System and Method for Key Generation in the Authentication and Key Management Unit (AKMA) for Applications

JP7900479B2Active Publication Date: 2026-08-04SAMSUNG ELECTRONICS CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2022-07-07
Publication Date
2026-08-04

AI Technical Summary

Benefits of technology

【0023】 本開示の実施形態は、1次認証を実行せずにAKMAキー及びAFキーをリフレッシュするための方法及び装置を提供する。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007900479000001
    Figure 0007900479000001
  • Figure 0007900479000002
    Figure 0007900479000002
  • Figure 0007900479000003
    Figure 0007900479000003
Patent Text Reader

Abstract

The present disclosure relates to 5G or 6G communication systems to support higher data transmission rates. The present disclosure provides a system and method for key refresh in an authentication and key management unit (AKMA) for applications. The proposed method is AF If expires soon, K can be refreshed by requesting a refresh parameter from the network. AKMA The aim of the proposed method is to support refresh. AF If expires soon, K can be refreshed by requesting a refresh parameter from the network. AF The proposed method also uses a specific mechanism to provide refresh parameters to the AUSF, AAnF, and UE as part of the AKMA refresh procedure or as part of the UPU procedure. Furthermore, the proposed method supports AKMA key refresh while limiting the impact on AKMA services in 5G systems. The proposed method is also used to support a mechanism for solving the key synchronization problem on the user equipment (UE) side, the AF, and the network side.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to authentication in wireless networks in general, and more specifically to a system and method for authentication and key management in an application (AKMA) for key generation. [Background technology]

[0002] 5G mobile communication technology defines a wide frequency band to enable high transmission rates and new services, and can be implemented not only in "sub-6GHz" bands such as 3.5GHz, but also in "super-6GHz" bands called mmWave, including 28GHz and 39GHz. Furthermore, to achieve transmission rates 50 times faster than 5G mobile communication technology and ultra-low latency at one-tenth the level of 5G mobile communication technology, the implementation of 6G mobile communication technology (called Beyond 5G systems) in the terahertz band (e.g., 95GHz to 3THz band) is being considered.

[0003] In the early stages of 5G mobile communication development, standardization is underway for beamforming and large-scale MIMO to reduce propagation path loss and increase propagation transmission distance in mmWave, efficient utilization of mmWave resources, support pneumatics for slot-type dynamic operation (e.g., multiple operating subcarrier spacing), initial access techniques for multi-beam transmission and broadband support, definition and operation of BWP (BandWidth Part), new channel coding methods such as LDPC (Low Density Parity Check) code for high-capacity data transmission and polar code for highly reliable control information transmission, L2 preprocessing, and network slicing to provide dedicated networks for specific services, in order to meet the service support and requirements associated with eMBB (enhanced Mobile Broadband), URLLC (Ultra Reliable Low Latency Communications), and mMTC (massive Machine-Type Communications).

[0004] Currently, discussions are underway regarding improvements and performance enhancements to initial 5G mobile communication technologies, with a view to services supported by 5G mobile communication technology. Physical layer standardization is progressing for technologies such as V2X (Vehicle-to-Everything), which supports autonomous vehicles' driving decisions based on information about the vehicle's location and status transmitted by the vehicle, thereby improving user convenience; NR-U (New Radio Unlicensed), which aims for system operation that complies with various regulatory requirements in unlicensed bands; NR UE power saving; and Non-Terrestrial Network (NTN), which is UE-satellite direct communication for positioning, providing coverage in areas where communication with terrestrial networks is impossible.

[0005] Furthermore, standardization of wireless interface architectures / protocols is underway for technologies such as IOT (Industrial Internet of Things) to support new services through collaboration and integration with other industries, IAB (Integrated Access and Backhaul) to provide nodes for expanding network service areas by supporting wireless backhaul links and access links in an integrated manner, improved mobility including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-stage random access (two-stage RACH for NR) to simplify random access procedures. In addition, standardization of system architectures / services is underway for 5G basic architectures (e.g., service-based architectures or service-based interfaces) to combine NFV (Network Functions Virtualization) and SDN (Software-Defined Networking) technologies, and MEC (Mobile Edge Computing) for receiving services based on UE location.

[0006] As 5G mobile communication systems become commercialized, the number of connected devices will increase exponentially, connecting to communication networks. Accordingly, improvements in the functionality and performance of 5G mobile communication systems and the integrated operation of connected devices are expected to be necessary. To this end, new research is planned that leverages artificial intelligence (AI) and machine learning (ML), AI service support, metabus service support, and drone communications to efficiently support augmented reality (AR), virtual reality (VR), mixed reality (MR), and other technologies, in conjunction with 5G performance improvements and complexity reduction.

[0007] Furthermore, the development of such 5G mobile communication systems will serve as a foundation for developing 6G mobile communication technologies, FD-MIMO (Full Dimensional MIMO) to improve terahertz band signal coverage, multiplex antenna transmission technologies such as array antennas and large-scale antennas, metamaterial-based lenses and antennas, and new waveforms to provide terahertz band coverage for high-dimensional spatial multiplexing technologies using OAM (Orbital Angular Momentum) and RIS (Reconfigurable Intelligent Surface), as well as full-duplex technology to improve the frequency efficiency of 6G mobile communication technologies and enhance system networks, AI-based communication technologies to realize system optimization by leveraging satellites and artificial intelligence (AI) from the design stage and internalizing end-to-end AI support functions, ultra-high performance communication, and next-generation distributed computing technologies to realize services at complexity levels that exceed the limits of UE operation capabilities by leveraging computing resources.

[0008] The 3rd Generation Partnership Project (3GPP) (registered trademark) Rel-16 introduces a new feature known as the Authentication and Key Management Unit (AKMA) for 3GPP user credential-based applications in 5G. AKMA leverages user Authentication and Key Management Unit (AKMA) credentials to bootstrap security between the user terminal (UE) and the application function unit (AF), allowing the UE to securely exchange data with the AF.

[0009] According to 3GPP, as described in TS 33.535, primary authentication is performed using an AKMA key (K AKMA ) refresh or generate new AKMA keys and new K AKMA When generating it, the AF key (K AF ) refresh or new K AF It generates K. AF is K AFis associated with a timer indicating the validity period. K AF When the validity period of K AF expires, AF can reject UE access to AF. K AUSF At the expiration of K AUSF and when the AUSF key (K

[0010] is changed by a successful execution of the primary authentication, the UE can retry accessing AF using a new A-KID (AKMA Key Identity) derived from the new K AF until a new primary authentication occurs. K AF Therefore, K AF cannot be refreshed immediately after the expiration of the validity period of K AF until a new primary authentication occurs. Thus, the user may not be able to use the application (requiring authentication using AKMA) until a new primary authentication procedure occurs after the expiration of K AF which may occur after a very long period. However, K AF must be refreshed as needed by applications that depend on K

[0011] According to 3GPP TS 33.535, K AF can be refreshed through Ua*, but this not only depends on whether the Ua* protocol supports such a function, but also on whether the operator or application uses Ua* to refresh K AFIn some cases, it may be intentionally undesirable to implement a refresh, and instead, it may be possible to rely on AKMA verification by the network each time. If key refresh is supported by the Ua* protocol, key refreshes will be performed independently regardless of the number of times, which raises issues of subscriber credential abuse in 5G systems and legal interception, which is part of the regulatory requirements in certain regions.

[0012] In this scenario, UE and AAnF are K AF It has an old K AF. AF Either the AF has a key, or the UE derives a new key based on the Ua* protocol, while the UE derives a new key and is unaware that it should use the latest key. In such cases, key synchronization problems can occur, mainly due to misalignment and miscoordination of contexts derived from different entities.

[0013] Therefore, it is preferable to resolve the aforementioned or other drawbacks, or at least provide a useful alternative. [Overview of the project] [Problems that the invention aims to solve]

[0014] The main objective of this embodiment is to provide a method for generating new authentication and key management (AKMA) keys for applications in wireless networks.

[0015] Another object of this embodiment is to provide a system for generating at least one new Authentication and Key Management Unit (AKMA) key for applications in wireless networks.

[0016] Another objective of this embodiment is the application key (K A The application key (K) expires or expires immediately, by requesting the network to provide a refresh parameter to the UE. AFThe objective is to provide a system and method for refreshing ).

[0017] Another object of this embodiment is to provide a system and method for avoiding key synchronization problems when the key is refreshed on the UE or network side.

[0018] Furthermore, the proposed method will be used to support a mechanism for resolving key synchronization issues on the user terminal (UE) side. [Means for solving the problem]

[0019] Therefore, this embodiment provides a method performed by a Unified Data Management (UDM) in a wireless network to generate a new authentication and key management (AKMA) key for an application. The method includes the step of the UDM receiving a first request from an AKMA Anchor Function (AAnF) in the wireless network, where the first request includes an AKMA refresh request indication and a Subscription Permanent Identifier (SUPI) associated with a user terminal (UE) in the wireless network, wherein the first request indicates a request to generate a new AKMA key to establish communication between the user terminal (UE) in the wireless network and at least one Application Function (AF). The method further includes the UDM generating an AKMA refresh parameter (AKMA) based on the received first request. RP The method includes the step of generating the generated AKMA refresh parameters (AKMA) by UDM, along with at least one SUPI, in order to generate at least one new AKMA key. RP This further includes the step of sending the data to the Authentication Server Function (AUSF) within the wireless network.

[0020] Therefore, this embodiment provides a method for generating a new authentication and key management (AKMA) key for an application by an authentication server function unit (AUSF) in a wireless network. The method includes the step of the AUSF receiving a first request from an integrated data management unit (UDM) in the wireless network, where the first request is an AKMA refresh parameter (AKMA RP The first request includes a user terminal (UE) in the wireless network and at least one subscriber permanent identifier (SUPI) associated with the UE in the wireless network, wherein the first request represents a request to generate at least one new AKMA key to establish communication between the UE in the wireless network and at least one application function unit (AF). The method further includes a step by AUSF generating at least one new AKMA key and associated new AKMA key identifiers based on the received first request. The method further includes a step by AUSF transmitting the generated at least one new AKMA key to an AKMA anchor function unit (AAnF) in the wireless network, where the AAnF is associated with at least one AF.

[0021] Therefore, this embodiment provides a method for generating a new Authentication and Key Management Unit (AKMA) key for an application by a user terminal (UE) in a wireless network. The method includes the step of the user terminal (UE) receiving a first request from an Integrated Data Management Unit (UDM) in the wireless network, where the first request is an Authentication and Key Management Unit (AKMA) refresh parameter (AKMA) for an application. RPThe method further includes a step by which the user terminal (UE) generates at least one new AKMA key and associated new AKMA key identifier based on the received first request. The method further includes a step by which the user terminal (UE) sends a second request based on the generated at least one new AKMA key, where the second request is an application session establishment request to establish communication between the user terminal (UE) and at least one application function unit (AF).

[0022] This and other embodiments of the embodiments specified herein will be better recognized and understood when considered in conjunction with the following description and accompanying drawings. However, it should be understood that the following description, while illustrating preferred embodiments and many specific details thereof, is provided as examples and not as a limitation. Many changes and modifications can be made within the scope of these embodiments, and the embodiments specified herein include all such modifications. [Effects of the Invention]

[0023] Embodiments of this disclosure provide a method and apparatus for refreshing AKMA keys and AF keys without performing primary authentication.

[0024] Embodiments of this disclosure provide methods and apparatus for avoiding key synchronization problems by defining a method in which an AKMA key ID indicates a refreshed key.

[0025] This method is illustrated in the attached drawings, and similar reference letters throughout the drawings indicate corresponding parts in various drawings. Embodiments of this specification will be better understood from the following description with reference to the drawings. [Brief explanation of the drawing]

[0026] [Figure 1] This diagram illustrates a sequence flow scenario for establishing communication between a user terminal (UE) and an application function unit (AF) using conventional technology. [Figure 2] This drawing shows a block diagram of network entities for generating new AKMA keys and new AF keys according to embodiments disclosed in this application. [Figure 3] This drawing shows a block diagram of a user terminal for generating new AKMA keys and new AF keys according to the embodiments disclosed herein. [Figure 4A] This flowchart illustrates the various operations embodied by the network entity to generate new AKMA keys and new AF keys, as disclosed in the present invention. [Figure 4B] This flowchart illustrates the various operations embodied by the network entity to generate new AKMA keys and new AF keys, as disclosed in the present invention. [Figure 4C] This flowchart illustrates the various operations embodied by the UE to generate new AKMA keys and new AF keys, as disclosed in the present invention. [Figure 5] This is an exemplary sequential flowchart illustrating the generation of a new AKMA key and associated AKMA key identifier by an embodiment disclosed herein. [Figure 6] The embodiment disclosed herein illustrates the generation of a new AKMA key and associated AKMA key identifiers, as shown in this application. [Figure 7] The embodiment disclosed herein illustrates the generation of a new AKMA key and associated AKMA key identifiers, as shown in this application. [Figure 8]The embodiment disclosed herein illustrates the generation of a new AKMA key and associated AKMA key identifiers, as shown in this application. [Figure 9] The embodiments disclosed herein illustrate an exemplary sequential flowchart for generating a new AF key. [Figure 10] The embodiments disclosed herein illustrate an exemplary sequential flowchart for the generation of a new AKMA key based on a timer. [Figure 11] The embodiments disclosed herein illustrate an exemplary sequential flowchart for generating a new AF key based on a timer. [Modes for carrying out the invention]

[0027] The embodiments described herein and various features and advantageous details thereof are more fully described with reference to non-limiting embodiments shown in the accompanying drawings and described in detail in the following description. Descriptions of widely known components and processing techniques are omitted in order not to unnecessarily obscure the embodiments described herein. Furthermore, the various embodiments described herein are not necessarily mutually exclusive, as some embodiments may be combined with one or more other embodiments to form new embodiments. The term “or” as used herein means non-exclusive unless otherwise indicated. The examples used herein are for the purpose of facilitating the understanding of how the embodiments described herein may be carried out and further enabling persons skilled in the art to carry out the embodiments described herein. Accordingly, the examples should not be construed as limiting the scope of the embodiments described herein.

[0028] As is traditional in the art, embodiments may be described and illustrated in terms of a function or block that performs a function described. These blocks, which may be referred to herein as units or modules, etc., may be physically embodied by analog or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, etc., and may optionally be driven by firmware. The circuits may be embodied, for example, in one or more semiconductor chips, or on a substrate support such as a printed circuit board. The circuits constituting a block may be embodied by dedicated hardware, or by a processor (e.g., one or more programmed microprocessors and associated circuits), or by a combination of dedicated hardware that performs some of the functions of the block and a processor that performs other functions of the block. Each block of an embodiment may be physically separated into two or more interacting separate blocks without departing from the scope of the invention. Similarly, blocks of an embodiment may be physically coupled into more complex blocks without departing from the scope of the invention.

[0029] The accompanying drawings are provided to facilitate understanding of various technical features, and it should be understood that the embodiments presented herein are not limited by these drawings. Therefore, this disclosure should be construed as extending to any modifications, equivalents, and substitutions beyond those specifically designated in the accompanying drawings. While terms such as "first," "second," etc., may be used in this application to describe various elements, these elements should not be limited by these terms. These terms are generally used solely to distinguish one element from another.

[0030] The terms "electronic device," "user terminal," and "UE" have the same meaning and are used interchangeably throughout this document.

[0031] Therefore, this embodiment provides a method for generating a new authentication and key management (AKMA) key for an application by an authentication server function unit (AUSF) in a wireless network. The method includes the step of the AUSF receiving a first request from an integrated data management unit (UDM) in the wireless network, where the first request is an AKMA refresh parameter (AKMA RP The method includes a first request which includes a new AKMA key and an associated new AKMA key identifier,

[0032] In conventional methods and systems, the AF key (K AF ) cannot be immediately refreshed after the validity period expires until a new primary authentication occurs. This is because the user, K AF This means that after the authentication expires (which can happen after a very long period of time), you may not be able to use the application (which requires authentication using AKMA) until a new primary authentication procedure becomes available. However, K AF is, K AF Applications that depend on it must refresh it as needed, and therefore a mechanism is needed to request the network to provide refresh parameters for the AKMA service to refresh the AKMA key and AF key. AFPerforming primary authentication every time a new AF key needs to be created is a cumbersome approach and requires significant effort. Unlike conventional methods and systems, this disclosure generates a new AF key without requiring primary authentication.

[0033] A preferred embodiment is illustrated here, with reference to the drawings, and in particular to Figures 1 to 11, where similar reference letters consistently correspond to features throughout the drawings.

[0034] Figure 1 is a diagram illustrating a sequence flow scenario for a method of establishing communication between a user terminal (UE) and an application function unit (AF) using conventional technology. As shown in Figure 1, in step 110, UE102 initiates the network access authentication procedure by requesting AUSF104 to register UE102 for the AKMA service. In step 112, once the network access authentication procedure is completed, UE102 receives the AUSF key (K AUSF ) generates. Similarly, in step 114, AUSF104 further generates the AUSF key (K AUSF ) generates. In step 116, UE102 generates K AUSF Based on AKMA key (K AKMA ) Derive 116. Then UE102 is K AKMA Use the AF key (K AF ) is derived. Similarly, in step 118, AUSF104 generates K AUSF Based on K AKMA Derive K AKMA Once the result is derived, in step 120, AUSF104 sends a key response to AAnF106. In step 122, UE102 initiates an application session establishment request using A-KID1(112). In step 124, AF108, upon receiving the application session establishment request from UE102, will send a key request to AANF106. In step 126, AAnF10 will use A-KID1 to send a key request to AANF106. AF Derive (126). In step 128, AAnF106 is KAF A key response is sent to AF108 during generation. In step 130, AF108 sends an initial provisioning response including counter AF to UE102. AF When the effect expires, in stages 132 and 134, when UE102 sends an initial provisioning request using the previous A-KID1, AF108 will determine the K associated with the A-KID. AF The request is rejected because it is not enabled. In step 136, AF108 is unable to provide application access to UE102, and a new K for AF is not available. AF This cannot be generated until the next primary authentication is performed according to the conventional method. Therefore, UE102 may not be able to use applications that require AKMA services from AF108.

[0035] Figure 2 is a drawing showing a block diagram of a network entity 200 for generating new AKMA keys and new AF keys according to embodiments disclosed herein. In one embodiment, the network entity 200 includes a memory 210, a processor 220, a communicator 230, an AKMA refresh parameter generator 240, an AKMA key generator 250, an AKMA key identifier generator 260, and an AF key generator 280. In one embodiment, the network entity 200 includes AMF201, AUSF202, UDM203, AAnF204, and AF205 (not shown in Figure 2). In other embodiments, the network entity 200 may be one of AMF201, AUSF202, UDM203, AAnF204, and AF205.

[0036] Memory 210 further stores instructions executed by processor 220. Memory 210 may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memory, or EPROM (electrically programmable memory), or EEPROM (electrically erasable and programmable) memory. Furthermore, memory 210 can be considered a non-transitory storage medium in some examples. The term "non-transitory" can mean that the storage medium does not materialize as a carrier wave or propagated signal. However, the term "non-transitory" should not be interpreted as meaning that memory 210 is non-movable. In some examples, memory 210 may be configured to store more information than memory. In certain examples, a non-transitory storage medium may store data that can be modified over time (e.g., in RAM (Random Access Memory) or a cache). In one embodiment, the memory 210 may be an internal storage unit, an external storage unit of the network entity 200, cloud storage, or any other type of external storage.

[0037] The processor 220 communicates with the memory 210, the communicator 230, the AKMA refresh parameter generator 240, the AKMA key generator 250, the AKMA key identifier generator 260, and the AF key generator 270. The processor 220 is configured to execute instructions stored in the memory 210 and run various processes. The communicator 230 is configured to communicate internally between external devices and internal hardware components through one or more networks.

[0038] In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameter (AKMA RP ) generates AKMA RPThis can be generated by one of AUSF202, UDM203, and AAnF204 based on the received AKMA refresh display request. In one embodiment, AKMA RP This is a random (RAND) value, counter AKMA , and counter AF It may also be a value.

[0039] In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA ') generates. The AKMA key generator 250 generates AKMA, AUSF keys (K AUSF ), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE102 are input to the Key Distribution Function Unit (KDF) as shown in Equation 1. [Mathematics 1] K AKMA '=KDF(SUPI,K AUSF ,“AKMA”,AKMA RP )

[0040] In one embodiment, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') and generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates an AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300(102). In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (KAUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300. [Math 2] A-TID'=KDF(“A-TID”,K AUSF AKMA RP ,SUPI)

[0041] In one embodiment, the AF key generator 270 generates a new application function unit (AF) key. The AF key generator 270 generates an AKMA key (K AKMA ), at least one AF identifier (AF-ID), and AKMA refresh parameters (AKMA RP ) generates a new application function unit (AF) key based on. In one embodiment, the AF key generator 280 generates an AKMA key (K AKMA ), at least one AF identifier (AF-ID), and AKMA refresh parameters (AKMA RP Enter at least one of the following into the KDF as shown in Equation 3: a new application function unit (AF) key (K AF ) generates. [Math 3] K AF '=KDF(K AKMA, AF-ID, AKMA RP )

[0042] Figure 2 shows various hardware components of the network entity 200, but it should be understood that other embodiments are not limited thereto. In other embodiments, the network entity 200 may include fewer or more components. Furthermore, the labels or names of the components are used for illustrative purposes only and do not limit the scope of the invention. One or more components that perform the same or substantially similar functions can be combined together to generate new AKMA keys and new AF keys for establishing communication between UE102 and AF205 in a wireless network.

[0043] Figure 3 shows a block diagram of a UE300 for generating new AKMA keys and new AF keys according to embodiments disclosed herein. In one embodiment, the user terminal 300 includes a memory 310, a processor 320, a communicator 330, an AKMA key generator 340, an AKMA key identifier generator 350, and an AF key generator 360.

[0044] Memory 310 further stores instructions to be executed by processor 320. Memory 310 may include non-volatile storage elements. Examples of such non-volatile storage elements may include magnetic hard disks, optical disks, floppy disks, flash memory, or EPROM (electrically programmable memory), or EEPROM (electrically erasable and programmable) memory. Furthermore, memory 310 can be considered a non-transitory storage medium in some examples. The term "non-transitory" can mean that the storage medium does not materialize as a carrier wave or propagated signal. However, the term "non-transitory" should not be interpreted as meaning that memory 310 is non-movable. In some examples, memory 310 may be configured to store more information than memory. In certain examples, a non-transitory storage medium may store data that can be modified over time (e.g., in RAM (Random Access Memory) or a cache). In one embodiment, the memory 310 may be an internal storage unit, an external storage unit of the network entity 300, cloud storage, or any other type of external storage.

[0045] The processor 320 communicates with the memory 310, the communicator 330, the AKMA key generator 340, the AKMA key identifier generator 350, and the AF key generator 380. The processor 320 is configured to execute instructions stored in the memory 310 and run various processes. The communicator 330 is configured to communicate internally between external devices and internal hardware components through one or more networks.

[0046] In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA ') generates. AKMA key generator 360 generates AKMA, AUSF keys (K AUSF ), AKMA refresh parameters (AKMA RP) and generate a new AKMA key (K AKMA ’) based on at least one SUPI associated with the UE300. In one embodiment, the new AKMA key (K AKMA ’) is generated by inputting the AKMA, the AUSF key (K AUSF ), the AKMA refresh parameter (AKMA RP ), and at least one SUPI associated with the UE300 into the key distribution function KDF as shown in Equation 1.

[0047] In one embodiment, the AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID’). The AKMA key identifier generator 370 generates a new AKMA temporary identifier (A-TID’) and generates a new AKMA key identifier (A-KID’). The AKMA key identifier generator 370 generates a new AKMA temporary identifier (A-TID’) based on the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameter (AKMA RP ), and at least one SUPI associated with the UE300. In one embodiment, the AKMA key identifier generator 370 generates a new AKMA temporary identifier (A-TID’) by inputting the AUSF key (K AUSF ), the current AKMA temporary identifier (A-TID), the AKMA refresh parameter (AKMA RP ), and at least one SUPI associated with the UE300 into the KDF as shown in Equation 2.

[0048] In one embodiment, the AF key generator 360 generates a new application function key (K AF ’). The AF key generator 360 generates a new application function key (K AKMA ’) based on the new AKMA key (K RP ), the identifier of the AF205 (AF-ID), and the AKMA refresh parameter (AKMA AF ’). In one embodiment, the AF key generator 360 uses the new AKMA key (K AKMA'), at least one AF identifier (AF-ID), and AKMA refresh parameter (AKMA RP A new application function key (K) is created by entering at least one of the following into the KDF as shown in Equation 3. AF Generates ').

[0049] Figure 3 shows various hardware components of the user terminal 300, but it should be understood that other embodiments are not limited thereto. In other embodiments, the user terminal 300 may include fewer or more components. Furthermore, the labels or names of the components are used for illustrative purposes only and do not limit the scope of the invention. One or more components that perform the same or substantially similar functions can be combined together to generate new AKMA keys and new AF keys for establishing communication between the UE300 and the application function unit 205 in a wireless network.

[0050] Figures 4A and 4B are flowcharts illustrating various operations embodied by the network entity 200 to generate new AKMA keys and new AF keys according to embodiments disclosed herein.

[0051] In 402, the method includes the step of receiving an AKMA refresh request from the AAnF204 via the UDM203. In one embodiment, the AKMA refresh request received from the AAnF204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user terminal (UE) 300.

[0052] In block 404, the method includes the step of generating AKMA refresh parameters based on an AKMA refresh request received by UDM203. In one embodiment, the AKMA refresh parameter generator 240 generates AKMA refresh parameters (AKMA RP ) generates AKMA RPcan be generated by one of AUSF202, UDM203, and AAnF204 based on the received AKMA refresh display request. In one embodiment, AKMA RP is at least one of a random (RAND) value, a counter AKMA , and a counter AF value.

[0053] In block 406, the method includes the step of the UDM203 sending an AKMA refresh parameter (AKMA RP ) to the AUSF202. In one embodiment, the UDM203 sends the AKMA refresh parameter (AKMA RP ) to the AUSF202 together with at least one SUPI associated with the UE300.

[0054] In block 408, the method includes the step of the AUSF202 generating a new AKMA key (K AKMA ’) and an associated new AKMA key identifier (A-KID’). In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA ’). The AKMA key generator 250 generates a new AKMA key (K AUSF ) based on AKMA, the AUSF key (K RP ), the AKMA refresh parameter (AKMA AKMA ’), and at least one SUPI associated with the UE300. In one embodiment, the new AKMA key (K AKMA ’) is based on AKMA, the AUSF key (K AUSF ), the AKMA refresh parameter (AKMA RP), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates an AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0055] In block 410, the method includes the step of AUSF202 transmitting an AKMA response to UDM203. In one embodiment, AUSF202 transmits an AKMA refresh response to UDM203. The AKMA refresh response includes an acknowledgment of the AKMA refresh request received from UDM203. The AKMA refresh response further includes an AKMA MAC-I AUSF and counter AKMA This includes.

[0056] In block 412, the method includes the step of AUSF202 sending an AKMA anchor key registration request refresh response to AAnF204. In one embodiment, AUSF202 sends an AKMA anchor key registration request refresh response to AAnF204. In one embodiment, the AKMA anchor key registration request refresh response is a new AKMA key (K AKMA'), including at least one SUPI associated with UE300, and a new AKMA key identifier (A-KID').

[0057] In block 414, the method includes the step of having UDM203 send a notification to UE300 via AMF201. In one embodiment, UDM203 sends a notification to UE300 via AMF201. The notification is an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0058] In block 416, the method includes the step of having the UDM203 receive an acknowledgment from the UE300 through the AMF201. In one embodiment, the UDM203 receives an acknowledgment from the UE300.

[0059] Figure 4C is a flowchart illustrating the various operations embodied by the UE300 to generate new AKMA keys and new AF keys according to the embodiments disclosed herein.

[0060] In block 452, the method includes the step of receiving a notification from UDM203 via UE300. In one embodiment, UE300 receives a notification from UDM203. In one embodiment, UE300 receives a notification from UDM203 via AMF201. The notification is an AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0061] In block 454, the method includes the step of generating a new AKMA key and associated AKMA key identifier (A-KID) based on a notification received by the UE300. In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA ') generates. The AKMA key generator 340 generates AKMA, AUSF keys (K AUSF), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 370 generates a new AKMA temporary identifier (A-TID') and generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 370 generates the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP Based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0062] In 456, the method includes the step of sending an acknowledgment to the UDM203 via the UE300. In one embodiment, the UE300 sends an acknowledgment to the UDM203 via the AMF201.

[0063] In 458, the method includes the step of having the UE300 send an application session establishment request to the AF205. In one embodiment, the UE300 sends an application session establishment request to the AF205 based on a new AKMA key identifier (A-KID').

[0064] Figure 5 is an exemplary sequential flowchart illustrating the generation of a new AKMA key and associated AKMA key identifier by an embodiment disclosed herein.

[0065] In 510, UE300 performs primary authentication with the network entity by registering with UDM203. After primary authentication, UE300 and AUSF202 use the AUSF key (K AUSF This will lead to the deriving of ).

[0066] In 515, UE300 and AF205 are K in accordance with TS 33.535. AKMA and K AF This is generated.

[0067] In 520, AAnF204 sends an AKMA refresh request to UDM203. In one embodiment, the AKMA refresh request received from AAnF204 includes an AKMA refresh indicator and at least one SUPI associated with the UE300.

[0068] In 525, UDM203 generates AKMA refresh parameters based on the received AKMA refresh request. In one embodiment, the AKMA refresh parameter generator 240 generates AKMA refresh parameters (AKMA RP ) generates AKMA RP This can be generated by one of AUSF202, UDM203, and AAnF204 based on the received AKMA refresh display request. In one embodiment, AKMA RP This is a random (RAND) value, a counterAKMA , and counter AF It may be at least one of the values.

[0069] At 530, UDM203 sends the AKMA refresh parameters to AUSF202. In one embodiment, UDM203 sends the AKMA refresh parameters (AKMA) along with at least one SUPI associated with UE300. RP ) is sent to AUSF202.

[0070] In 535, AUSF202 has a new AKMA key (K AKMA ') and associated AKMA key identifier (A-KID) are generated. In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA ') generates. The AKMA key generator 250 generates AKMA, AUSF keys (K AUSF ), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is the AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), “AKMA” and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates the AUSF key (K AUSF ), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF), “A-TID”, AKMA refresh parameter (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0071] At 540, AUSF202 sends an AKMA response to UDM203. In one embodiment, AUSF202 sends an AKMA refresh response to UDM203. The AKMA refresh response includes an acknowledgment of the AKMA refresh request received from UDM203. The AKMA refresh response further includes an AKMA MAC-I AUSF and counter AKMA This includes.

[0072] In step 545, AUSF202 sends an AKMA anchor key registration request refresh response to AAnF204. In one embodiment, AUSF202 sends an AKMA anchor key registration request refresh response to AAnF204. In one embodiment, the AKMA anchor key registration request refresh response is a new AKMA key (K AKMA '), including at least one SUPI associated with UE300, and a new AKMA key identifier (A-KID').

[0073] In 550, UDM203 sends a notification to AMF201. In one embodiment, UDM203 sends a notification to AMF201. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0074] At 555, the AMF201 sends a notification to the UE300. In one embodiment, the AMF201 sends a notification to the UE300. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0075] In step 560, the UE300 generates a new AKMA key and associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, the AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 340 generates the AUSF key (K). AUSF ), "AKMA", AKMA refresh parameter (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 370 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') and generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the key distribution function unit, as shown in Equation 2: ) and at least one SUPI associated with the UE300.

[0076] At 565, the UE300 sends an acknowledgment to the AMF201. In one embodiment, the UE300 sends an acknowledgment to the AMF201.

[0077] At 570, AMF201 sends an acknowledgment to UDM203. In one embodiment, AMF201 sends an acknowledgment to UDM203.

[0078] At step 575, the UE300 sends an application session establishment request to the AF205. In one embodiment, the UE300 sends an application session establishment request to the AF205 based on a new AKMA key identifier (A-KID').

[0079] Figure 6 is an exemplary sequential flowchart illustrating the generation of a new AKMA key and associated AKMA key identifier by an embodiment disclosed herein.

[0080] In 610, UE300 performs primary authentication with the network entity by registering with UDM203. After primary authentication, UE300 and AUSF202 use the AUSF key (K AUSF This will lead to the deriving of ).

[0081] In 615, UE300 and AF205 are K in accordance with TS 33.535. AKMA and K AF Generates.

[0082] In 620, AAnF204 sends an AKMA refresh request to UDM203. In one embodiment, the AKMA refresh request received from AAnF204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user terminal (UE).

[0083] In 625, UDM203 generates AKMA refresh parameters based on the received AKMA refresh request. In one embodiment, the AKMA refresh parameter generator 240 generates AKMA refresh parameters (AKMA RP) generates AKMA RP This can be generated by one of AUSF202, UDM203, and AAnF204 based on the received AKMA refresh display request. In one embodiment, AKMA RP This is a random (RAND) value, a counter AKMA , and counter AF It may be at least one of the values.

[0084] At 630, UDM203 sends the AKMA refresh parameters to AUSF202. In one embodiment, UDM203 sends the AKMA refresh parameters (AKMA) along with at least one SUPI associated with UE300. RP ) is sent to AUSF202.

[0085] In 635, AUSF202 has a new AKMA key (K AKMA ') and associated AKMA key identifier (A-KID) are generated. In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA ') is generated. The AKMA key generator 250 generates AUSF keys (K AUSF ), "AKMA", AKMA refresh parameter (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates an AUSF key (K AUSF), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0086] At 640, AUSF202 sends an AKMA response to UDM203. In one embodiment, AUSF202 sends an AKMA refresh response to UDM203. The AKMA refresh response includes an acknowledgment of the AKMA refresh request received from UDM203. The AKMA refresh response further includes an AKMA MAC-I AUSF and counter AKMA This includes.

[0087] In step 645, UDM203 sends a notification to AMF201. In one embodiment, UDM203 sends a notification to AMF201. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0088] At 650, the AMF201 sends a notification to the UE300. In one embodiment, the AMF201 sends a notification to the UE300. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0089] In 655, UE300 generates a new AKMA key and associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, AKMA key generator 340 generates a new AKMA key (K AKMA’ ) generates. The AKMA key generator 340 generates AUSF keys (K AUSF ), "AKMA", AKMA refresh parameter (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') and generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0090] In 660, the UE300 sends an acknowledgment to the AMF201. In one embodiment, the UE300 sends an acknowledgment to the AMF201.

[0091] At step 665, UDM203 transmits refresh information to AUSF202. In one embodiment, UDM203 transmits refresh information to AUSF202 that includes an acknowledgment for receiving an acknowledgment from AMF201.

[0092] At 670, AMF201 sends an acknowledgment to UDM203. In one embodiment, AMF201 sends an acknowledgment to UDM203.

[0093] In step 675, AUSF202 sends an AKMA anchor key registration request refresh response to AANF204. In one embodiment, AUSF202 sends an AKMA anchor key registration request refresh response to AANF204. In one embodiment, the AKMA anchor key registration request refresh response is a new AKMA key (K AKMA '), including at least one SUPI associated with UE300, and a new AKMA key identifier (A-KID').

[0094] In step 680, the UE300 sends an application session establishment request to the AF205. In one embodiment, the UE300 sends an application session establishment request to the AF205 based on a new AKMA key identifier ('A-KID').

[0095] Figure 7 is an exemplary sequential flowchart illustrating the generation of a new AKMA key and associated AKMA key identifier by an embodiment disclosed herein.

[0096] In 710, UE300 performs primary authentication with the network entity by registering with UDM203. After primary authentication, UE300 and AUSF202 use the AUSF key (K AUSF This will lead to the deriving of ).

[0097] In 715, UE300 and AF205 are K in accordance with TS 33.535. AKMA and K AFGenerates.

[0098] In 720, AAnF204 sends an AKMA refresh request to UDM203. In one embodiment, the AKMA refresh request received from AAnF204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user terminal (UE).

[0099] At step 725, UDM203 sends an AKMA refresh request to AUSF202. In one embodiment, UDM203 sends an AKMA refresh request to AUSF202 along with at least one SUPI associated with UE300.

[0100] In 730, AUSF202 is the AKMA refresh parameter (AKMA RP ), new AKMA key (K AKMA '), and the associated AKMA key identifier (A-KID') are generated. In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameter (AKMA RP ) generates. In one embodiment, AKMA RP This is a random (RAND) value, a counter AKMA , and counter AF It may be at least one of the values. In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA The AKMA key generator 250 generates a new AKMA key (K). AKMA '), AUSF key (K AUSF ), "AKMA", AKMA refresh parameter (AKMA RP ), and generate at least one SUPI associated with the UE300. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0101] At step 735, AUSF202 sends an AKMA response to UDM203. In one embodiment, AUSF202 sends an AKMA refresh response to UDM203. The AKMA refresh response includes an acknowledgment of the AKMA refresh request received from UDM203. The AKMA refresh response further includes an AKMA MAC-I AUSF and counter AKMA and 。

[0102] In 740, AUSF202 sends an AKMA anchor key registration request refresh response to AANF204. In one embodiment, AUSF202 sends an AKMA anchor key registration request refresh response to AANF204. In one embodiment, the AKMA anchor key registration request refresh response is a new AKMA key (K AKMA '), including at least one SUPI associated with UE300, and a new AKMA key identifier (A-KID').

[0103] In step 745, UDM203 sends a notification to AMF201. In one embodiment, UDM203 sends a notification to AMF201. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0104] In 750, the AMF201 sends a notification to the UE300. In one embodiment, the AMF201 sends a notification to the UE300. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0105] In 755, UE300 generates a new AKMA key and associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 340 generates the AUSF key (K). AUSF ), "AKMA", AKMA refresh parameter (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') and generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates an AUSF key (K AUSF), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0106] At 760, the UE300 sends an acknowledgment to the AMF201. In one embodiment, the UE300 sends an acknowledgment to the AMF201.

[0107] At 765, AMF201 sends an acknowledgment to UDM203. In one embodiment, AMF201 sends an acknowledgment to UDM203.

[0108] In step 770, the UE300 sends an application session establishment request to the AF205. In one embodiment, the UE300 sends an application session establishment request to the AF205 based on a new AKMA key identifier ('A-KID').

[0109] Figure 8 is another exemplary sequential flowchart illustrating the generation of a new AKMA key and associated AKMA key identifier by an embodiment disclosed herein.

[0110] In 810, UE300 performs primary authentication with the network entity by registering with UDM203. After primary authentication, UE300 and AUSF202 use the AUSF key (K AUSF This will lead to the deriving of ).

[0111] In 815, UE300 and AF205 conform to TS 33.535 K AKMAand K AF Generates.

[0112] In 820, AAnF204 generates AKMA refresh parameters. In one embodiment, the AKMA refresh parameter generator 240 generates AKMA refresh parameters (AKMA RP ) generates. In one embodiment, AKMA RP This is a random (RAND) value, a counter AKMA , and counter AF It may be at least one of the values.

[0113] In step 825, AAnF204 sends an AKMA refresh request to UDM203. In one embodiment, the AKMA refresh request received from AAnF204 includes AKMA refresh parameters and at least one SUPI associated with at least one user terminal (UE).

[0114] At 830, UDM203 sends the AKMA refresh parameters to AUSF202. In one embodiment, UDM203 sends the AKMA refresh parameters (AKMA) along with at least one SUPI associated with UE300. RP ) is sent to AUSF202.

[0115] In 835, AUSF202 has a new AKMA key (K AKMA ') and associated AKMA key identifier (A-KID) are generated. In one embodiment, the AKMA key generator 250 generates a new AKMA key (K AKMA ') generates. The AKMA key generator 250 generates AKMA, AUSF keys (K AUSF ), AKMA refresh parameters (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is “AKMA”, AUSF key (K AUSF), AKMA refresh parameters (AKMA RP ), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 260 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') to generate a new AKMA key identifier (A-KID'). The AKMA key identifier generator 260 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 260 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the ), and at least one SUPI associated with the UE300 into the key distribution function unit as shown in Equation 2.

[0116] At 840, AUSF202 sends an AKMA response to UDM203. In one embodiment, AUSF202 sends an AKMA refresh response to UDM203. The AKMA refresh response includes an acknowledgment of the AKMA refresh request received from UDM203. The AKMA refresh response further includes an AKMA MAC-I AUSF and counter AKMA This includes.

[0117] In step 845, AUSF202 sends an AKMA anchor key registration request refresh response to AANF204. In one embodiment, AUSF202 sends an AKMA anchor key registration request refresh response to AANF204. In one embodiment, the AKMA anchor key registration request refresh response is a new AKMA key (K AKMA'), including at least one SUPI associated with UE300, and a new AKMA key identifier (A-KID').

[0118] In 850, UDM203 sends a notification to AMF201. In one embodiment, UDM2003 sends a notification to AMF201. The notification is the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0119] In step 855, the AMF201 sends a notification to the UE300. In one embodiment, the AMF201 sends a notification to the UE300. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0120] In 860, UE300 generates a new AKMA key and associated AKMA key identifier (A-KID) based on the received notification. In one embodiment, AKMA key generator 340 generates a new AKMA key (K AKMA The AKMA key generator 340 generates the AUSF key (K). AUSF ), "AKMA", AKMA refresh parameter (AKMA RP ), and a new AKMA key (K AKMA ') is generated. In one embodiment, a new AKMA key (K AKMA ') is AKMA, AUSF key (K AUSF ), AKMA refresh parameters (AKMA RP), and at least one SUPI associated with UE300 are input to the KDF as shown in Equation 1. Furthermore, in other embodiments, the AKMA key identifier generator 350 generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') and generates a new AKMA key identifier (A-KID'). The AKMA key identifier generator 350 generates an AUSF key (K AUSF ), “A-TID”, AKMA refresh parameter (AKMA RP ), and a new AKMA temporary identifier (A-TID') is generated based on at least one SUPI associated with UE300. In one embodiment, the AKMA key identifier generator 350 generates a new AKMA temporary identifier (A-TID') based on the AUSF key (K AUSF ), current AKMA temporary identifier (A-TID), AKMA refresh parameters (AKMA RP A new AKMA temporary identifier (A-TID') is generated by inputting the following into the KDF as shown in Equation 2: ) and at least one SUPI associated with UE300.

[0121] At 865, the UE300 sends an acknowledgment to the AMF201. In one embodiment, the UE300 sends an acknowledgment to the AMF201.

[0122] At 870, AMF201 sends an acknowledgment to UDM203. In one embodiment, AMF201 sends an acknowledgment to UDM203.

[0123] At step 875, the UE300 sends an application session establishment request to the AF205. In one embodiment, the UE300 sends an application session establishment request to the AF205 based on a new AKMA key identifier ('A-KID').

[0124] Figure 9 is an exemplary sequential flowchart illustrating the generation of a new AF key according to the embodiments disclosed herein.

[0125] In 910, UE300 performs primary authentication with the network entity by registering with UDM203. After primary authentication, UE300 and AUSF202 use the AUSF key (K AUSF This will lead to the deriving of ).

[0126] In 915, UE300 and AF205 comply with TS 33.535 K AKMA and K AF Generates.

[0127] At 920, AAnF204 sends an AKMA refresh request to UDM203. In one embodiment, the AKMA refresh request received from AAnF204 includes an AKMA refresh indicator and at least one SUPI associated with at least one user terminal (UE).

[0128] At 925, UDM203 receives a new K based on an AKMA refresh request received from AAnF. AF Trigger a refresh.

[0129] At 930, UDM203 sends an AKMA refresh request to AUSF202. In one embodiment, the AKMA refresh request received from AUSF202 includes an AKMA refresh indicator and at least one SUPI associated with at least one user terminal (UE).

[0130] At 935, UDM203 generates AKMA refresh parameters based on the received AKMA refresh request. In one embodiment, the AKMA refresh parameter generator 240 generates the AKMA refresh parameters (AKMA RP ) generates. In one embodiment, AKMA RP This is a random (RAND) value, a counter AKMA , and counter AF It may be at least one of the values.

[0131] At 940, AUSF202 sends an AKMA response to UDM203. In one embodiment, AUSF202 sends an AKMA refresh response to UDM203. The AKMA refresh response includes an acknowledgment of the AKMA refresh request received from UDM203. The AKMA refresh response further includes an AKMA MAC-I AUSF and counter AKMA This includes.

[0132] At 945, UDM203 sends an AKMA refresh response to AAnF204. In one embodiment, the AKMA refresh response is sent to the AKMA refresh parameter (AKMA RP ) includes.

[0133] At 950, the AAnF204 features a new AF key (K) based on AKMA refresh response. AF ) generates.

[0134] In step 955, UDM203 sends a notification to AMF201. In one embodiment, UDM203 sends a notification to AMF201. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0135] In 960, the AMF201 sends a notification to the UE300. In one embodiment, the AMF201 sends a notification to the UE300. The notification is for the AKMA refresh parameter (AKMA RP ), AKMA MAC-I AUSF , and counter AKMA It includes at least one of the following.

[0136] In version 965, the UE300 generates a new AF key based on the received notification.

[0137] At 970, the UE300 sends an acknowledgment to the AMF201. In one embodiment, the UE300 sends an acknowledgment to the AMF201.

[0138] At 975, AMF201 sends an acknowledgment to UDM203. In one embodiment, AMF201 sends an acknowledgment to UDM203.

[0139] Figure 10 is an exemplary sequential flowchart illustrating the generation of a new AKMA key based on a timer, as disclosed in this application.

[0140] In step 1010, UE300 performs primary authentication with the network entity by registering with AAnF204. After primary authentication is performed, UE300 and AAnF202 use the AUSF key (K AUSF This will lead to the deriving of ).

[0141] In step 1015, the UE300 sends an application session establishment request to the AF205. In one embodiment, the UE300 sends an application session establishment request to the AF based on an AKMA key identifier (A-KID).

[0142] 1020, AF205 is K AF When the associated timer expires, K AF It is determined to be invalid.

[0143] In 1025, the AF205 has a new AF key (K AF Send the request to AAnF204.

[0144] In the 1030, the AAnF204 has a new AF key (K AF ) is K AF If the current timer value is unavailable in AAnF204, a request rejection is sent to AF205.

[0145] At 1035, AF205 sends a rejection message to UE300 according to the current timer value.

[0146] At 1040, AAnF204 has a new AKMA key (K AKMA Triggers ').

[0147] At 1045, AAnF204 sends a refresh parameter request to UDM203.

[0148] At 1050, UDM203 is the AKMA refresh parameter (AKMA RP ) generates and the generated AKMA RP Along with this, an AKMA refresh response is sent to the AUSF202 as an acknowledgment.

[0149] At step 1055, when AUSF202 receives the AKMA refresh parameter from UDM203, it sends an AKMA refresh response.

[0150] At 1060, the UDM203 was produced by AKMA along with a new associated timer. RP Send this to UE300.

[0151] 1065, UE300 has new AKMA key (K AKMA Generates ').

[0152] 1070, AUSF202 has a new AKMA key (K AKMA Generates ').

[0153] At 1075, AUSF202 sends an AKMA anchor key registration request to AANF204. In one embodiment, the AKMA anchor key registration request is generated K AKMA 'Includes.

[0154] At 1080, AAnF204 sends an AKMA anchor key registration request to AUSF202. In one embodiment, the AKMA anchor key registration response is received by AAnF204. AKMA’ Includes an acknowledgment of the above.

[0155] Figure 11 is an exemplary sequential flowchart illustrating the generation of a new AF key based on a timer, as disclosed in this application.

[0156] In 1110, UE300 performs primary authentication with the network entity by registering with AAnF203. After primary authentication, UE300 and AUSF202 use the AUSF key (K AUSF This will lead to the deriving of ).

[0157] At step 1115, the UE300 sends an application session establishment request to the AF205. In one embodiment, the UE300 sends an application session establishment request to the AF205 based on an AKMA key identifier (A-KID).

[0158] At 1120, AF205 is K AF When the associated timer expires, K AF It is determined to be invalid.

[0159] In 1125, the AF205 has a new AF key (K AF Send the request to AAnF204.

[0160] In 1130, the AAnF204 has a new AF key (K AF ) is K AF If the current timer value is unavailable in AAnF204, a request rejection is sent to AF205.

[0161] At 1135, AF205 sends a rejection message to UE300 according to the current timer value.

[0162] In 1140, the AAnF204 has a new AF key (K AF Triggers ').

[0163] At 1145, AAnF204 sends a refresh parameter request to UDM203.

[0164] At 1150, the UDM 203 generates AKMA refresh parameters (AKMA RP ), and sends the generated AKMA RP along with an AKMA refresh response as a confirmation response to the AUSF 204.

[0165] At 1155, the UDM 203 sends the generated AKMA RP to the UE 300 together with the relevant new timer.

[0166] At 1160, the UE 300 generates a new AF key (K AF ’).

[0167] At 1165, the AAnF 204 generates a new AF key (K AF ’).

[0168] The foregoing description of specific embodiments is to fully disclose the general characteristics of the embodiments of the present application so that others can, without departing from the general concept, easily modify and / or adapt it for various applications such as specific embodiments. Therefore, such adaptations and modifications should be understood to be within the meaning and scope of the equivalents of the disclosed embodiments and are intended to be so understood. The phrases or terms used in the present application should be understood to be for the purpose of explanation rather than limitation. Therefore, although the embodiments of the present application are described from the perspective of preferred embodiments, those skilled in the art will recognize that the embodiments of the present application can be modified and implemented within the scope of the embodiments described in the present application.

Description of Reference Numerals

[0169] 200 Network entity 205 Application function unit 210 Memory 220 Processor 230 Communicator 240 AKMA refresh parameter generator 250 AKMA key generator 260 AKMA Key Identifier Generator 270 AF Key Generator 280 AF Key Generator 300 User Terminal 310 Memory 320 Processor 330 Communicator 340 AKMA Key Generator 350 AKMA Key Identifier Generator 360 AF Key Generator 370 AKMA Key Identifier Generator 380 AF Key Generator

Claims

1. A method performed by an Integrated Data Management Unit (UDM) in a wireless network to generate at least one new Authentication and Key Management Unit (AKMA) key for an application, A receiving step in which a first request is received from an AKMA anchor function unit (AAnF), wherein the first request is for an AKMA refresh and includes a subscription permanent identifier (SUPI) associated with at least one user terminal (UE), The steps include generating at least one AKMA parameter for refreshing based on the received first request, A method comprising the step of sending at least one generated AKMA parameter for refresh to an authentication server function unit (AUSF) in order to generate the at least one new AKMA key.

2. The method according to claim 1, further comprising the step of receiving at least one response message from the AUSF when the AUSF generates the at least one new AKMA key.

3. The method according to claim 1, further comprising the step of transmitting at least one AKMA parameter for the generated refresh to at least one user terminal via an Access and Mobility Management Function (AMF).

4. The method according to claim 1, wherein the at least one new AKMA key is associated with a new AKMA key identifier.

5. A method for generating at least one new authentication and key management (AKMA) key for an application by an authentication server function unit (AUSF) in a wireless network, The receiving step includes receiving a message from the Integrated Data Management Unit (UDM), wherein the message includes at least one AKMA parameter for refresh and at least one Subscriber Permanent Identifier (SUPI) associated with a User Terminal (UE), The steps include generating at least one new AKMA key and a new AKMA key identifier (A-KID') based on the received message, A method comprising the step of transmitting the generated at least one new AKMA key to an AKMA anchor function unit (AAnF).

6. The method according to claim 5, further comprising the step of sending at least one acknowledgment to the UDM when at least one new AKMA key is generated.

7. AUSF key (K AUSF ), by inputting at least one of AKMA, AKMA parameters for refresh, or at least one SUPI into the Key Derivation Function Unit (KDF) AKMA The stage of generating ', K AUSF The steps include: generating a new AKMA temporary identifier (A-TID') by inputting at least one of the following into the KDF: an AKMA temporary identifier (A-TID), an AKMA parameter for refreshing, or at least one SUPI; The method according to claim 5, further comprising the step of generating a new AKMA key identifier (A-KID') based on the new AKMA temporary identifier (A-TID').

8. A method for generating at least one new Authentication and Key Management Unit (AKMA) key for an application by a user terminal (UE) in a wireless network, A step of receiving authentication and key management (AKMA) parameters for refresh in order to generate at least one new AKMA key from the Integrated Data Management Unit (UDM), The steps include generating at least one new AKMA key and associated new AKMA key identifier (A-KID') based on the received AKMA parameters for refresh, The process includes the step of sending a second request to at least one application function (AF) based on the generated at least one new AKMA key, The method wherein the second request is an application session establishment request for establishing communication between the UE and at least one AF.

9. The method according to claim 8, further comprising the step of sending at least one acknowledgment to the UDM in response to generating the at least one new AKMA key.

10. The method according to claim 8, wherein the at least one new AKMA key generated is associated with the A-KID'.

11. An integrated data management unit (UDM) in a wireless network for generating at least one new authentication and key management unit (AKMA) key for an application, Communication equipment, The communication device includes a processor connected to the aforementioned communication device, The aforementioned processor, The AKMA Anchor Function Unit (AAnF) receives a first request, the first request being for an AKMA refresh, and includes a Subscriber Permanent Identifier (SUPI) associated with at least one User Terminal (UE), Based on the received first request, at least one AKMA parameter for refresh is generated, A UDM configured to send at least one AKMA parameter for the generated refresh to the Authentication Server Function Unit (AUSF) in order to generate the at least one new AKMA key.

12. The aforementioned processor, The UDM according to claim 11, further configured to receive at least one response message from the AUSF when the AUSF generates the at least one new AKMA key.

13. Authentication Server Function Unit (AUSF) in a Wireless Network for generating at least one new Authentication and Key Management Unit (AKMA) key for an application, Communication equipment, The communication device includes a processor connected to the aforementioned communication device, The aforementioned processor, A message is received from the Integrated Data Management Unit (UDM), and the message includes at least one AKMA parameter for refresh and at least one Subscriber Permanent Identifier (SUPI) associated with a User Terminal (UE). Based on the received message, generate at least one new AKMA key and a new AKMA key identifier (A-KID'), AUSF is configured to send the generated at least one new AKMA key to the AKMA Anchor Function Unit (AAnF).

14. The aforementioned processor, The AUSF according to claim 13, further configured to send at least one acknowledgment to the UDM when generating the at least one new AKMA key.

15. A user terminal (UE) in a wireless network for generating at least one new authentication and key management unit (AKMA) key for an application, Communication equipment, The communication device includes a processor connected to the aforementioned communication device, The aforementioned processor, The Integrated Data Management Unit (UDM) receives the Authentication and Key Management (AKMA) parameters for refresh in order to generate at least one new AKMA key. Based on the received AKMA parameters for refresh, at least one new AKMA key and an associated new AKMA key identifier (A-KID') are generated. At least one application function (AF) is configured to send a second request based on the at least one new AKMA key that was generated. The second request is an application session establishment request for establishing communication between the UE and at least one AF, provided the user terminal (UE).