Patent Document 1 and the following abbreviations apply. The abbreviations defined in this document shall take precedence over those defined in Non-Patent Document 1 if the same abbreviation is defined in both. 5GC 5G Core Network 5GLAN 5G Local Area Network 5GS 5G System 5G-AN 5G Access Network 5G-AN PDB 5G Access Network Packet Delay Budget 5G-EIR 5G-Equipment Identity Register 5G-GUTI 5G Globally Unique Temporary Identifier 5G-BRG5G Broadband Residential Gateway 5G-CRG5G Cable Residential Gateway 5G GM 5G Grand Master 5G-RG 5G Residential Gateway 5G-S-TMSI 5G S-Temporary Mobile Subscription Identifier 5G VN 5G Virtual Network 5QI 5G QoS Identifier AF Application Function AKMA Authentication and Key Agreement for Applications AMF Access and Mobility Management Function ARPF Authentication credential Repository and Processing Function AS Access Stratum ATSSS Access Traffic Steering, Switching, Splitting ATSSS-LL ATSSS Low-Layer AUSF Authentication Server Function AUTN Authentication token AV Authentication Vector BMCA Best Master Clock Algorithm BSF Binding Support Function CAG Closed Access Group CAPIF Common API Framework for 3GPP northbound APIs CHF Charging Function CN PDBCore Network Packet Delay Budget CP Control Plane DAPS Dual Active Protocol Stacks DL Downlink DN Data Network DNAI DN Access Identifier DNN Data Network Name DRX Discontinuous Reception DS-TT Device-side TSN translator ePDG evolved Packet Data Gateway EBI EPS Bearer Identity EUI Extended Unique Identifier FAR Forwarding Action Rule FN-BRGFixed Network Broadband RG FN-CRGFixed Network Cable RG FN-RG Fixed Network RG FQDN Fully Qualified Domain Name GFBR Guaranteed Flow Bit Rate GMLC Gateway Mobile Location Centre GPSI Generic Public Subscription Identifier GUAMI Globally Unique AMF Identifier HR Home Routed (roaming) IAB Integrated access and backhaul IMEI / TAC IMEI Type Allocation Code IPUPS Inter PLMN UP Security I-SMF Intermediate SMF I-UPF Intermediate UPF LADN Local Area Data Network LBO Local Break Out (roaming) LMF Location Management Function LoA Level of Automation LPP LTE Positioning Protocol LRF Location Retrieval Function MCX Mission Critical Service MDBV Maximum Data Burst Volume MFBR Maximum Flow Bit Rate MICO Mobile Initiated Connection Only MPS Multimedia Priority Service MPTCP Multi-Path TCP Protocol N3IWF Non-3GPP InterWorking Function N5CW Non-5G-Capable over WLAN NAI Network Access Identifier NEF Network Exposure Function NF Network Function NGAP Next Generation Application Protocol NID Network identifier NPN Non-Public Network NR New Radio NRF Network Repository Function NSI IDNetwork Slice Instance Identifier NSSAA Network Slice-Specific Authentication and Authorization NSSAAFNetwork Slice-Specific Authentication and Authorization Function NSSAI Network Slice Selection Assistance Information NSSF Network Slice Selection Function NSSP Network Slice Selection Policy NW-TT Network-side TSN translator NWDAF Network Data Analytics Function PCF Policy Control Function PDB Packet Delay Budget PDR Packet Detection Rule PDU Protocol Data Unit PEI Permanent Equipment Identifier PER Packet Error Rate PFD Packet Flow Description PNI-NPN Public Network Integrated Non-Public Network PPD Paging Policy Differentiation PPF Paging Proceed Flag PPI Paging Policy Indicator PSA PDU Session Anchor PTP Precision Time Protocol QFI QoS Flow Identifier QoE Quality of Experience RACS Radio Capabilities Signalling optimization IAN (Radio) Access Network RG Residential Gateway RIM Remote Interference Management RQA Reflective QoS Attribute RQI Reflective QoS Indication RSN Redundancy Sequence Number SA NR Standalone New Radio SBA Service Based Architecture SBI Service Based Interface SCP Service Communication Proxy SD Slice Differentiator SEAF Security Anchor Functionality SEPP Security Edge Protection Proxy SMF Session Management Function SMSF Short Message Service Function SN Sequence Number SNPN Stand-alone Non-Public Network S-NSSAI Single Network Slice Selection Assistance Information SSC Session and Service Continuity SSCMSP Session and Service Continuity Mode Selection Policy SST Slice / Service Type SUCI Subscription Concealed Identifier SUPI Subscription Permanent Identifier SV Software Version TNAN Trusted Non-3GPP Access Network TNAP Trusted Non-3GPP Access Point TNGF Trusted Non-3GPP Gateway Function TNL Transport Network Layer TNLA Transport Network Layer Association TSC Time Sensitive Communication TSCAI TSC Assistance Information TSN Time Sensitive Networking TSN GMT SN Grand Master TSP Traffic Steering Policy TT TSN Translator TWIF Trusted WLAN Interworking Function UCMF UE radio Capability Management Function UDM Unified Data Management UDR Unified Data Repository UDSF Unstructured Data Storage Function UL Uplink UL CL Uplink Classifier UPF User Plane Function URLLC Ultra Reliable Low Latency Communication URRP-AMF UE Reachability Request Parameter for AMF URSP UE Route Selection Policy VID VLAN Identifier VLAN Virtual Local Area Network W-5GAN Wireline 5G Access Network W-5GBAN Wireline BBF Access Network W-5GCAN Wireline 5G Cable Access Network W-AGF Wireline Access Gateway Function

[0281] <Definition> For the purposes of this document, the terms and definitions described in Non-Patent Document 1 and below are applicable. The terms defined in this document take precedence over the definitions of the same terms in Non-Patent Document 1, if any.

[0282] Although the present invention has been particularly shown and described with reference to its embodiments, the present invention is not limited to these embodiments. It will be understood by those skilled in the art that various changes in form and detail can be made without departing from the spirit and scope of the invention defined in the claims.

[0283] This application claims the benefit of priority based on Indian Provisional Patent Application No. 202011045154 filed on October 16, 2020, the disclosure of which is incorporated herein by reference in its entirety.

Explanation of Signs

[0284] 1000 UEs 1001 Antenna 1002 Transceiver Circuit 1003 User Interface 1004 Controller 1005 Memory 1100 (R)AN Node 1101 Antenna 1102 Transceiver Circuit 1103 Network Interface 1104 Controller 1105 Memory 1200 AMF 1201 Transceiver Circuit 1202 Controller 1203 Memory 1204 Network Interface< / amf>

Claims

1. A method executed by a communication terminal using a first security key, comprising: Receiving an authentication request message from a first core network device; Calculating a second security key and a first authentication response; Returning the first authentication response to the first core network device in an authentication response message; When receiving a first NAS message related to 5G Authentication and Key Agreement (5G AKA) from the first core network device, considering the 5G AKA authentication as successful, responding to the first NAS message, and using the second security key as the latest security key; When receiving a second NAS message related to the 5G AKA set with NEA0 and NIA0 algorithms from the first core network device, not storing the second security key, wherein the second NAS message is a security mode command message received from the first core network device when the communication terminal attempts to establish a PDU session for an emergency service. A method.

2. The method according to claim 1, wherein when using the second security key as the latest security key, setting CounterSoR to 0x00 0x00.

3. The method according to claim 1, wherein when using the second security key as the latest security key, setting CounterUPU to 0x00 0x00.

4. The second security key is a new Kausf. The method according to any one of claims 1 to 3.

5. The first security key is an old Kausf. The method according to any one of claims 1 to 4.

6. The first core network device is an Access and Mobility Management function (AMF). The method according to any one of claims 1 to 5.

7. A method executed by a first core network device, comprising: Sending a first authentication request message to a second core network device to start authentication with a communication terminal using a first security key; Sending a second authentication request message to the communication terminal. Receiving, from the communication terminal, a first authentication response in a first authentication response message; Receiving, from the second core network device, a second authentication response message corresponding to the first authentication request message; Sending, to the communication terminal, a first NAS message related to 5G Authentication and Key Agreement (5G AKA) for causing the communication terminal to use a second security key as the latest security key; Sending, to the communication terminal, a second NAS message related to the 5G AKA, which is set to NEA0 and NIA0 algorithms, so that the communication terminal does not store the second security key; The second NAS message is a security mode command message sent to the communication terminal when the communication terminal attempts to establish a PDU session for an emergency service; Method.

8. The second security key is a new Kausf; The method according to claim 7.

9. The first security key is an old Kausf; The method according to claim 7 or 8.

10. The first core network device is an Access and Mobility Management function (AMF); The method according to any one of claims 7 to 9.

11. A communication terminal using a first security key, comprising: means for receiving an authentication request message from a first core network device; means for calculating a second security key and a first authentication response; means for returning the first authentication response to the first core network device in an authentication response message; when receiving a first NAS message related to 5G Authentication and Key Agreement (5G AKA) from the first core network device, considering that the 5G AKA authentication is successful, responding to the first NAS message, using the second security key as the latest security key, and when receiving a second NAS message related to the 5G AKA, which is set to NEA0 and NIA0 algorithms, from the first core network device, means for not storing the second security key; comprising; The second NAS message is a security mode command message received from the first core network device when the communication terminal attempts to establish a PDU session for an emergency service. Communication terminal.

12. The second security key is a new Kausf. The communication terminal according to claim 11.

13. The first security key is an old Kausf. The communication terminal according to claim 11 or 12.

14. The first core network device is an Access and Mobility Management function (AMF). The communication terminal according to any one of claims 11 to 13.

15. A first core network device, means for transmitting a first authentication request message to a second core network device to start authentication with a communication terminal using a first security key; means for transmitting a second authentication request message to the communication terminal; means for receiving a first authentication response in a first authentication response message from the communication terminal; means for receiving a second authentication response message corresponding to the first authentication request message from the second core network device; transmitting to the communication terminal a first NAS message related to 5G Authentication and Key Agreement (5G AKA) for causing the communication terminal to use a second security key as the latest security key, and setting to NEA0 and NIA0 algorithms for not storing the second security key in the communication terminal, means for transmitting a second NAS message related to the 5G AKA to the communication terminal; comprising The second NAS message is a security mode command message transmitted to the communication terminal when the communication terminal attempts to establish a PDU session for an emergency service. First core network device.

16. The second security key is a new Kausf. The first core network device according to claim 15.

17. The first security key is an old Kausf. The first core network device according to claim 15 or 16.

18. The first core network device is an Access and Mobility Management function (AMF). The first core network device according to any one of claims 15 to 17.