Methods and apparatuses for supporting multiple accesses of UE to core network

The patent addresses the challenge of supporting multiple accesses of a UE to a core network across different 3GPP networks by deriving independent keys and determining path awareness, resulting in efficient and secure multiple access scenarios.

WO2025123706A1PCT designated stage Publication Date: 2025-06-19LENOVO (BEIJING) LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/109464
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-02
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing technologies face challenges in supporting multiple accesses of a user equipment (UE) to a core network across different 3GPP networks, particularly in generating independent security keys and implementing secondary path awareness in 5G and 6G dual-access scenarios.

Method used

A network node in the core network performs access procedures and key deriving procedures for a UE accessing the core network via multiple 3GPP networks. This involves deriving independent keys for each network based on a root key, and determining whether a 3GPP network is a primary or secondary path for the UE, with information being transmitted to RAN nodes to adjust radio configurations accordingly.

Benefits of technology

The solution enables efficient and secure multiple access scenarios for UEs across different 3GPP networks, ensuring independent key management and optimal radio resource allocation based on path awareness, thereby enhancing network flexibility and performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024109464_19062025_PF_FP_ABST
    Figure CN2024109464_19062025_PF_FP_ABST
Patent Text Reader

Abstract

Various aspects of the present disclosure relate to methods and apparatuses for supporting multiple accesses of a user equipment (UE) to a core network. According to an embodiment of the present disclosure, a network node in a core network can include: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network node to: perform a first access procedure with a UE for access of the UE to the core network via a first 3rd generation partnership project (3 GPP) network; perform a first key deriving procedure for deriving first key(s) for access stratum operation in the first 3 GPP network based on a root key; perform a second access procedure with the UE for access of the UE to the core network via a second 3 GPP network; and perform a second key deriving procedure for deriving second key(s) for access stratum operation in the second 3 GPP network based on the root key, wherein the second key(s) is independent of the first key(s).
Need to check novelty before this filing date? Find Prior Art

Description

METHODS AND APPARATUSES FOR SUPPORTING MULTIPLE ACCESSES OF UE TO CORE NETWORKTECHNICAL FIELD

[0001] The present disclosure relates to wireless communications, and more specifically to methods and apparatuses for supporting multiple accesses of a user equipment (UE) to a core network.BACKGROUND

[0002] A wireless communications system may include one or multiple network communication devices, such as base stations (BSs) , which may support wireless communications for one or multiple user communication devices, which may be otherwise known as UE, or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like) . Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G) ) .SUMMARY

[0003] An article "a" before an element is unrestricted and understood to refer to "at least one" of those elements or "one or more" of those elements. The terms "a, " "at least one, " "one or more, " and "at least one of one or more" may be interchangeable. As used herein, including in the claims, "or" as used in a list of items (e.g., a list of items prefaced by a phrase such as "at least one of" or "one or more of" or "one or both of" ) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C) . Also, as used herein, the phrase "based on" shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as "based on condition A" may be based on both a condition A and a condition B without departing from the  scope of the present disclosure. In other words, as used herein, the phrase "based on" shall be construed in the same manner as the phrase "based at least in part on. " Further, as used herein, including in the claims, a "set" may include one or more elements.

[0004] Some implementations of the methods and apparatuses described herein may include network node in a core network. The network node may include: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the network node to: perform a first access procedure with a UE for access of the UE to the core network via a first 3rd generation partnership project (3GPP) network; perform a first key deriving procedure for deriving first key (s) for access stratum operation in the first 3GPP network based on a root key; perform a second access procedure with the UE for access of the UE to the core network via a second 3GPP network; and perform a second key deriving procedure for deriving second key(s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0005] In some implementations of the network node described herein, the network node is an authentication server function (AUSF) , the first key (s) comprises a first security anchor function (SEAF) key for a first SEAF associated with the first 3GPP network, and the second key(s) comprises a second SEAF key for a second SEAF associated with the second 3GPP network, wherein: the first key deriving procedure comprises deriving the first SEAF key based on an AUSF key and a first access type indicator associated with the first 3GPP network, wherein the AUSF key is based on the root key; and the second key deriving procedure comprises deriving the second SEAF key based on the AUSF key and a second access type indicator associated with the second 3GPP network.

[0006] In some implementations of the network node described herein, the network node is an SEAF, the first key (s) comprises a first access and mobility management function (AMF) key for a first AMF associated with the first 3GPP network, and the second key (s) comprises a second AMF key for a second AMF associated with the second 3GPP network, wherein: the first key deriving procedure comprises deriving the first AMF key based on an SEAF key and a first access type indicator associated with the first 3GPP network, wherein the SEAF key is based on the root key; and the second key deriving procedure comprises deriving the second  AMF key based on the SEAF key and a second access type indicator associated with the second 3GPP network.

[0007] In some implementations of the network node described herein, the network node is an AMF, the first key (s) comprises a first radio access network (RAN) key for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network, wherein: the first key deriving procedure comprises deriving the first RAN key based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; and the second key deriving procedure comprises deriving the second RAN key based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0008] In some implementations of the network node described herein, the network node is an AMF, the first key (s) comprises a first next hop (NH) parameter for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network, wherein: the first key deriving procedure comprises deriving the first NH parameter based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; and the second key deriving procedure comprises deriving the second NH parameter based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0009] In some implementations of the network node described herein, the network node is an AMF, the first key (s) comprises a first RAN key for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to: derive a common RAN key based on an AMF key which is based on the root key; wherein: the first key deriving procedure comprises deriving the first RAN key based on the common RAN key and a first counter value associated with the first 3GPP network; and the second key deriving procedure comprises deriving the second RAN key based on the common RAN key and a second counter value associated with the second 3GPP network.

[0010] In some implementations of the network node described herein, the network node is an AMF, the first key (s) comprises a first NH parameter for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to: derive a common NH parameter based on an AMF key which is based on the root key; wherein: the first key deriving procedure comprises deriving the first NH parameter based on the common NH parameter and a first counter value associated with the first 3GPP network; and the second key deriving procedure comprises deriving the second NH parameter based on the common NH parameter and a second counter value associated with the second 3GPP network.

[0011] In some implementations of the network node described herein, the network node is an AMF, the first key (s) comprises a first RAN key for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to: derive a common RAN key based on an AMF key which is based on the root key; wherein: the first key deriving procedure comprises transmitting the common RAN key and a first counter value associated with the first 3GPP network to a first RAN node associated with the first 3GPP network for the first RAN node to derive the first RAN key; and the second key deriving procedure comprises transmitting the common RAN key and a second counter value associated with the second 3GPP network to a second RAN node associated with the second 3GPP network for the second RAN node to derive the second RAN key.

[0012] In some implementations of the network node described herein, the network node is an AMF, the first key (s) comprises a first NH parameter for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to: derive a common NH parameter based on an AMF key which is based on the root key; wherein: the first key deriving procedure comprises transmitting the common NH parameter and a first counter value associated with the first 3GPP network to a first RAN node associated with the first 3GPP network for the first RAN node to derive the first NH parameter; and the second key deriving procedure comprises transmitting the common  NH parameter and a second counter value associated with the second 3GPP network to a second RAN node associated with the second 3GPP network for the second RAN node to derive the second NH parameter.

[0013] In some implementations of the network node described herein, the network node is an AMF, and the at least one processor is further configured to cause the network node to determine whether the first 3GPP network is a primary path or a secondary path for the UE to access the core network based on at least one of: whether the first access procedure is performed before or after the second access procedure; an indication included in an access request associated with the first access procedure; a traffic steering rule configured by a policy control function (PCF) ; an indication provided by the PCF or a peer AMF; or subscription information of the UE stored in a unified data management (UDM) .

[0014] In some implementations of the network node described herein, the network node is an AMF, and the at least one processor is further configured to cause the network node to: transmit, to a RAN node associated with the first 3GPP network, information indicating that the first 3GPP network is a primary path or a secondary path for the UE to access the core network, wherein the information includes at least one of: an indicator indicating that the first 3GPP network is the primary path or the secondary path; or information related to a traffic steering rule between the primary path and the secondary path.

[0015] Some implementations of the methods and apparatuses described herein may include a UE for wireless communication. The UE may include: at least one memory; and at least one processor coupled with the at least one memory and configured to cause the UE to: perform a first access procedure for access to a core network via a first 3GPP network; derive first key (s) for access stratum operation in the first 3GPP network based on a root key; perform a second access procedure for access to the core network via a second 3GPP network; and derive second key(s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0016] In some implementations of the UE described herein, the first key (s) comprises a first SEAF key for a first SEAF associated with the first 3GPP network derived based on an AUSF key and a first access type indicator associated with the first 3GPP network, wherein the  AUSF key is based on the root key; and the second key (s) comprises a second SEAF key for a second SEAF associated with the second 3GPP network derived based on the AUSF key and a second access type indicator associated with the second 3GPP network.

[0017] In some implementations of the UE described herein, the first key (s) comprises a first AMF key for a first AMF associated with the first 3GPP network derived based on an SEAF key and a first access type indicator associated with the first 3GPP network, wherein the SEAF key is based on the root key; and the second key (s) comprises a second AMF key for a second AMF associated with the second 3GPP network derived based on the SEAF key and a second access type indicator associated with the second 3GPP network.

[0018] In some implementations of the UE described herein, the first key (s) comprises a first RAN key for a first RAN node associated with the first 3GPP network derived based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network derived based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0019] In some implementations of the UE described herein, the first key (s) comprises a first NH parameter for a first RAN node associated with the first 3GPP network derived based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network derived based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0020] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to: derive a common RAN key based on an AMF key which is based on the root key; wherein: the first key (s) comprises a first RAN key for a first RAN node associated with the first 3GPP network derived based on the common RAN key and a first counter value associated with the first 3GPP network; and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network derived based on the common RAN key and a second counter value associated with the second 3GPP network.

[0021] In some implementations of the UE described herein, the at least one processor is further configured to cause the UE to: derive a common NH parameter based on an AMF key which is based on the root key; wherein: the first key (s) comprises a first NH parameter for a first RAN node associated with the first 3GPP network derived based on the common NH parameter and a first counter value associated with the first 3GPP network; and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network based on the common NH parameter and a second counter value associated with the second 3GPP network.

[0022] Some implementations of the methods and apparatuses described herein may include a processor for wireless communication. The processor may include: at least one controller coupled with at least one memory and configured to cause the processor to: perform a first access procedure for access to a core network via a first 3GPP network; derive first key (s) for access stratum operation in the first 3GPP network based on a root key; perform a second access procedure for access to the core network via a second 3GPP network; and derive second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0023] Some implementations of the methods and apparatuses described herein may include a method performed by a UE. The method may include: performing a first access procedure for access to a core network via a first 3GPP network; deriving first key (s) for access stratum operation in the first 3GPP network based on a root key; performing a second access procedure for access to the core network via a second 3GPP network; and deriving second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0024] Some implementations of the methods and apparatuses described herein may include a method performed by a network node in a core network. The method may include: performing a first access procedure with a UE for access of the UE to the core network via a first 3GPP network; performing a first key deriving procedure for deriving first key (s) for access stratum operation in the first 3GPP network based on a root key; performing a second access procedure with the UE for access of the UE to the core network via a second 3GPP network; and performing a second key deriving procedure for deriving second key (s) for access stratum  operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to describe the manner in which advantages and features of the application can be obtained, a description of the application is rendered by reference to specific embodiments thereof, which are illustrated in the appended drawings. These drawings depict only example embodiments of the application and are not therefore to be considered limiting of its scope.

[0026] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.

[0027] Figure 2 illustrates an exemplary key hierarchy generation scheme in a 5G system in accordance with aspects of the present disclosure.

[0028] Figure 3A illustrates an exemplary 5G and 6G dual-access scenario in accordance with aspects of the present disclosure.

[0029] Figure 3B illustrates an exemplary hybrid core network (CN) in accordance with aspects of the present disclosure.

[0030] Figure 4A illustrates an exemplary dual-access scenario in accordance with aspects of the present disclosure.

[0031] Figure 4B illustrates another exemplary dual-access scenario in accordance with aspects of the present disclosure.

[0032] Figure 5 illustrates yet another exemplary dual-access scenario in accordance with aspects of the present disclosure.

[0033] Figure 6 illustrates yet another exemplary dual-access scenario in accordance with aspects of the present disclosure.

[0034] Figure 7 illustrates a flowchart of an exemplary method for establishing 5G and 6G dual-access in accordance with aspects of the present disclosure.

[0035] Figure 8 illustrates a flowchart of an exemplary method performed by a network node in a CN in accordance with aspects of the present disclosure.

[0036] Figure 9 illustrates a flowchart of an exemplary method performed by a UE in accordance with aspects of the present disclosure.

[0037] Figure 10 illustrates an example of a network node in a CN in accordance with aspects of the present disclosure.

[0038] Figure 11 illustrates an example of a UE in accordance with aspects of the present disclosure.

[0039] Figure 12 illustrates an example of a processor in accordance with aspects of the present disclosure.DETAILED DESCRIPTION

[0040] The detailed description of the appended drawings is intended as a description of preferred embodiments of the present application and is not intended to represent the only form in which the present application may be practiced. It should be understood that the same or equivalent functions may be accomplished by different embodiments that are intended to be encompassed within the spirit and scope of the present application.

[0041] While operations are depicted in the drawings in a particular order, persons skilled in the art will readily recognize that such operations need not be performed in the particular order as shown or in a sequential order, or that all illustrated operations need be performed, to achieve desirable results; sometimes one or more operations can be skipped. Further, the drawings can schematically depict one or more example processes in the form of a flow diagram. However, other operations that are not depicted can be incorporated in the example processes that are schematically illustrated. For example, one or more additional operations can be performed before, after, simultaneously, or between any of the illustrated operations. In certain circumstances, multitasking and parallel processing can be advantageous.

[0042] Reference will now be made in detail to some embodiments of the present disclosure, examples of which are illustrated in the accompanying drawings. To facilitate understanding, embodiments are provided under specific network architecture and service scenarios, such as  3GPP long-term evolution (LTE) and LTE advanced, 3GPP 5G new radio (NR) , 5G-Advanced, 6G, and so on. It is contemplated that along with developments of network architectures and new service scenarios, all embodiments in the present disclosure are also applicable to similar technical problems; and moreover, the terminologies recited in the present disclosure may change, which should not affect the principle of the present disclosure.

[0043] Aspects of the present disclosure are described in the context of a wireless communications system.

[0044] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more network equipments (NEs) (e.g., BSs) 102, one or more UEs 104, and a CN 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE-Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be an NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology (RAT) including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi) , IEEE 802.16 (WiMAX) , IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA) , frequency division multiple access (FDMA) , or code division multiple access (CDMA) , etc.

[0045] The one or more NEs 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NEs 102 described herein may be or include or may be referred to as a network node, a base station, a network element, a network function, a network entity, a RAN, a NodeB, an eNodeB (eNB) , a next-generation NodeB (gNB) , or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.

[0046] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc. ) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN) . In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NEs 102.

[0047] The one or more UEs 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (IoT) device, an Internet-of-Everything (IoE) device, or machine-type communication (MTC) device, among other examples.

[0048] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.

[0049] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., S1, N2, N2, or network interface) . In some implementations, the NEs 102 may communicate with each other directly. In some other implementations, the NEs 102 may communicate with each other indirectly (e.g., via the CN 106) . In some implementations, one or more NEs 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC) . An ANC may  communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as radio heads, smart radio heads, or transmission-reception points (TRPs) .

[0050] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC) , or a 5G core (5GC) , which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME) , an AMF) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW) , a Packet Data Network (PDN) gateway (P-GW) , or a user plane function (UPF) ) . In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc. ) for the one or more UEs 104 served by the one or more NEs 102 associated with the CN 106.

[0051] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an S1, N2, N2, or another network interface) . The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session) . The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106) .

[0052] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers) ) to perform various operations (e.g., wireless communications) . In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104  may support various frame structures (e.g., multiple frame structures) . The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.

[0053] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., μ=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., μ=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., μ=1) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., μ=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., μ=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., μ=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.

[0054] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames) . Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.

[0055] Additionally or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (e.g., μ=0, μ=1, μ=2, μ=3, μ=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., orthogonal frequency division multiplexing (OFDM) symbols) . In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a  numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing) , a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., μ=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.

[0056] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz –7.125 GHz) , FR2 (24.25 GHz –52.6 GHz) , FR3 (7.125 GHz –24.25 GHz) , FR4 (52.6 GHz –114.25 GHz) , FR4a or FR4-1 (52.6 GHz –71 GHz) , and FR5 (114.25 GHz –300 GHz) . In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data) . In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.

[0057] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies) . For example, FR1 may be associated with a first numerology (e.g., μ=0) , which includes 15 kHz subcarrier spacing; a second numerology (e.g., μ=1) , which includes 30 kHz subcarrier spacing; and a third numerology (e.g., μ=2) , which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies) . For example, FR2 may be associated with a third numerology (e.g., μ=2) , which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., μ=3) , which includes 120 kHz subcarrier spacing.

[0058] Figure 2 illustrates an exemplary key hierarchy generation scheme in a 5G system in accordance with aspects of the present disclosure. Figure 2 is the same as Figure 6.2.1-1 in TS  33.501, and detailed definitions for the elements illustrated in Figure 2 can be found in TS 33.501.

[0059] Referring to Figure 2, the keys related to authentication in the 5G system may include K, CK or IK, wherein CK or IK may be derived from K (referred to as a root key) . In case of improved extensible authentication protocol method for 3rd generation authentication and key agreement (EAP-AKA') , the keys CK', IK' are derived from CK, IK as specified in clause 6.1.3.1 in TS 33.501.

[0060] The key hierarchy may include the following keys: KAUSF, KSEAF, KAMF, KNASint, KNASenc, KN3IWF, KgNB, KRRCint, KRRCenc, KUPint and KUPenc.

[0061] As an example, keys for AUSF in a home public land mobile network (HPLMN) may include KAUSF and KSEAF, wherein:

[0062] - KAUSF is a key derived

[0063] - by mobile equipment (ME) and AUSF from CK', IK' in case of EAP-AKA', where CK' and IK' is received by AUSF as a part of a transformed authentication vector (AV) from an authentication credential repository and processing function (ARPF) ; or

[0064] - by ME and ARPF from CK, IK in case of 5G authentication and key agreement (AKA) , where KAUSF is received by AUSF as a part of a 5G home environment (HE) AV from ARPF.

[0065] - KSEAF is an anchor key derived by ME and AUSF from KAUSF. KSEAF is provided by AUSF to the SEAF in a serving network.

[0066] As an example, a key for AMF in the serving network may include KAMF, which is a key derived by ME and SEAF from KSEAF. KAMF is further derived by ME and a source AMF when performing horizontal key derivation.

[0067] As an example, keys for NAS signalling may include KNASint and KNASenc, wherein:

[0068] - KNASint is a key derived by ME and AMF from KAMF, which shall only be used for the protection of NAS signalling with a particular integrity algorithm.

[0069] - KNASenc is a key derived by ME and AMF from KAMF, which shall only be used for the protection of NAS signalling with a particular encryption algorithm.

[0070] As an example, a key for a next generation (NG) RAN may include KgNB (also referred to as KRAN) , which is a key derived by ME and AMF from KAMF. KgNB is further derived by ME and a source gNB when performing horizontal or vertical key derivation. KgNB is used as KeNB between ME and ng-eNB.

[0071] As an example, keys for user plane (UP) traffic may include KUPenc and KUPint, wherein:

[0072] - KUPenc is a key derived by ME and gNB from KgNB, which shall only be used for the protection of UP traffic between ME and gNB with a particular encryption algorithm.

[0073] - KUPint is a key derived by ME and gNB from KgNB, which shall only be used for the protection of UP traffic between ME and gNB with a particular integrity algorithm.

[0074] As an example, keys for radio resource control (RRC) signalling may include KRRCint and KRRCenc, wherein:

[0075] - KRRCint is a key derived by ME and gNB from KgNB, which shall only be used for the protection of RRC signalling with a particular integrity algorithm.

[0076] - KRRCenc is a key derived by ME and gNB from KgNB, which shall only be used for the protection of RRC signalling with a particular encryption algorithm.

[0077] Some intermediate keys may also be derived. As an example, the intermediate keys may include NH, which is a key derived by ME and AMF to provide forward security as described in clause A. 10 in TS 33.501.

[0078] As an example, a key for non-3GPP access may include KN3IWF, which is a key derived by ME and AMF from KAMF for the non-3GPP access. KN3IWF is not forwarded between non-3GPP access interworking functions (N3IWFs) .

[0079] Each of the above keys may be derived by using a generic key derivation function (KDF) as specified in TS 33.220. For example, the KDF may generate a key based on the  following operations as specified in TS 33.220. It is assumed that n+1 input parameters are used for deriving the key.

[0080] First, the input parameters (e.g., denoted as Pi, i=0, 1, …, n) and their lengths may be concatenated into a string S, wherein:

[0081] 1. The length of each input parameter Pi measured in octets may be encoded into a two octet-long string:

[0082] a) The number of octets in input parameter Pi is first expressed as a number k in the range of [0, 65535] .

[0083] b) Li is then a 16-bit long encoding of the number k, encoded as described in clause B. 2.1 in TS 33.220.

[0084] 2. String S may be constructed from the n+1 input parameters as follows:

[0085] S = FC || P0 || L0 || P1 || L1 || P2 || L2 || P3 || L3 || ... || Pn || Ln, wherein:

[0086] a) FC is used to distinguish between different instances of the algorithm and is either a single octet or consists of two octets of the form FC1|| FC2 where FC1 = 0xFF and FC2 is a single octet,

[0087] b) P0 ... Pn are the n+1 input parameter encodings, and

[0088] c) L0 ... Ln are the two-octet representations of the length of the corresponding input parameter encodings P0…Pn.

[0089] Then, the final output, i.e., the key, may be derived based on the string S and an input key (e.g., denoted as KEY) . For example, the derived key may be determined based on the following equation (1) , as specified in TS 33.220:

[0090] derived key = HMAC-SHA-256 (KEY, S)               (1) .

[0091] In a phase of 5G to future 6G migration, since a 6G RAN node (or cell) will not provide a full coverage at the beginning, in many scenarios, a UE may still connect to the network via a 5G RAN node (or cell) .

[0092] As one of possible options for 5G to future 6G migration, data aggregation for a UE may be performed at CN and the UE may maintain 5G and 6G dual-access to the CN (hereinafter referred to as 5G and 6G dual-access scenario) . In such scenario, for RAN, the UE is served by a 5G RAN and a 6G RAN at the same time but separately. That is, there is no access stratum coordination over the Xn-like interface between the 5G RAN and the 6G RAN. For CN, one hybrid CN is assumed to serve both the 5G RAN and the 6G RAN at the same time. The 5G RAN and the 6G RAN may both have connection to AMF (s) for the same UE. The user plane data may be aggregated in the CN (e.g., anchor UPF) . For example, some network functions (NFs) in the CN, e.g., UDM, AUSF, session management function (SMF) , and UPF, may be shared by the 5G RAN and the 6G RAN, while some NFs (e.g., AMF) may be specific for the 5G RAN or the 6G RAN. In addition, in such scenario, the UE may have one universal subscriber identity module (USIM) card, and be registered to the CN only once although the UE may perform multiple access (e.g., registration) procedures with the CN via different RANs. Herein, the terms "dual-access, " "dual-stack, " and "dual-path" may be used interchangeably.

[0093] Figure 3A illustrates an exemplary 5G and 6G dual-access scenario in accordance with aspects of the present disclosure.

[0094] Referring to Figure 3A, a UE is served by a 5G RAN and a 6G RAN at the same time but separately. That is, there is no access stratum coordination over the Xn-like interface between the 5G RAN and the 6G RAN. One hybrid CN is used to serve both the 5G RAN and 6G RAN at the same time. The hybrid CN may include a UDM, an AUSF, an SMF, and a UPF shared by the 5G RAN and the 6G RAN, a 5G AMF specific for the 5G RAN, and a 6G AMF specific for the 6G RAN. The 5G RAN may connect to the 5G AMF for exchanging control plane data of the UE. The 6G RAN may connect to the 6G AMF for exchanging control plane data of the UE. User plane data of the UE from the 5G RAN and the 6G RAN may be aggregated in the UPF. The SMF may connect to at least the 5G AMF. In some examples, the SMF may also connect to the 6G AMF (not shown in Figure 3A) . In some examples, the SMF may also connect to the 6G RAN (not shown in Figure 3A) .

[0095] Figure 3B illustrates an exemplary hybrid CN in accordance with aspects of the present disclosure.

[0096] Similar to Figure 3A, Figure 3B shows that the hybrid CN may include a UDM, an AUSF, an SMF, and a UPF shared by a 5G RAN and a 6G RAN, a 5G AMF specific for the 5G RAN, and a 6G AMF specific for the 6G RAN. The 5G RAN may connect to the 5G AMF for exchanging control plane data of a UE. The 6G RAN may connect to the 6G AMF for exchanging control plane data of a UE. User plane data of the UE from the 5G RAN and the 6G RAN may be aggregated in the UPF.

[0097] The 5G and 6G dual-access scenario may involve the following issues.

[0098] One issue is how to generate security key (s) for different accesses. The key generation approaches used in the dual-connection scenario, the dual-steer scenario, or the access traffic steering, switching, and splitting (ATSSS) scenario cannot be directly reused in the 5G and 6G dual-access scenario. The reasons are as follows.

[0099] In the dual-connection scenario, the key for the secondary path KSN is determined from the key for the master node KgNB. However, in the 5G and 6G dual-access scenario, the operations of 5G RAN and 6G RAN are independent and thus the keys for 5G access and 6G access may be independent.

[0100] In the dual-steer scenario, two USIM cards are used for two connections, respectively. Thus, there are two different root keys, and the key for each path is generated individually based on a corresponding root key. However, in the 5G and 6G dual-access scenario, only one USIM card with a single root key is assumed.

[0101] In the ATSSS scenario, the keys for the 3GPP access path and non-3GPP access path are generated based on the same KAMF with different input values. However, in the 5G and 6G dual-access scenario, both accesses are 3GPP accesses, and they may be associated with different AMFs.

[0102] Given the above, how to generate security key (s) for different accesses in the 5G and 6G dual-access scenario needs to be solved.

[0103] Another issue in the 5G and 6G dual-access scenario is how to implement secondary path awareness at the RAN node. Even though there is no access stratum coordination between the 5G RAN and the 6G RAN, it is still beneficial for the 5G RAN node or 6G RAN node to be  aware if it is configured as a secondary path for a UE to access a CN. In some cases, a UE may use the secondary path only if the primary path has connection problems. In such cases, the RAN node of the secondary path may adopt relaxed radio configurations, e.g., network energy saving (NES) , UE energy saving, or relaxed radio resource management (RRM) measurement. Given this, how to implement secondary path awareness at a RAN node in the 5G and 6G dual-access scenario needs to be solved.

[0104] Embodiments of the present disclosure provide solutions for supporting multiple accesses of a UE, which can solve at least one of the aforementioned issues and / or other issue (s) . For example, some embodiments of the present disclosure provide solutions for security key (s) generation in multi-access scenario. Some embodiments of the present disclosure provide solutions for secondary path awareness in multi-access scenario. More details will be described in the following text in combination with the appended drawings.

[0105] According to some embodiments of the present application, a network node in a core network may perform a first access procedure with a UE for access of the UE to the core network via a first 3GPP network. During the first access procedure, the network node may perform a first key deriving procedure for deriving first key (s) for access stratum operation in the first 3GPP network based on a root key. For example, the root key may include "K" as illustrated in Figure 2. The derivation of keys is mirrored in both the UE and the network node. Accordingly, during the first access procedure, the UE may also derive the first key (s) for access stratum operation in the first 3GPP network based on the root key.

[0106] In the case that another access of the UE is needed, the network node may perform a second access procedure with the UE for access of the UE to the core network via a second 3GPP network. During the second access procedure, the network node may perform a second key deriving procedure for deriving second key (s) for access stratum operation in the second 3GPP network based on a root key. As stated above, the UE may have only one USIM card and be registered to the core network only once although two access procedures are performed. In such scenario, the root key for the second 3GPP network is the same as the root key for the first 3GPP network. However, the second key (s) is independent of the first key (s) . Similarly, during the second access procedure, the UE may also derive the second key (s) for access stratum operation in the second 3GPP network based on the root key.

[0107] As an example, the first access procedure or the second access procedure may be a registration procedure, and an access request sent by the UE to initiate the first access procedure or the second access procedure may be a registration request.

[0108] The core network may be a hybrid core network that may serve the first 3GPP network and the second 3GPP network at the same time. In such embodiments, the first 3GPP network and the second 3GPP network may be any two different 3GPP networks. As an example, the first 3GPP network may be one of a 5G network and a 6G network, and the second 3GPP network may be the other of the 5G network and the 6G network. The UE may be served by the first 3GPP network and the second 3GPP network at the same time. The first 3GPP network may be associated with (e.g., include) a first RAN node for serving the UE. The second 3GPP network may be associated with (e.g., include) a second RAN node for serving the UE.

[0109] The following Embodiment I and Embodiment II provide solutions for derivation of the first key (s) and the second key (s) , wherein Embodiment I provides solutions for derivation of the first key (s) and the second key (s) in the case that the first 3GPP network and the second 3GPP network are connected to two different AMFs, respectively, and Embodiment II provides solutions for derivation of the first key (s) and the second key (s) in the case that the first 3GPP network and the second 3GPP network are connected to a same AMF.

[0110] Embodiment I

[0111] In Embodiment I, the first 3GPP network is associated with (e.g., connected to) a first AMF and the second 3GPP network is associated with (e.g., connected to) a second AMF different from the first AMF. Embodiment I may further include Embodiment I-1 and Embodiment I-2.

[0112] Embodiment I-1

[0113] In Embodiment I-1, the first AMF may be associated with a first SEAF and the second AMF may be associated with a second SEAF different from the first SEAF. For example, the first SEAF may be within the first AMF, and the second SEAF may be within the second AMF.

[0114] Figure 4A illustrates an exemplary dual-access scenario for Embodiment I-1.

[0115] Referring to Figure 4A, the first 3GPP network (or the first RAN node) is connected to a first AMF associated with a first SEAF, and the second 3GPP network (or the second RAN node) is connected to a second AMF associated with a second SEAF. Other connections illustrated in Figure 4A are the same as those in Figure 3A.

[0116] In Embodiment I-1, the aforementioned network node in the core network that performs both the first key deriving procedure for deriving the first key (s) and the second key deriving procedure for deriving the second key (s) may be the AUSF.

[0117] As an example, the first key (s) may include a first SEAF key (e.g., denoted as KSEAF1) for the first SEAF. KSEAF1 may be derived by the AUSF and the UE based on an AUSF key (e.g., denoted as KAUSF) and a first access type indicator associated with the first 3GPP network. KAUSF may be derived based on the root key. For example, KAUSF may be derived based on the schemes as described with respect to Figure 2.

[0118] Based on KSEAF1, the first SEAF and the UE may derive a first AMF key (e.g., denoted as KAMF1) associated with the first 3GPP network, e.g., according to the schemes as described with respect to Figure 2. Based on KAMF1, the first AMF and the UE may derive a first RAN key (e.g., denoted as KRAN1) and a first NH parameter (denoted as NH1) associated with the first 3GPP network, e.g., based on the schemes as described with respect to Figure 2. The derived KRAN1 and NH1 may be used to determine keys for access stratum operation in the first 3GPP network, e.g., keys for encryption / decryption and integration protection / integration checking for UP and control plane (CP) data transmission between the first RAN node and the UE (such as KRRCint, KRRCenc, KUPint and KUPenc) .

[0119] The second key (s) may include a second SEAF key (e.g., denoted as KSEAF2) for the second SEAF. KSEAF2 may be derived by the AUSF and the UE based on KAUSF (i.e., the same AUSF key as that used for deriving KSEAF1) and a second access type indicator associated with the second 3GPP network.

[0120] Based on KSEAF2, the second SEAF and the UE may derive a second AMF key (e.g., denoted as KAMF2) associated with the second 3GPP network, e.g., according to the schemes as described with respect to Figure 2. Based on KAMF2, the second AMF and the UE may derive a second RAN key (e.g., denoted as KRAN2) and a second NH parameter (denoted as NH2)  associated with the second 3GPP network, e.g., based on the schemes as described with respect to Figure 2. The derived KRAN2 and NH2 may be used to determine keys for access stratum operation in the second 3GPP network, e.g., for encryption / decryption and integration protection / integration checking for UP and CP data transmission between the second RAN node and the UE (such as KRRCint, KRRCenc, KUPint and KUPenc) .

[0121] As an example for Embodiment I-1, to derive an SEAF key (e.g., KSEAF1 or KSEAF2) , the following parameters may be used to form a string S to be input to a KDF (e.g., the KDF as specified in TS 33.220) :

[0122] - FC = 0x6C,

[0123] - P0 = <serving network name>,

[0124] - L0 = length of <serving network name>,

[0125] - P1 = access type indicator, and

[0126] - L1 = length of access type indicator.

[0127] The following Table 1 illustrates exemplary access type indicators. For example, the access type indicators for the first 3GPP network and the second 3GPP network may be 0x01 and 0x02, respectively.

[0128] Table 1

[0129] Then, the SEAF key may be derived based on the string S and KAUSF according to the KDF, e.g., according to aforementioned equation (1) in which KEY is KAUSF.

[0130] For example, to derive KSEAF1, FC = 0x6C, P0 = <name of the first 3GPP network>, L0 = length of <name of the first 3GPP network>, P1 = 0x01, and L1 = 0x00 0x01 may be used to form the string S, and KSEAF1 = HMAC-SHA-256 (KAUSF, S) .

[0131] Embodiment I-2

[0132] In Embodiment I-2, the first AMF and the second AMF may be associated with a same SEAF. For example, the SEAF may be a standalone network function in the core network.

[0133] Figure 4B illustrates an exemplary dual-access scenario for Embodiment I-2.

[0134] Figure 4B is different from Figure 4A in that both the first AMF and the second AMF connect to a same SEAF, which may connect to an UDM or an AUSF. Other connections illustrated in Figure 4B are the same as those in Figure 4A.

[0135] Since there is only one SEAF in Embodiment I-2, the AUSF and the UE may derive only one SEAF key (e.g., denoted as KSEAF) for the SEAF. KSEAF may be derived based on the root key. For example, according to the schemes as described with respect to Figure 2, KAUSF may be derived based on the root key (e.g., the key "K" in Figure 2) , and KSEAF may be derived based on KAUSF.

[0136] In Embodiment I-2, the aforementioned network node in the core network that performs both the first key deriving procedure for deriving the first key (s) and the second key deriving procedure for deriving the second key (s) may be the SEAF.

[0137] As an example, the first key (s) may include a first AMF key (e.g., denoted as KAMF1) for the first AMF. KAMF1 may be derived by the SEAF and the UE based on KSEAF and a first access type indicator associated with the first 3GPP network.

[0138] Based on KAMF1, the first AMF and the UE may derive a first RAN key (e.g., denoted as KRAN1) and a first NH parameter (denoted as NH1) associated with the first 3GPP network, e.g., based on the schemes as described with respect to Figure 2. The derived KRAN1 and NH1 may be used to determine keys for access stratum operation in the first 3GPP network, e.g., keys for encryption / decryption and integration protection / integration checking for UP and CP data transmission between the first RAN node and the UE (such as KRRCint, KRRCenc, KUPint and KUPenc) .

[0139] The second key (s) may include a second AMF key (e.g., denoted as KAMF2) for the second AMF. KAMF2 may be derived by the SEAF and the UE based on KSEAF (i.e., the same SEAF key as that used for deriving KAMF1) and a second access type indicator associated with the second 3GPP network.

[0140] Based on KAMF2, the second AMF and the UE may derive a second RAN key (e.g., denoted as KRAN2) and a second NH parameter (denoted as NH2) associated with the second 3GPP network, e.g., based on the schemes as described with respect to Figure 2. The derived KRAN2 and NH2 may be used to determine keys for access stratum operation in the second 3GPP network, e.g., for encryption / decryption and integration protection / integration checking for UP and CP data transmission between the second RAN node and the UE (such as KRRCint, KRRCenc, KUPint and KUPenc) .

[0141] As an example for Embodiment I-2, to derive an AMF key (e.g., KAMF1 or KAMF2) , the following parameters may be used to form a string S to be input to a KDF (e.g., the KDF as specified in TS 33.220) :

[0142] - FC = 0x6D,

[0143] - P0 = international mobile subscriber identity (IMSI) or international mobile subscriber identity (NAI) or global cable identifier (GCI) or global line identifier (GLI) ,

[0144] - L0 = P0 length (i.e., number of octets in P0) ,

[0145] - P1 = anti-bidding down between architectures (ABBA) parameter,

[0146] - L1 = P1 length (i.e., number of octets in P1) ,

[0147] - P2 = access type indicator, and

[0148] - L2 = length of access type indicator.

[0149] As an example, the access type indicators for the first 3GPP network and the second 3GPP network may be 0x01 and 0x02, respectively

[0150] Then, the AMF key may be derived based on the string S and KSEAF according to the KDF, e.g., according to aforementioned equation (1) in which KEY is KSEAF.

[0151] For example, to derive KAMF1, FC = 0x6D, P0 = IMSI or NAI or GCI or GLI, L0 =P0 length, P1 = ABBA parameter, L1 = P1 length, P2 = 0x01, and L2= 0x00 0x01 may be used to form the string S, and KAMF1 = HMAC-SHA-256 (KSEAF, S) .

[0152] Embodiment II

[0153] In Embodiment II, the first 3GPP network and the second 3GPP network are both associated with (e.g., connected to) a same AMF. For example, the AMF may be an enhanced AMF (eAMF) . The AMF may connect to 5G RAN via a next generation application protocol (NG-AP) interface and connect to 6G RAN via a service based interface (SBI) .

[0154] Figure 5 illustrates an exemplary dual-access scenario for Embodiment II.

[0155] Referring to Figure 5, the first 3GPP network (or the first RAN node) and the second 3GPP network (or the second RAN node) is connected to an eAMF. The eAMF may be further connected to UDM / AUSF and SMF. The user plane data of the UE from the first 3GPP network and the second 3GPP network may be aggregated in UPF.

[0156] Since there is only one AMF in Embodiment II, the SEAF associated with the AMF and the UE may derive only one AMF key (e.g., denoted as KAMF) for the AMF. KAMF may be derived based on the root key. For example, according to the schemes as described with respect to Figure 2, KAUSF may be derived based on the root key (e.g., the key "K" in Figure 2) , KSEAF may be derived based on KAUSF, and KAMF may be derived based on KSEAF.

[0157] In Embodiment II, the aforementioned network node in the core network that performs both the first key deriving procedure for deriving the first key (s) and the second key deriving procedure for deriving the second key (s) may be the AMF.

[0158] Embodiment II may further include Embodiment II-1, Embodiment II-2, Embodiment II-3, and Embodiment II-4.

[0159] Embodiment II-1

[0160] In Embodiment II-1, the first key (s) may include a first RAN key (denoted as KRAN1) for the first RAN node. KRAN1 may be derived by the AMF and the UE based on KAMF and a first access type indicator associated with the first 3GPP network.

[0161] The second key (s) may include a second RAN key (denoted as KRAN2) for the second RAN node. KRAN2 may be derived by the AMF and the UE based on KAMF (i.e., the same AMF key as that used for deriving KRAN1) and a second access type indicator associated with the second 3GPP network.

[0162] As an example for Embodiment II-1, to derive an RAN key (e.g., KRAN1 or KRAN2) , the following parameters may be used to form a string S to be input to a KDF (e.g., the KDF as specified in TS 33.220) :

[0163] - FC = 0x6E,

[0164] - P0 = uplink NAS COUNT,

[0165] - L0 = length of uplink NAS COUNT,

[0166] - P1 = access type indicator, and

[0167] - L1 = length of access type indicator.

[0168] The following Table 2 illustrates exemplary access type indicators. For example, the access type indicators for the first 3GPP network, non-3GPP network, and the second 3GPP network may be 0x01, 0x02, and 0x03, respectively.

[0169] Table 2

[0170] Then, the RAN key may be derived based on the string S and KAMF according to the KDF, e.g., according to aforementioned equation (1) in which KEY is KAMF.

[0171] For example, to derive KRAN1, FC = 0x6E, P0 = uplink NAS COUNT, L0 = length of uplink NAS COUNT, P1 = 0x01, L1 = 0x00 0x01 may be used to form the string S, and KRAN1 = HMAC-SHA-256 (KAMF, S) .

[0172] Embodiment II-2

[0173] In Embodiment II-2, the first key (s) may include a first NH parameter (denoted as NH1) for the first RAN node. NH1 may be derived by the AMF and the UE based on KAMF and a first access type indicator associated with the first 3GPP network.

[0174] The second key (s) may include a second NH parameter (denoted as NH2) for the second RAN node. NH2 may be derived by the AMF and the UE based on KAMF (i.e., the same AMF key as that used for deriving NH1) and a second access type indicator associated with the second 3GPP network.

[0175] As an example for Embodiment II-1, to derive an NH parameter (e.g., NH1 or NH2) , the following parameters may be used to form a string S to be input to a KDF (e.g., the KDF as specified in TS 33.220) :

[0176] - FC = 0x6F,

[0177] - P0 = SYNC-input,

[0178] - L0 = length of SYNC-input,

[0179] - P1 = access type indicator, and

[0180] - L1 = length of access type indicator.

[0181] As an example, the access type indicators for the first 3GPP network and the second 3GPP network may be 0x01 and 0x02, respectively.

[0182] Then, the NH parameter may be derived based on the string S and KAMF according to the KDF, e.g., according to aforementioned equation (1) in which KEY is KAMF.

[0183] For example, to derive NH1, FC = 0x6F, P0 = SYNC-input, L0 = length of SYNC-input, P1 = 0x01, L1 = 0x00 0x01 may be used to form the string S, and NH1 = HMAC-SHA-256 (KAMF, S) .

[0184] Embodiment II-3

[0185] In Embodiment II-3, the first key (s) may include a first RAN key (denoted as KRAN1) for the first RAN node, and the second key (s) may include a second RAN key (denoted as KRAN2) for the second RAN node.

[0186] At the AMF side, the AMF may derive a common RAN key (denoted as KRAN*) based on KAMF. For example, KRAN*may be derived based on KAMF according to the schemes as described with respect to Figure 2. Then, based on KRAN*and additional input values (e.g.,  counter values) associated with the first 3GPP network and the second 3GPP network respectively, KRAN1 and KRAN2 may be derived. The additional input values may be generated or determined by the AMF.

[0187] In some cases of Embodiment II-3, KRAN1 and KRAN2 may be derived by the AMF.

[0188] In such cases, the first key deriving procedure performed by the AMF may include deriving KRAN1 based on KRAN*and a first counter value associated with the first 3GPP network. The second key deriving procedure performed by the AMF may include deriving KRAN2 based on KRAN*and a second counter value associated with the second 3GPP network.

[0189] In some cases of Embodiment II-3, KRAN1 may be derived by the first RAN node and KRAN2 may be derived by the second RAN node.

[0190] In such cases, the first key deriving procedure performed by the AMF may include transmitting KRAN*and the first counter value associated with the first 3GPP network to the first RAN node. In response to receiving KRAN*and the first counter value, the first RAN node may derive KRAN1 based on KRAN*and the first counter value. The second key deriving procedure performed by the AMF may include transmitting KRAN*and the second counter value associated with the second 3GPP network to the second RAN node. In response to receiving KRAN*and the second counter value, the second RAN node may derive KRAN2 based on KRAN*and the second counter value.

[0191] At the UE side, the UE may also derive KRAN*based on KAMF, as the AMF does. Then, the UE may derive KRAN1 based on KRAN*and the first counter value associated with the first 3GPP network, and derive KRAN2 based on KRAN*and the second counter value associated with the second 3GPP network. At the UE side, the first counter value and the second counter value may be generated or determined by the UE, which has the same values as those generated or determined by the AMF.

[0192] As an example for Embodiment II-3, to derive an RAN key (e.g., KRAN1 or KRAN2) , the following parameters may be used to form a string S to be input to a KDF (e.g., the KDF as specified in TS 33.220) :

[0193] - FC = 0x79,

[0194] - P0 = a counter value as a non-negative integer,

[0195] - L0 = length of the counter value,

[0196] Then, the RAN key may be derived based on the string S and KRAN*according to the KDF, e.g., according to aforementioned equation (1) in which KEY is KRAN*.

[0197] Embodiment II-4

[0198] In Embodiment II-4, the first key (s) may include a first NH parameter (denoted as NH1) for the first RAN node, and the second key (s) may include a second NH parameter (denoted as NH2) for the second RAN node.

[0199] At the AMF side, the AMF may derive a common NH parameter (denoted as NH*) based on KAMF. For example, NH*may be derived based on KAMF according to the schemes as described with respect to Figure 2. Then, based on NH*and additional input values (e.g., counter values) associated with the first 3GPP network and the second 3GPP network respectively, NH1 and NH2 may be derived. The additional input values may be generated or determined by the AMF.

[0200] In some cases of Embodiment II-4, NH1 and NH2 may be derived by the AMF.

[0201] In such cases, the first key deriving procedure performed by the AMF may include deriving NH1 based on NH*and a first counter value associated with the first 3GPP network. The second key deriving procedure performed by the AMF may include deriving NH2 based on NH*and a second counter value associated with the second 3GPP network.

[0202] In some cases of Embodiment II-4, NH1 may be derived by the first RAN node and NH2 may be derived by the second RAN node.

[0203] In such cases, the first key deriving procedure performed by the AMF may include transmitting NH*and the first counter value associated with the first 3GPP networto the first RAN node. In response to receiving NH*and the first counter value, the first RAN node may derive NH1 based on NH*and the first counter value. The second key deriving procedure performed by the AMF may include transmitting NH*and the second counter value associated with the second 3GPP network to the second RAN node. In response to receiving NH*and the  second counter value, the second RAN node may derive NH2 based on NH*and the second counter value.

[0204] At the UE side, the UE may also derive NH*based on KAMF, as the AMF does. Then, the UE may derive NH1 based on NH*and the first counter value associated with the first 3GPP network, and derive NH2 based on NH*and the second counter value associated with the second 3GPP network. At the UE side, the first counter value and the second counter value may be generated or determined by the UE, which has the same values as those generated or determined by the AMF.

[0205] Embodiment II-1 and Embodiment II-2 may be implemented independently or in combination. Embodiment II-3 and Embodiment II-4 may be implemented independently or in combination.

[0206] The derived KRAN1 and NH1 in Embodiment II may be used to determine keys for access stratum operation in the first 3GPP network, e.g., for encryption / decryption and integration protection / integration checking for UP and CP data transmission between the first RAN node and the UE (such as KRRCint, KRRCenc, KUPint and KUPenc) . The derived KRAN2 and NH2 in Embodiment II may be used to determine keys for access stratum operation in the second 3GPP network, e.g., for encryption / decryption and integration protection / integration checking for UP and CP data transmission between the second RAN node and the UE (such as KRRCint, KRRCenc, KUPint and KUPenc) .

[0207] In some cases of the present disclosure, during or after an access procedure, the first RAN node associated with the first 3GPP network or the second RAN node associated with the second 3GPP network may be informed by the associated AMF with information related to whether it serves the UE or a protocol data unit (PDU) session (e.g., multi-access PDU Session) of the UE as the primary or secondary stack / access / path. If the RAN node is the secondary stack / access / path, then the RAN node may serve the UE with relaxed radio configurations. In the embodiments of the present disclosure, a RAN node being or serving as a primary (or a secondary) stack, access, or path may mean that a 3GPP network associated with the RAN node is a primary (or a secondary) stack, access, or path, and also means that an access via the 3GPP  network to the core network is a primary (or a secondary) access. These expressions may be interchangeable.

[0208] According to some embodiments of the present disclosure, the AMF may determine whether the first 3GPP network is a primary path or a secondary path for the UE to access the core network based on at least one of:

[0209] · whether the first access procedure is performed before or after the second access procedure;

[0210] - for example, if the first access procedure is performed before the second access procedure, then the first 3GPP network is determined as the primary path; if the first access procedure is performed after the second access procedure, then the first 3GPP network is determined as the secondary path;

[0211] - this condition also means that if the UE transmits an access request via the first 3GPP network and the UE has not been registered to the core network before, then the first 3GPP network is considered as a primary path, and if the UE transmits an access request via the first 3GPP network and the UE has been registered to the core network before, then the first 3GPP network is considered as a secondary path;

[0212] · an indication included in an access request associated with the first access procedure;

[0213] - for example, the indication may indicate whether the first 3GPP network is a primary path or a secondary path;

[0214] · a traffic steering rule configured by a PCF;

[0215] · an indication provided by the PCF or a peer AMF (e.g., an AMF associated with the second 3GPP network) ;

[0216] - for example, the indication may indicate whether the first 3GPP network is a primary path or a secondary path; or

[0217] · subscription information of the UE stored in a UDM.

[0218] According to some embodiments of the present disclosure, after the AMF determines whether the first 3GPP network is a primary path or a secondary path for the UE to access the core network (e.g., based on any of the aforementioned methods or other methods) , the AMF  may transmit, to the first RAN node associated with the first 3GPP network, information indicating that the first 3GPP network is the primary path or the secondary path. The information may include at least one of:

[0219] · an indicator indicating that the first 3GPP network is the primary path or the secondary path; or

[0220] · information related to a traffic steering rule between the primary path and the secondary path.

[0221] As an example, the content of a traffic steering rule between the primary or secondary may be as follows:

[0222] · "Traffic Descriptor: user datagram protocol (UDP) , DestAddr 1.2.3.4" , "Steering Mode: Active-Standby, Active= 6G, Standby= 5G" .

[0223] In such example, the traffic steering rule means: steering UDP traffic with destination IP address 1.2.3.4 to the active access (6G) , if available; if the active access is not available, using the standby access (5G) . "

[0224] Based on the traffic steering rule, the 6G RAN is considered as the primary path while the 5G RAN is considered as the secondary path, which will be used only if the primary path does not work. For the sake of energy saving, the 5G RAN may adopt relaxed radio configurations, e.g., configuring the UE with relaxed RRM measurement, or serving the UE with a cell of NES mode, etc.

[0225] The schemes for determining whether the first 3GPP network is a primary path or a secondary path may also apply for determining whether the second 3GPP network is a primary path or a secondary path. Thus, details are omitted for simplicity.

[0226] In addition, after the AMF determines whether the second 3GPP network is a primary path or a secondary path for the UE to access the core network (e.g., based on any of the aforementioned methods or other methods) , the AMF may also transmit, to the second RAN node associated with the second 3GPP network, information indicating that the second 3GPP network is a primary path or a secondary path. The information may include at least one of:

[0227] · an indicator indicating that the second 3GPP network is the primary path or the secondary path; or

[0228] · information related to a traffic steering rule between the primary path and the secondary path.

[0229] Figure 6 illustrates yet another exemplary dual-access scenario in accordance with aspects of the present disclosure.

[0230] The connections illustrated in Figure 6 are the same as those in Figure 4B. In the example of Figure 6, the second 3GPP network (e.g., 6G RAN) may be a primary path, and the first 3GPP network (e.g., 5G RAN) may be a secondary path. The first AMF may transmit an indication indicating that the first 3GPP network is a secondary path to the first 3GPP network such that it may adopt relaxed radio configurations.

[0231] It is contemplated that any of the aforementioned methods for determining or indicating the primary path or the secondary path may be implemented separately from or in combination with any the aforementioned methods for generating security key (s) for different accesses.

[0232] Persons skilled in the art should understand that as the 3GPP and electronic technology develop, the terminologies recited in the specification may change, which should not affect the principle of the disclosure. As the 3GPP and electronic technology develop, the network functions providing the same functionality / service may be named differently.

[0233] For example, "UDM" in the present disclosure may be changed to another terminology which supports at least one of the following functionalities:

[0234] - Generation of 3GPP AKA authentication credentials;

[0235] - User identification handling (e.g., storage and management of subscription permanent identifier (SUPI) for each subscriber in the 5G system) ;

[0236] - Support of de-concealment of privacy-protected subscription identifier (SUCI) ;

[0237] - Access authorization based on subscription data (e.g., roaming restrictions) ;

[0238] - UE's serving NF registration management (e.g., storing serving AMF for UE, storing serving SMF for UE's PDU session) ;

[0239] - Support to service / session continuity e.g. by keeping SMF / data network name (DNN) assignment of ongoing sessions;

[0240] - Mobile terminated short message service (MT-SMS) delivery support;

[0241] - Lawful intercept functionality (especially in outbound roaming case where UDM is the only point of contact for lawful intercept (LI) ) ;

[0242] - Subscription management;

[0243] - Short message service (SMS) management;

[0244] - 5G-virtual network (VN) group management handling;

[0245] - Support of external parameter provisioning (expected UE Behaviour parameters or network configuration parameters) ;

[0246] - Support for the disaster roaming; or

[0247] - Support for the control of time synchronization service based on subscription data;

[0248] "AUSF" may be changed to another terminology which supports at least one of the following functionalities:

[0249] - authentication for 3GPP access and untrusted non-3GPP access; or

[0250] - authentication of UE for a disaster roaming service.

[0251] "AMF" may be changed to another terminology which supports at least one of the following functionalities:

[0252] - Registration management;

[0253] - Connection management;

[0254] - Reachability management;

[0255] - Mobility Management; or

[0256] - UE mobility event notification.

[0257] "UPF" may be changed to another terminology which supports at least one of the following functionalities:

[0258] - Anchor point for Intra- / Inter-RAT mobility (when applicable) ;

[0259] - Allocation of UE IP address / prefix (if supported) in response to SMF request;

[0260] - External PDU session point of interconnect to data network;

[0261] - Packet routing &forwarding (e.g. support of uplink classifier to route traffic flows to an instance of a data network, support of branching point to support multi-homed PDU session, support of traffic forwarding within a 5G VN group (UPF local switching, via N6, via N19) ) ;

[0262] - Packet inspection (e.g. application detection based on service data flow template and the optional packet flow descriptions (PFDs) received from the SMF in addition) ; or

[0263] - Downlink packet buffering and downlink data notification triggering.

[0264] "RAN" may be changed to another terminology which supports at least one of the following functions.

[0265] - Functions for radio resource management: radio bearer control, radio admission control, connection mobility control, dynamic allocation of resources to UEs in both uplink and downlink (scheduling) ;

[0266] - IP and Ethernet header compression, uplink data decompression, encryption and integrity protection of data;

[0267] - Connection setup and release;

[0268] - Scheduling and transmission of paging messages;

[0269] - Scheduling and transmission of system broadcast information (originated from the AMF or operation administration and maintenance (OAM) ;

[0270] - Measurement and measurement reporting configuration for mobility and scheduling; or

[0271] - Computing service.

[0272] Figure 7 illustrates a flowchart of an exemplary method for establishing 5G and 6G dual-access in accordance with aspects of the present disclosure.

[0273] In the example of Figure 7, a UE may perform a first access procedure for access of the UE to a CN via a first 3GPP network, wherein the first 3GPP network may be a 6G RAN including a 6G RAN node (not shown in Figure 7) . The UE may further perform a second access procedure for access of the UE to the CN via a second 3GPP network, wherein the second 3GPP network may be a 5G RAN including a 5G RAN node (not shown in Figure 7) . The first or second access procedure may be a registration procedure.

[0274] In the example of Figure 7, the 6G RAN may be connected to a 6G AMF associated with a SEAF, and the 5G RAN may be connected to a 5G AMF associated with a SEAF.

[0275] In step 701, after the random access to the 6G RAN, the UE may initiate a first registration procedure to register to CN via the 6G RAN by sending a registration request message (which is a NAS message) to the 6G AMF.

[0276] In response to receiving the registration request message, in step 702, the 6G AMF may send an authentication request (e.g., Nausf_UEAuthentication_Authenticate Request message as specified in TS 33.501) to an AUSF, wherein the authentication request may include a subscriber identity (e.g., SUCI or SUPI) and a service network name (SN-name) .

[0277] In response to receiving the registration request message, in step 703, the AUSF may transmit, to a UDM, an authentication data request (e.g., Nudm_UEAuthentication_Get Request as specified in TS 33.501) message to request authentication data from the UDM using the subscriber identity and service network name. The authentication data request message may include the subscriber identity and the service network name.

[0278] In response to receiving the authentication data request, in step 704, the UDM may generate authentication vector (AV) . Then, in step 705, the UDM may transmit, to the AUSF, an authentication data response (e.g., Nudm_UEAuthentication_Get Response as specified in TS 33.501) . The authentication data response may include the AV, SUPI (if available) , an authentication and key management for applications (AKMA) indication, and a routing indicator.

[0279] In step 706, the AUSF may store XRES*value and calculate HXRES*as specified in TS 33.501. In addition, the AUSF may derive KSEAF1 for the SEAF associated with the 6G AMF.

[0280] In step 707, the AUSF may transmit an authentication response (e.g., Nausf_UEAuthentication_UEAuthentication Response as specified in TS 33.501) message to the 6G AMF. The authentication response message may include serving environment authentication vector (SE AV) as specified in TS 33.501.

[0281] In step 708, the 6G AMF (or the SEAF associated with the 6G AMF) may send, to the UE, an authentication request message which at least includes a random number RAND and AUthentication TokeN (AUTN) as specified in TS 33.501.

[0282] In response to receiving the authentication request, in step 709, the UE may calculate its own RES*value based on the received authentication parameters in the authentication request message. Then, in step 710, the UE may send an authentication response message including its calculated RES*value back to the 6G AMF (or the SEAF associated with the 6G AMF) .

[0283] In step 711, the 6G AMF (or the SEAF associated with the 6G AMF) may calculates HRES*value and compares it to the previously stored HXRES*value. If they coincide, the 6G AMF (or the SEAF associated with the 6G AMF) may consider the authentication successful from the serving network point of view. Then, in step 712, the 6G AMF (or the SEAF associated with the 6G AMF) may send another authentication request to the AUSF, which includes the RES*value received from the UE.

[0284] In response to receiving the another authentication request, in step 713, the AUSF may verify RES*value. Then, in step 714, the AUSF may transmit, to the 6G AMF (or the SEAF associated with the 6G AMF) , an authentication response message, which includes the verification result, SUPI (if available) , and the shared security key (KSEAF1) .

[0285] Based on the received KSEAF1, in step 715, the 6G AMF may derive KRAN1 and NH1 for the 6G RAN, e.g., based on the schemes described in Embodiment I.

[0286] In step 716, the 6G AMF may send KRAN1 and NH1 to the 6G RAN (or 6G RAN node) via a UE context setup message.

[0287] In step 717, the 6G AMF may send a registration accept message to the UE, which implies that the first registration procedure is fulfilled.

[0288] When the UE decides to access to the CN via a 5G network, the UE may perform random access and connect to the 5G RAN. In step 718, the UE may initiate a second registration procedure to register to CN via the 5G RAN by sending a registration request message (which is an NAS message) to the 5G AMF. As an example, the registration request message may include an indication indicating that the 5G RAN is the secondary path.

[0289] The following step 719 for registering the UE to the CN may include steps similar to steps 702 to 714. Thus, details are omitted for simplicity. The difference is that the AUSF may derive KSEAF2 for the SEAF associated with the 5G AMF and transmit KSEAF2 to the 5G AMF (or the SEAF associated with the 5G AMF) .

[0290] Based on the received KSEAF2, in step 732, the 5G AMF may derive KRAN2 and NH2 for the 5G RAN, e.g., based on the schemes described in Embodiment I.

[0291] In step 733, the 5G AMF may send KRAN1 and NH1 to the 5G RAN (or 5G RAN node) via a UE context setup message. In an embodiment, the UE context setup message may further include an indication indicating that the 5G RAN is served as a secondary path. As such, the 5G RAN may serve the UE with relaxed radio configurations.

[0292] In step 734, the 5G AMF may send a registration accept message to the UE, which implies that the second registration procedure is fulfilled.

[0293] Figure 8 illustrates a flowchart of an exemplary method in accordance with aspects of the present disclosure. The operations of the method illustrated in Figure 8 may be performed by a network node in a core network as described herein or other apparatus with the like functions. In some implementations, the network node may execute a set of instructions to control functional elements of the network node to perform the described operations or functions.

[0294] As shown in Figure 8, the method may include steps 802-808.

[0295] At step 802, the network node may perform a first access procedure with a UE for access of the UE to the core network via a first 3GPP network.

[0296] At step 804, the network node may perform a first key deriving procedure for deriving first key (s) for access stratum operation in the first 3GPP network based on a root key.

[0297] At step 806, the network node may perform a second access procedure with the UE for access of the UE to the core network via a second 3GPP network.

[0298] At step 808, the network node may perform a second key deriving procedure for deriving second key (s) for access stratum operation in the second 3GPP network based on the root key. The second key (s) is independent of the first key (s) .

[0299] According to some embodiments of the present disclosure, the network node may be an AUSF, the first key (s) may include a first SEAF key for a first SEAF associated with the first 3GPP network, and the second key (s) may include a second SEAF key for a second SEAF associated with the second 3GPP network. The first key deriving procedure may include deriving the first SEAF key based on an AUSF key and a first access type indicator associated with the first 3GPP network, wherein the AUSF key is based on the root key, and the second key deriving procedure may include deriving the second SEAF key based on the AUSF key and a second access type indicator associated with the second 3GPP network.

[0300] According to some embodiments of the present disclosure, the network node may be an SEAF, the first key (s) may include a first AMF key for a first AMF associated with the first 3GPP network, and the second key (s) may include a second AMF key for a second AMF associated with the second 3GPP network, and wherein: the first key deriving procedure may include deriving the first AMF key based on an SEAF key and a first access type indicator associated with the first 3GPP network, wherein the SEAF key is based on the root key; and the second key deriving procedure may include deriving the second AMF key based on the SEAF key and a second access type indicator associated with the second 3GPP network.

[0301] According to some embodiments of the present disclosure, the network node may be an AMF, the first key (s) may include a first RAN key for a first RAN node associated with the first 3GPP network, and the second key (s) may include a second RAN key for a second RAN node associated with the second 3GPP network. The first key deriving procedure may include  deriving the first RAN key based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; and the second key deriving procedure may include deriving the second RAN key based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0302] According to some embodiments of the present disclosure, the network node may be an AMF, the first key (s) may include a first NH parameter for a first RAN node associated with the first 3GPP network, and the second key (s) may include a second NH parameter for a second RAN node associated with the second 3GPP network. The the first key deriving procedure may include deriving the first NH parameter based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the the AMF key is based on the root key; and the second key deriving procedure may include deriving the second NH parameter based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0303] According to some embodiments of the present disclosure, the network node may be an AMF, the first key (s) may include a first RAN key for a first RAN node associated with the first 3GPP network, and the second key (s) may include a second RAN key for a second RAN node associated with the second 3GPP network. In such embodiments, the network node may derive a common RAN key based on an AMF key which is based on the root key; the first key deriving procedure may include deriving the first RAN key based on the common RAN key and a first counter value associated with the first 3GPP network; and the second key deriving procedure may include deriving the second RAN key based on the common RAN key and a second counter value associated with the second 3GPP network.

[0304] According to some embodiments of the present disclosure, the network node may be an AMF, the first key (s) may include a first NH parameter for a first RAN node associated with the first 3GPP network, and the second key (s) may include a second NH parameter for a second RAN node associated with the second 3GPP network. In such embodiments, the network node may derive a common NH parameter based on an AMF key which is based on the root key; the first key deriving procedure may include deriving the first NH parameter based on the common NH parameter and a first counter value associated with the first 3GPP network; and the second key deriving procedure may include deriving the second NH parameter based on the common NH parameter and a second counter value associated with the second 3GPP network.

[0305] According to some embodiments of the present disclosure, the network node may be an AMF, the first key (s) may include a first RAN key for a first RAN node associated with the first 3GPP network, and the second key (s) may include a second RAN key for a second RAN node associated with the second 3GPP network. In such embodiments, the network node may derive a common RAN key based on an AMF key which is based on the root key; the first key deriving procedure may include transmitting the common RAN key and a first counter value associated with the first 3GPP network to a first RAN node associated with the first 3GPP network for the first RAN node to derive the first RAN key; and the second key deriving procedure may include transmitting the common RAN key and a second counter value associated with the second 3GPP network to a second RAN node associated with the second 3GPP network for the second RAN node to derive the second RAN key.

[0306] According to some embodiments of the present disclosure, the network node may be an AMF, the first key (s) may include a first NH parameter for a first RAN node associated with the first 3GPP network, and the second key (s) may include a second NH parameter for a second RAN node associated with the second 3GPP network. In such embodiments, the network node may derive a common NH parameter based on an AMF key which is based on the root key; the first key deriving procedure comprises transmitting the common NH parameter and a first counter value associated with the first 3GPP network to a first RAN node associated with the first 3GPP network for the first RAN node to derive the first NH parameter; and the second key deriving procedure comprises transmitting the common NH parameter and a second counter value associated with the second 3GPP network to a second RAN node associated with the second 3GPP network for the second RAN node to derive the second NH parameter.

[0307] According to some embodiments of the present disclosure, the network node may be an AMF, and the network node may determine whether the first 3GPP network is a primary path or a secondary path for the UE to access the core network based on at least one of: whether the first access procedure is performed before or after the second access procedure; an indication included in an access request associated with the first access procedure; a traffic steering rule configured by a PCF; an indication provided by the PCF or a peer AMF; or subscription information of the UE stored in a UDM.

[0308] According to some embodiments of the present disclosure, the network node may be an AMF, and the network node may: transmit, to a RAN node associated with the first 3GPP network, information indicating that the first 3GPP network is a primary path or a secondary path for the UE to access the core network, wherein the information includes at least one of: an indicator indicating that the first 3GPP network is the primary path or the secondary path; or information related to a traffic steering rule between the primary path and the secondary path.

[0309] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be arranged or otherwise modified and that other implementations are possible.

[0310] Figure 9 illustrates a flowchart of an exemplary method in accordance with aspects of the present disclosure. The operations of the method illustrated in Figure 2 may be performed by a UE (e.g., UE 104 in Figure 1) as described herein or other apparatus with the like functions. In some implementations, the UE may execute a set of instructions to control functional elements of the UE to perform the described operations or functions.

[0311] At step 902, the UE may perform a first access procedure for access to a core network via a first 3GPP network.

[0312] At step 904, the UE may derive first key (s) for access stratum operation in the first 3GPP network based on a root key.

[0313] At step 906, the UE may perform a second access procedure for access to the core network via a second 3GPP network

[0314] At step 908, the UE may derive second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0315] According to some embodiments of the present disclosure, the first key (s) may include a first SEAF key for a first SEAF associated with the first 3GPP network derived based on an AUSF key and a first access type indicator associated with the first 3GPP network, wherein the AUSF key is based on the root key; and the second key (s) may include a second  SEAF key for a second SEAF associated with the second 3GPP network derived based on the AUSF key and a second access type indicator associated with the second 3GPP network.

[0316] According to some embodiments of the present disclosure, the first key (s) may include a first AMF key for a first AMF associated with the first 3GPP network derived based on an SEAF key and a first access type indicator associated with the first 3GPP network, wherein the SEAF key is based on the root key; and the second key (s) may include a second AMF key for a second AMF associated with the second 3GPP network derived based on the SEAF key and a second access type indicator associated with the second 3GPP network.

[0317] According to some embodiments of the present disclosure, the first key (s) may include a first RAN key for a first RAN node associated with the first 3GPP network derived based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; and the second key (s) may include a second RAN key for a second RAN node associated with the second 3GPP network derived based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0318] According to some embodiments of the present disclosure, the first key (s) may include a first NH parameter for a first RAN node associated with the first 3GPP network derived based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; and the second key (s) may include a second NH parameter for a second RAN node associated with the second 3GPP network derived based on the AMF key and a second access type indicator associated with the second 3GPP network.

[0319] According to some embodiments of the present disclosure, the UE may derive a common RAN key based on an AMF key which is based on the root key; the first key (s) may include a first RAN key for a first RAN node associated with the first 3GPP network derived based on the common RAN key and a first counter value associated with the first 3GPP network; and the second key (s) may include a second RAN key for a second RAN node associated with the second 3GPP network derived based on the common RAN key and a second counter value associated with the second 3GPP network.

[0320] According to some embodiments of the present disclosure, the UE may derive a common NH parameter based on an AMF key which is based on the root key; the first key (s) may include a first NH parameter for a first RAN node associated with the first 3GPP network derived based on the common NH parameter and a first counter value associated with the first 3GPP network; and the second key (s) may include a second NH parameter for a second RAN node associated with the second 3GPP network based on the common NH parameter and a second counter value associated with the second 3GPP network.

[0321] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be arranged or otherwise modified and that other implementations are possible.

[0322] Figure 10 illustrates an example of a network node 1000 in a core network in accordance with aspects of the present disclosure. The network node 1000 may include at least one processor 1002 and at least one memory 1004. Additionally, the network node 1000 may also include one or more of at least one controller 1006 or at least one transceiver 1008. The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0323] The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations or components thereof may be implemented in hardware (e.g., circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0324] The processor 1002 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof) . In some implementations, the processor 1002 may be configured to operate the memory 1004. In some other implementations, the memory 1004 may be integrated into the processor 1002. The  processor 1002 may be configured to execute computer-readable instructions stored in the memory 1004 to cause the network node 1000 to perform various functions of the present disclosure.

[0325] The memory 1004 may include volatile or non-volatile memory. The memory 1004 may store computer-readable, computer-executable code including instructions when executed by the processor 1002 cause the network node 1000 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 1004 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0326] In some implementations, the processor 1002 and the memory 1004 coupled with the processor 1002 may be configured to cause the network node 1000 to perform one or more of the functions described herein (e.g., executing, by the processor 1002, instructions stored in the memory 1004) . For example, the processor 1002 may support wireless communication at the network node 1000 in accordance with examples as disclosed herein. The network node 1000 may be configured to support a means for performing the operations of the methods described in the embodiments of the present disclosure. In an embodiment, the processor 1002 may be configured to cause the network node 1000 to: perform a first access procedure with a UE for access of the UE to the core network via a first 3GPP network; perform a first key deriving procedure for deriving first key (s) for access stratum operation in the first 3GPP network based on a root key; perform a second access procedure with the UE for access of the UE to the core network via a second 3GPP network; and perform a second key deriving procedure for deriving second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0327] The controller 1006 may manage input and output signals for the network node 1000. The controller 1006 may also manage peripherals not integrated into the network node 1000. In some implementations, the controller 1006 may utilize an operating system such as or other operating systems. In some implementations, the controller 1006 may be implemented as part of the processor 1002.

[0328] In some implementations, the network node 1000 may include at least one transceiver 1008. In some other implementations, the network node 1000 may have more than one transceiver 1008. The transceiver 1008 may represent a wireless transceiver. The transceiver 1008 may include one or more receiver chains 1010, one or more transmitter chains 1012, or a combination thereof.

[0329] A receiver chain 1010 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1010 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 1010 may include at least one amplifier (e.g., a low-noise amplifier (LNA) ) configured to amplify the received signal. The receiver chain 1010 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1010 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0330] A transmitter chain 1012 may be configured to generate and transmit signals (e.g., control information, data, packets) . The transmitter chain 1012 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmitter chain 1012 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1012 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0331] Figure 11 illustrates an example of a UE 1100 in accordance with aspects of the present disclosure. The UE 1100 may include at least one processor 1102 and at least one memory 1104. Additionally, the UE 1100 may also include one or more of at least one controller 1106 or at least one transceiver 1108. The processor 1102, the memory 1104, the controller  1106, or the transceiver 1108, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.

[0332] The processor 1102, the memory 1104, the controller 1106, or the transceiver 1108, or various combinations or components thereof may be implemented in hardware (e.g., circuitry) . The hardware may include a processor, a digital signal processor (DSP) , an application-specific integrated circuit (ASIC) , or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.

[0333] The processor 1102 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof) . In some implementations, the processor 1102 may be configured to operate the memory 1104. In some other implementations, the memory 1104 may be integrated into the processor 1102. The processor 1102 may be configured to execute computer-readable instructions stored in the memory 1104 to cause the UE 1100 to perform various functions of the present disclosure.

[0334] The memory 1104 may include volatile or non-volatile memory. The memory 1104 may store computer-readable, computer-executable code including instructions when executed by the processor 1102 cause the UE 1100 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 1104 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.

[0335] In some implementations, the processor 1102 and the memory 1104 coupled with the processor 1102 may be configured to cause the UE 1100 to perform one or more of the functions described herein (e.g., executing, by the processor 1002, instructions stored in the memory 1104) . For example, the processor 1102 may support wireless communication at the UE 1100 in accordance with examples as disclosed herein. The UE 1100 may be configured to  support a means for performing the operations of the methods described in the embodiments of the present disclosure. In an embodiment, the processor 1102 may be configured to cause the UE 1100 to: perform a first access procedure for access to a core network via a first 3GPP network; derive first key (s) for access stratum operation in the first 3GPP network based on a root key; perform a second access procedure for access to the core network via a second 3GPP network; and derive second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0336] The controller 1106 may manage input and output signals for the UE 1100. The controller 1106 may also manage peripherals not integrated into the UE 1100. In some implementations, the controller 1106 may utilize an operating system such as  or other operating systems. In some implementations, the controller 1106 may be implemented as part of the processor 1102.

[0337] In some implementations, the UE 1100 may include at least one transceiver 1108. In some other implementations, the UE 1100 may have more than one transceiver 1108. The transceiver 1108 may represent a wireless transceiver. The transceiver 1108 may include one or more receiver chains 1110, one or more transmitter chains 1112, or a combination thereof.

[0338] A receiver chain 1110 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1110 may include one or more antennas for receive the signal over the air or wireless medium. The receiver chain 1110 may include at least one amplifier (e.g., a low-noise amplifier (LNA) ) configured to amplify the received signal. The receiver chain 1110 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1110 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.

[0339] A transmitter chain 1112 may be configured to generate and transmit signals (e.g., control information, data, packets) . The transmitter chain 1112 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM) , frequency modulation (FM) , or digital  modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM) . The transmitter chain1112 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1112 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.

[0340] Figure 12 illustrates an example of a processor 1200 in accordance with aspects of the present disclosure. The processor 1200 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 1200 may include at least one controller 1202 configured to perform various operations in accordance with examples as described herein. The processor 1200 may optionally include at least one memory 1204, which may be, for example, a layer 1 (L1) , layer 2 (L2) , or layer 3 (L3) cache. Additionally, or alternatively, the processor 1200 may optionally include one or more arithmetic-logic units (ALUs) 1206. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses) .

[0341] The processor 1200 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 1200) or other memory (e.g., random access memory (RAM) , read-only memory (ROM) , dynamic RAM (DRAM) , synchronous dynamic RAM (SDRAM) , static RAM (SRAM) , ferroelectric RAM (FeRAM) , magnetic RAM (MRAM) , resistive RAM (RRAM) , flash memory, phase change memory (PCM) , and others) .

[0342] The controller 1202 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 1200 to cause the processor 1200 to support various operations in accordance with examples as described herein. For example, the controller 1202 may operate as a control unit of the processor 1200, generating control signals that manage the operation of various components of the processor 1200. These  control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.

[0343] The controller 1202 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 1204 and determine subsequent instruction (s) to be executed to cause the processor 1200 to support various operations in accordance with examples as described herein. The controller 1202 may be configured to track memory address of instructions associated with the memory 1204. The controller 1202 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 1202 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 1200 to cause the processor 1200 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 1202 may be configured to manage flow of data within the processor 1200. The controller 1202 may be configured to control transfer of data between registers, ALUs, and other functional units of the processor 1200.

[0344] The memory 1204 may include one or more caches (e.g., memory local to or included in the processor 1200 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. ) . In some implementations, the memory 1204 may reside within or on a processor chipset (e.g., local to the processor 1200) . In some other implementations, the memory 1204 may reside external to the processor chipset (e.g., remote to the processor 1200) .

[0345] The memory 1204 may store computer-readable, computer-executable code including instructions that, when executed by the processor 1200, cause the processor 1200 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 1202 and / or the processor 1200 may be configured to execute computer-readable instructions stored in the memory 1204 to cause the processor 1200 to perform various functions. For example, the processor 1200 and / or the controller 1202 may be coupled with or to the memory 1204, the processor 1200, the controller 1202, and the memory 1204 may be configured to perform various functions described herein. In some examples, the processor 1200 may include multiple processors and the memory 1204 may include multiple memories. One or more of the  multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.

[0346] The one or more ALUs 1206 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 1206 may reside within or on a processor chipset (e.g., the processor 1200) . In some other implementations, the one or more ALUs 1206 may reside external to the processor chipset (e.g., the processor 1200) . One or more ALUs 1206 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 1206 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 1206 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 1206 may support logical operations such as AND, OR, exclusive-OR (XOR) , not-OR (NOR) , and not-AND (NAND) , enabling the one or more ALUs 1206 to handle conditional operations, comparisons, and bitwise operations.

[0347] The processor 1200 may support wireless communication in accordance with examples as disclosed herein. The processor 1200 may be configured to or operable to support a means for performing the operations of the methods described in the embodiments of the present disclosure. In an embodiment, the controller 1202 may cause the processor 1200 to: perform a first access procedure for access to a core network via a first 3GPP network; derive first key (s) for access stratum operation in the first 3GPP network based on a root key; perform a second access procedure for access to the core network via a second 3GPP network; and derive second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .

[0348] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.

Claims

1.A network node in a core network, comprising:at least one memory; andat least one processor coupled with the at least one memory and configured to cause the network node to:perform a first access procedure with a user equipment (UE) for access of the UE to the core network via a first 3rd generation partnership project (3GPP) network;perform a first key deriving procedure for deriving first key (s) for access stratum operation in the first 3GPP network based on a root key;perform a second access procedure with the UE for access of the UE to the core network via a second 3GPP network; andperform a second key deriving procedure for deriving second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .2.The network node of Claim 1, wherein the network node is an authentication server function (AUSF) , the first key (s) comprises a first security anchor function (SEAF) key for a first SEAF associated with the first 3GPP network, and the second key (s) comprises a second SEAF key for a second SEAF associated with the second 3GPP network, and wherein:the first key deriving procedure comprises deriving the first SEAF key based on an AUSF key and a first access type indicator associated with the first 3GPP network, wherein the AUSF key is based on the root key; andthe second key deriving procedure comprises deriving the second SEAF key based on the AUSF key and a second access type indicator associated with the second 3GPP network.3.The network node of Claim 1, wherein the network node is an SEAF, the first key (s) comprises a first access and mobility management function (AMF) key for a first AMF associated with the first 3GPP network, and the second key (s) comprises a second AMF key for a second AMF associated with the second 3GPP network, and wherein:the first key deriving procedure comprises deriving the first AMF key based on an SEAF key and a first access type indicator associated with the first 3GPP network, wherein the SEAF key is based on the root key; andthe second key deriving procedure comprises deriving the second AMF key based on the SEAF key and a second access type indicator associated with the second 3GPP network.4.The network node of Claim 1, wherein the network node is an AMF, the first key (s) comprises a first radio access network (RAN) key for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network, and wherein:the first key deriving procedure comprises deriving the first RAN key based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; andthe second key deriving procedure comprises deriving the second RAN key based on the AMF key and a second access type indicator associated with the second 3GPP network.5.The network node of Claim 1, wherein the network node is an AMF, the first key (s) comprises a first next hop (NH) parameter for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network, and wherein:the first key deriving procedure comprises deriving the first NH parameter based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; andthe second key deriving procedure comprises deriving the second NH parameter based on the AMF key and a second access type indicator associated with the second 3GPP network.6.The network node of Claim 1, wherein the network node is an AMF, the first key (s) comprises a first radio access network (RAN) key for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to:derive a common RAN key based on an AMF key which is based on the root key; and wherein:the first key deriving procedure comprises deriving the first RAN key based on the common RAN key and a first counter value associated with the first 3GPP network; andthe second key deriving procedure comprises deriving the second RAN key based on the common RAN key and a second counter value associated with the second 3GPP network.7.The network node of Claim 1, wherein the network node is an AMF, the first key (s) comprises a first next hop (NH) parameter for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to:derive a common NH parameter based on an AMF key which is based on the root key; and wherein:the first key deriving procedure comprises deriving the first NH parameter based on the common NH parameter and a first counter value associated with the first 3GPP network; andthe second key deriving procedure comprises deriving the second NH parameter based on the common NH parameter and a second counter value associated with the second 3GPP network.8.The network node of Claim 1, wherein the network node is an AMF, the first key (s) comprises a first radio access network (RAN) key for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to:derive a common RAN key based on an AMF key which is based on the root key; and wherein:the first key deriving procedure comprises transmitting the common RAN key and a first counter value associated with the first 3GPP network to a first RAN node associated with the first 3GPP network for the first RAN node to derive the first RAN key; andthe second key deriving procedure comprises transmitting the common RAN key and a second counter value associated with the second 3GPP network to a second RAN node associated with the second 3GPP network for the second RAN node to derive the second RAN key.9.The network node of Claim 1, wherein the network node is an AMF, the first key (s) comprises a first next hop (NH) parameter for a first RAN node associated with the first 3GPP network, and the second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network, and the at least one processor is further configured to cause the network node to:derive a common NH parameter based on an AMF key which is based on the root key; and wherein:the first key deriving procedure comprises transmitting the common NH parameter and a first counter value associated with the first 3GPP network to a first RAN node associated with the first 3GPP network for the first RAN node to derive the first NH parameter; andthe second key deriving procedure comprises transmitting the common NH parameter and a second counter value associated with the second 3GPP network to a second RAN node associated with the second 3GPP network for the second RAN node to derive the second NH parameter.10.The network node of Claim 1, wherein the network node is an AMF, and the at least one processor is further configured to cause the network node to determine whether the first 3GPP network is a primary path or a secondary path for the UE to access the core network based on at least one of:whether the first access procedure is performed before or after the second access procedure;an indication included in an access request associated with the first access procedure;a traffic steering rule configured by a policy control function (PCF) ;an indication provided by the PCF or a peer AMF; orsubscription information of the UE stored in a unified data management (UDM) .11.The network node of Claim 1, wherein the network node is an AMF, and the at least one processor is further configured to cause the network node to:transmit, to a RAN node associated with the first 3GPP network, information indicating that the first 3GPP network is a primary path or a secondary path for the UE to access the core network, wherein the information includes at least one of:an indicator indicating that the first 3GPP network is the primary path or the secondary path; orinformation related to a traffic steering rule between the primary path and the secondary path.12.A user equipment (UE) for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and configured to cause the UE to:perform a first access procedure for access to a core network via a first 3rd generation partnership project (3GPP) network;derive first key (s) for access stratum operation in the first 3GPP network based on a root key;perform a second access procedure for access to the core network via a second 3GPP network; andderive second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .13.The UE of Claim 12, wherein:the first key (s) comprises a first security anchor function (SEAF) key for a first SEAF associated with the first 3GPP network derived based on an AUSF key and a first access type indicator associated with the first 3GPP network, wherein the AUSF key is based on the root key; andthe second key (s) comprises a second SEAF key for a second SEAF associated with the second 3GPP network derived based on the AUSF key and a second access type indicator associated with the second 3GPP network.14.The UE of Claim 12, wherein:the first key (s) comprises a first access and mobility management function (AMF) key for a first AMF associated with the first 3GPP network derived based on an SEAF key and a first access type indicator associated with the first 3GPP network, wherein the SEAF key is based on the root key; andthe second key (s) comprises a second AMF key for a second AMF associated with the second 3GPP network derived based on the SEAF key and a second access type indicator associated with the second 3GPP network.15.The UE of Claim 12, wherein:the first key (s) comprises a first radio access network (RAN) key for a first RAN node associated with the first 3GPP network derived based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; andthe second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network derived based on the AMF key and a second access type indicator associated with the second 3GPP network.16.The UE of Claim 12, wherein:the first key (s) comprises a first next hop (NH) parameter for a first RAN node associated with the first 3GPP network derived based on an AMF key and a first access type indicator associated with the first 3GPP network, wherein the AMF key is based on the root key; andthe second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network derived based on the AMF key and a second access type indicator associated with the second 3GPP network.17.The UE of Claim 12, wherein the at least one processor is further configured to cause the UE to:derive a common RAN key based on an AMF key which is based on the root key; and wherein:the first key (s) comprises a first RAN key for a first RAN node associated with the first 3GPP network derived based on the common RAN key and a first counter value associated with the first 3GPP network; andthe second key (s) comprises a second RAN key for a second RAN node associated with the second 3GPP network derived based on the common RAN key and a second counter value associated with the second 3GPP network.18.The UE of Claim 12, wherein the at least one processor is further configured to cause the UE to:derive a common NH parameter based on an AMF key which is based on the root key; and wherein:the first key (s) comprises a first NH parameter for a first RAN node associated with the first 3GPP network derived based on the common NH parameter and a first counter value associated with the first 3GPP network; andthe second key (s) comprises a second NH parameter for a second RAN node associated with the second 3GPP network based on the common NH parameter and a second counter value associated with the second 3GPP network.19.A processor for wireless communication, comprising:at least one controller coupled with at least one memory and configured to cause the processor to:perform a first access procedure for access to a core network via a first 3rd generation partnership project (3GPP) network;derive first key (s) for access stratum operation in the first 3GPP network based on a root key;perform a second access procedure for access to the core network via a second 3GPP network; andderive second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key (s) .20.A method performed by a user equipment (UE) , the method comprising:performing a first access procedure for access to a core network via a first 3rd generation partnership project (3GPP) network;deriving first key (s) for access stratum operation in the first 3GPP network based on a root key;performing a second access procedure for access to the core network via a second 3GPP network; andderiving second key (s) for access stratum operation in the second 3GPP network based on the root key, wherein the second key (s) is independent of the first key(s) .

Citation Information

Patent Citations

  • Multi-RAT Access Stratum Security

    US20180041901A1

  • Application Function Key Derivation and Refresh

    US20220278835A1

  • Key hierarchies in trusted networks with 5g networks

    US20240155338A1

  • Apparatus, method, and computer program

    WO2024145946A1