Key update method, network element, user equipment, and storage medium

The key update method addresses the issue of invalid application keys in 5G wireless communication networks by sending an update request to a second network element, ensuring secure and reliable application sessions through consistent key management.

JP7690682B2Active Publication Date: 2025-06-10ZTE CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024506211
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-18
Filing Date
2022-03-23
Publication Date
2025-06-10
Estimated Expiration
2042-03-23

AI Technical Summary

Technical Problem

In the 5G wireless communication network, when the application key becomes invalid, the Access Management Function (AMF) cannot obtain the correct application key, leading to insecure application sessions and unreliable services.

Method used

A key update method is introduced, where when an invalid application key is detected, an application key update request is sent to a second network element based on the user identifier, and an updated application key is determined based on the message related to the application key update request.

Benefits of technology

This method ensures the security and reliability of application sessions by updating the application key when it becomes invalid, maintaining consistent and secure key management across user equipment and network elements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007690682000001
    Figure 0007690682000001
  • Figure 0007690682000002
    Figure 0007690682000002
  • Figure 0007690682000003
    Figure 0007690682000003
Patent Text Reader

Abstract

A key update method, a network element, a user equipment, and a storage medium are provided, which include sending (110) an application key update request to a second network element based on a user identifier if an application key corresponding to a key identifier carried in a session establishment request is invalid, and determining (120) an application key to be updated based on a message associated with the application key update request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application is filed based on a Chinese patent application with an application number of 202110949003.X and an application date of August 18, 2021, claims the priority of the Chinese patent application, and the entire content of the Chinese patent application is incorporated herein by reference.

[0002] This application relates to the field of wireless communication network technologies, for example, key update methods, network elements, user equipment, and storage media.

Background Art

[0003] The 5G (Fifth Generation) mobile communication network architecture is composed of several network functions (NFs). For example, the Unified Data Management (UDM) network element is a permanent storage location for the data subscribed by the user and is in the home network subscribed by the user. The Access Management Function (AMF) network element manages the user's need to access the network and is responsible for functions such as non-access stratum (NAS layer) signaling management from the device to the network and user mobility management. The AMF network element further has a Security Anchor Function (SAF) and, by interacting with the Authentication Server Function (AUSF) network element and the User Equipment (UE), receives the intermediate key (denoted as KAMF) and the key set identifier (KSI: Key Set Identity) established for the UE authentication process and obtains security-related data, etc. from the AUSF. The Application Function (AF) network element manages the UE's session. In addition, the 5G network architecture further introduces an Authentication and Key Management for Applications (AKMA) key anchor function (AAnF) entity. The AAnF entity is in the home network and is mainly used to generate the session key between the UE and the AF entity and maintain the security context with the UE. The AKMA technology provides end-to-end security protection from the user to the application for the 5G network.

[0004] After the UE starts an application session establishment request to the AF, the AF requests the AAnF to obtain the corresponding application key based on the key identifier carried therein. The application key is generated by the AAnF using the AKMA key and the application server identifier. The key generation function parameters of the application key relate only to two parameters, namely the application server identifier and the AKMA key. If the application key is invalid, the AF cannot obtain the correct application key, the application session cannot be carried out securely, and the user cannot obtain a reliable service.

Summary of the Invention

Problems to be Solved by the Invention

[0005] This application provides a key update method, a network element, a user equipment, and a storage medium.

Means for Solving the Problems

[0006] An embodiment of this application provides a key update method applied to a first network element. The key update method includes: when the application key corresponding to the key identifier carried in the session establishment request is invalid, sending an application key update request to a second network element based on the user identifier; and determining an application key updated based on a message related to the application key update request.

[0007] An embodiment of this application further provides a key update method applied to a second network element. The key update method includes: receiving an application key update request sent by the first network element based on the user identifier; and sending instruction information for updating the application key based on the application key update request.

[0008] Embodiments of the present application further provide a key update method applicable to a user device. The key update method includes: receiving instruction information for updating an application key; and updating the application key that is invalid based on the instruction information.

[0009] Embodiments of the present application further provide a network element. The network element includes a memory, a processor, and a computer program stored in the memory and operable on the processor. When the processor executes the program, the above key update method applicable to the first network element or the second network element is realized.

[0010] Embodiments of the present application further provide a user device. The user device includes a memory, a processor, and a computer program stored in the memory and operable on the processor. When the processor executes the program, the above key update method applicable to the user device is realized.

[0011] Embodiments of the present application further provide a computer-readable storage medium. A computer program is stored in the computer-readable storage medium, and when the program is executed by a processor, the above key update method is realized.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Modes for Carrying Out the Invention

[0013] Hereinafter, the present application will be described with reference to the drawings and embodiments. The specific embodiments described herein are merely for interpreting the present application and do not limit the present application. In addition, when there is no contradiction, the embodiments of the present application and the features of the embodiments can be arbitrarily combined with each other. For ease of explanation, the drawings show only some structures related to the present application, not all structures.

[0014] In the AKMA scenario, when a UE accesses a 5G network, after successful authentication by 5G - Authentication and Key Agreement (AKA), that is, 5G - AKA, or the Extensible Authentication Protocol (EAP) - AKA’, that is, EAP - AKA’, an intermediate key (denoted as KAUSF) can be generated between the AUSF and the Mobile Equipment (abbreviated as ME), the AKMA anchor key KAKMA can be derived by the key KAUSF, and the AKMA anchor key KAKMA - related key identifier A - KID can be generated.

[0015] Figure 1 is a schematic diagram of application key generation according to an embodiment. As shown in Figure 1, the UE (or ME) and the AAnF first complete the primary authentication flow, derive the KAKMA by the KAUSF, and generate the A-KID. Based on this, the application key generation process includes the following.

[0016] a. The UE initiates an application session establishment request to the application AF, and the A-KID generated by the UE is carried in the request.

[0017] b. If the AF cannot find the context related to the A-KID and the AF is in the operator network, the AF sends a key acquisition request (Naanf_AKMA_ApplicationKey_Get Request) to the AAnF. The A-KID received by the AF and the AF's own identifier AF ID are carried in the key acquisition request. If the AF belongs to a third-party application and is outside the operator network, the AF may send the key acquisition request to the AAnF via the Network Exposure Function (NEF).

[0018] c. After the AAnF receives the key acquisition request sent by the AF (or the AF via the NEF), it generates the KAF based on the KAKMA. Specifically, KAF = KDF(AF ID, KAKMA), where KDF represents a key generation function.

[0019] d. AAnF sends the key acquisition response message (Naanf_AKMA_ApplicationKey_Get Response) to the AF. The response message contains the generated KAF and the corresponding expiration time (expTime). When the AF is in the operator network, the response message further carries the Subscription Permanent Identifier (SUPI) or the Generic Public Subscription Identifier (GPSI). When the AF belongs to a third-party application and is outside the operator network, AAnF may send the response message to the AF via the NEF, and the user identifier GPSI is carried.

[0020] e. The AF sends an application session establishment response message to the UE.

[0021] In the above application key generation process, since the key generation function parameters of the application key KAF only relate to two parameters, namely the AF ID and KAKMA, when the expiration period of KAF times out or KAF becomes invalid, the AF cannot update KAF. Therefore, the establishment of the application session fails and the service quality cannot be ensured.

[0022] In the embodiments of the present application, a key update method is provided, and the method can be applied to a first network element. The first network element is a network element for managing the session of the UE, for example, the AF.

[0023] FIG. 2 is a flowchart of a key update method according to an embodiment. As shown in FIG. 2, the method according to this embodiment includes step 110 and step 120.

[0024] In step 110, when the application key corresponding to the key identifier carried in the session establishment request is invalid, an application key update request is sent to the second network element based on the user identifier.

[0025] In this embodiment, the UE starts a session establishment request for the first network element, and a key identifier A-KID is carried therein. The first network element may query the corresponding application key KAF based on the A-KID. If KAF is invalid, for example, if the expiration date of KAF has timed out, or if the service provider determines that KAF is not secure, the first network element sends an application key update request to the second network element, and a user identifier for instructing the UE that requests the establishment of the application session is carried therein. The user identifier may be the SUPI or the GPSI. The second network element is a network element that stores the data subscribed by the user, for example, the UDM.

[0026] In step 120, an application key to be updated is determined based on the message related to the application key update request.

[0027] In this embodiment, the message related to the application key update request may be a key update response message returned from the second network element. The key update response message instructs the first network element to update KAF using a predetermined parameter. Further, the second network element may also instruct the UE to update KAF using a predetermined parameter, thereby ensuring the consistency of the application keys used by the UE and the first network element. The message related to the application key update request may be a session establishment request restarted after the UE completes the reregistration flow. In the reregistration flow, the UE and the AUSF have already generated a new A-KID’ and KAKMA’, and the AAnF generates KAF’ based on the KAKMA’. After receiving the session establishment request resent from the UE, the first network element can reacquire the updated KAF’ from the AAnF based on the A-KID’.

[0028] When the application key is invalid, the key update method of this embodiment requests the second network element to obtain the updated application key, and can determine the updated application key based on the message related to the application key update request. Thereby, the security of the application session and the reliability of the service are ensured.

[0029] In one embodiment, the method further includes step 100.

[0030] Step 100: Generate key update parameters, and the key update parameters are carried in the application key update request.

[0031] In this embodiment, the first network element generates key update parameters for updating the application key and carries them in the application key update request. Based on this, the second network element can notify the UE of the key update parameters, and the UE updates the KAF based on the key update parameters. Thereby, the consistency of the application keys between the UE and the first network element is ensured. In some embodiments, the first network element may update the KAF when it determines that the UE has obtained the key update parameters. For example, when the UE returns a confirmation message to the second network element and the second network element returns an application key update response message to the first network element, the KAF is updated to further ensure the consistency of the application keys between the UE and the first network element.

[0032] In one embodiment, the message related to the application key update request includes the application key update response message sent from the second network element.

[0033] In step 120, the step of determining the updated application key based on the message related to the application key update request includes the step of determining the updated application key based on the key update parameters when receiving the application key update response message sent from the second network element.

[0034] In this embodiment, the message related to the application key update request may be a key update response message returned from the second network element, and the key update response message instructs the first network element to update the KAF by using a predetermined parameter (i.e., the key update parameter). When the first network element discovers that the KAF corresponding to the A-KID is invalid, it may generate one key update parameter (which may be a random number, denoted as RANDAF). The AF starts an application key update request to the second network element based on the user identifier (GPSI or SUPI), and the user identifier and RANDAF are carried in the message. When receiving the application key update response message sent from the second network element, the RANDAF is used to update the KAF. Based on this, the second network element may further start a UE parameter update request to the UE. The RANDAF is carried in the UE parameter update request, thereby instructing the UE to update the KAF by using the RANDAF.

[0035] In one embodiment, the step of determining the application key updated based on the key update parameter includes the step of calculating the key update parameter and the invalid application key based on the key generation function to obtain the updated application key.

[0036] In this embodiment, the updated KAF' may be obtained by calculating RANDAF and the invalid KAF by using the key generation function (KDF) that generates KAF based on KAKMA. Specifically, it may be obtained according to KAF' = KDF(RANDAF, KAF).

[0037] In one embodiment, the method further includes step 130 of setting the expiration date of the updated application key.

[0038] In this embodiment, the first network element sets an expiration date for the updated KAF'. Within the expiration date, KAF' can be used to establish an application session. When the expiration date is exceeded, KAF' becomes invalid and cannot be used to establish an application session. Thereby, the security of the session is ensured.

[0039] In one embodiment, the key update parameter is a random number generated based on a hash function.

[0040] In one embodiment, in step 110, the step of sending an application key update request to the second network element based on the user identifier includes, when the first network element is outside the operator network, sending an application key update request to the second network element via the network exposure function NEF network element. Based on this, the first network element outside the operator network can also realize the update of the application key.

[0041] FIG. 3 is a realization schematic diagram of a key update method according to an embodiment. As shown in FIG. 3, the first network element is the AF, and the second network element is the UDM. The UE and the AAnF first complete the main authentication flow, derive the KAKMA by the KAUSF, and generate the A-KID. Based on this, the key update process mainly includes that when the AF discovers that the KAF corresponding to the A-KID is invalid, it generates a key update parameter RANDAF, the AF sends an application key update request to the UDM based on the user identifier, and the user identifier and RANDAF are carried therein, the UDM sends a UE parameter update request to the UE, and RANDAF is carried therein, the UE uses RANDAF to update the KAF to obtain KAF', the AF uses RANDAF to update the KAF to obtain KAF', and sets the expiration date of KAF'. Specifically, it is as follows.

[0042] Step 201: The UE starts an application session establishment request for the application AF, and the A-KID generated by the UE is carried in the application session establishment request.

[0043] Step 202: The AF discovers that the KAF corresponding to the A-KID is invalid. For example, the KAF expiration time has timed out or the service provider determines that the KAF is not secure, and the AF invalidates the KAF.

[0044] Step 203: The AF generates the application key update parameter RANDAF, and the RANDAF may be a random number generated based on a hash function.

[0045] Step 204: The AF sends an application key update message (Nudm_APP_Key_Update Request) to the UDM based on the user identifier, and the RANDAF is carried in the application key update message. Also, when the AF is in the operator network, the user identifier (SUPI or GPSI) is further carried in the application key update message. When the AF is a third-party application and outside the operator network, the AF may send the application key update message to the UDM via the NEF, and the GPSI is carried therein.

[0046] Step 205: The UDM starts a UE parameter update process. Specifically, it sends a user data management notification (Nudm_SDM_Notification) to the AMF, and the key update parameter RANDAF is carried therein. In one embodiment, the user data management notification may include a reply instruction for instructing the UE to need to return a confirmation message (ACK).

[0047] Step 206: The AMF sends a downlink non-access stratum transport message (DL NAS TRANSPORT) to the UE. It contains the transparent container received from the UDM. The UE verifies the key update parameters of the UDM. If the security check on the key update parameters of the UDM is successful, the UE stores the key update parameters, starts using the RANDAF from that position, or transfers the key update parameters to the Universal Subscriber Identity Module (USIM). If the security check fails, the UE discards the content of the key update parameters.

[0048] Step 207: If the UE has already verified the key update parameters and the UDM requests the UE to send an ACK to the UDM, the UE sends an uplink non-access stratum transport message (UL NAS TRANSPORT) to the AMF, which carries a transparent container containing the ACK.

[0049] Step 208: The UE updates KAF using the RANDAF. Specifically, KAF’ = KDF(RANDAF, KAF).

[0050] Step 209: If the uplink non-access stratum transport message received by the AMF carries an ACK, the AMF sends a user data management response message (Nudm_SDM_Info) to the UDM, which carries a transparent container containing the ACK.

[0051] Step 210: The UDM returns an application key update response message (Nudm_APPKey_Update Response) to the AF (or the UDM does so via the NEF).

[0052] Step 211: The AF updates the application key KAF using the RANDAF. Specifically, KAF’ = KDF(RANDAF, KAF). Also, the AF may set an expiration date for KAF’.

[0053] The UE and the AF can generate KAF' and perform session communication using KAF'. In this embodiment, the AF may further return an application session establishment request response message to the UE.

[0054] If the user data management notification does not include a reply instruction, steps 207 and 209 may be omitted.

[0055] In one embodiment, the message related to the application key update request includes the session establishment request message resent from the user equipment, The step of determining the application key updated based on the message related to the application key update request includes the step of querying the application key updated based on the resent session establishment request message.

[0056] In this embodiment, the message related to the application key update request may be the session establishment request message resent from the UE, and the resent session establishment request message instructs the first network element to obtain the application key to be updated. Specifically, when the first network element discovers that the KAF corresponding to the A-KID is invalid, it may initiate an application key update request to the second network element based on the user identifier (GPSI or SUPI). The second network element may initiate a UE parameter update request to the UE, and the re-registration instruction and the application key update instruction are carried therein. The UE initiates a re-registration flow and generates new KAKMA', A-KID' and KAF' after the re-registration flow. The UE transmits a new session establishment request message using A-KID', and after receiving the new session establishment request message, the first network element may query KAF' based on A-KID' therein.

[0057] Also, before starting the re-registration flow, the UE may set the key set identifier (ngKSI) to a predetermined value, which is used to indicate that the application key is invalid or the network layer key is invalid.

[0058] In one embodiment, the method further includes step 112 of sending a message indicating session establishment failure to the user equipment when receiving an application key update response message sent from a second network element.

[0059] In this embodiment, when the first network element receives an application key update response message sent from the second network element, it may send a message indicating session establishment failure to the UE. The UE may start a re-registration flow when receiving the message indicating session establishment failure.

[0060] FIG. 4 is a realization schematic diagram of another key update method according to an embodiment. As shown in FIG. 4, the first network element is the AF, and the second network element is the UDM. The UE and the AAnF first complete the primary authentication flow, derive KAKMA by KAUSF, and generate an A-KID. Based on this, the key update process mainly includes: when the AF discovers that the KAF corresponding to the A-KID is invalid, starting an application key update request to the UDM based on the user identifier (GPSI or SUPI); the UDM starts a UE parameter update request to the UE, and a re-registration instruction and an application key update instruction are carried therein; the UE modifies the ngKSI to be invalid, and starts a re-registration flow to the network with the ngKSI carried. The specific flow is as follows.

[0061] Step 301: The UE starts an application session establishment request to the application AF, and the A-KID generated by the UE is carried in the request.

[0062] Step 302: AF discovers that the application key KAF corresponding to A-KID is invalid, where the invalidity is due to the expiration of the KAF validity period or the service provider's determination that KAF is not secure, and AF invalidates KAF.

[0063] Step 303: AF sends an application key update message (Nudm_APP_Key_Update Request) to the UDM based on the user identifier, and RANDAF is carried in the application key update message. Also, when AF is in the operator network, the user identifier (SUPI or GPSI) is further carried in the application key update message. When AF is a third-party application and outside the operator network, AF may send the application key update message to the UDM via the NEF, and GPSI is carried in it.

[0064] Step 304: The UDM starts the UE parameter update process. Specifically, it sends a user data management notification (Nudm_SDM_Notification) to the AMF, which carries the reregistration instruction information and the application key update instruction information.

[0065] In one embodiment, the user data management notification may include a reply instruction for instructing the UE to return a confirmation message (ACK).

[0066] Step 305: The AMF sends a downlink non-access stratum transport message (DL NAS TRANSPORT) to the UE, which contains the transparent container received from the UDM. The UE verifies the updated data of the UDM. If the security check on the updated data of the UDM is successful, the UE may update the application key based on the updated data. If the security check fails, the UE discards the content of the updated data.

[0067] Step 306: If the UE has already verified the updated data and the UDM has requested the UE to send an ACK to the UDM, the UE sends an uplink non-access stratum transport message (UL NAS TRANSPORT) to the AMF, with a transparent container carrying the ACK.

[0068] Step 307: The UE modifies ngKSI to be invalid, i.e., modifies ngKSI to 7. If the UE does not need to return an ACK, after returning to the idle state, based on the reregistration indication, it may start the reregistration process for the network while carrying ngKSI.

[0069] If the UE needs to return an ACK, after step 309 and after the UE receives a message indicating that the application session establishment has failed, it may start the reregistration process for the network while carrying ngKSI.

[0070] Step 308: If the uplink non-access stratum transport message received by the AMF carries an ACK, the AMF sends a user data management response message (Nudm_SDM_Info) to the UDM, with a transparent container carrying the ACK.

[0071] Step 309: The UDM returns an application key update response message (Nudm_APPKey_Update Response) to the AF (or the UDM returns it via the NEF).

[0072] After receiving the application key update response message, the AF sends a message indicating that the application session establishment has failed to the UE. Note that new KAKMA’, A-KID’ and KAF’ are generated after the reregistration flow. After completing the reregistration, the UE may restart the application session establishment request using A-KID’.

[0073] If the user data management notification does not contain a reply instruction, steps 306 and 308 may be omitted.

[0074] In an embodiment of the present application, a key update method is further provided, and the method can be applied to a second network element. The second network element is a network element for storing data subscribed by a user, for example, a UDM.

[0075] FIG. 5 is a flowchart of another key update method according to an embodiment. As shown in FIG. 5, the method according to this embodiment includes step 410 and step 420.

[0076] In step 410, a first network element receives an application key update request sent based on a user identifier.

[0077] In this embodiment, the UE starts a session establishment request to the first network element, and a key identifier A-KID is carried therein. The first network element may query a corresponding application key KAF based on A-KID. If KAF is invalid, the first network element sends an application key update request to the second network element, which carries a user identifier for identifying the UE that requests the establishment of the application session. After receiving the application key update request, the second network element instructs the corresponding UE to update KAF. The user identifier may be a SUPI or a GPSI.

[0078] In step 420, based on the application key update request, instruction information for updating the application key is sent.

[0079] In this embodiment, the instruction information for updating the application key is used to instruct the corresponding UE to update KAF. Specifically, it instructs the corresponding UE to update KAF via the AMF.

[0080] When the application key is invalid, the key update method of this embodiment instructs the UE to update the KAF based on the application key update request of the first network element, thereby ensuring the security of the application session and the reliability of the service.

[0081] In one embodiment, the step of sending the instruction information to update the application key based on the application key update request includes sending a user data management notification to the AMF network element based on the application key update request, and sending a downlink non-access stratum transmission message to the user equipment via the AMF network element.

[0082] In this embodiment, the second network element instructs the UE to update the KAF, specifically, it may be instructed via the AMF. Sending the instruction information to update the application key may refer to the second network element sending a user data management notification to the AMF. The user data management notification may carry the key update parameter RANDAF generated by the first network element, thereby instructing the UE to update the KAF based on the key update parameter. The user data management notification may carry re-registration instruction information and application key update instruction information, thereby instructing the UE to start the re-registration flow to obtain a new A-KID' and KAF'. Further, the user data management notification may also carry a reply instruction that the UE needs to return confirmation information.

[0083] In one embodiment, the application key update request includes the key update parameter generated by the first network element. The user data management notification includes the key update parameter. The downlink non-access stratum transmission message is used to instruct the user equipment to update the application key based on the key update parameter.

[0084] In this embodiment, the first network element generates a key update parameter RANDAF for updating the application key and carries it in an application key update request. Based on this, the second network element notifies the key update parameter to the AMF via a user data management notification. The AMF notifies the key update parameter to the UE via a downlink non-access stratum transmission message. The UE updates the KAF based on the key update parameter (see steps 203 to 206 in FIG. 3). Thereby, the consistency of the application keys between the UE and the first network element is ensured.

[0085] In one embodiment, the user data management notification further includes a reply instruction for confirmation information, and the method further includes steps 4310 to 4320.

[0086] Step 4310: Receive a user data management response message sent from the AMF. The user data management response message is sent after the AMF receives an uplink non-access stratum transmission message from the user equipment. The uplink non-access stratum transmission message includes confirmation information returned from the user equipment.

[0087] Step 4320: Send an application key update response message to the first network element. The application key update response message is used to instruct the first network element to determine an application key updated based on the key update parameter.

[0088] In this embodiment, the user data management notification further includes a reply instruction. After the second network element notifies the UE of the key update parameters via the AMF, the UE may update the KAF using the key update parameters and, at the same time, send confirmation information to the AMF via the uplink non-access stratum transmission message. Thereafter, the AMF may send a user data management response message to the second network element. After receiving the user data management response message, the second network element may send an application key update response message to the first network element to instruct the first network element to update the KAF using the key update parameters (see steps 207 to 211 in FIG. 3).

[0089] In one embodiment, the user data management notification includes re-registration instruction information and application key update instruction information. The downlink non-access stratum transmission message is used to instruct the user equipment to start a re-registration flow to obtain an updated application key.

[0090] In this embodiment, the user data management notification includes re-registration instruction information and application key update instruction information. The re-registration instruction information is used to instruct the UE to start a re-registration flow. In the re-registration flow, new KAKMA’, A-KID’ and KAF’ are generated. The application key update instruction information is used to instruct the UE to obtain KAF’. Based on this, the UE can restart the application session establishment request using the new A-KID. Specifically, the second network element may send the re-registration instruction information and the application key update instruction information to the AMF via the user data management notification. The AMF sends the re-registration instruction information and the application key update instruction information to the UE via the downlink non-access stratum transmission message, and instructs the UE to start a re-registration flow to obtain an updated application key (see steps 304 to 305 in FIG. 4). Thereby, the consistency of the application keys between the UE and the first network element is ensured.

[0091] In this embodiment, before starting the re-registration flow, the UE may set the key set identifier (ngKSI) to a predetermined value, which is used to indicate that the application key is invalid or the network layer key is invalid.

[0092] In one embodiment, the user data management notification further includes an instruction to return confirmation information, and the method further includes steps 4410 to 4420.

[0093] Step 4410: Receive a user data management response message sent from the AMF. The user data management response message is sent by the AMF after receiving the uplink non-access stratum transport message of the user equipment. The uplink non-access stratum transport message includes confirmation information.

[0094] Step 4420: Send an application key update response message to the first network element. The application key update response message is used to return a message indicating that session establishment has failed to the user equipment and to instruct the first network element to receive a re-transmitted session establishment request from the user equipment.

[0095] In this embodiment, the user data management notification further includes a return instruction. After the second network element sends the re-registration instruction information and the application key update instruction information to the UE via the AMF, the UE obtains the updated application key by starting the re-registration flow, and may return the confirmation information to the AMF via the uplink non-access stratum transport message. Thereafter, the AMF may send a user data management response message to the second network element. After receiving the user data management response message, the second network element may send an application key update response message to the first network element to notify the first network element that the UE has already confirmed the start of the re-registration flow (see steps 306 to 309 in FIG. 4).

[0096] In an embodiment of the present application, a key update method is further provided, and the method can be applied to a user device. FIG. 6 is a flowchart of still another key update method according to an embodiment. As shown in FIG. 6, the method according to this embodiment includes step 510 and step 520.

[0097] In step 510, instruction information for updating an application key is received.

[0098] In step 520, the application key that is invalid based on the instruction information is updated.

[0099] In this embodiment, the UE may update the application key that is invalid based on the instruction information for updating the application key. The updated application key can ensure the security of the application session and the reliability of the service. The instruction information for updating the application key may be sent by the second network element to the UE via the AMF. For this purpose, the key update parameter RANDAF generated by the first network element may be carried, and the UE updates the KAF based on the key update parameter. The instruction information may carry re-registration instruction information and application key update instruction information, and the UE starts a re-registration flow based on this to obtain a new application key. Further, the instruction information may further carry a reply instruction that the UE needs to return confirmation information.

[0100] In one embodiment, the step of receiving instruction information for updating an application key includes the step of receiving a downlink non-access stratum transmission message sent from an AMF network element, and the downlink non-access stratum transmission message is sent by the AMF based on a user data management notification of the second network element.

[0101] In one embodiment, the downlink non-access stratum transmission message includes key update parameters generated by the first network element. In step 520, the step of updating the application key that is invalid based on the instruction information is It includes the step of calculating, by a key generation function, a key update parameter and an invalid application key to obtain an updated application key.

[0102] In this embodiment, the first network element generates a key update parameter RANDAF for updating the application key and carries it to an application key update request. Based on this, the second network element may notify the key update parameter to the AMF via a user data management notification. The AMF notifies the key update parameter to the UE via a downlink non-access stratum transport message. Based on this, the UE updates the KAF based on the key update parameter (see steps 203 to 206 in FIG. 3). Specifically, the UE may use a key generation function KDF that generates the KAF based on the KAKMA to calculate the invalid KAF and the RANDAF to obtain an updated KAF'. Thereby, the consistency of the application keys between the UE and the first network element is ensured.

[0103] In one embodiment, the downlink non-access stratum transport message includes re-registration indication information and application key update indication information. The downlink non-access stratum transport message is used to instruct the user equipment to start a re-registration flow to obtain an updated application key.

[0104] In this embodiment, the user data management notification includes re-registration instruction information and application key update instruction information. The re-registration instruction information is used to instruct the UE to start the re-registration flow. In the re-registration flow, new KAKMA’, A-KID’ and KAF’ are generated. The application key update instruction information is used to instruct the UE to obtain KAF’. Based on this, the UE can restart the application session establishment request using the new A-KID. Specifically, the second network element may send the re-registration instruction information and the application key update instruction information to the AMF via the user data management notification. The AMF sends the re-registration instruction information and the application key update instruction information to the UE via the downlink non-access stratum transport message, and instructs the UE to start the re-registration flow and obtain the updated KAF (see steps 304 to 305 in FIG. 4). Thereby, the consistency of the application keys between the UE and the first network element is ensured.

[0105] In one embodiment, the downlink non-access stratum transport message further includes an instruction to return confirmation information, and the method further includes step 512 of sending an uplink non-access stratum transport message to the AMF network element, where the uplink non-access stratum transport message includes confirmation information returned from the user equipment.

[0106] In this embodiment, when the reply instruction is included in the user data management notification sent by the second network element to the AMF, the confirmation information (ACK) is included in the uplink non-access stratum transport message sent by the UE to the AMF network element.

[0107] In one embodiment, the step of updating the application key that is invalid based on the instruction information includes steps 5210 to 5220.

[0108] Step 5210: Set the key set identifier to a predetermined value. The predetermined value is used to indicate that the application key is invalid or the network layer key is invalid. The network layer key includes an intermediate key or a non-access stratum key.

[0109] Step 5220: When in the idle state, start a re-registration flow based on the key set identifier to obtain an updated application key.

[0110] In this embodiment, the UE sets the key set identifier ngSKI to the predetermined value 7, indicating that the application key KAF is invalid or the network layer key (intermediate key KAUSF or non-access stratum key) is invalid. If the user data management notification does not include a reply instruction, the UE does not need to return confirmation information and may start a re-registration flow based on the key set identifier in the idle state to obtain an updated application key.

[0111] In one embodiment, the step of updating an invalid application key based on the instruction information includes steps 5230 to 5240.

[0112] Step 5230: Set the key set identifier to a predetermined value. The predetermined value is used to indicate that the network key is invalid or the network layer key is invalid. The network layer key includes an intermediate key or a non-access stratum key.

[0113] Step 5240: When receiving a message indicating failure of session establishment returned from the first network element, start a re-registration flow based on the key set identifier to obtain an updated application key.

[0114] In this embodiment, the UE sets the key set identifier ngSKI to a predetermined value 7, indicating that the application key KAF is invalid or the network layer key (the intermediate key KAUSF or the non-access stratum key) is invalid. When a reply instruction is included in the user data management notification, the UE needs to return confirmation information. Specifically, an ACK may be sent to the AMF via an uplink non-access stratum transmission message. The AMF sends a user data management response message to the second network element, and the second network element sends an application key update response message to the first network element (see steps 306 to 309 in FIG. 4). After confirming that the UE attempts to start a reregistration flow, the first network element may send a message indicating that the session establishment has failed to the UE. Thereafter, the UE may start a reregistration flow based on the key set identifier to obtain an updated application key.

[0115] The embodiment of the present application further provides a key update device. FIG. 7 is a structural schematic diagram of a key update device according to an embodiment. As shown in FIG. 7, the key update device includes a request module 610 and a key determination module 620.

[0116] When the application key corresponding to the key identifier carried in the session establishment request is invalid, the request module 610 is configured to send an application key update request to the second network element based on the user identifier.

[0117] The key determination module 620 is configured to determine an updated application key based on a message related to the application key update request.

[0118] The key update device of this embodiment can request the second network element to obtain an updated application key when the application key is invalid, and determine an updated application key based on a message related to the application key update request. Thereby, the security of the application session and the reliability of the service are ensured.

[0119] In one embodiment, the apparatus further includes a generation module configured to generate key update parameters, and the key update parameters are carried in the application key update request.

[0120] In one embodiment, the message related to the application key update request includes an application key update response message sent from the second network element, The key determination module 620 is specifically configured to When receiving the application key update response message sent from the second network element, determine an application key updated based on the key update parameters.

[0121] In one embodiment, the key determination module 620 is specifically configured to Based on a key generation function, calculate the key update parameters and an invalid application key to obtain the updated application key.

[0122] In one embodiment, the apparatus further includes a setting module configured to set an expiration date of the updated application key.

[0123] In one embodiment, the key update parameters are random numbers generated based on a hash function.

[0124] In one embodiment, the request module 610 is specifically configured to send the application key update request to the second network element via a network exposure function NEF network element when the first network element is outside the operator network.

[0125] In one embodiment, the message related to the application key update request includes a session establishment request message resent from a user equipment, The key determination module 620 is specifically configured to query the updated application key based on the retransmitted session establishment request message.

[0126] In one embodiment, the apparatus further includes a failure message sending module configured to send a message indicating failure to establish a session to the user equipment when receiving an application key update response message sent from the second network element.

[0127] The key update apparatus according to this embodiment belongs to the same inventive concept as the key update method according to the above embodiment. Technical details not described in detail in this embodiment can refer to any of the above embodiments, and this embodiment has the same beneficial effects as the execution of the key update method.

[0128] Embodiments of the present application further provide a key update apparatus. FIG. 8 is a structural schematic diagram of another key update apparatus according to an embodiment. As shown in FIG. 8, the key update apparatus includes a request receiving module 710 and an instruction module 720.

[0129] The request receiving module 710 is configured to receive an application key update request sent by the first network element based on a user identifier.

[0130] The instruction module 720 is configured to send instruction information for updating the application key based on the application key update request.

[0131] When the application key of this embodiment is invalid, the key update apparatus of this embodiment instructs the UE to update the KAF based on the application key update request of the first network element, thereby ensuring the security of the application session and the reliability of the service.

[0132] In one embodiment, the instruction module 720 is specifically configured to send a user data management notification to an access management function AMF network element based on the application key update request, and to send a downlink non-access stratum transmission message to the user equipment via the AMF network element.

[0133] In one embodiment, the application key update request includes key update parameters generated by the first network element. The user data management notification includes the key update parameters. The downlink non-access stratum transmission message is used to instruct the user equipment to update the application key based on the key update parameters.

[0134] In one embodiment, the user data management notification further includes an instruction to return confirmation information. The apparatus further includes a first receiving module and a first transmitting module. The first receiving module is configured to receive a user data management response message transmitted from the AMF. The user data management response message is transmitted by the AMF after receiving an uplink non-access stratum transmission message of the user equipment. The uplink non-access stratum transmission message includes confirmation information returned from the user equipment. The first transmitting module is configured to send an application key update response message to the first network element. The application key update response message is used to instruct the first network element to determine an application key updated based on the key update parameters.

[0135] In one embodiment, the user data management notification includes re-registration instruction information and application key update instruction information. The downlink non-access stratum transmission message is used to instruct the user equipment to start a re-registration process to obtain an updated application key.

[0136] In one embodiment, the user data management notification further includes an instruction to reply with confirmation information, and the apparatus further includes a second receiving module and a second transmitting module. The second receiving module is configured to receive the user data management response message transmitted from the AMF. The user data management response message is transmitted by the AMF after receiving the uplink non-access stratum transmission message of the user equipment. The uplink non-access stratum transmission message includes confirmation information. The second transmitting module is configured to transmit an application key update response message to the first network element. The application key update response message is used to reply to the user equipment with a message indicating that session establishment has failed and to instruct the first network element to receive a session establishment request retransmitted from the user equipment.

[0137] The key update apparatus according to this embodiment belongs to the same inventive concept as the key update method according to the above embodiment. Technical details not described in detail in this embodiment can refer to any of the above embodiments, and this embodiment has the same beneficial effects as the execution of the key update method.

[0138] The embodiments of the present application further provide a key update apparatus. FIG. 9 is a structural schematic diagram of still another key update apparatus according to an embodiment. As shown in FIG. 9, the key update apparatus includes an instruction receiving module 810 and an update module 820. The instruction receiving module 810 is configured to receive instruction information for updating an application key. The update module 820 is configured to update an invalid application key based on the instruction information.

[0139] The key update apparatus of this embodiment can update an invalid application key based on instruction information for updating the application key. The updated application key can ensure the security of the application session and the reliability of the service.

[0140] In one embodiment, the instruction receiving module 810 is specifically configured to receive a downlink non-access stratum transmission message transmitted from an AMF network element. The downlink non-access stratum transmission message is transmitted by the AMF based on a user data management notification of a second network element.

[0141] In one embodiment, the downlink non-access stratum transmission message includes key update parameters generated by the first network element. The update module 820 is specifically configured to calculate the key update parameters and the invalid application key by a key generation function to obtain an updated application key.

[0142] In one embodiment, the downlink non-access stratum transmission message includes reregistration instruction information and application key update instruction information. The downlink non-access stratum transmission message is used to instruct the user equipment to start a reregistration process to obtain an updated application key.

[0143] In one embodiment, the downlink non-access stratum transmission message further includes an instruction to return confirmation information. The apparatus further includes a confirmation module configured to transmit an uplink non-access stratum transmission message to the AMF network element. The uplink non-access stratum transmission message includes confirmation information returned from the user equipment.

[0144] In one embodiment, the update module 820 includes a first setting module and a first reregistration module. The first setting module is configured to set a key set identifier to a predetermined value. The predetermined value is used to indicate that the application key is invalid or the network layer key is invalid. The network layer key includes an agreed intermediate key or a non-access stratum key. When in an idle state, the first re-registration module is configured to start a re-registration flow based on the key set identifier to obtain an updated application key.

[0145] In one embodiment, the update module 820 includes a second setting module and a second re-registration module. The second setting module is configured to set the key set identifier to a predetermined value. The predetermined value is used to indicate that the network key is invalid or the network layer key is invalid. The network layer key includes an agreed intermediate key or a non-access layer key. When the second re-registration module receives a message indicating a failure in session establishment returned from the first network element, it is configured to start a re-registration flow based on the key set identifier to obtain an updated application key.

[0146] The key update device according to this embodiment belongs to the same inventive concept as the key update method according to the above embodiment. Technical details not described in detail in this embodiment can refer to any of the above embodiments, and this embodiment has the same beneficial effects as the execution of the key update method.

[0147] The embodiments of the present application further provide a network element. FIG. 10 is a schematic diagram of the hardware structure of a network element according to an embodiment. As shown in FIG. 10, the network element according to the present application includes a memory 902, a processor 901, and a computer program stored in the memory and operable on the processor. When the processor 901 executes the program, the above key update method applicable to the first network element or the second network element is realized.

[0148] The network element may further include a memory 902. The processor 901 of the network element may be one or more, and FIG. 10 takes one processor 901 as an example. The memory 902 is used to store one or more programs, and the one or more programs are executed by the one or more processors 901, whereby the one or more processors 901 implement the key update method applicable to the first network element or the second network element described in the embodiments of the present application.

[0149] The network element further includes a communication device 903, an input device 904, and an output device 905.

[0150] The processor 901, the memory 902, the communication device 903, the input device 904, and the output device 905 of the network element may be connected by a bus or other means. FIG. 10 takes connection by a bus as an example.

[0151] The input device 904 may be used to receive the input numerical or character information and generate a key signal input related to the user setting and function control of the network element. The output device 905 may include a display device such as a display screen.

[0152] The communication device 903 may include a receiver and a transmitter. The communication device 903 is configured to perform information transmission and reception communication based on the control of the processor 901.

[0153] Memory 902, as a computer-readable storage medium, may be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the key update method described in the embodiments of the present application (for example, the request module 610 and the key determination module 620 of the key update device). Memory 902 may include a program storage area and a data storage area. The program storage area may store an operating system and application programs required for at least one function. The data storage area may store data created based on the use of network elements, etc. Further, memory 902 may include a high-speed random access memory and may further include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid storage devices. In some examples, memory 902 may include a memory remotely installed with respect to processor 901, and these remote memories may be connected to network elements via a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0154] The embodiments of the present application further provide a user device. FIG. 11 is a schematic structural diagram of the hardware of a user device according to an embodiment. As shown in FIG. 11, the user device according to the present application includes a memory 912, a processor 911, and a computer program stored in the memory and operable on the processor. When the processor 911 executes the program, the key update method applicable to the user device is realized.

[0155] The user equipment may further include a memory 912. The processor 911 of the user equipment may be one or more, and FIG. 11 takes one processor 911 as an example. The memory 912 is used to store one or more programs, and the one or more programs are executed by the one or more processors 911, whereby the one or more processors 911 implement the key update method applicable to the user equipment of the embodiments of the present application.

[0156] The user equipment further includes a communication device 913, an input device 914, and an output device 915.

[0157] The processor 911, memory 912, communication device 913, input device 914, and output device 915 of the user equipment may be connected by a bus or other means. FIG. 11 takes connection by a bus as an example.

[0158] The input device 914 may be used to receive the input numerical or character information and generate a key signal input related to the user setting and function control of the user equipment. The output device 915 may include a display device such as a display screen.

[0159] The communication device 913 may include a receiver and a transmitter. The communication device 913 is configured to perform information transmission and reception communication based on the control of the processor 911.

[0160] The memory 912 may be configured as a computer-readable storage medium to store software programs, computer-executable programs, and modules, for example, program instructions / modules corresponding to the key update method described in the embodiments of the present application (for example, the instruction receiving module 810 and the update module 820 of the key update device). The memory 912 may include a program storage area and a data storage area. The program storage area may store an operating system and at least one application program required for functions. The data storage area may store data created based on the use of the user device. Further, the memory 912 may include a high-speed random access memory and may further include a non-volatile memory, for example, at least one disk storage device, a flash memory device, or other non-volatile solid storage devices. In some examples, the memory 912 may include a memory remotely installed with respect to the processor 911, and these remote memories may be connected to the user device via a network. Examples of the above network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0161] The embodiments of the present application further provide a storage medium, in which a computer program is stored. When the computer program is executed by a processor, the key update method described in any of the embodiments of the present application is realized. The method includes: when the application key corresponding to the key identifier carried in the session establishment request is invalid, sending an application key update request to a second network element based on the user identifier; and determining an updated application key based on a message related to the application key update request.

[0162] Alternatively, the method includes: receiving an application key update request sent by a first network element based on a user identifier; and sending instruction information for updating the application key based on the application key update request.

[0163] Alternatively, the method includes receiving instruction information for updating an application key, and updating an invalid application key based on the instruction information.

[0164] The computer storage medium of the embodiments of the present application may use any combination of one or more computer-readable media. The computer-readable media may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of the computer-readable storage medium (not an exhaustive list of all examples) include an electrical connection having one or more conductors, a portable computer magnetic disk, a hard disk, a random access memory (RAM), a read only memory (ROM), an erasable programmable read only memory (EPROM), a flash memory, an optical fiber, a portable CD-ROM, an optical storage device, a magnetic storage device, or any suitable combination of the above. The computer-readable storage medium may be any tangible medium that includes or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device.

[0165] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. The data signal so propagated may take any of a variety of forms including, but not limited to, an electromagnetic signal, an optical signal, or any suitable combination of the foregoing. The computer-readable signal medium may further be any computer-readable medium other than a computer-readable storage medium, which can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0166] The program code included in the computer-readable medium may be transmitted using any appropriate medium including, but not limited to, wireless, wire, optical cable, radio frequency (RF), or any suitable combination of the foregoing.

[0167] Computer program code for carrying out operations of this application may be written in one or more program design languages or combinations thereof. The program design languages include object-oriented program design languages such as Java (registered trademark), Smalltalk, C++, and also include conventional procedural program design languages such as the "C" language or similar program design languages. The program code may be executed entirely on the user computer, partly on the user computer, as a stand-alone software package, partly on the user computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user computer through any network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, connected through the Internet using an Internet service provider).

[0168] The above are merely exemplary embodiments of the present application and are not intended to limit the protection scope of the present application.

[0169] The term "user terminal" covers any suitable type of wireless user equipment, such as, for example, a mobile phone, a portable data processing device, a portable web browser, or an in-vehicle mobile station.

[0170] Generally, multiple embodiments of the present application may be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. For example, some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software executable by a controller, a microprocessor, or other computing device, and the present application is not limited thereto.

[0171] Embodiments of the present application may also be realized by a data processor of a mobile device executing computer program instructions, for example, in a processor entity, realized by hardware, or by a combination of software and hardware. The computer program instructions may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, or source code or target code programmed in any combination of one or more programming languages.

[0172] Any block diagram of a logic flow in the drawings of the present application may represent program steps, or may represent logic circuits, modules, and functions connected to each other, or may represent a combination of program steps and logic circuits, modules, and functions. A computer program may be stored in a memory. The memory may have any type suitable for the local technical environment and may be implemented with any suitable data storage technology, for example, read-only memory (ROM), random access memory (RAM), optical memory devices and systems (such as digital versatile discs (DVDs) or compact discs (CDs), but not limited thereto). A computer-readable medium may include a non-transitory storage medium. The data processor may be of any type suitable for the local technical environment, for example, a general-purpose computer, a dedicated computer, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), and a processor based on a multi-core processor architecture, but not limited thereto.

[0173] The above has provided a detailed description of exemplary embodiments of the present application by way of illustrative and non-limiting examples. However, considering with reference to the drawings and the claims, various modifications and adjustments to the above embodiments will be apparent to those skilled in the art and will not depart from the scope of the present application. Therefore, the appropriate scope of the present application is determined based on the claims.

Claims

1. A key update method applied to a first network element, comprising: when an application key corresponding to a key identifier carried in a session establishment request is invalid, generating key update parameters and sending an application key update request to a second network element, wherein the application key update request includes a user identifier for instructing a user equipment that requests establishment of an application session and the key update parameters; when receiving an application key update response message sent from the second network element, determining an application key to be updated based on the key update parameters.

2. The step of determining an application key to be updated based on the key update parameters includes: calculating, based on a key generation function, the key update parameters and the invalid application key to obtain the updated application key, according to the method of Claim 1.

3. The method according to Claim 1, further comprising setting an expiration date of the updated application key.

4. The key update parameters are random numbers generated based on a hash function, according to the method of Claim 1.

5. The step of sending an application key update request to a second network element includes: when the first network element is outside an operator network, sending the application key update request to the second network element via a network exposure function (NEF) network element, according to the method of Claim 1.

6. The method according to Claim 1, further comprising querying the updated application key based on a session establishment request message resent from the user equipment.

7. The method according to Claim 1, further comprising, when receiving an application key update response message sent from the second network element, sending a message indicating session establishment failure to the user equipment.

8. A key update method applied to a second network element, comprising: A step of receiving an application key update request sent by a first network element, wherein the application key update request includes a user identifier for instructing a user equipment that requests establishment of an application session, and key update parameters generated by the first network element. A step of transmitting a user data management notification to an access management function AMF network element based on the application key update request, and transmitting a downlink non-access stratum transport message to the user equipment via the AMF network element. The user data management notification includes the key update parameters. The downlink non-access stratum transport message is used to instruct the user equipment to update the application key based on the key update parameters.

9. The user data management notification further includes an instruction to return confirmation information. The method includes A step of receiving a user data management response message sent from the AMF, wherein the user data management response message is sent after the AMF receives an uplink non-access stratum transport message of the user equipment, and the uplink non-access stratum transport message includes confirmation information returned from the user equipment. A step of transmitting an application key update response message to the first network element, wherein the application key update response message is used to instruct the first network element to determine an application key updated based on the key update parameters. The method according to claim 8 further includes the above steps.

10. A key update method applied to a second network element, comprising A step of receiving an application key update request sent by a first network element, wherein the application key update request includes a user identifier for instructing a user equipment that requests establishment of an application session, and key update parameters generated by the first network element. A step of transmitting a user data management notification to an access management function AMF network element based on the application key update request, and transmitting a downlink non-access stratum transport message to the user equipment via the AMF network element. The user data management notification includes re-registration instruction information and application key update instruction information, The downlink non-access stratum transmission message is used to instruct the user equipment to start a re-registration process to obtain an updated application key, method. **Claim 11**: The user data management notification further includes an instruction to return confirmation information, The method includes: Receiving a user data management response message sent from the AMF, where the user data management response message is sent by the AMF after receiving an uplink non-access stratum transmission message from the user equipment, and the uplink non-access stratum transmission message includes confirmation information; Sending an application key update response message to the first network element, where the application key update response message is used to return a message indicating that session establishment has failed to the user equipment and to instruct the first network element to receive a re-transmitted session establishment request from the user equipment. The method according to claim 10 further includes these steps. **Claim 12** A network element including a memory, a processor, and a computer program stored in the memory and operable on the processor, where when the processor executes the program, the key update method according to any one of claims 1 to 7 is implemented. **Claim 13**: A network element including a memory, a processor, and a computer program stored in the memory and operable on the processor, where when the processor executes the program, the key update method according to any one of claims 8 to 11 is implemented. **Claim 14** A computer-readable storage medium having a computer program stored thereon, where when the program is executed by a processor, the key update method according to any one of claims 1 to 7 is implemented. **Claim 15**: A computer-readable storage medium having a computer program stored thereon, where when the program is executed by a processor, the key update method according to any one of claims 8 to 11 is implemented.

Citation Information

Patent Citations

  • Method, device, and system for application key generation and management in a communication network for encrypted communication with service applications

    WO2021093163A1