Key request method and apparatus, functional entity, and network device

By introducing a key request method in the mobile communication network, the first functional entity is allowed to determine whether to provide AKMA application layer keys based on the current network status of the terminal, solving the problem that the user cannot provide AKMA services in the roaming state, and realizing security control of the terminal in different network environments.

WO2025107879A1PCT designated stage expired Publication Date: 2025-05-30CHINA MOBILE COMM LTD RES INST +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/121741
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-21
Filing Date
2024-09-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing mobile communication networks cannot provide application layer key management services (AKMA) in the user roaming state.

Method used

The first functional entity receives the message sent by the second functional entity, determines whether it is allowed to provide the AKMA application layer key to the terminal of the current network, and controls it according to the key service setting information.

Benefits of technology

It realizes the control of providing AKMA application layer key service in the user roaming state, ensuring the security and reliability of the terminal in different network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024121741_30052025_PF_FP_ABST
    Figure CN2024121741_30052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a key request method and apparatus, a functional entity, and a network device. The method comprises: receiving a first message sent by a second functional entity, wherein the first message is related to acquisition of an authentication and key management for applications (AKMA) application-layer key of a terminal; sending a second message to a second functional entity, wherein the second message comprises a determination result which indicates that an AKMA application-layer key is provided for the terminal in the current network, or indicates that an AKMA application-layer key is not allowed to be provided for the terminal in the current network.
Need to check novelty before this filing date? Find Prior Art

Description

Key request method, device, functional entity and network equipment

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese Patent Application No. 202311557315.1 filed in China on November 21, 2023, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates to the field of security technology, and in particular to a key request method, apparatus, functional entity, and network equipment. Background Art

[0004] Existing mobile communication networks have the ability to use network layer keys to provide access authentication and key management services for the application layer. Depending on whether the application function (AF) is outside or inside the operator, there are two ways for the AF to obtain the application layer key of the identity authentication and key management service (AKMA). One way is for the AF to directly communicate with the AKMA key anchor function (AAnF) entity to obtain the AKMA application layer key. The other way is for the AF to obtain the AKMA application layer key through the network exposure function (NEF).

[0005] In the above method, AF is connected to AAnF or NEF through IP, and AF is considered to belong to the Home Public Land Mobile Network (HPLMN), and cannot implement AKMA application layer key service for roaming users.

[0006] Summary of the Invention

[0007] The purpose of the technical solution disclosed herein is to provide a key request method, apparatus, functional entity and network equipment for implementing the control of AKMA application layer key provisioning services for users in different networks.

[0008] One embodiment of the present disclosure provides a key request method, wherein the method is performed by a first functional entity and includes:

[0009] receiving a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal;

[0010] Send a second message to the second functional entity; wherein the second message includes a judgment result, the judgment result indicating that the AKMA application layer key is provided for the terminal in the current network, or indicating that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0011] Optionally, the key request method further comprises:

[0012] Determining, based on the first information, whether an AKMA application layer key can be provided for the terminal in the current network;

[0013] Among them, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0014] Optionally, the key request method further comprises:

[0015] Obtain a third message sent by a third functional entity; wherein the third message includes the first information.

[0016] Optionally, in the key request method, the first information includes one or more of the following information:

[0017] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0018] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0019] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0020] Optionally, in the key request method, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0021] Security key K AKMA Identifier A-KID

[0022] General Public Subscription Identifier GPSI;

[0023] Subscription Permanent Identifier SUPI;

[0024] Slice identification;

[0025] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0026] Optionally, the key request method further comprises:

[0027] In a case where the first information does not include terminal indication information, it is determined that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0028] One embodiment of the present disclosure further provides a key request method, wherein the method is performed by a second functional entity and includes:

[0029] Sending a first message to the first functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of the terminal;

[0030] Obtain a second message sent by the first functional entity based on the first message, where the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0031] Optionally, the key request method further comprises:

[0032] According to the second message, a fourth message is sent to a fourth functional entity, where the fourth message includes the judgment result.

[0033] One embodiment of the present disclosure further provides a key request method, wherein the method is performed by a first functional entity and includes:

[0034] Obtain first information, where the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in a current network.

[0035] Optionally, in the key request method, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0036] Optionally, in the key request method, the obtaining of the first information includes:

[0037] Obtain a third message sent by a third network device; wherein the third message includes the first information.

[0038] Optionally, in the key request method, the first information includes one or more of the following information:

[0039] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0040] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0041] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0042] Optionally, in the key request method, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0043] Security key K AKMA Identifier A-KID

[0044] General Public Subscription Identifier GPSI;

[0045] Subscription Permanent Identifier SUPI;

[0046] Slice identification;

[0047] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0048] One embodiment of the present disclosure further provides a key request method, wherein the method is performed by a third functional entity and includes:

[0049] A third message is sent to the first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in the current network.

[0050] Optionally, in the key request method, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0051] Optionally, in the key request method, the first information includes one or more of the following information:

[0052] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0053] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0054] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0055] Optionally, in the key request method, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0056] Security key K AKMA Identifier A-KID

[0057] General Public Subscription Identifier GPSI;

[0058] Subscription Permanent Identifier SUPI;

[0059] Slice identification;

[0060] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0061] One embodiment of the present disclosure further provides a functional entity, wherein the functional entity is a first functional entity, including a transceiver, wherein the transceiver is configured to:

[0062] receiving a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal;

[0063] Send a second message to the second functional entity; wherein the second message includes a judgment result, the judgment result indicating that the AKMA application layer key is provided for the terminal in the current network, or indicating that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0064] One embodiment of the present disclosure provides a functional entity, wherein the functional entity is a second functional entity, including a transceiver, wherein the transceiver is configured to:

[0065] Sending a first message to the first functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of the terminal;

[0066] Obtain a second message sent by the first functional entity based on the first message, where the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0067] One embodiment of the present disclosure provides a functional entity, wherein the functional entity is a first functional entity, including a transceiver, wherein the transceiver is configured to:

[0068] Obtain first information, where the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in a current network.

[0069] One embodiment of the present disclosure provides a functional entity, wherein the functional entity is a third functional entity, including a transceiver, wherein the transceiver is configured to:

[0070] A third message is sent to the first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in the current network.

[0071] One embodiment of the present disclosure provides a key requesting device, which is applied to a first functional entity and includes:

[0072] A first receiving module is configured to receive a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal;

[0073] The first sending module is used to send a second message to the second functional entity; wherein the second message includes a judgment result, and the judgment result indicates that the AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0074] One embodiment of the present disclosure provides a key requesting device, which is applied to a second functional entity and includes:

[0075] A second sending module is configured to send a first message to the first functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of the terminal;

[0076] The first acquisition module is used to obtain a second message sent by the first functional entity based on the first message, where the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0077] One embodiment of the present disclosure provides a key requesting device, which is applied to a first functional entity and includes:

[0078] The second acquisition module is used to obtain first information, where the first information is used by the first functional entity to determine whether it can provide an AKMA application layer key for a terminal in the current network.

[0079] One embodiment of the present disclosure provides a key requesting device, which is applied to a third functional entity, and includes:

[0080] The third sending module is used to send a third message to the first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether it can provide an AKMA application layer key for the terminal in the current network.

[0081] One embodiment of the present disclosure provides a network device, which includes a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program implements the key request method as described above when executed by the processor.

[0082] One embodiment of the present disclosure provides a readable storage medium, wherein a program is stored on the readable storage medium, and when the program is executed by a processor, the steps in any one of the above key request methods are implemented.

[0083] One embodiment of the present disclosure provides a computer program product, comprising computer instructions, which, when executed by a processor, implement the steps in any one of the above-mentioned key request methods.

[0084] At least one of the above technical solutions of the present disclosure has the following beneficial effects:

[0085] In the key request method described in the embodiment of the present disclosure, the first functional entity determines whether an AKMA application layer key can be provided to the terminal based on the current network of the terminal, so as to control the AKMA application layer key provision service when the terminal is in a different network. In this way, in addition to realizing the AKMA application layer key provision service function control when the terminal is in the home network, the AKMA application layer key provision service function control can also be realized when the terminal is roaming. BRIEF DESCRIPTION OF THE DRAWINGS

[0086] FIG1 is a schematic diagram of a network architecture using one embodiment of the key request method described in the embodiments of the present disclosure;

[0087] FIG2 is a schematic diagram of a process of a key request method according to a first embodiment of the present disclosure;

[0088] FIG3 is a flow chart of implementation mode 1 of the key request method according to an embodiment of the present disclosure;

[0089] FIG4 is a flow chart of a second embodiment of the key request method according to an embodiment of the present disclosure;

[0090] FIG5 is a flow chart of implementation method 3 of the key request method according to an embodiment of the present disclosure;

[0091] FIG6 is a flow chart of a fourth embodiment of the key request method according to an embodiment of the present disclosure;

[0092] FIG7 is a flow chart of a fifth embodiment of the key request method according to an embodiment of the present disclosure;

[0093] FIG8 is a flow chart of a sixth embodiment of the key request method according to an embodiment of the present disclosure;

[0094] FIG9 is a flow chart of implementation method 7 of the key request method according to an embodiment of the present disclosure;

[0095] FIG10 is a flow chart of an eighth embodiment of the key request method according to an embodiment of the present disclosure;

[0096] FIG11 is a flow chart of a key request method according to a second embodiment of the present disclosure;

[0097] FIG12 is a flow chart of a key request method according to Embodiment 3 of the present disclosure;

[0098] FIG13 is a flow chart of a key request method according to a fourth embodiment of the present disclosure;

[0099] FIG14 is a schematic diagram of the structure of the functional entity according to the first embodiment of the present disclosure;

[0100] FIG15 is a schematic diagram of the structure of the functional entity described in Example 2 of the present disclosure;

[0101] FIG16 is a schematic diagram of the structure of the functional entity described in Example 3 of the present disclosure;

[0102] FIG17 is a schematic diagram of the structure of the functional entity according to the fourth embodiment of the present disclosure;

[0103] FIG18 is a schematic structural diagram of a key requesting device according to a first embodiment of the present disclosure;

[0104] FIG19 is a schematic structural diagram of a key requesting device according to a second embodiment of the present disclosure;

[0105] FIG20 is a schematic diagram of the structure of a key requesting device according to Embodiment 3 of the present disclosure;

[0106] FIG21 is a schematic diagram of the structure of the key request device according to the fourth embodiment of the present disclosure. DETAILED DESCRIPTION

[0107] In order to make the technical problems, technical solutions and advantages to be solved by the present disclosure clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0108] Figure 1 is a schematic diagram of the network architecture of one embodiment of the key request method described in the embodiment of the present disclosure. As shown in Figure 1, the user terminal (User Equipment, UE) communicates with the access network (Access Network, AN) or the radio access network (Radio Access Network, RAN) through multiple functional entities. The Access Management Function (Access Management Function, AMF) is used to manage the user's demand for access to the network, and is responsible for the terminal-to-network non-access stratum (Non-Access Stratum, NAS) signaling management, user mobility management, etc. The AMF entity has a security anchor function and can interact with the Authentication Service Function (Authentication Server Function) entity and the UE to receive the intermediate key established for the UE authentication process. For the authentication method based on the Universal Subscriber Identity Module (USIM), the AMF entity also obtains security-related data from the AUSF entity. AF is used to manage the UE's session.

[0109] The UDM entity is used to store user subscription data and is located in the user's home network. The Authentication Credential Repository and Processing Function (ARPF) entity stores long-term security credentials used for authentication and uses them as input to perform key operations.

[0110] The AAnF entity is located in the home network and is mainly used to generate session keys between the UE and the AF entity and maintain security context with the UE. The NEF entity is used to manage external network data. External applications can access core network internal data through the NEF.

[0111] Before accessing the network, the UE requests the AUSF entity and the UDM entity to perform key negotiation authentication. The AUSF entity is used to generate the session key between the UE and the AF entity and maintain the security context between the UE and the UDM entity. The UDM entity is used to store user subscription data and determine whether the user is an AKMA subscriber. After passing the key negotiation authentication, the UE can generate the AKMA-Key Identification (A-KID) and the related AKMA anchor key (denoted as K) according to the Routing Indicator (RID). AKMA ) and pass A-KID and K AKMA During this process, the AUSF entity also generates an A-KID using the RID and sends the user's SUPI, the generated A-KID and K AKMA Sent to the AAnF entity, the AAnF entity responds to the AUSF entity to complete the authentication and registration of the user.

[0112] Usually, the AF entity obtains the AKMA application layer key, and the AF entity is regarded as belonging to the HPLMN. It cannot provide the AKMA application layer key service for roaming users. In order to realize the control of the AKMA application layer key service provision for users in different networks, the embodiment of the present disclosure provides a key request method, in which the first functional entity determines whether the AKMA application layer key can be provided to the terminal according to the current network of the terminal, so as to control the AKMA application layer key service when the terminal is in different networks. In this way, in addition to realizing the AKMA application layer key service provision function control in the home network, the AKMA application layer key service provision function control can also be realized when the terminal is in a roaming network.

[0113] One embodiment of the present disclosure provides a key request method, which is performed by a first functional entity, as shown in FIG2 , and includes:

[0114] S210, receiving a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal;

[0115] S220, sending a second message to the second functional entity; wherein the second message includes a judgment result, the judgment result indicating that the AKMA application layer key is provided for the terminal in the current network, or indicating that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0116] Using the key request method described in this embodiment, during the process of a terminal acquiring an AKMA application layer key, the first functional entity determines, based on a first message received from a second functional entity related to the terminal's AKMA application layer key acquisition, whether the terminal can provide the AKMA application layer key to the terminal requesting AKMA application layer key acquisition in its current network. The terminal's current network includes both its home network and its roaming network. Thus, the first functional entity determines whether the terminal can be provided with an AKMA application layer key based on the terminal's current network, thereby controlling the AKMA application layer key provisioning service when the terminal is in different networks.

[0117] Optionally, the first functional entity includes one or more of the following:

[0118] AKMA key anchoring function AAnF entity;

[0119] Authentication Server Function (AUSF) entity;

[0120] Unified Data Management (UDM) functional entity.

[0121] Using this implementation, any one of the above-mentioned AAnF entity, AUSF entity and UDM entity can determine whether it can provide the AKMA application layer key for the terminal in the current network based on the received first message related to the AKMA application layer key of the terminal, and feedback a second message including the judgment result to the second functional entity.

[0122] In one embodiment, optionally, the method further comprises:

[0123] Determining, based on the first information, whether an AKMA application layer key can be provided for the terminal in the current network;

[0124] Among them, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0125] In this embodiment, the first information indicates the key service setting information of the terminal in at least one network, and the first functional entity can determine whether it can provide the AKMA application layer key for the terminal in the current network based on the key service setting information corresponding to the corresponding network indicated in the first information.

[0126] Optionally, the first information includes one or more of the following information:

[0127] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0128] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0129] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0130] Specifically, in one embodiment, the first information records network information of multiple networks and corresponding key service setting information. For example, the content of the first information is as follows:

[0131] The first information {Network 1: allowed; Network 2: not allowed; Network 3, allowed; ...}.

[0132] In another embodiment, the first information includes network information of at least one network, and the network information is a list of network information for which corresponding key service setting information is not allowed to provide application layer keys to the terminal. That is, the network information recorded in the first information indicates that application layer keys are not allowed to be provided to the terminal when the terminal is in the corresponding network, and the network information not recorded in the first information indicates that application layer keys are allowed to be provided to the terminal by default when the terminal is in the corresponding network. For example, the content of the first information is as follows:

[0133] First information {network 1, network 2, network 3, ...}.

[0134] In another embodiment, the first information includes network information of at least one network, and the network information is a list of network information for which corresponding key service setting information is allowed to provide application layer keys to the terminal. That is, the network information recorded in the first information indicates that the terminal is allowed to provide application layer keys to the terminal when in the corresponding network, and the network information not recorded in the first information indicates that the terminal is not allowed to provide application layer keys to the terminal by default when in the corresponding network. For example, the content of the first information is as follows:

[0135] First information {network 4, network 5, network 6, ...}.

[0136] In one embodiment of the present disclosure, optionally, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0137] Identifier of the security key KAKMA (AKMA-Key Identification, A-KID);

[0138] Generic Public Subscription Identification (GPSI);

[0139] Subscription Permanent Identifier (SUPI);

[0140] Slice identification;

[0141] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0142] In this embodiment, the terminal indication information in the first information is used to indicate the terminal to which the first information is applicable.

[0143] For example, when the terminal indication information includes an A-KID, it is used to indicate that the corresponding first information is applicable to a terminal that sends an AKMA application layer key acquisition request and has the A-KID;

[0144] When the terminal indication information includes the GPSI, it is used to indicate that the corresponding first information is applicable to the terminal that sends the AKMA application layer key acquisition request and has the GPSI;

[0145] When the terminal indication information includes a SUPI, it is used to indicate that the corresponding first information is applicable to a terminal that sends an AKMA application layer key acquisition request and has the SUPI;

[0146] When the terminal indication information includes a slice identifier, it is used to indicate that the corresponding first information is applicable to the terminal that sends the AKMA application layer key acquisition request and has the slice identifier;

[0147] When the terminal indication information includes a preset identifier, it is used to indicate that the corresponding first information is applicable to each terminal of the AKMA application layer key acquisition request.

[0148] Optionally, each first information corresponds to a terminal indication information, and the terminal indication information is used to indicate, for the corresponding terminal including the terminal indication information, whether to allow the terminal in the current network to provide an AKMA application layer key according to the corresponding first information.

[0149] For example, when the terminal indication information includes a slice identifier, after obtaining the first message, the slice identifier corresponding to the terminal is determined according to the terminal indicated by the first message, and the first information corresponding to the slice identifier is determined. In this way, based on the corresponding first information, it is determined whether to allow the AKMA application layer key to be provided to the terminal in the current network.

[0150] In another implementation manner in the embodiment of the present disclosure, optionally, the first information may not include terminal indication information. In this implementation manner, the method further includes:

[0151] In a case where the first information does not include terminal indication information, it is determined that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0152] The key request method according to the embodiment of the present disclosure may optionally further include:

[0153] Obtain a third message sent by a third functional entity; wherein the third message includes the first information.

[0154] With this implementation, before the terminal obtains the AKMA application layer key, when initializing network registration, the third functional entity may send the first information to the first functional entity as a basis for determining control of the AKMA application layer key provision service.

[0155] Optionally, the third functional entity includes one or more of a UDM functional entity and an AUSF entity.

[0156] In one embodiment, optionally, an indication option of the first information is added to the entry about AKMA of the UDM functional entity, and by issuing the first information to the AAnF in advance and during the AKMA application layer key acquisition interaction, the AAnF can judge whether to allow the provision of the AKMA application layer key to the terminal of the current network based on the first information, or, during the AKMA application layer key acquisition interaction, the UDM functional entity or the AUSF entity can judge whether to allow the provision of the AKMA application layer key to the terminal of the current network based on the first information.

[0157] Optionally, in combination with FIG3 , during initialization, the UE and the network side generate a key identifier of the anchor key of the KAMA, and the UDM entity includes the first information in the message sent to the AUSF entity, and / or the message sent by the AUSF to the AAnF. The implementation process includes the following steps:

[0158] S301, the UE and the AUSF entity perform an initial authentication process;

[0159] S302, the AUSF sends a terminal authentication request to the UDM entity, where the terminal authentication request includes a Subscription Concealed Identifier (SUCI) and / or SUPI;

[0160] S303, the UDM function entity sends an authentication response message to the AUSF entity, where the authentication response message includes an authentication vector (AV). In the embodiment of the present disclosure, the authentication response message includes the first information; optionally, the authentication response message may also include a routing indicator (RID) and / or AKMA service indication information (AKMA Ind);

[0161] S304, UE and AUSF entities are respectively represented by K AUSF Generate security key K AKMA ;

[0162] S305, the UE and the AUSF entity generate an A-KID respectively;

[0163] S306, the AUSF entity sends an AKMA anchor key registration request to the AAnF entity. The AKMA anchor key registration request includes SUPI, A-KID, K AKMA In the embodiment of the present disclosure, optionally, the first information may also be included;

[0164] S307, the AAnF entity returns an AKMA anchor key registration response to the AUSF entity.

[0165] In the above implementation manner of the embodiment of the present disclosure, in one implementation manner, the first functional entity may be an AUSF entity, the third functional entity may be a UDM functional entity, and the UDM functional entity may send an authentication response message (third message) to the AUSF entity, including the first information, and the AUSF entity may determine whether to allow provision of an AKMA application layer key for the terminal in the current network based on the first information;

[0166] In another embodiment, the first functional entity may be an AUSF entity, and the third functional entity may be an AAnF entity. The AUSF entity sends an AKMA anchor key registration response (third message) to the AAnF entity, including the first information. The AAnF entity determines whether to allow the provision of AKMA application layer keys for the terminal in the current network based on the first information.

[0167] It should be noted that, in one implementation manner, the first functional entity may also be a UDM functional entity, and the UDM functional entity may directly determine based on the first information whether to allow provision of the AKMA application layer key for the terminal in the current network.

[0168] It should be noted that the above-mentioned way in which the third functional entity sends the first information to the first functional entity, and the specific content information included in the first information, are only examples and are not limited to this. The specific implementation methods of each function will not be described in detail here.

[0169] In one implementation of the key request method described in the embodiments of the present disclosure, optionally, the first functional entity includes an AKMA key anchoring function AAnF entity. When the terminal attempts to use the AKMA service, it requests to obtain the corresponding AKMA application layer key from the AAnF entity, and the AAnF entity determines whether to allow the AKMA application layer key to be provided to the terminal in the current network.

[0170] In one embodiment, the terminal may directly request the AAnF entity to obtain the AKMA application layer key through the AF. The specific implementation process of this embodiment, as shown in FIG4 , includes the following steps:

[0171] S401, UE and AAnF entity perform K AKMA the initial certification and registration process;

[0172] S402, the terminal sends an application session establishment request to the AF entity; optionally, the application session establishment request includes the terminal's A-KID;

[0173] S403, the AF entity sends an AKMA application key acquisition request to the AAnF entity; optionally, the AKMA application key acquisition request includes the terminal's A-KID and the application identifier AF_ID;

[0174] S404, the AAnF entity sends a Subscriber Data Management (SDM) acquisition request to the UDM entity. Optionally, the SDM acquisition request includes a conversion identity and SUPI.

[0175] S405, the UDM entity returns a response message of the SDM acquisition request to the AAnF entity, where the response message includes the GPSI;

[0176] S406, the AAnF entity determines whether to provide the AKMA application layer key for the terminal in the current network based on one or more of the A-KID, SUPI, and GPSI of the terminal and the pre-acquired first information, and obtains a determination result; if the determination result is that the AKMA application layer key is allowed to be provided for the terminal in the current network, executing the following step S407; if the determination result is that the AKMA application layer key is not allowed to be provided for the terminal in the current network, executing the following step S408;

[0177] S407, the AAnF entity sends a response message to the AF entity for the AKMA application key acquisition request. Optionally, the response message includes the judgment result, indicating that the AKMA application layer key is provided for the terminal in the current network. In another embodiment, the response message also includes the K requested by the terminal. AF , K AF one or more of expiry date, SUPI and GPSI;

[0178] S408, the AAnF entity sends a response message to the AF entity for the AKMA application key acquisition request. Optionally, the response message includes the judgment result, indicating that it is not allowed to provide the AKMA application layer key for the terminal in the current network.

[0179] S409: The AF entity sends an application session establishment response message to the terminal. The application session establishment response message includes the above judgment result obtained by the AAnF entity.

[0180] In one embodiment of the present disclosure, in the above-described implementation, the first functional entity includes an AAnF entity, and the second functional entity includes an AF entity. The first message sent by the second functional entity to the first functional entity may be an AKMA application key acquisition request in step S403, and the second message sent by the first functional entity to the second functional entity may be a response message to the AKMA application key acquisition request in step S407 or step S408. Specifically, the key request method described in this implementation can be applied when the AF is located in a local network.

[0181] In one embodiment of the key request method described in the embodiments of the present disclosure, the AF optionally requests the AAnF entity to obtain an AKMA application layer key through the NEF entity. In this embodiment, the first functional entity optionally includes an AKMA key anchoring function AAnF entity. When a terminal attempts to use an AKMA service, the AF obtains the corresponding AKMA application layer key from the AAnF entity through the NEF request. The AAnF entity then determines whether to allow the provision of the AKMA application layer key to the terminal in the current network. Optionally, the determination of whether to allow the provision of the AKMA application layer key to the terminal in the current network is made based on the first information.

[0182] Specifically, the key request method described in this embodiment can be applied to the case where the AF is located outside the local network.

[0183] As shown in FIG5 , this embodiment mainly describes the process in which the AF sends an AKMA application key acquisition request to the AAnF entity through the NEF as an example. The implementation process includes the following steps:

[0184] S501, the AF entity sends an AKMA application key acquisition request to the NEF entity; optionally, the AKMA application key acquisition request includes the terminal's A-KID and the application identifier AF_ID;

[0185] S502, the NEF entity performs AAnF entity selection;

[0186] S503, the NEF entity forwards the AKMA application key acquisition request to the selected AAnF entity;

[0187] S504, the AAnF entity determines whether the AKMA application layer key can be provided for the terminal in the current network based on the A-KID of the terminal and the pre-acquired first information, and obtains a determination result; wherein, if the determination result is that the AKMA application layer key can be provided for the terminal in the current network, the following steps S505 and S506 are executed; if the determination result is that the AKMA application layer key cannot be provided for the terminal in the current network, the following steps S507 and S508 are executed;

[0188] S505, the AAnF entity sends a response message to the NEF entity for the AKMA application key acquisition request. Optionally, the response message includes the judgment result, indicating that the AKMA application layer key is provided for the terminal in the current network. Optionally, the response message also includes the K requested by the terminal. AF , K AF One or more of the expiry date and SUPI;

[0189] S506, the NEF entity forwards the response message to the AF entity; wherein the response message includes K AF and K AF Expiration time, optionally including GPSI;

[0190] S507, the AAnF entity sends a response message to the NEF entity for the AKMA application key acquisition request. Optionally, the response message includes the judgment result, indicating that it is not allowed to provide the AKMA application layer key for the terminal in the current network.

[0191] S508: The NEF entity forwards the response message to the AF entity; optionally, the response message may further include GPSI.

[0192] In one of the embodiments of the present disclosure, in the above-mentioned implementation mode, the first functional entity includes an AAnF entity, the second functional entity includes an NEF entity, and the first message sent by the second functional entity to the first functional entity can be an AKMA application key acquisition request in step S503, and the second message sent by the first functional entity to the second functional entity is a response message to the AKMA application key acquisition request in step S505 or step S507.

[0193] In this implementation, the NEF entity further forwards the response message to the AF entity (fourth functional entity), that is, sends a fourth message to the fourth functional entity, where the fourth message includes the above-mentioned judgment result.

[0194] In one implementation mode of the key request method disclosed in the present invention, optionally, the first functional entity includes an AUSF entity. When the terminal attempts to use the AKMA service, the AF entity can directly request the AAnF entity to obtain the corresponding AKMA application layer key. After obtaining the request, the AAnF entity sends a verification request to the AUSF entity, and the AUSF entity determines whether to allow the provision of the AKMA application layer key for the terminal in the current network.

[0195] As shown in FIG6 , the implementation process of this embodiment includes the following steps:

[0196] S601, UE and AAnF entity perform K AKMA the initial certification and registration process;

[0197] S602, the terminal sends an application session establishment request to the AF entity; optionally, the application session establishment request includes the terminal's A-KID;

[0198] S603, the AF entity sends an AKMA application key acquisition request to the AAnF entity; optionally, the AKMA application key acquisition request includes the terminal's A-KID and the application identifier AF_ID;

[0199] S604, the AAnF entity sends a Subscriber Data Management (SDM) acquisition request to the UDM entity. Optionally, the SDM acquisition request includes a conversion identity and SUPI.

[0200] S605, the UDM entity returns a response message of the SDM acquisition request to the AAnF entity, where the response message includes the GPSI;

[0201] S606, the AAnF entity sends a verification request to the AUSF entity. Optionally, the verification request includes one or more of the above-mentioned A-KID, SUPI, and GPSI;

[0202] S607, the AUSF entity determines whether an AKMA application layer key can be provided for the terminal in the current network based on one or more of the A-KID, SUPI, and GPSI of the terminal, and optionally based on the pre-acquired first information, and obtains a determination result;

[0203] S608, the AUSF entity sends a response message to the verification message to the AAnF entity, where the response message includes the judgment result;

[0204] S609, when the result of the judgment is that the AKMA application layer key is allowed to be provided to the terminal in the current network, the AAnF entity sends a response message of the AKMA application key acquisition request to the AF entity. Optionally, the response message includes the K requested by the terminal. AF , K AF one or more of expiry date, SUPI and GPSI;

[0205] S610, if the judgment result is that the AKMA application layer key is not allowed to be provided to the terminal in the current network, the AAnF entity sends a response message to the AF entity for the AKMA application key acquisition request, where the response message includes the judgment result, indicating that the AKMA application layer key is not allowed to be provided to the terminal in the current network;

[0206] S611: The AF entity sends an application session establishment response message to the terminal. The application session establishment response message includes the content of the above response message obtained by the AF entity.

[0207] In the above embodiment, the first functional entity includes an AUSF entity, the second functional entity includes an AAnF entity, the first message sent by the second functional entity to the first functional entity may be the verification request in step S606, and the second message sent by the first functional entity to the second functional entity may be a response message to the verification request in step S608.

[0208] In this implementation, the AAnF entity further forwards the response message to the AF entity (fourth functional entity), that is, sends a fourth message to the fourth functional entity, where the fourth message includes the above-mentioned judgment result.

[0209] In one implementation mode of the key request method disclosed in the present invention, optionally, the first functional entity includes an AUSF entity. When the terminal attempts to use the AKMA service, the AF entity requests the AAnF entity through the NEF entity to obtain the corresponding AKMA application layer key. After obtaining the request, the AAnF entity sends a verification request to the AUSF entity, and the AUSF entity determines whether to allow the provision of the AKMA application layer key for the terminal in the current network.

[0210] As shown in FIG7 , the implementation process of this embodiment includes the following steps:

[0211] S701, the AF entity sends an AKMA application key acquisition request to the NEF entity; optionally, the AKMA application key acquisition request includes the terminal's A-KID and the application identifier AF_ID;

[0212] S702, the NEF entity performs AAnF entity selection;

[0213] S703, the NEF entity forwards the AKMA application key acquisition request to the selected AAnF entity;

[0214] S704, the AAnF entity sends a verification request to the AUSF entity according to the AKMA application key acquisition request. Optionally, the verification request includes one or more of the terminal A-KID, SUPI, and GPSI.

[0215] S705, the AUSF entity determines whether an AKMA application layer key can be provided for the terminal in the current network based on one or more of the A-KID, SUPI, and GPSI of the terminal, and optionally based on the pre-acquired first information, to obtain a determination result;

[0216] S706, the AUSF entity sends a response message to the verification request to the AAnF entity, where the response message includes the judgment result;

[0217] S707, when the judgment result is that the AKMA application layer key is allowed to be provided to the terminal in the current network, the AAnF entity sends a response message of the AKMA application key acquisition request to the NEF entity. Optionally, the response message includes the judgment result and, optionally, the K requested by the terminal. AF , K AF one or more of expiry date, SUPI and GPSI;

[0218] S708, the NEF entity forwards the response message to the AF entity; wherein the response message includes K AF and K AF Expiration time, optionally including GPSI;

[0219] S709, if the judgment result is that the AKMA application layer key is not allowed to be provided to the terminal in the current network, the AAnF entity sends a response message to the NEF entity for the AKMA application key acquisition request, optionally including the judgment result, indicating that the AKMA application layer key is not allowed to be provided to the terminal in the current network;

[0220] S710, the NEF entity forwards the response message to the AF entity; optionally, the response message may further include GPSI.

[0221] In the above embodiment, the first functional entity includes an AUSF entity, the second functional entity includes an AAnF entity, the first message sent by the second functional entity to the first functional entity may be the verification request in step S704, and the second message sent by the first functional entity to the second functional entity may be a response message to the verification request in step S706.

[0222] In this implementation, the AAnF entity sends a response message of the AKMA application key acquisition request to the NEF entity (fourth functional entity), that is, sends a fourth message to the fourth functional entity, and the fourth message includes the above-mentioned judgment result.

[0223] In one implementation mode of the key request method disclosed in the present invention, optionally, the first functional entity includes a UDM entity. When the terminal attempts to use the AKMA service, the AF entity can directly request the AAnF entity to obtain the corresponding AKMA application layer key. After obtaining the request, the AAnF entity sends the verification request to the UDM entity through the AUSF entity, and the UDM entity determines whether to allow the provision of the AKMA application layer key for the terminal in the current network.

[0224] As shown in FIG8 , the implementation process of this embodiment includes the following steps:

[0225] S801, UE and AAnF entity perform K AKMA the initial certification and registration process;

[0226] S802, the terminal sends an application session establishment request to the AF entity; optionally, the application session establishment request includes the terminal's A-KID;

[0227] S803, the AF entity sends an AKMA application key acquisition request to the AAnF entity; optionally, the AKMA application key acquisition request includes the terminal's A-KID and the application identifier AF_ID;

[0228] S804, the AAnF entity sends a Subscriber Data Management (SDM) acquisition request to the UDM entity. Optionally, the SDM acquisition request includes a conversion identity and SUPI.

[0229] S805, the UDM entity returns a response message of the SDM acquisition request to the AAnF entity, where the response message includes the GPSI;

[0230] S806, the AAnF entity sends a verification request to the AUSF entity. Optionally, the verification request includes one or more of the above-mentioned A-KID, SUPI, and GPSI;

[0231] S807, the AUSF entity forwards the verification request to the UDM entity;

[0232] S808, the UDM entity determines, based on one or more of the A-KID, SUPI, and GPSI of the terminal, and optionally based on the pre-acquired first information, whether an AKMA application layer key can be provided for the terminal in the current network, and obtains a determination result;

[0233] S809, the UDM entity sends a response message to the verification request to the AUSF entity, where the response message includes the judgment result;

[0234] S810, the AUSF entity forwards a response message of the verification request to the AAnF entity, where the response message includes the judgment result;

[0235] S811, when the result of the judgment is that the AKMA application layer key is allowed to be provided to the terminal in the current network, the AAnF entity sends a response message of the AKMA application key acquisition request to the AF entity. Optionally, the response message includes the K requested by the terminal. AF , K AF one or more of expiry date, SUPI and GPSI;

[0236] S812, if the judgment result is that the AKMA application layer key is not allowed to be provided to the terminal in the current network, the AAnF entity sends a response message to the AF entity for the AKMA application key acquisition request, where the response message includes the judgment result, indicating that the AKMA application layer key is not allowed to be provided to the terminal in the current network;

[0237] S813: The AF entity sends an application session establishment response message to the terminal. The application session establishment response message includes the content of the above response message obtained by the AF entity.

[0238] In the above embodiment, the first functional entity includes a UDM entity, the second functional entity includes an AUSF entity, the first message sent by the second functional entity to the first functional entity may be the verification request in step S807, and the second message sent by the first functional entity to the second functional entity may be a response message to the verification request in step S809.

[0239] In this implementation, the AUSF entity forwards the response message of the verification request to the AAnF entity (fourth functional entity), that is, sends a fourth message to the fourth functional entity, and the fourth message includes the above-mentioned judgment result.

[0240] In one implementation of the key request method disclosed in the embodiments of the present invention, optionally, the first functional entity includes a UDM entity. When the terminal attempts to use the AKMA service, the AF entity requests the AAnF entity to obtain the corresponding AKMA application layer key through the NEF entity. After obtaining the request, the AAnF entity sends a verification request to the UDM through the AUSF entity, and the UDM entity determines whether to allow the provision of the AKMA application layer key for the terminal in the current network.

[0241] As shown in FIG9 , the implementation process of this embodiment includes the following steps:

[0242] S901, the AF entity sends an AKMA application key acquisition request to the NEF entity; optionally, the AKMA application key acquisition request includes the terminal's A-KID and the application identifier AF_ID;

[0243] S902, the NEF entity performs AAnF entity selection;

[0244] S903, the NEF entity forwards the AKMA application key acquisition request to the selected AAnF entity;

[0245] S904, the AAnF entity sends a verification request to the AUSF entity according to the AKMA application key acquisition request. Optionally, the verification request includes one or more of the terminal's A-KID, SUPI, and GPSI;

[0246] S905, the AUSF entity forwards the verification request to the UDM entity;

[0247] S906, the UDM entity determines whether an AKMA application layer key can be provided for the terminal in the current network based on one or more of the terminal's A-KID, SUPI, and GPSI, and optionally based on pre-acquired first information, to obtain a determination result;

[0248] S907, the UDM entity sends a response message to the verification request to the AUSF entity, where the response message includes the judgment result;

[0249] S908, the AUSF entity forwards the response message to the AAnF entity;

[0250] S909, when the UDM entity determines that it is allowed to provide the AKMA application layer key for the terminal in the current network, the AAnF entity sends a response message of the AKMA application key acquisition request to the NEF entity. Optionally, the response message includes the determination result and, optionally, the K requested by the terminal. AF , K AFone or more of expiry date, SUPI and GPSI;

[0251] S910, the NEF entity forwards the response message to the AF entity; wherein the response message includes K AF and K AF Expiration time, optionally including GPSI;

[0252] S911, when the UDM entity determines that it is not allowed to provide the AKMA application layer key to the terminal in the current network, the AAnF entity sends a response message to the NEF entity for the AKMA application key acquisition request, optionally including the determination result, indicating that it is not allowed to provide the AKMA application layer key to the terminal in the current network;

[0253] S912: The NEF entity forwards the response message to the AF entity; optionally, the response message may further include GPSI.

[0254] In the above embodiment, the first functional entity includes a UDM entity, the second functional entity includes an AUSF entity, the first message sent by the second functional entity to the first functional entity may be the verification request in step S905, and the second message sent by the first functional entity to the second functional entity may be a response message to the verification request in step S907.

[0255] In this implementation, the AUSF entity forwards the response message of the verification request to the AAnF entity (fourth functional entity), that is, sends a fourth message to the fourth functional entity, and the fourth message includes the above-mentioned judgment result.

[0256] In one implementation of the key request method disclosed in the embodiments of the present invention, optionally, the first functional entity includes a UDM entity. When the terminal attempts to use the AKMA service, it can directly request the AAnF entity to obtain the corresponding AKMA application layer key through the AF entity. After obtaining the request, the AAnF entity sends the verification request to the UDM entity, and the UDM entity determines whether to allow the provision of the AKMA application layer key for the terminal in the current network.

[0257] As shown in FIG10 , the implementation process of this embodiment includes the following steps:

[0258] S1001, UE and AAnF entity perform K AKMA the initial certification and registration process;

[0259] S1002, the terminal sends an application session establishment request to the AF entity; optionally, the application session establishment request includes the terminal's A-KID;

[0260] S1003, the AF entity sends an AKMA application key acquisition request to the AAnF entity; optionally, the AKMA application key acquisition request includes the terminal's A-KID and the application identifier AF_ID;

[0261] S1004, the AAnF entity sends a Subscriber Data Management (SDM) acquisition request to the UDM entity. Optionally, the SDM acquisition request includes a conversion identity and SUPI.

[0262] S1005, the UDM entity returns a response message of the SDM acquisition request to the AAnF entity, where the response message includes the GPSI;

[0263] S1006, the AAnF entity sends a verification request to the UDM entity. Optionally, the verification request includes one or more of the above-mentioned A-KID, SUPI, and GPSI;

[0264] S1007, the UDM entity determines, based on one or more of the A-KID, SUPI, and GPSI of the terminal, and optionally based on the pre-acquired first information, whether an AKMA application layer key can be provided for the terminal in the current network, and obtains a determination result;

[0265] S1008, the UDM entity sends a response message to the verification request to the AAnF entity, where the response message includes the judgment result;

[0266] S1009, when the result of the judgment is that the AKMA application layer key is allowed to be provided to the terminal in the current network, the AAnF entity sends a response message of the AKMA application key acquisition request to the AF entity. Optionally, the response message includes the K requested by the terminal. AF , K AF one or more of expiry date, SUPI and GPSI;

[0267] S1010, if the judgment result is that the AKMA application layer key is not allowed to be provided to the terminal in the current network, the AAnF entity sends a response message to the AF entity for the AKMA application key acquisition request, where the response message includes the judgment result, indicating that the AKMA application layer key is not allowed to be provided to the terminal in the current network;

[0268] S1011 : The AF entity sends an application session establishment response message to the terminal. The application session establishment response message includes the content of the above response message obtained by the AF entity.

[0269] In the above embodiment, the first functional entity includes a UDM entity, the second functional entity includes an AAnF entity, the first message sent by the second functional entity to the first functional entity may be the verification request in step S1006, and the second message sent by the first functional entity to the second functional entity may be a response message to the verification request in step S1008.

[0270] In this implementation, the AAnF entity forwards the response message of the verification request to the AF entity (fourth functional entity), that is, sends a fourth message to the fourth functional entity, and the fourth message includes the above-mentioned judgment result.

[0271] It should be noted that in another implementation manner of the embodiment of the present disclosure, in the implementation process shown in Figure 10 above, in step S1004, the SDM acquisition request sent by the AAnF entity to the UDM entity may also include verification request information. After step S1004, the UDM entity can judge whether it can provide the AKMA application layer key for the terminal in the current network based on the verification request information in the SDM acquisition request, and obtain a judgment result. When the UDM entity returns a response message of the SDM acquisition request to the AAnF entity, the response message may also include the judgment result, that is, the implementation process of steps S1007 to S1009 above can be executed simultaneously with the implementation process of steps S1004 and S1005, and this implementation method will not be described in detail here.

[0272] According to the above, in the embodiment of the present disclosure, the first functional entity includes one or more of the following:

[0273] AKMA key anchoring function AAnF entity;

[0274] Authentication Service Function AUSF entity;

[0275] Unified Data Management (UDM) functional entity.

[0276] Optionally, the first functional entity includes an AAnF, and the second functional entity includes one or more of an AF entity, a network open function NEF entity, and a UDM functional entity.

[0277] Optionally, the first functional entity includes an AUSF entity, and the second functional entity includes an AAnF entity.

[0278] Optionally, the first functional entity includes a UDM functional entity, and the second functional entity includes an AUSF entity.

[0279] It should be noted that the implementation processes of Figures 3 to 10 above are only several examples of specific implementation methods of executing the key request method described in the embodiment of the present disclosure, and are not limited to these. Each possible implementation method will not be described in detail here.

[0280] One embodiment of the present disclosure further provides a key request method, which is performed by a second functional entity, as shown in FIG11 , and includes:

[0281] S1101, sending a first message to a first functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal;

[0282] S1102, obtain a second message sent by the first functional entity based on the first message, the second message including a judgment result, the judgment result indicating that an AKMA application layer key is provided for the terminal in the current network, or indicating that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0283] By adopting the key request method described in the embodiment of the present disclosure, during the process of obtaining the AKMA application layer key of the terminal, after the second functional entity sends the first message to the first functional entity, the first functional entity determines whether it can provide the terminal with the AKMA application layer key based on the current network of the terminal, so as to control the AKMA application layer key provision service when the terminal is in a different network. In this way, in addition to realizing the AKMA application layer key provision service function control when the terminal is in the home network, it can also realize the AKMA application layer key provision service function control when the terminal is roaming.

[0284] Optionally, the key request method further comprises:

[0285] According to the second message, a fourth message is sent to a fourth functional entity, where the fourth message includes the judgment result.

[0286] The specific implementation of the key request method described in the embodiment of the present disclosure when applied to the second functional entity can refer to the detailed description of the specific implementation when applied to the first functional entity, and will not be described again here.

[0287] One embodiment of the present disclosure further provides a key request method, which is performed by a first functional entity, as shown in FIG12 , and includes:

[0288] S1201: Obtain first information, where the first information is used by the first functional entity to determine whether it can provide an AKMA application layer key for a terminal in the current network.

[0289] By adopting the key request method described in the embodiment of the present disclosure, the first functional entity can obtain the first information in advance, and judge whether the AKMA application layer key can be provided to the terminal based on the first information and the current network of the terminal, so as to control the AKMA application layer key provision service when the terminal is in a different network. In this way, in addition to realizing the AKMA application layer key provision service function control when the terminal is in the home network, the AKMA application layer key provision service function control can also be realized when the terminal is roaming in the network.

[0290] Optionally, in the key request method, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0291] Optionally, in the key request method, the obtaining of the first information includes:

[0292] Obtain a third message sent by a third network device; wherein the third message includes the first information.

[0293] Optionally, in the key request method, the first information includes one or more of the following information:

[0294] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0295] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0296] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0297] Optionally, in the key request method, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0298] Security key K AKMA Identifier A-KID

[0299] General Public Subscription Identifier GPSI;

[0300] Subscription Permanent Identifier SUPI;

[0301] Slice identification;

[0302] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0303] One embodiment of the present disclosure further provides a key request method, which is performed by a third functional entity, as shown in FIG13 , and includes:

[0304] S1301: Send a third message to a first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in the current network.

[0305] Optionally, in the key request method, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0306] Optionally, in the key request method, the first information includes one or more of the following information:

[0307] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0308] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0309] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0310] Optionally, in the key request method, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0311] Security key K AKMA Identifier A-KID

[0312] General Public Subscription Identifier GPSI;

[0313] Subscription Permanent Identifier SUPI;

[0314] Slice identification;

[0315] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0316] One embodiment of the present disclosure further provides a functional entity, which is a first functional entity. As shown in FIG14 , the first functional entity 1400 includes a transceiver 1401 and a processor 1402. The transceiver 1401 is configured to:

[0317] receiving a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal;

[0318] Send a second message to the second functional entity; wherein the second message includes a judgment result, the judgment result indicating that the AKMA application layer key is provided for the terminal in the current network, or indicating that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0319] Optionally, in the functional entity, the processor 1402 is configured to:

[0320] Determining, based on the first information, whether an AKMA application layer key can be provided for the terminal in the current network;

[0321] Among them, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0322] Optionally, in the functional entity, the transceiver 1401 is further configured to:

[0323] Obtain a third message sent by a third functional entity; wherein the third message includes the first information.

[0324] Optionally, in the functional entity, the first information includes one or more of the following information:

[0325] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0326] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0327] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0328] Optionally, in the functional entity, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0329] Security key K AKMA Identifier A-KID

[0330] General Public Subscription Identifier GPSI;

[0331] Subscription Permanent Identifier SUPI;

[0332] Slice identification;

[0333] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0334] Optionally, in the functional entity, the processor 1402 is further configured to:

[0335] In a case where the first information does not include terminal indication information, it is determined that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0336] One embodiment of the present disclosure further provides a functional entity, which is a second functional entity. As shown in FIG15 , the second functional entity 1500 includes a transceiver 1501, and the transceiver 1501 is configured to:

[0337] Sending a first message to the first functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of the terminal;

[0338] Obtain a second message sent by the first functional entity based on the first message, where the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0339] Optionally, in the functional entity, the transceiver 1501 is further configured to:

[0340] According to the second message, a fourth message is sent to a fourth functional entity, where the fourth message includes the judgment result.

[0341] One embodiment of the present disclosure further provides a functional entity, which is a first functional entity. As shown in FIG16 , the first functional entity 1600 includes a transceiver 1601, and the transceiver 1601 is configured to:

[0342] Obtain first information, where the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in a current network.

[0343] Optionally, the functional entity, wherein the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the provision of AKMA application layer keys to the terminal in the corresponding network, or does not allow the provision of AKMA application layer keys to the terminal in the corresponding network.

[0344] Optionally, in the functional entity, the transceiver 1601 acquiring the first information includes:

[0345] Obtain a third message sent by a third network device; wherein the third message includes the first information.

[0346] Optionally, in the functional entity, the first information includes one or more of the following information:

[0347] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0348] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0349] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0350] Optionally, in the functional entity, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0351] Security key K AKMA Identifier A-KID

[0352] General Public Subscription Identifier GPSI;

[0353] Subscription Permanent Identifier SUPI;

[0354] Slice identification;

[0355] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0356] One embodiment of the present disclosure further provides a functional entity, which is a third functional entity. As shown in FIG17 , the third functional entity 1700 includes a transceiver 1701, and the transceiver 1701 is configured to:

[0357] A third message is sent to the first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in the current network.

[0358] Optionally, the functional entity, wherein the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the provision of AKMA application layer keys to the terminal in the corresponding network, or does not allow the provision of AKMA application layer keys to the terminal in the corresponding network.

[0359] Optionally, in the functional entity, the first information includes one or more of the following information:

[0360] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0361] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0362] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0363] Optionally, in the functional entity, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0364] Security key K AKMA Identifier A-KID

[0365] General Public Subscription Identifier GPSI;

[0366] Subscription Permanent Identifier SUPI;

[0367] Slice identification;

[0368] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0369] One embodiment of the present disclosure further provides a key requesting device, which is applied to a first functional entity. As shown in FIG18 , the device includes:

[0370] The first receiving module 1801 is configured to receive a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal;

[0371] The first sending module 1802 is used to send a second message to the second functional entity; wherein the second message includes a judgment result, and the judgment result indicates that the AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0372] Optionally, the key requesting device further comprises:

[0373] A determination module 1803 is configured to determine, based on the first information, whether an AKMA application layer key can be provided for the terminal in the current network;

[0374] Among them, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

[0375] Optionally, the key requesting device further comprises:

[0376] The third obtaining module 1804 is configured to obtain a third message sent by a third functional entity; wherein the third message includes the first information.

[0377] Optionally, in the key requesting device, the first information includes one or more of the following information:

[0378] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0379] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0380] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0381] Optionally, in the key requesting device, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0382] Security key K AKMA Identifier A-KID

[0383] General Public Subscription Identifier GPSI;

[0384] Subscription Permanent Identifier SUPI;

[0385] Slice identification;

[0386] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0387] Optionally, the key requesting device further comprises:

[0388] The determination module 1805 is configured to determine, when the first information does not include terminal indication information, whether the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0389] One embodiment of the present disclosure further provides a key requesting device, which is applied to a second functional entity, as shown in FIG19 , and includes:

[0390] The second sending module 1901 is configured to send a first message to the first functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of the terminal;

[0391] The first acquisition module 1902 is used to obtain a second message sent by the first functional entity based on the first message, and the second message includes a judgment result, and the judgment result indicates that the AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

[0392] Optionally, in the key requesting device, the second sending module 1901 is further configured to:

[0393] According to the second message, a fourth message is sent to a fourth functional entity, where the fourth message includes the judgment result.

[0394] One embodiment of the present disclosure further provides a key requesting device, which is applied to a first functional entity, as shown in FIG20 , and includes:

[0395] The second acquisition module 2001 is used to obtain first information, where the first information is used by the first functional entity to determine whether it can provide an AKMA application layer key for a terminal in the current network.

[0396] Optionally, the key requesting device, wherein the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the provision of AKMA application layer keys to the terminal in the corresponding network, or does not allow the provision of AKMA application layer keys to the terminal in the corresponding network.

[0397] Optionally, in the key requesting device, the second obtaining module 2001 obtaining the first information includes:

[0398] Obtain a third message sent by a third network device; wherein the third message includes the first information.

[0399] Optionally, in the key requesting device, the first information includes one or more of the following information:

[0400] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0401] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0402] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0403] Optionally, in the key requesting device, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0404] Security key K AKMA Identifier A-KID

[0405] General Public Subscription Identifier GPSI;

[0406] Subscription Permanent Identifier SUPI;

[0407] Slice identification;

[0408] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0409] One embodiment of the present disclosure further provides a key requesting device, which is applied to a third functional entity. As shown in FIG21 , the device includes:

[0410] The third sending module 2101 is used to send a third message to the first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether it can provide an AKMA application layer key for the terminal in the current network.

[0411] Optionally, the key requesting device, wherein the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the provision of AKMA application layer keys to the terminal in the corresponding network, or does not allow the provision of AKMA application layer keys to the terminal in the corresponding network.

[0412] Optionally, in the key requesting device, the first information includes one or more of the following information:

[0413] Network information of at least one network and the key service setting information corresponding to each of the networks;

[0414] The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal;

[0415] The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

[0416] Optionally, in the key requesting device, the first information further includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following:

[0417] Security key K AKMA Identifier A-KID

[0418] General Public Subscription Identifier GPSI;

[0419] Subscription Permanent Identifier SUPI;

[0420] Slice identification;

[0421] A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

[0422] One embodiment of the present disclosure further provides a network device, which includes a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the key request method as described in any one of the above items.

[0423] The specific implementation of the key request method executed by the program running on the processor of the network device can refer to the detailed description of the key request method when applied to the above functional entity, and will not be repeated here.

[0424] In addition, a specific embodiment of the present disclosure further provides a readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps in the key request method as described in any one of the above items.

[0425] Specifically, the readable storage medium is applied to the above-mentioned first functional entity, second functional entity or third functional entity. When applied to the first functional entity, second functional entity or third functional entity, the execution steps corresponding to the key request method are described in detail above and will not be repeated here.

[0426] An embodiment of the present disclosure also provides a computer program product, including computer instructions, which, when executed by a processor, implement the steps in the key request method described in any one of the above items and can achieve the same technical effect. To avoid repetition, they will not be repeated here.

[0427] In the several embodiments provided in the present disclosure, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection of some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0428] In addition, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, each unit may be physically included separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or hardware plus software functional units.

[0429] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute some steps of the sending and receiving methods described in various embodiments of the present disclosure. The aforementioned storage medium includes: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc., various media that can store program code.

[0430] The above is a preferred embodiment of the present disclosure. It should be pointed out that for ordinary personnel in this technical field, several improvements and modifications can be made without departing from the principles described in the present disclosure. These improvements and modifications should also be regarded as within the scope of protection of the present disclosure.

Claims

1. A key request method, performed by a first functional entity, the method comprising: Receiving a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal; Send a second message to the second functional entity; wherein the second message includes a judgment result, the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

2. The key request method according to claim 1, further comprising: According to the first information, determining whether an AKMA application layer key can be provided for the terminal in the current network; Among them, the first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

3. The key request method according to claim 2, further comprising: Obtain a third message sent by a third functional entity; wherein the third message includes the first information.

4. The key request method according to any one of claims 2 to 3, wherein: The first information includes one or more of the following information: Network information of at least one network and the key service setting information corresponding to each of the networks; The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal; The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

5. The key request method according to claim 4, wherein: The first information also includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following: Security Key K AKMA Identifier A-KID General Public Subscription Identifier GPSI; Subscription Permanent Identifier SUPI; Slice identification; A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

6. The key request method according to claim 2, further comprising: In a case where the first information does not include terminal indication information, it is determined that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

7. A key request method, performed by a second functional entity, the method comprising: Send a first message to the first functional entity, wherein the first message is associated with the identity authentication and key management service of the terminal AKMA application layer key acquisition related; Obtain a second message sent by the first functional entity according to the first message, wherein the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

8. The key request method according to claim 7, further comprising: According to the second message, a fourth message is sent to a fourth functional entity, wherein the fourth message includes the judgment result.

9. A key request method, performed by a first functional entity, the method comprising: Obtain first information, where the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in a current network.

10. The key request method according to claim 9, wherein: The first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

11. The key request method according to claim 9 or 10, wherein: The obtaining of the first information comprises: Acquire a third message sent by a third network device; wherein the third message includes the first information.

12. The key request method according to claim 9 or 10, wherein: The first information includes one or more of the following information: Network information of at least one network and the key service setting information corresponding to each of the networks; The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal; The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

13. The key request method according to claim 12, wherein: The first information also includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following: Security Key K AKMA Identifier A-KID General Public Subscription Identifier GPSI; Subscription Permanent Identifier SUPI; Slice identification; A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

14. A key request method, performed by a third functional entity, the method comprising: A third message is sent to the first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in a current network.

15. The key request method according to claim 14, wherein: The first information is used to record the key service setting information of the terminal in at least one network; the key service setting information allows the terminal to be provided with an AKMA application layer key in the corresponding network, or does not allow the terminal to be provided with an AKMA application layer key in the corresponding network.

16. The key request method according to claim 14 or 15, wherein: The first information includes one or more of the following information: Network information of at least one network and the key service setting information corresponding to each of the networks; The key service setting information is network information of at least one network that is not allowed to provide an application layer key to the terminal; The key service setting information is network information of at least one network that is allowed to provide an application layer key to the terminal.

17. The key request method according to claim 16, wherein: The first information also includes terminal indication information corresponding to the terminal, and the terminal indication information includes one or more of the following: Security Key K AKMA Identifier A-KID General Public Subscription Identifier GPSI; Subscription Permanent Identifier SUPI; Slice identification; A preset identifier is used to indicate that the first information is applicable to each terminal that sends an AKMA application layer key acquisition request.

18. A functional entity, the functional entity being a first functional entity, comprising a transceiver, the transceiver being configured to: Receiving a first message sent by a second functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal; Sending a second message to the second functional entity; wherein, The second message includes a determination result, where the determination result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

19. A functional entity, the functional entity being a second functional entity, comprising a transceiver, the transceiver being configured to: Sending a first message to a first functional entity, where the first message is related to obtaining an Authentication and Key Management Service (AKMA) application layer key of a terminal; Obtain a second message sent by the first functional entity according to the first message, wherein the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

20. A functional entity, the functional entity being a first functional entity, comprising a transceiver, the transceiver being configured to: Obtain first information, where the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in a current network.

21. A functional entity, the functional entity being a third functional entity, comprising a transceiver, the transceiver being configured to: Sending a third message to the first functional entity, wherein: The third message includes first information, and the first information is used by the first functional entity to determine whether an AKMA application layer key can be provided for a terminal in the current network.

22. A key request device, applied to a first functional entity, the device comprising: A first receiving module, configured to receive a first message sent by a second functional entity, wherein the first message is related to obtaining an Authentication and Key Management Service AKMA application layer key of a terminal; The first sending module is used to send a second message to the second functional entity; wherein the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

23. A key request device, applied to a second functional entity, the device comprising: A second sending module, configured to send a first message to the first functional entity, where the first message is related to obtaining an AKMA application layer key of an identity authentication and key management service of a terminal; The first acquisition module is used to obtain a second message sent by the first functional entity according to the first message, wherein the second message includes a judgment result, and the judgment result indicates that an AKMA application layer key is provided for the terminal in the current network, or indicates that the AKMA application layer key is not allowed to be provided for the terminal in the current network.

24. A key request device, applied to a first functional entity, the device comprising: The second acquisition module is used to acquire first information, where the first information is used by the first functional entity to determine whether it can provide an AKMA application layer key for a terminal in a current network.

25. A key request device, applied to a third functional entity, the device comprising: The third sending module is used to send a third message to the first functional entity, wherein the third message includes first information, and the first information is used by the first functional entity to determine whether it can provide an AKMA application layer key for a terminal in a current network.

26. A network device, comprising a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the key request method according to any one of claims 1 to 17.

27. A readable storage medium having a program stored thereon, wherein the program, when executed by a processor, implements the steps in the key request method according to any one of claims 1 to 17.

28. A computer program product, comprising computer instructions, which, when executed by a processor, implement the steps in the key request method according to any one of claims 1 to 17.

Citation Information

Patent Citations

  • Method and system of enabling AKMA service in roaming scenario

    US20220210636A1

  • Secure communication method and device

    WO2022147803A1

  • Information transmission method, and device

    WO2023208183A2

  • Key management method and apparatus, and device and storage medium

    WO2023216272A1