Apparatus and method for obtaining security key in wireless communication system

By generating a new security key using previously stored information and access type identifiers, the method addresses the inefficiency of repeated authentication in wireless communication systems, thereby minimizing service delay and ensuring secure reconnection.

WO2025127293A1PCT designated stage expired Publication Date: 2025-06-19LG ELECTRONICS INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/009763
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-07-09
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

In wireless communication systems, the repeated authentication procedures required when a terminal reconnects can cause service delay and inefficiency, especially in scenarios where the terminal has previously established security context.

Method used

A method and device for generating a new security key based on previously stored security information, using at least a portion of a previously obtained security key, and an access type identifier, to facilitate reconnection in a wireless communication system without performing a new authentication procedure.

Benefits of technology

This approach minimizes service delay by reusing existing security information, reducing the need for repeated authentication processes, and ensuring secure reconnection of terminals in wireless communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024009763_19062025_PF_FP_ABST
    Figure KR2024009763_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure is to obtain a security key in a wireless communication system, and a method performed by a first network node may comprise the steps of: receiving, from a second network node, a message requesting registration of a terminal; obtaining a second security key on the basis of a first security key; and transmitting, to the second network node, a message including the second security key.
Need to check novelty before this filing date? Find Prior Art

Description

Device and method for obtaining a security key in a wireless communication system The following description relates to a wireless communication system, and more particularly, to a device and method for obtaining a security key in a wireless communication system. Wireless access systems are being widely deployed to provide various types of communication services such as voice and data. In general, wireless access systems are multiple access systems that can support communication with multiple users by sharing available system resources (bandwidth, transmission power, etc.). Examples of multiple access systems include CDMA (code division multiple access) systems, FDMA (frequency division multiple access) systems, TDMA (time division multiple access) systems, OFDMA (orthogonal frequency division multiple access) systems, and SC-FDMA (single carrier frequency division multiple access) systems. In particular, as many communication devices require large communication capacity, enhanced mobile broadband (eMBB) communication technology is being proposed compared to the existing radio access technology (RAT). In addition, a communication system that considers reliability and latency-sensitive services / UE (user equipment) as well as mMTC (massive machine type communications) that connects a large number of devices and objects to provide various services anytime and anywhere is being proposed. Various technology configurations are being proposed for this. The present disclosure relates to a device and method for effectively obtaining a security key in a wireless communication system. The present disclosure relates to a device and method for obtaining a new security key based on previously stored security information in a wireless communication system. The present disclosure relates to a device and method for obtaining a new security key based on at least a portion of a previously obtained security key in a wireless communication system. The present disclosure relates to a device and method for storing at least a portion of a security key obtained during an initial registration procedure of a terminal in a wireless communication system. The present disclosure relates to a device and method for generating a new security key based on at least a portion of a previously stored security key when a terminal reconnects in a wireless communication system. The present disclosure relates to a device and method for generating a new security key using at least a portion of a previously stored security key and an access type identifier in a wireless communication system. The present disclosure relates to a device and method for setting an access type identifier based on at least one of whether a terminal is reconnected and whether there is previously stored security information in a wireless communication system. The present disclosure relates to a device and method for deleting previously stored security information when a terminal is deregistered in a wireless communication system. The technical objectives to be achieved in the present disclosure are not limited to those mentioned above, and other technical tasks not mentioned can be considered by a person having ordinary skill in the art to which the technical configuration of the present disclosure is applied from the embodiments of the present disclosure described below. As an example of the present disclosure, a method performed by a first network node in a wireless communication system includes the steps of receiving a message requesting registration of a terminal from a second network node, obtaining a second security key based on a first security key, and transmitting a message including the second security key to the second network node, wherein the second network node is connected to the first network node via a wireline access network and supports the non-access stratum (NAS) signaling on behalf of the terminal, and the second security key can be obtained based on an uplink NAS count or further based on the stored security information based on whether there is pre-stored security information for the terminal. As an example of the present disclosure, a method performed by a terminal in a wireless communication system includes the steps of transmitting an authentication related message including network access identification information to a second network node, receiving an authentication success message from the second network node, and establishing security with the second network node based on a pairwise master key (PMK) obtained by the authentication success message, wherein the second network node is connected to a first network node through a wireline access network and supports non-access stratum (NAS) signaling to the first network node on behalf of the terminal, and the PMK is obtained based on a second security key obtained by the second network node from the first network node, and the second security key can be obtained based on an uplink NAS count or the pre-stored security information based on whether there is security information pre-stored in the first network node. As an example of the present disclosure, in a wireless communication system, a first network node includes a transceiver and a processor connected to the transceiver, wherein the processor controls to receive a message requesting registration of a terminal from a second network node, to obtain a second security key based on a first security key, and to transmit a message including the second security key to the second network node, wherein the second network node is connected to the first network node via a wireline access network and supports the NAS (non-access stratum) signaling on behalf of the terminal, and the second security key can be obtained based on an uplink NAS count or further based on the stored security information based on whether there is pre-stored security information for the terminal. As an example of the present disclosure, in a wireless communication system, a terminal includes a transceiver, and a processor connected to the transceiver, wherein the processor controls to transmit an authentication related message including network access identification information to a second network node, receive an authentication success message from the second network node, and establish security with the second network node based on a pairwise master key (PMK) obtained by the authentication success message, wherein the second network node is connected to a first network node through a wireline access network and supports NAS (non-access stratum) signaling to the first network node on behalf of the terminal, wherein the PMK is obtained based on a second security key obtained from the first network node by the second network node, and the second security key can be obtained based on an uplink NAS count or the pre-stored security information based on whether there is security information pre-stored in the first network node. As an example of the present disclosure, a communication device includes at least one processor, and at least one computer memory coupled to the at least one processor and storing instructions that, when executed by the at least one processor, direct operations, the operations including: receiving a message requesting registration of a terminal from a second network node, obtaining a second security key based on a first security key, and transmitting a message including the second security key to the second network node, wherein the second network node is coupled to the first network node via a wireline access network and supports the non-access stratum (NAS) signaling on behalf of the terminal, and the second security key can be obtained based on an uplink NAS count or further based on the pre-stored security information, based on whether there is pre-stored security information for the terminal. As an example of the present disclosure, a non-transitory computer-readable medium storing at least one instruction includes the at least one instruction executable by a processor, the at least one instruction controlling a device to receive a message requesting registration of a terminal from a second network node, to acquire a second security key based on a first security key, and to transmit a message including the second security key to the second network node, wherein the second network node is connected to the first network node via a wireline access network and supports the non-access stratum (NAS) signaling on behalf of the terminal, and the second security key can be acquired based on an uplink NAS count or further based on the stored security information, based on whether there is pre-stored security information for the terminal. The following effects may be achieved by embodiments based on the present disclosure. The present disclosure can minimize the service delay time of a terminal by preventing an authentication procedure from being repeatedly performed in a wireless communication system. The effects obtainable from the embodiments of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned can be clearly derived and understood by a person having ordinary skill in the art to which the technical configuration of the present disclosure is applied from the description of the embodiments of the present disclosure below. That is, unintended effects resulting from implementing the configuration described in the present disclosure can also be derived by a person having ordinary skill in the art from the embodiments of the present disclosure. The drawings attached below are intended to aid in understanding the present disclosure and may provide embodiments of the present disclosure together with detailed descriptions. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form a new embodiment. Reference numerals in each drawing may mean structural elements. Figure 1 illustrates an example of a communication system applicable to the present disclosure. FIG. 2 illustrates an example of a user equipment (UE) applicable to the present disclosure. FIG. 3 illustrates an example of functional separation of a next generation radio access network (NG-RAN) and a 5th generation core (5GC) applicable to the present disclosure. FIG. 4 illustrates an example of a general architecture of a 5G (5th generation) system applicable to the present disclosure. Figure 5 illustrates a 5G-RG authentication procedure applicable to the present disclosure. Figure 6 illustrates an FN-RG authentication procedure applicable to the present disclosure. Figure 7 illustrates the registration and authentication procedure of an AUN3 terminal supporting the 5G key layer. Figure 8 illustrates a key hierarchy generation structure of 5GS applicable to the present disclosure. FIG. 9a illustrates an example of a security key acquisition procedure according to one embodiment of the present disclosure. FIG. 9b illustrates an example of a security establishment procedure according to one embodiment of the present disclosure. FIG. 10 illustrates an example of a specific procedure for obtaining a security key according to one embodiment of the present disclosure. FIG. 11 illustrates an example of a key derivation function according to one embodiment of the present disclosure. FIGS. 12A and 12B illustrate examples of procedures for initial registration of an AUN3 terminal according to one embodiment of the present disclosure. FIG. 13 illustrates an example of a reconnection procedure of an AUN3 terminal according to one embodiment of the present disclosure. The following embodiments are combinations of components and features of the present disclosure in a given form. Each component or feature may be considered optional unless otherwise explicitly stated. Each component or feature may be implemented in a form that is not combined with other components or features. In addition, some components and / or features may be combined to form an embodiment of the present disclosure. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment, or may be replaced with corresponding components or features of another embodiment. In the description of the drawings, procedures or steps that may obscure the gist of the present disclosure are not described, and procedures or steps that can be understood by those skilled in the art are also not described. Throughout the specification, when a part is said to "comprising" or "including" a component, this does not mean that other components are excluded, but rather that other components can be included, unless otherwise specifically stated. In addition, terms such as "... part," "... unit," "module," etc. described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware, software, or a combination of hardware and software. In addition, "a" or "an," "one," "the," and similar related words may be used in the context of describing the present disclosure (especially in the context of the claims below) to include both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context. In this specification, embodiments of the present disclosure have been described with a focus on data transmission and reception relationships between a base station and a mobile station. Here, the base station is meant as a terminal node of a network that directly communicates with a mobile station. A specific operation described as being performed by the base station in this document may in some cases be performed by an upper node of the base station. That is, in a network consisting of a plurality of network nodes including a base station, various operations performed for communication with a mobile station may be performed by the base station or other network nodes other than the base station. In this case, the 'base station' may be replaced by terms such as a fixed station, a Node B, an eNode B (eNB), a gNode B (gNB), an ng-eNB, an advanced base station (ABS), or an access point. Additionally, in the embodiments of the present disclosure, the term terminal may be replaced with terms such as user equipment (UE), mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, or advanced mobile station (AMS). In addition, the transmitter refers to a fixed and / or mobile node that provides data service or voice service, and the receiver refers to a fixed and / or mobile node that receives data service or voice service. Accordingly, in the case of uplink, a mobile station can be a transmitter and a base station can be a receiver. Similarly, in the case of downlink, a mobile station can be a receiver and a base station can be a transmitter. Embodiments of the present disclosure are wireless access systems such as IEEE 802.xx system, 3rd Generation Partnership Project (3GPP) system, 3GPP LTE (Long Term Evolution) system, 3GPP 5G (5 th generation) NR (New Radio) system and at least one of the 3GPP2 system may be supported by standard documents disclosed, and in particular, embodiments of the present disclosure may be supported by 3GPP TS (technical specification) 38.211, 3GPP TS 38.212, 3GPP TS 38.213, 3GPP TS 38.321 and 3GPP TS 38.331 documents. In addition, the embodiments of the present disclosure may be applied to other wireless access systems and are not limited to the above-described system. For example, they may be applied to systems applied after the 3GPP 5G NR system and are not limited to a specific system. That is, obvious steps or parts that are not described in the embodiments of the present disclosure can be described by referring to the above documents. In addition, all terms disclosed in this document can be described by the above standard documents. Hereinafter, preferred embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below together with the accompanying drawings is intended to explain exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the technical configuration of the present disclosure may be implemented. Additionally, specific terms used in the embodiments of the present disclosure are provided to aid in understanding of the present disclosure, and the use of such specific terms may be changed to other forms without departing from the technical spirit of the present disclosure. The following technology can be applied to various wireless access systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access). For the sake of clarity, the following description is based on a 3GPP communication system (e.g., LTE, NR, etc.), but the technical spirit of the present invention is not limited thereto. LTE may refer to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 may be referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 may be referred to as LTE-A pro. 3GPP NR may refer to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. “xxx” refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system. For background technology, terms, abbreviations, etc. used in this disclosure, reference may be made to matters described in standard documents published prior to the present invention. For example, reference may be made to standard documents 36.xxx and 38.xxx. For terms, abbreviations, and other background technologies that may be used in this document, refer to the following standard documents published prior to this document. In particular, terms, abbreviations, and other background technologies related to LTE / EPS (Evolved Packet System) refer to the 36.xxx series, 23.xxx series, and 24.xxx series, and terms, abbreviations, and other background technologies related to NR (new radio) / 5GS (5G system) refer to the 38.xxx series, 23.xxx series, and 24.xxx series. Below, this specification is described based on the terms defined above. The three key requirement areas for 5G include (1) Enhanced Mobile Broadband (eMBB), (2) Massive Machine Type Communication (mMTC), and (3) Ultra-reliable and Low Latency Communications (URLLC). Some use cases may require multiple areas to optimize, while others may focus on just one Key Performance Indicator (KPI). 5G supports these diverse use cases in a flexible and reliable way. Communication system applicable to the present disclosure Although not limited thereto, the various descriptions, functions, procedures, proposals, methods, and / or operational flowcharts of the present disclosure disclosed in this document may be applied to various fields requiring wireless communication / connectivity (e.g., 5G) between devices. Hereinafter, more specific examples will be provided with reference to the drawings. In the drawings / descriptions below, the same drawing symbols may illustrate identical or corresponding hardware blocks, software blocks, or functional blocks, unless otherwise described. Figure 1 illustrates an example of a communication system applied to the present disclosure. Referring to FIG. 1, a communication system (100) applied to the present disclosure includes a wireless device, a base station, and a network. Here, the wireless device means a device that performs communication using a wireless access technology (e.g., 5G NR, LTE) and may be referred to as a communication / wireless / 5G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (extended reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Thing) device (100f), and an AI (artificial intelligence) device / server (100g). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicles (100b-1, 100b-2) may include unmanned aerial vehicles (UAVs) (e.g., drones). The XR devices (100c) include augmented reality (AR) / virtual reality (VR) / mixed reality (MR) devices, and may be implemented in the form of a head-mounted device (HMD), a head-up display (HUD) equipped in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc. The portable devices (100d) may include a smartphone, a smart pad, a wearable device (e.g., a smart watch, smart glasses), a computer (e.g., a laptop, etc.), etc. The home appliances (100e) may include a TV, a refrigerator, a washing machine, etc. The IoT devices (100f) may include sensors, smart meters, etc. For example, the base station (120) and network (130) may also be implemented as wireless devices, and a specific wireless device (120a) may act as a base station / network node to other wireless devices. Wireless devices (100a to 100f) can be connected to a network (130) via a base station (120). AI technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (100g) via a network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, etc. The wireless devices (100a to 100f) can communicate with each other via the base station (120) / network (130), but can also communicate directly (e.g., sidelink communication) without going through the base station (120) / network (130). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). Additionally, an IoT device (100f) (e.g., a sensor) can communicate directly with another IoT device (e.g., a sensor) or another wireless device (100a to 100f). Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a to 100f) / base stations (120), and base stations (120) / base stations (120). Here, the wireless communication / connection can be established through various wireless access technologies (e.g., 5G NR) such as uplink / downlink communication (150a), sidelink communication (150b) (or, D2D communication), and communication between base stations (150c) (e.g., relay, IAB (integrated access backhaul)). Through the wireless communication / connection (150a, 150b, 150c), the wireless device and base station / wireless device, and the base station and base station can transmit / receive wireless signals to each other. For example, the wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, based on various proposals of the present disclosure, at least some of various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), resource allocation processes, etc. may be performed. Figure 2 illustrates an example of a UE applicable to the present disclosure. Referring to FIG. 2, the UE (200) may include a processor (202), a memory (204), a transceiver (206), one or more antennas (208), a power management module (241), a battery (242), a display (243), a keypad (244), a SIM (Subscriber Identification Module) card (245), a speaker (246), and a microphone (247). The processor (202) may be configured to implement the descriptions, functions, procedures, suggestions, methods and / or flowcharts disclosed herein. The processor (202) may be configured to control one or more other components of the UE (200) to implement the descriptions, functions, procedures, suggestions, methods and / or flowcharts disclosed herein. A layer of a radio interface protocol may be implemented in the processor (202). The processor (202) may include an ASIC, other chipset, logic circuitry and / or data processing devices. The processor (202) may be an application processor. The processor (202) may include at least one of a DSP, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a modem (modulator and demodulator). The memory (204) is operatively coupled with the processor (202) and can store various information for operating the processor (202). The memory (204) can include ROM, RAM, flash memory, memory cards, storage media, and / or other storage devices. When the implementation is implemented in software, the techniques described herein can be implemented using modules (e.g., procedures, functions, etc.) that perform the descriptions, functions, procedures, suggestions, methods, and / or operational flowcharts disclosed herein. The modules can be stored in the memory (204) and executed by the processor (202). The memory (204) can be implemented within the processor (202) or external to the processor (202), in which case it can be communicatively coupled with the processor (202) via various methods known in the art. A transceiver (206) is operatively coupled to the processor (202) and can transmit and / or receive wireless signals. The transceiver (206) can include a transmitter and a receiver. The transceiver (206) can include baseband circuitry for processing radio frequency signals. The transceiver (206) can control one or more antennas (208) to transmit and / or receive wireless signals. The power management module (241) can manage power of the processor (202) and / or the transceiver (206). The battery (242) can supply power to the power management module (241). The display (243) can output the result processed by the processor (202). The keypad (244) can receive input to be used by the processor (202). The keypad (244) can be displayed on the display (243). A SIM card (245) is an integrated circuit for securely storing an International Mobile Subscriber Identity (IMSI) and associated keys, and can be used to identify and authenticate subscribers in mobile phone devices such as mobile phones or computers. Contact information can also be stored on many SIM cards. The speaker (246) can output sound-related results processed by the processor (202). The microphone (247) can receive sound-related input to be used by the processor (202). In an implementation of the present specification, a UE may operate as a transmitter in uplink and as a receiver in downlink. In an implementation of the present specification, a base station may operate as a receiver in UL and as a transmitter in DL. In the present specification, a base station may be referred to as a Node B, an eNode B (eNB), a gNB, and may not be limited to a specific form. In addition, for example, the UE may be implemented in various forms depending on the use case / service. The UE may be composed of various components, devices / parts, and / or modules. For example, each UE may include a communication device, a control device, a memory device, and additional components. The communication device may include a communication circuit and a transceiver. For example, the communication circuit may include one or more processors and / or one or more memories. For example, the transceiver may include one or more transceivers and / or one or more antennas. The control device is electrically connected to the communication device, the memory device, and the additional components, and may control the overall operation of each UE. For example, the control device may control the electrical / mechanical operation of each UE based on a program / code / command / information stored in the memory device. The control device may transmit information stored in the memory device to an external device (e.g., another communication device) via the communication device via a wireless / wired interface, or may store information received from an external device (e.g., another communication device) via the communication device via a wireless / wired interface in the memory device. The additional components may be configured in various ways depending on the type of the UE. For example, the additional components may include at least one of a power unit / battery, an input / output (I / O) device (e.g., an audio I / O port, a video I / O port), a driving device, and a computing device. In addition, the UE is not limited thereto, and may be implemented in the form of a robot (100a in FIG. 1), a vehicle (100b-1 and 100b-2 in FIG. 1), an XR device (100c in FIG. 1), a portable device (100d in FIG. 1), a home appliance (100e in FIG. 1), an IoT device (100f in FIG. 1), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (100g in FIG. 1), a base station (120 in FIG. 1), or a network node. UE can be used in mobile or fixed locations depending on the use case / service. The various components, devices / parts and / or modules of the UE may all be connected to each other via wired interfaces, or at least some of them may be connected wirelessly via communication devices. In addition, each component, device / part and / or module of the UE may further include one or more elements. For example, the control device may be configured by a set of one or more processors. For example, the control device may be configured by a set of a communication control processor, an application processor (AP), an electronic control unit (ECU), a graphic processing unit and a memory control processor. As another example, the memory device may be configured by a RAM, a DRAM (Dynamic RAM), a ROM, a flash memory, a volatile memory, a nonvolatile memory and / or a combination thereof. 5G system architecture applicable to the present disclosure The 5G system is an advanced technology from the 4th generation LTE mobile communication technology. It supports new radio access technology (RAT: Radio Access Technology), extended LTE (eLTE) as an extended technology of LTE (Long Term Evolution), and non-3GPP (e.g., WLAN) access through the evolution or clean-state structure of the existing mobile communication network structure. 5G systems are defined as service-based, and the interaction between network functions (NF) within the architecture for 5G systems can be expressed in two ways as follows. - Reference point representation: Represents the interaction between NF services within NFs described by a point-to-point reference point (e.g., N11) between two NFs (e.g., AMF and SMF). - Service-based representation: Network functions (e.g., AMF) within the Control Plane (CP) allow other authorized network functions to access their services. This representation also includes point-to-point reference points, if required. 5GC (5G Core) may include various components, some of which include access and mobility management function (AMF), session management function (SMF), policy control function (PCF), user plane function (UPF), application function (AF), unified data management (UDM), and non-3GPP interworking function (N3IWF). The UE connects to the data network via the UPF through the next generation radio access network (NG-RAN) including the gNB. The UE can receive data services via untrusted non-3GPP access, for example, a wireless local area network (WLAN). To connect the non-3GPP access to the core network, an N3IWF can be deployed. The N3IWF performs the function of managing interworking between non-3GPP access and 5G system. When UE is connected to non-3GPP access (e.g. WiFi, also known as IEEE 802.11), UE can be connected to 5G system through N3IWF. N3IWF performs control signaling with AMF and connects to UPF through N3 interface for data transmission. AMF can manage access and mobility in 5G systems. AMF can perform the function of managing NAS (non-access stratum) security. AMF can perform the function of handling mobility in idle state. UPF performs the function of a gateway for transmitting and receiving user data. UPF node can perform all or part of the user plane functions of S-GW (serving gateway) and P-GW (packet data network gateway) of 4th generation mobile communication. The UPF acts as an interface between the next generation RAN (NG-RAN) and the core network, and is an element that maintains the data path between the gNB and the SMF. In addition, the UPF acts as a mobility anchor point when the UE moves across the area served by the gNB. The UPF can perform the function of handling PDUs. For mobility within the NG-RAN (e.g., NG-RAN defined after 3GPP Release-15), the UPF can route packets. In addition, the UPF can also act as an anchor point for mobility with other 3GPP networks (e.g., RAN defined before 3GPP Release-15), such as UTRAN (UMTS (universal mobile telecommunications system) terrestrial radio access network)), E-UTRAN (evolved-UTRAN) or GERAN (GSM (global system for mobile communication) / EDGE (enhanced data rates for global evolution) radio access network). A UPF may correspond to the termination point of a data interface toward a data network. PCF is a node that controls the operator's policy. AF is a server that provides various services to UE. UDM is a server that manages subscriber information, such as the HSS (home subscriber server) of 4th generation mobile communication. UDM (460) stores and manages subscriber information in a unified data repository (UDR). SMF can perform the function of allocating IP (Internet protocol) address of UE. And, SMF can control PDU (protocol data unit) session. For convenience of explanation below, the drawing symbols for AMF, SMF, PCF, UPF, AF, UDM, N3IWF, gNB, or UE may be omitted, and operation may be performed by referring to the matters described in standard documents published before this document. FIG. 3 illustrates an example of functional separation of NG-RAN and 5GC (5th generation core) applicable to the present disclosure. Referring to Fig. 3, the UE is connected to a data network (DN) through a next-generation RAN. A control plane function (CPF) node performs all or part of the functions of a mobility management entity (MME) of 4th generation mobile communication, and all or part of the control plane functions of a serving gateway (S-GW) and a PDN gateway (P-GW). The CPF node includes an AMF and an SMF. The UPF node functions as a gateway through which user data is transmitted and received. The authentication server function (AUSF) authenticates and manages the UE. The Network Slice Selection Function (NSSF) is a node for network slicing as described below. The network exposure function (NEF) provides a mechanism to securely expose services and features of the 5G core. The reference points shown in Fig. 3 are as follows. N1 represents a reference point between the UE and the AMF. N2 represents a reference point between the (R)AN and the AMF. N3 represents a reference point between the (R)AN and the UPF. N4 represents a reference point between the SMF and the UPF. N5 represents a reference point between the PCF and the AF. N6 represents a reference point between the UPF and the DN. N7 represents a reference point between the SMF and the PCF. N8 represents a reference point between the UDM and the AMF. N9 represents a reference point between the UPFs. N10 represents a reference point between the UDM and the SMF. N11 represents a reference point between the AMF and the SMF. N12 represents a reference point between the AMF and the AUSF. N13 represents a reference point between the UDM and the AUSF. N14 represents a reference point between the AMFs. N15 represents a reference point between a PCF and an AMF in a non-roaming scenario, and a reference point between an AMF and a PCF of a visited network in a roaming scenario. N16 represents a reference point between SMFs. N22 represents a reference point between an AMF and an NSSF. N30 represents a reference point between a PCF and an NEF. N33 may represent a reference point between an AF and an NEF, and the entities and interfaces described above may be configured with reference to those described in standard documents published before this document. N58 represents a reference point between an AMF and an NSSAAF. N59 represents a reference point between a UDM and an NSSAAF. N80 represents a reference point between an AMF and an NSACF. N81 represents a reference point between an SMF and an NSACF. The radio interface protocol is based on the 3GPP radio access network standard. The radio interface protocol is divided horizontally into the physical layer, data link layer, and network layer, and vertically into the user plane for data information transmission and the control plane for control signal transmission. Protocol layers can be divided into L1 (layer-1), L2 (layer-2), and L3 (layer-3) based on the three lower layers of the open systems interconnection (OSI) standard model, which is widely known in communication systems. Below, the present disclosure describes each layer of the wireless protocol. FIG. 4 illustrates an example of a general architecture of a 5G (5th generation) system applicable to the present disclosure. Referring to FIG. 4, the AS (access stratum) layer may include a physical (PHY) layer, a medium access control layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, and a radio resource control (RRC) layer, and operations based on each layer may be performed by referring to matters described in standard documents published prior to this document. Specific embodiments of the present disclosure The present disclosure relates to a device and method for obtaining a security key in a wireless communication system. Specifically, the present disclosure relates to a device and method for storing at least a portion of a security key obtained during a registration procedure and an authentication procedure of a terminal in a wireless communication system, and generating a new security key for reconnection of the terminal using at least a portion of the security key. The background art, terminology, and / or abbreviations used in the present disclosure may further refer to matters described in standard documents published prior to the present disclosure, for example, 3GPP TS 23.501, 3GPP TS 33.501, and 3GPP TS 23.502. The 5G system supports wireline and wireless convergence functions. Terminals that do not support NAS signaling are linked to 5GC through NF that acts as a proxy. For example, an AUN3 (authenticable non-3GPP) terminal that does not support NAS signaling is registered in the 5G system by performing a registration procedure through NF that acts as a proxy. During the registration procedure of the AUN3 terminal, an authentication procedure is performed between the AUN3 terminal and 5GC, and thus, necessary information, a security context, is created. The security context is used for securing signaling or traffic data in the future. When the AUN3 terminal attempts to reconnect to 5GC, a new authentication procedure is performed for the AUN3 terminal through NF that acts as a proxy server, thereby creating new security information. That is, when the AUN3 terminal attempts to reconnect to 5GC, even if previously created security information exists, new security information is created through a new authentication procedure. The present disclosure discloses a method for reusing previously generated security information without performing a new authentication procedure when an AUN3 terminal reconnects to 5GC. According to 3GPP TS 23.501[1], the 5G system architecture is defined to support deployable data connectivity and services by leveraging technologies such as network function virtualization and software defined networking. The 5G system architecture leverages service-based interactions between identified control plane (CP) network functions. In particular, the 5G system architecture allows each network function and its network function services to interact directly or indirectly with other NFs and their network function services via service communication proxies, if necessary. The 5G system architecture does not exclude the use of other intermediate functions to facilitate the routing of control plane messages. In addition, the 5G system architecture minimizes dependencies between the access network (AN) and the core network (CN). The 5G system architecture is defined as a converged core network with a common AN-CN interface that integrates different access types. An AUN3 (authenticable non-3GPP) terminal can access a 5GC of a PLMN or SNPN through a 5G-RG (5G residential gateway) or a FN-RG (fixed network residential gateway). In this case, the AUN3 terminal can support 5G through 3GPP access and can be treated as a 5G terminal through 3GPP access. The method for an AUN3 terminal to connect to a 5G-RG or FN-RG and simultaneously register with a 5G core network is similar to the registration procedure of a terminal that does not support 5GC NAS through WLAN access defined in section 4.12b of TS 23.502. For the connection of an AUN3 terminal to a 5G-RG and the registration of an AUN3 terminal to a 5G core network, an authentication procedure is performed. If the authentication is successful, the AMF issues a K AMF Key is derived, K AMF The PMK (Pairwise Master Key) is derived by the 5G-RG or RN-RG that is provided with the key. The PMK is defined in IEEE Std 802.11

[0048] It is used to protect WLAN wireless interface communications. To support wireline and wireless convergence for 5G systems, two new network entities, 5G-RG and FN-RG, are introduced. 5G-RG acts as a 5G UE and can connect to 5GC via wireline 5G access network (W-5GAN) or fixed wireless access (FWA). For this purpose, the security procedures defined in TS 33.501 are reused. 5G-RG acts as an endpoint of N1 and provides NAS signaling connection to 5GC on behalf of AUN3 terminals behind 5G-RG. FN-RG connects to 5GC via W-5GAN, and W-AGF performs registration procedure on behalf of FN-RG. In addition, W-AGF acts as an endpoint of N1 and provides NAS signaling connection to 5GC on behalf of FN-RG. 5G-capable terminals can connect to 5GC via RG connected to 5GC via W-5GAN or NG-RAN. 5G-capable terminals support untrusted non-3GPP access and / or trusted non-3GPP access. 5G-RG can be connected to 5GC via W-5GAN, NG RAN or both accesses. The registration procedure for 5G-RG connected to 5GC via NG RAN is defined in TS 23.316

[0079] section 4.11, and the registration procedure for 5G-RG connected to 5GC via W-5GAN is defined in TS 23.316

[0079] section 7.2.1. The untrusted non-3GPP access procedure defined in section 7.2.1 is used as the basis for 5G-RG registration. 5G-RG shall support both 5G-authentication and key agreement (5G-AKA) and extensible authentication protocol (EAP-AKA)-AKA' and shall be authenticated by the 3GPP home network. From the 5GC perspective, 5G-RG is the same as a normal UE, so the authentication framework defined in Section 6.1.3 is used for authentication of 5G-RG. The difference compared to Section 6.1 is that when 5G-RG is connected to 5GC via 5G-RAN, UE is replaced with 5G-RG. When 5G-RG connects to 5GC via W-5GAN, W-CP protocol stack message should be used between 5G-RG and W-5GAN to encapsulate NAS message. Authentication method is executed between 5G-RG and AUSF as illustrated in Fig. 5. FIG. 5 illustrates a 5G-RG authentication procedure applicable to the present disclosure. Referring to FIG. 5, in step 1, the 5G-RG establishes a W-CP (control plane) connection with the W-5GAN. Since the details of the connection are beyond the scope of 3GPP, their description is omitted. In step 3, the 5G-RG transmits a message using the W-CP protocol stack including a registration message including UE security capabilities and SUCI. If there is an available security context, the 5G-RG performs integrity protection on the registration request message and transmits 5G-GUTI instead of subscription concealed identifier (SUCI). If the 5G-RG is registered to the same AMF via NG RAN, and the 5G-RG is connected to the 5GC via the W-5GAN for the first time, the corresponding uplink NAS count value used for integrity protection is 0. Otherwise, the existing non-3GPP specific uplink NAS count can be used for integrity protection. Note that since 5G-RG does not use non-3GPP access and avoids creating a new category of security context, the non-3GPP specific security context is used to refer to the security context used by 5G-RG over wired. In step 4, the W-AGF shall select an AMF as defined in TS 23.316

[0079] . The W-AGF forwards the registration request received from the UE to the selected AMF within the N2 Initial UE message. In step 5, AMF can use the security context to verify the integrity protection defined in section 6.4.6 if 5G-GUTI and registration are integrity protected. If 5G-RG is registered to the same AMF via NG RAN and this is the first time AMF receives NAS signaling from UE via wired connection, the corresponding uplink NAS count value used for integrity verification is 0. If G-RG is not registered to the same AMF via NG RAN or this is the first time AMF receives NAS signaling from UE via wired connection, existing non-3GPP specific uplink NAS count can be used for integrity verification. If integrity is successfully verified, it is indicated that 5G-RG is authenticated by AMF. If integrity is successfully verified and there is no new security context activated via NG RAN, steps 8 to 11 can be skipped. If the integrity is successfully verified and a new security context is activated via NG RAN, authentication can be skipped, but the AMF shall activate the new context using the NAS SMC procedure as described in step 8 and previously. Otherwise, the AMF shall authenticate the 5G-RG. If the AMF decides to authenticate the 5G-RG, it shall use one of the methods in Section 6.1.3. In this case, the AMF sends a key request to the AUSF. The AUSF initiates the authentication procedure as defined in Section 6.1.3. Between the AMF and the UE (5G-RG), the authentication packet is encapsulated within a NAS authentication message, which is conveyed in N2 signaling between the AMF and the W-AGF, and encapsulated using W-CP protocol stack messages between the W-AGF and the UE (5G-RG). In the final authentication message in the home network, the AUSF shall include the K AUSF Anchor key K derived from SEAF is transmitted to SEAF. SEAF is K SEAF From KAMF Induce and induce K AMF The AUSF sends the AMF a message to be used by the AMF for deriving the NAS security key. As defined in Section 6.1.3.1, if EAP-AKA' is used for authentication, the AUSF includes EAP-Success. The 5G-RG includes the anchor key K SEAF Obtain and key K SEAF In K AMF and derives the NAS security key. The NAS count associated with the NAS connection identifier "0x02" is set in 5G-RG and AMF. In step 6, the AMF sends a security mode command (SMC) to the UE (5G-RG) to activate NAS security associated with the NAS connection identifier "0x02". The security command message is sent to the W-AGF within an N2 message. If EAP-AKA' is used for authentication, the AMF encapsulates the EAP-Success received from the AUSF within an SMC message. In step 7, the W-AGF forwards the NAS SMC to the 5G-RG. In step 8, the W-AGF forwards the NAS packet containing the NAS SMC complete to the AMF over the N2 interface. In step 9, if the AMF receives the NAS SMC completion from the UE (5G-RG) or the integrity protection verification succeeds, it initiates the NGAP procedure to establish the AN context. The AMF uses the uplink NAS count associated with the NAS connection identifier "0x02" as defined in Appendix A.9 to set the key K N3IWF W-AGF key K equivalent to WAGF In step 10, when AMF receives NAS security mode completion, it sends N2 initial context setup request message to W-AGF. The message is K WAGF Includes. Note that the key K WAGFWhether or not it is utilized by 5G-RG and W-AGF is beyond the scope of 3GPP, so its description is omitted. In step 12, upon receiving a NAS registration accept message from AMF, W-AGF forwards it to 5G-RG through the established W-CP. All further NAS messages between UE and W-AGF are transmitted through the established W-CP. FN-RG is connected to 5GC via W-5GAN with W-AGF function which provides connectivity to 5GC via N2 and N3 reference points. FN-RG is a non-wireless entity defined by BBF or CableLabs and therefore does not support N1. W-AGF provides N1 connectivity on behalf of FN-RG. Authentication is performed between FN-RN and AUSF as illustrated in Fig. 6. W-AGF authenticates FN-RG and this is controlled by local policy. It is assumed that there is a trust relationship between the wireline operator managing W-5GAN and the PLMN operator managing 5GC. AMF trusts W-5GAN based on mutual authentication which is performed when security is established on the interface between them using NDS / IP or DTLS. FIG. 6 illustrates an FN-RG authentication procedure applicable to the present disclosure. Referring to FIG. 6, in step 1, an L2 (layer-2) connection is established between the FN-RG and the FAGF function within the W-AGF. In step 2, the FN-RG is authenticated by the W-AGF. The authentication method used for the FN-RG is defined by BBF or CableLabs, and is outside the scope of 3GPP, so its description is omitted. In steps 3 and 4, the W-AGF shall perform the initial registration on behalf of the FN-RG. The W-AGF generates a Registration Request message and sends it to the AMF over N2. The Registration Request message includes the SUCI of the FN-RG, and the N2 message includes an indication that the W-AGF authenticates the FN-RG. In step 5, the AMF selects an AUSF based on the received SUCI. The AMF sends a Nausf_UEAuthentication_Authenticate request message to the AUSF. The Nausf_UEAuthentication_Authenticate request message includes the SUCI of the FN-RG and the authenticated indication generated by the W-AGF. In step 6, the AUSF sends a Nudm_UEAuthentication_Get request to the UDM. The Nudm_UEAuthentication_Get request includes the SUCI of the FN-RG and the authenticated indication. In step 7, the UDM calls the Subscription identifier de-concealing function (SIDF) and maps the SUCI to the SUPI. In step 8, the UDM determines that authentication by the home network is not required for the FN-RG based on the subscription profile of the SUPI and the authenticated indication indicating that authentication was completed by the W-5GAN. In step 9, the UDM sends a Nudm_UEAuthentication_Get response to the AUSF. The Nudm_UEAuthentication_Get response to the AUSF includes the SUPI of the FN-RG and an indication indicating that home network authentication is not required. In step 10, after verifying the indication set by the UDM, the AUSF does not perform authentication and sends a Nausf_UEAuthentication_Authenticate response to the AMF.The Nausf_UEAuthentication_Authenticate response contains an indication that home network authentication is not required as established by the SUPI and UDM of the FN-RG. The AUSF response indicates that no authentication is required and K. SEAF In step 11, the AMF establishes NAS security between the AMF and the W-AGF using NULL encryption and NULL integrity protection after verifying the indication indicating that authentication by the home network is not required. In step 12, the AMF sends a Registration Acknowledgement message to the W-AGF. The Registration Acknowledgement message includes the 5G-GUTI and other parameters. In step 13, the W-AGF sends a Registration Complete message back to the AMF. The W-AGF stores the 5G-GUTI for use in subsequent NAS procedures. A UE attached to a 5G-RG or FN-RG can access 5GC via N3IWF or TNGF. A UE behind the FN-RG may use the untrusted non-3GPP access procedure defined in clause 4.12.2.2 of TS 23.502 [8] to access 5GC via N3IWF. A UE behind the 5G-RG may use the untrusted non-3GPP access procedure defined in clause 4.12.2.2 of TS 23.502 [8] or the trusted N3GPP access defined in clause 4.12a.2.2 of TS 23.502 [8]. A UE attached to a 5G-RG or FN-RG over a WLAN supporting IEEE 802.1X may use the NSWO authentication procedure specified in Annex S of TS 33.501. When the UE uses untrusted non-3GPP access, authentication of the UE is as defined in Section 7.2.1. On the other hand, when the UE uses trusted non-3GPP access, authentication of the UE is as defined in Section 7A.2.1. The requirements and procedures for UE related to subscriber privacy protection in clauses 5.2.5, 6.12 of TS 33.501 and Annex C apply to 5G-RG and not to FG-RG. When SUPI includes GCI, 5G-CRG may construct SUCI using null scheme. For W-AGF representing FN-RG, null scheme is used to construct SUCI as described in clauses 4.7.3 and 4.7.4 of TS 23.316

[0079] . The requirements and procedures for UE related to subscriber privacy protection in clauses 5.2.5, 6.12 of TS 33.501 and Annex C apply to N5CW. As defined in TS 23.316

[0079] , AUN3 terminals behind 5G-RG are registered to 5GC by 5G-RG and authenticated by 5G using EAP-AKA' as defined in RFC 5448

[0012] . Storage of 3GPP credentials for EAP-AKA' is defined in clause 6 of TS 33.501. 5GC registration and authentication procedure of AUN3 terminal It is based on whether AUN3 terminal supports 5G key hierarchy. The 5GC registration and authentication procedure of AUN3 terminal that does not support 5G key hierarchy is defined in section 7B.7.2 of TS 33.501, and the 5GC registration and authentication procedure of AUN3 terminal that supports 5G key hierarchy is defined in section 7B.7.3 of TS 33.501. In particular, section 7B.7.3 of TS 33.501 defines how AUN3 terminal supporting 5G key hierarchy behind 5G-RG is registered to 5GC by 5G-RG, and authenticated by 5GC using EAP-AKA'. Figure 7 illustrates the registration and authentication procedure of an AUN3 terminal supporting the 5G key layer. Referring to FIG. 7, in step 1, the AUN3 terminal initiates a layer 2 connection with the 5G-RG via Ethernet or WLAN. If the layer 2 connection is based on Ethernet, steps 20 and 21 may be skipped. In step 2, the 5G-RG initiates an EAP authentication procedure by transmitting an EAP request / ID to the AUN3 terminal in a layer 2 frame (e.g., EAPOL). In step 3, the AUN3 terminal sends back an EAP response / ID including a network access identifier (NAI) in the format of username@realm. If the AUN3 terminal supports SUPI privacy protection, the AUN3 terminal transmits SUCI in the EAP response / ID. In step 4, if the 5G-RG receives an NAI-based SUPI from the AUN3 terminal via step 3, it configures SUCI using a null scheme in the NAI-based SUPI. 5G-RG transmits NAS registration request message to AMF. NAS registration request message includes SUCI of AUN3 terminal and AUN3 terminal indicator. In step 5, AMF / SEAF selects AUSF based on SUCI of received registration request and transmits Nausf_UEAuthentication_Authenticate request message including SUCI of AUN3 terminal and AUN3 terminal indicator to AUSF. In step 6, AUSF transmits Nudm_UEAuthentication_Get request message including SUCI of AUN3 terminal and AUN3 terminal indicator to UDM. In step 7, upon receiving Nudm_UEAuthentication_Get request message, UDM calls SIDF to map SUCI to SUPI and selects EAP-AKA' as authentication method based on SUPI and AUN3 terminal indicator. UDM / ARPF generates authentication vector using access network ID as KDF input parameter.In step 8, UDM sends Nudm_UEAuthentication_Get response message to AUSF containing EAP-AKA' authentication vectors (RAND, AUTN, XRES, CK' and IK'), and SUPI. In step 9, the AUSF stores the XRES for later verification. The AUSF sends the EAP-Request / AKA'-Challenge message to the AMF / SEAF via a Nausf_UEAuthentication_Authenticate response message. In step 10, the AMF / SEAF sends the EAP-Request / AKA'-Challenge message to the 5G-RG using the NAS Authentication Request message. In step 11, the 5G-RG sends the EAP-Request / AKA'-Challenge message encapsulated in a Layer 2 (L2) message to the AUN3 terminal. In step 12, upon receiving the EAP-Request / AKA'-Challenge message, the AUN3 terminal verifies the received message, generates an authentication response and derives the key as described in RFC 5448

[0012] . In step 13, the AUN3 terminal sends an EAP-Response / AKA'-Challenge message encapsulated in a Layer 2 message to 5G-RG. In step 14, the 5G-RG sends the EAP-Response / AKA'-Challenge message included in the NAS authentication response message to AMF / SEAF. In step 15, the AMF / SEAF sends the EAP-Response / AKA'-Challenge message in the Nausf_UEAuthentication_Authenticate request message to AUSF. In step 16, AUSF verifies the AKA'-Challenge message as described in RFC 5448

[0012] . If the AKA'-Challenge message is successfully verified, AUSF verifies the K AUSFIn step 17, the AUSF sends a Nausf_UEAuthentication_Authenticate response message containing EAP-Success, anchor key and SUPI to the AMF / SEAF. In step 18, in the final authentication message of the home network, the AUSF sends the anchor key K SEAF If transmitted, SEAF will send K SEAF In K AMF Induces and transmits to AMF. In step 19, AMF transmits K WAGF Induces key. K WAGF Whether the key is used in 5G-RG and W-AGF is beyond the scope of 3GPP, so its description is omitted. In step 20, 5G-RG transmits EAP-Success message in layer 2 frame to AUN3 terminal. In steps 21a and 21b, if layer 2 connection is made via WLAN (IEEE 802.11), AUN3 terminal and 5G-RG transmit K from which WLAN key is derived. WAGF As PMK, in step 22, the AUN3 terminal and 5G-RG perform 4-way handshake to establish a WLAN security connection. Figure 8 illustrates a key hierarchy generation structure of 5GS applicable to the present disclosure. The key hierarchy generation structure illustrated in Figure 8 is defined in section 6.2 of TS 33.501. Referring to Figure 8, the keys involved in authentication include the K key, the CK key, and the IK key. For EAP-AKA', the CK' key and the IK' key are derived from the CK key and the IK key as defined in 6.1.3.1 of TS 33.501. The key hierarchy is K AUSF , K SEAF , K AMF , K NASint , K NASenc , K N3IWF , K gNB , K RRCint , K RRCenc, K UPint and K UPenc Contains keys such as: K is the key for AUSF within your home network. AUSF is derived from CK' and IK', or CK and IK. That is, in the case of EAP-AKA', K AUSF is derived from CK' and IK' by ME and AUSF. At this time, CK' and IK' are received as part of AV converted from ARPF in AUSF. For 5G AKA, K AUSF is derived from CK and IK by ME and ARPF. At this time, K AUSF is received from ARPF at AUSF as part of 5G HE AV. K SEAF is by ME and AUSF AUSF The anchor key is derived from and is provided to the SEAF of the serving network by the AUSF. K is the key for AMF in the serving network. AMF is K by ME and SEAF SEAF is derived from K AMF is additionally derived by the ME and source AMF during horizontal key derivation. K is the key for NAS signaling NASint is K by ME and AMF AMF is derived from and is used to protect NAS signaling using a specific integrity algorithm. In addition, K, the key for NAS signaling, is NASenc is K by ME and AMF AMF It is derived from and used to protect NAS signaling using a specific encryption algorithm. K is the key for NG-RAN gNB is K by ME and AMF AMF is derived from K gNBis further derived by ME and source gNB during horizontal or vertical key derivation, and K between ME and ng-eNB. gNB It is used as. K is the key for UP traffic UPenc is K by ME and gNB gNB is derived from and is used to protect UP traffic using a specific encryption algorithm. In addition, K, the key for UP traffic, is UPint is K by ME and gNB gNB , and is used to protect UP traffic between ME and gNB using a specific integrity algorithm. K is the key for RRC signaling RRCint is K by ME and gNB gNB is derived from and is used to protect RRC signaling using a specific integrity algorithm. In addition, K, which is a key for RRC signaling, RRCenc is K by ME and gNB gNB It is derived from and used to protect RRC signaling using a specific encryption algorithm. NH, one of the intermediate keys, is derived by ME and AMF to provide forward security. Also, K, one of the intermediate keys, NG-RAN * is derived by the ME and NG-RAN (e.g. gNB or ng-eNB) during horizontal or vertical key derivation using a key derivation function (KDF) as defined in clause A.11 and / or clause A.12 of TS 33.501. In addition, one of the intermediate keys, K AMF ' can be derived by the ME and the AMF when moving from one AMF to another during inter-AMF mobility using the KDF as specified in Annex A.13 of TS 33.501. Key K for non-3GPPN3IWF is K for non-3GPP access by ME and AMF. AMF is derived from K N3IWF is not transmitted between N3IWFs. K AMF From K gNB , K WAGF , K TNGF , K TWIF and K N3IWF When deriving keys and NAS counts in UE and AMF, the following input parameters are used to form the input S for the key derivation function (KDF). - FC = 0x6E - P0 = uplink NAS count - L0 = length of uplink NAS COUNT (e.g. 0x00 0x04) - P1 = access type distinguisher - L1 = length of Access type distinguisher (e.g. 0x00 0x01) The values ​​of the access type identifiers are defined as in [Table 1]. This is the same as Table A.9-1 of section A,9 of TS 33.501. Access type distinguisher value 3GPP access0x01Non 3GPP access0x02 The values ​​0x00 and 0x03~0xf0 are reserved for future use, and the values ​​0xf1~0xff are reserved for private use. K gNB The access type identifier for induction should be set to 0x01, which is the value for 3GPP, and K N3IWF , K WAGF , K TWIF , or K TNGFThe access type identifier in the induction should be set to 0x02, which is the value for non-3GPP. The input key, KEY, is a 256-bit K AMF The key derivation function is applied when a 5G wireless bearer protected by encryption is established and key changes are performed on-the-fly. Since AUN3 terminals do not support NAS via non-3GPP access, the uplink NAS count is K WAGF Must be set to 0 for key generation (see Section 7B.7.3). As described above, the 5G system includes an NF, such as 5G-RG or FN-RG, which acts as a proxy between the AUN3 terminal and the 5G system to support wireline and wireless convergence functions. In particular, the 5G-RG can support NAS signaling on behalf of the AUN3 terminal that does not support NAS signaling, which is a protocol between the terminal and the 5G system. Accordingly, the AUN3 terminal can be registered in the 5G system by performing a registration procedure through the 5G-RG. During the registration procedure of the AUN3 terminal, a mutual authentication procedure is performed between the AUN3 terminal and 5GC, and a security context, which is necessary information, is generated accordingly. The security context is used to secure signaling or traffic data in the future. Meanwhile, according to the conventional technology, when an AUN3 terminal registered in a 5G system reconnects to the 5G system through the same 5G-RG or attempts to reconnect to the 5G system through a new 5G-RG due to a change in location, a mutual authentication procedure is performed again between the AUN3 terminal and the 5G system. This is to prevent the AUN3 terminal and the 5G system from using the same security key as before by changing the root key through the new authentication procedure. However, if the authentication procedure is performed every time the AUN3 terminal reconnects to the 5G system, the service of the terminal may be affected. Therefore, in Rel-19, discussions are underway to minimize the impact of the service delay of the terminal due to the new authentication procedure in the aforementioned situation. In order to solve the above-mentioned problems, the present disclosure proposes a method to prevent the AUN3 terminal and the 5G system from using the same security key as before by utilizing the security context, which is existing security information, without performing a new authentication procedure. In other words, the present disclosure discloses a method to minimize the service delay of the terminal by generating a new security key for encrypting data using the security information acquired in the previous registration procedure. Specifically, the present disclosure discloses a method and device for newly generating only a security key necessary for data encryption, instead of repeatedly re-performing an authentication procedure when an AUN3 terminal reconnects to a 5GC. The scenario where AUN3 terminal wants to reconnect to the 5G system via 5G-RG / W-AGF is as follows. 1) When the AUN3 terminal is connected to the 5G system via 5G-RG / W-AGF and then disconnects and connects via a new 5G-RG / W-AGF 2) When the AUN3 terminal is connected to the 5G system via 5G-RG / W-AGF, then disconnects and reconnects via the same 5G-RG / W-AGF 3) When the AUN3 terminal is connected to the 5G system through 5G-RG / W-AGF, then disconnects and reconnects through another 5G-RG within the same W-AGF. In the above scenarios, 5GC may already have a security context for the AUN3 terminal through the initial registration procedure of the terminal. Therefore, the present disclosure proposes a method for generating a new security key based on the existing security context without repeatedly performing the authentication procedure between the AUN3 terminal and the 5G system in the above scenarios. FIG. 9a illustrates an example of a security key acquisition procedure according to one embodiment of the present disclosure. FIG. 9a illustrates a method performed by a first network node. The first network node may be an AMF, or an AMF and a SEAF. Referring to FIG. 9a, at step S901, a first network node receives a registration request message. In other words, the first network node may receive a registration request message from a second network node acting as a proxy between the AUN3 terminal and the 5GC system. The second network node may include a 5G-RG supporting NAS signaling. The registration request message includes an NAI and an AUN3 indicator of the AUN3 terminal that has requested registration. The NAI may include SUCI or 5G-GUTI. For example, if the AUN3 terminal is not registered with 5GC, the NAI may include SUCI, and if the AUN3 terminal is already registered with 5GC, the NAI may include 5G-GUTI. The AUN3 indicator indicates that the terminal that has requested registration is an AUN3 terminal. At step S903, the first network node obtains a second security key based on the first security key. The first security key is K AMF , and the second security key is K WAGF may include. The first security key may be obtained based on one of an authentication and key agreement procedure, a NAS key re-keying, a NAS key refresh, or an interworking procedure with an EPS. Here, the authentication and key agreement procedure may include an EAP-AKA' authentication procedure performed during initial registration. For example, the first network node may include an anchor key K obtained according to the authentication and key agreement procedure. SEAF Based on K AMF can be obtained. The second security key can be obtained by further utilizing the uplink NAS count or the pre-stored security information based on whether there is pre-stored security information for the AUN3 terminal. If there is no pre-stored security information for the AUN3 terminal, the first network node can obtain the second security key based on the first security key and the uplink NAS count. The uplink NAS count is a value related to the NAS connection and is a new K AMFWhen generated, it can be set to have a start value. For example, the start value of the uplink NAS count can be 0. In other words, if there is no pre-stored security information for the N5CW terminal, the first network node can obtain the second security key based on the first security key and the uplink NAS count set to 0. Here, the uplink NAS count is set to 0 because the AUN3 terminal does not support NAS signaling. On the other hand, if there is pre-stored security information for the AUN3 terminal, the first network node can obtain the second security key based on the first security key and the pre-stored security information. The pre-stored security information can include at least a part of the second security key obtained during a previous registration procedure. If the second security key is obtained, the first network node can store at least a part of the obtained second security key as security information for the AUN3 terminal. In step S905, the first network node transmits a message including the second security key. The first network node transmits a message including the second security key to the second network node. The message including the second security key may be an authentication result message or a registration acceptance message. The message including the second security key may further include EAP-Success indicating that EAP-based authentication is successful. The second security key is used to generate a PMK, and the PMK may be used to obtain a WALN key used for security settings for a wireless interface between the AUN3 terminal and the 5G-RG. FIG. 9b illustrates an example of a security establishment procedure according to one embodiment of the present disclosure. FIG. 9b illustrates a method performed by a terminal. The terminal may be an AUN3 terminal. Referring to FIG. 9b, at step S911, the terminal transmits an authentication-related message. The terminal transmits the authentication-related message including NAI to a second network node. The second network node is connected to a first network node (e.g., AMF) via a wireline access network and may include a 5G-RG that supports NAS signaling to the first network node on behalf of the terminal. In other words, the terminal may transmit the authentication-related message including NAI to the 5G-RG. Specifically, the terminal creates a layer 2 connection with the 5G-RG and receives an EAP-Req / Identify message requesting identification information of the terminal from the 5G-RG. Thereafter, the terminal transmits an EAP-Res / Identify message including NAI to the 5G-RG. The NAI may include SUCI or 5G-GUTI. For example, when the terminal performs initial registration with 5GC via 3GPP access, the NAI may include SUCI. On the other hand, if the terminal is already registered to 5GC via the selected 3GPP access, i.e., performing a reconnect, the NAI may contain the 5G-GUTI assigned to the terminal via the 3GPP access. In step S913, the terminal receives an authentication success message. The terminal receives the authentication success message from the second network. The authentication success message may include an EAP-success message. During initial registration of the terminal, the terminal may receive the authentication success message after performing an authentication key agreement procedure. The authentication key agreement procedure may include a step in which the terminal receives an EAP-Request / AKA'-Challenge message from a second network node, a step in which the terminal verifies the received EAP-Request / AKA'-Challenge message, and a step in which the terminal transmits an EAP-Request / AKA'-Challenge message as an authentication response to the second network node. The EAP-Request / AKA'-Challenge and EAP-Response / AKA'-Challenge messages may be transmitted and received after being encapsulated in a layer 2 (L2) message. On the other hand, when the terminal reconnects, the terminal may receive an authentication success message without performing the authentication key agreement procedure. In step S915, the terminal establishes security based on the PMK. The terminal obtains a WLAN key based on the PMK, and performs a security setup procedure for the wireless interface based on the WLAN key. The security setup procedure for the wireless interface may include four-way handshaking. The PMK may be generated or derived by the terminal or may be received from a second network node. For example, the terminal may obtain a second security key based on the first security key, and obtain the PMK based on the second security key. The first security key may be K AMF , and the second security key is K WAGFmay include. The first security key may be obtained based on one of the authentication and key agreement procedure, NAS key re-keying, NAS key refresh, or interworking procedure with EPS. Here, the authentication and key agreement procedure may include the EAP-AKA' authentication procedure performed at the time of initial registration. For example, the terminal may obtain the K based on the authentication and key agreement procedure. SEAF From K AMF can be obtained. The terminal has the first security key, K AMF Based on the second security key, K WAGF However, the second security key may be obtained by further utilizing the uplink NAS count set to 0 or the pre-stored security information based on whether the initial registration has been performed and / or whether pre-stored security information exists. Here, whether the initial registration has been performed may be determined based on whether 5G-GUTI is allocated to the terminal. If the initial registration has not been performed or the pre-stored security information does not exist, the terminal may obtain the second security key based on the first security key and the uplink NAS count set to 0. Here, the uplink NAS count is set to 0 because the N5CW terminal does not support NAS signaling. On the other hand, if the initial registration has already been performed or pre-stored security information exists, the terminal may obtain the second security key based on the first security key and the pre-stored security information. The pre-stored security information may include at least a part of the second security key obtained during a previous registration procedure of the terminal. When a second security key is acquired, the terminal can store at least a portion of the acquired second security key as security information and derive a PMK based on the second security key. FIG. 10 illustrates an example of a specific procedure for obtaining a security key according to one embodiment of the present disclosure. FIG. 10 illustrates a method performed by a first network node. The first network node may be an AMF, or an AMF and a SEAF. Referring to FIG. 10, in step S1001, the first network node detects reconnection. In other words, the first network node receives a registration request message from the second network node, and can detect reconnection of the AUN3 terminal based on at least one of a registration type and NAI in the received registration request message. For example, if the NAI included in the registration request message is 5G-GUTI, the first network node can detect that a registration request message for reconnection of the AUN3 terminal has been received. Here, the second network node may include a 5G-RG that supports NAS signaling on behalf of the AUN3 terminal. In step S1003, the first network node can check whether there is pre-stored security information. In other words, the first network node can check whether there is security information stored at the time of initial registration or previous connection of the AUN3 terminal. Here, the pre-stored security information is K acquired at the time of initial registration or previous connection. WAGF may include at least a portion of. If there is pre-stored security information, the first network node generates a second security key using the uplink NAS count set based on the pre-stored security information at step S1005. In other words, the first network node sets the uplink NAS count based on the pre-stored security information, and K AMFAnd the second security key can be generated based on the uplink NAS count based on the stored security information. The stored security information can be set as the uplink NAS count. The first network node can set the value of at least one input parameter of the KDF using the uplink NAS count set based on the stored security information, and set the value of at least one other input parameter of the KDF based on the access type identifier. The first network node can set the KDF with the values ​​of the input parameters set. AMF By entering , the newly derived K WAGF can be obtained. Here, the access type identifier can indicate non-3GPP access with enhanced mobility. Non-3GPP access with enhanced mobility is a newly defined access type identifier in the present disclosure, and can be used when an AUN3 terminal reconnects and there is previously stored security information. If there is no previously stored security information, at step S1007, the first network node generates a second security key using the uplink NAS count. In other words, the first network node generates K AMF and can generate a second security key based on the uplink NAS count set to 0. The first network node can set a value of at least one input parameter of the KDF based on the uplink NAS count set to 0, and can set a value of at least one other input parameter of the KDF based on the access type identifier. The first network node can generate a second security key based on the KDF with the set parameter values. AMF By entering , the newly derived K WAGF can be obtained. Here, the access type identifier can indicate non-3GPP access. In step S1009, the first network node stores at least a portion of the second security key as security information. For example, the first network node stores K generated or derived in step S1005 or step S1007. WAGF At least a portion of the second security key may be stored as security information for the AUN3 terminal. In other words, the first network node may select at least a portion of the second security key as security information and store the selected security information. At this time, the uplink NAS count may be set or updated based on the stored security information. The first network node may select and store at least a portion corresponding to a designated position and / or length of the entire key stream of the second security key as security information. For example, the first network node may select and store a first portion corresponding to n bits from the MSB of the key stream of the second security key, a second portion corresponding to n bits from the LSB, or a third portion corresponding to n bits in the middle as security information. At least one of the position and the length of at least a portion of the second security key to be stored as security information in the entire key stream of the second security key may be designated or set by the network operator and / or business operator. The position and / or the length of at least a portion of the second security key to be stored as security information is not changed. In the description referring to Fig. 10, the method in which the first network node derives the second security key is described. However, the AUN3 terminal can also derive the second security key in the same manner as the first network node. FIG. 11 illustrates an example of a key derivation function according to one embodiment of the present disclosure. Referring to Figure 11, K WAGF The key derivation function (KDF) (1110) that derives the 256-bit K AMF (1111) is input, and the input K AMF and K of 256 bits based on parameters WAGFPrints (1113). The input parameters of KDF can be set as follows. - FC = 0x6E - P0 = Uplink NAS count or previously stored security information - L0 = length of uplink NAS count or previously stored security information - P1 = access type distinguisher - L1 = length of access type identifier Here, the previously stored security information is the security context acquired and stored during the previous access procedure of the AUN3 terminal, and the K acquired during the previous access procedure of the AUN3 terminal. WAGF may include at least a portion of. The values ​​of the access type identifier are defined as in [Table 2]. Access type distinguisher value 3GPP access0x01Non 3GPP access0x02Non 3GPP access with enhanced mobility0x03 In Table 2, non-3GPP access with enhanced mobility is a newly defined access type identifier, which can be used when AUN3 terminals reconnect and pre-stored security information exists. The value of non-3GPP access with enhanced mobility is set to 0x03, but can be set to another reserved value. For example, the value of non-3GPP access with enhanced mobility can be set to any one of 0x00 and 0x03~0xf0, which are reserved for future use. During initial registration of the AUN3 terminal, P0 is set to the uplink NAS count, L0 is set to the length of the uplink NAS count, P1 is set to 0x02, which is a non-3GPP access value, and L1 is set to the length of the non-3GPP access value. Thereafter, when the AUN3 terminal reconnects, if there is security information pre-stored for the AUN3 terminal in the first network node, P0 is set to the pre-stored security information, L0 is set to the length of the pre-stored security information, P1 is set to 0x03, which is a non-3GPP access value with enhanced mobility, and L1 is set to the length of the non-3GPP access value with enhanced mobility. The first network node and / or the AUN3 terminal can derive the second security key based on the first security key by setting the input parameters of the KDF (1110) as described above. FIGS. 12A and 12B illustrate examples of procedures for initial registration of an AUN3 terminal according to one embodiment of the present disclosure. Referring to FIGS. 12A and 12B, at step S1201, the AUN3 terminal (1210) creates a layer 2 connection with the 5G-RG via Ethernet or WLAN. At step S1203, the 5G-RG (1220) initiates an EAP authentication procedure by transmitting an EAP request / ID (identity) to the AUN3 terminal (1210) in a layer 2 frame (e.g., EAPOL). At step S1205, the AUN3 terminal (1210) transmits an EAP response / ID including a network access identifier (NAI) to the 5G-RG (1220). The NAI may be configured in the format of username@realm. If the AUN3 terminal (1210) supports SUPI privacy, the NAI includes SUCI. The SUCI may be configured using a null scheme in NAI-based SUPI. At step S1207, 5G-RG (1220) transmits a NAS registration request message to AMF / SEAF (1240). The NAS registration request message includes SUCI and AUN3 terminal indicator. The AUN3 terminal indicator indicates that the terminal is an AUN3 terminal. At step S1209, AMF / SEAF (1240) selects AUSF (1250) based on SUCI included in the received NAS registration request message and transmits Nausf_UEAuthentication_Authenticate request message including SUCI of AUN3 terminal (1210) and AUN3 terminal indicator to AUSF (1250). At step S1211, AUSF (1250) transmits a Nudm_UEAuthentication_Get request message including the SUCI and AUN3 terminal indicator of AUN3 terminal (1210) to UDM (1260). At step S1213, upon receiving a Nudm_UEAuthentication_Get request message, UDM (1260) calls SIDF to obtain SUPI from SUCI, and selects EAP-AKA' as an authentication method based on SUPI and AUN3 terminal indicator. At step S1215, the UDM (1260) sends a Nudm_UEAuthentication_Get response message to the AUSF (1250) including EAP-AKA' authentication vectors (RAND, AUTN, XRES, CK' and IK'), and SUPI. The EAP-AKA' authentication vectors can be generated using the access network ID as an input parameter of the KDF. The UDM (1260) can include UDM / ARPF. At step S1217, AUSF (1250) stores XRES for later verification. AUSF sends EAP-Request / AKA'-Challenge message to AMF / SEAF (1240) via Nausf_UEAuthentication_Authenticate response message. At step S1219, AMF / SEAF (1250) sends EAP-Request / AKA'-Challenge message to 5G-RG (1220) using NAS authentication request message. At step S1221, the 5G-RG (1220) transmits an EAP-Request / AKA'-Challenge message encapsulated in a layer 2 (L2) message to the AUN3 terminal (1210). At step S1223, the AUN3 terminal (1210) verifies the received EAP-Request / AKA'-Challenge message and generates an authentication response. At this time, the AUN3 terminal (1210) derives a key as described in RFC 5448

[0012] . At step S1225, the AUN3 terminal (1210) transmits a layer 2 message including an encapsulated EAP-Response / AKA'-Challenge message to the 5G-RG (1220). At step S1227, 5G-RG (1220) transmits an EAP-Response / AKA'-Challenge message included in the NAS authentication response message to AMF / SEAF (1240). At step S1229, AMF / SEAF (1240) transmits an EAP-Response / AKA'-Challenge message to AUSF (1250) using a Nausf_UEAuthentication_Authenticate request message. At step S1231, the AUSF (1250) verifies the AKA'-Challenge message as described in RFC 5448

[0012] . If the AKA'-Challenge message is successfully verified, the AUSF (1250) sends K AUSFIn step S1233, AUSF (1250) sends a Nausf_UEAuthentication_Authenticate response message containing EAP-Success, anchor key and SUPI to AMF / SEAF (1240). At step S1235, AMF / SEAF (1240) is K AMF From K WAGF Induce and induce K WAG Stores at least a portion of the Nausf_UEAuthentication_Authenticate response message, which is the last authentication message of the home network, and stores K used as the anchor key through the Nausf_UEAuthentication_Authenticate response message. SEAF Receives the received K SEAF Rotor K AMF Induce and induce K AMF is sent to AMF. AMF sends K AMF From K WAGF Induce K WAGF Stores at least a portion of the AMF in the KDF as shown in Fig. 11. AMF By typing K WAGF can be obtained. At this time, the input parameters of the KDF can be set based on values ​​indicating non-3GPP access among the uplink NAS count and access type identifier values. For example, the input parameter P0 is set to the uplink NAS count, the input parameter L0 is set to the length of the uplink NAS count, the input parameter P1 is set to 0x02, which is a non-3GPP access value, and the input parameter L1 is set to the length of the non-3GPP access value. The uplink NAS count is a new K AMFWhen AMF is generated, it has a start value. For example, the start value of the uplink NAS count may be 0. This is because the N5CW terminal (1210) does not support NAS signaling. Since the uplink NAS count is 0 at the time of initial registration, the input parameter P0 may be set to 0. AMF is derived K WAGF of At least part of it is stored as a security context for the AUN3 terminal (1210). AMF is derived K WAGF can select n bits at a specified location or a specified portion of a key stream and store the selected n bits. For example, AMF can be derived from K WAGF A first part corresponding to n bits from the MSB of a key stream, a second part corresponding to n bits from the LSB, or a third part corresponding to n bits in the middle are selected and stored as a security context. Here, the number n of bits to be selected as the security context and / or the position or part of the key stream to be selected as the security context may be preset by a network operator and / or a business operator. The value n and / or the designated position or part are not changed after being preset. According to one embodiment, the position of the key stream to be selected as the security context may be set so that n consecutive bits are selected, or may be set so that n discontinuous bits are selected. According to one embodiment, n may be set to a maximum of 8. At step S1237, AMF / SEAF (1240) sends EAP_Success and K WAGF The authentication result message including the authentication result is transmitted to the 5G-RG (1220), and at step S1239, the 5G-RG (1220) transmits an EAP-Success message to the AUN3 terminal (1210) using the message of layer 2. In steps S1241 and S1243, 5G-RG (1220) and AUN3 terminal (1210) are KWAGF As PMK, WLAN keys are derived from PMK. Deriving WLAN keys from PMK is because layer 2 connection is made on WALN. AUN3 terminal (1210) can generate or derive PMK or obtain PMK from 5G-RG (1220). For example, AUN3 terminal (1210) can generate or derive PMK through authentication procedure based on EAP-Request / AKA'-Challenge and EAP-Response / AKA'-Challenge. AMF Obtained, and obtained K AMF From K WAGF Induce K WAGF Stores at least a portion of the AUN3 terminal (1210) in the KDF as shown in Fig. 11. AMF By typing K WAGF can be obtained. At this time, the input parameters of the KDF can be set based on the value indicating non-3GPP access among the uplink NAS count and access type identifier values ​​set to 0. In the AUN3 terminal (1210), K AMF From K WAGF Induce K WAGF A method of storing at least part of the K in AMF (1240) AMF From K WAGF Induce K WAGF It is identical to the way in which at least part of a is stored. At step S1245, the 5G-RG (1220) and the AUN3 terminal (1210) perform four-way handshaking to establish a WLAN security connection. WLAN keys are used for the WLAN security connection. In the description referring to Figures 12a and 12b, the derived K WAGF At least part of the derived K was stored as security information. WAGFSecurity information including at least a portion of the AUN3 terminal (1210) is deleted when the 5GC is deregistrated. FIG. 13 illustrates an example of a reconnection procedure of an AUN3 terminal according to one embodiment of the present disclosure. FIG. 13 illustrates a 5GC reconnection procedure of an AUN3 terminal that has completed an initial registration procedure for 5GC. Referring to FIG. 13, at step S1301, the AUN3 terminal (1310) creates a layer 2 connection with the 5G-RG via Ethernet or WLAN. At step S1303, the 5G-RG (1320) initiates an EAP authentication procedure by transmitting an EAP request / ID (identity) to the AUN3 terminal (1310) in a layer 2 frame (e.g., EAPOL). At step S1305, the AUN3 terminal (1310) transmits an EAP response / ID including a network access identifier (NAI) to the 5G-RG (1320). Since the AUN3 terminal (1310) has completed the initial registration procedure, the NAI includes the 5G-GUTI. At step S1307, the 5G-RG (1320) transmits a NAS registration request message to the AMF / SEAF (1340). The 5G-RG (1320) may select the same AMF as before, i.e., the AMF selected during the initial registration procedure, based on the 5G-GUTI received from the AUN3 terminal (1310). The NAS registration request message includes the 5G-GUTI and an AUN3 terminal indicator. The AUN3 terminal indicator indicates that the corresponding terminal is an AUN3 terminal. At step S1309, AMF / SEAF (1340) checks whether there is a previously stored security context for the AUN3 terminal (1310). For example, when a NAS registration request message including 5G-GUIT is received, AMF checks whether there is a security context stored during the initial registration procedure or the previous reconnection procedure of the AUN3 terminal (1310) with 5G-GUTI. The security context is K acquired during the initial registration procedure or the previous reconnection procedure of the AUN3 terminal (1310). WAGF If there is a previously stored security context for the AUN3 terminal (1310), the AMF / SEAF (1340) performs step S1311. At step S1311, AMF / SEAF (1340) uses the previously stored security context to create a new K WAGF , and the newly derived K WAGF stores at least a portion of the KDF. Specifically, AMF / SEAF (1340) sets the input of the KDF based on the previously stored security context, thereby generating a new KDF. WAGF At this time, the parameters of KDF are obtained from the previously obtained K WAGF may be set based on a value indicating non-3GPP access with enhanced mobility among the values ​​of the security context and access type identifier including at least a part of the security context and access type identifier. For example, the parameter P0 may be set based on a previously stored security context, i.e., K acquired during an initial registration procedure or a previous reconnect procedure. WAGF At least part of, parameter L0 is set to the length of a previously stored security context, parameter P1 is set to 0x03, which is the value of a newly defined non-3GPP access with enhanced mobility, and parameter L1 is set to the length of a non-3GPP access value with enhanced mobility. AMF / SEAF (1340) deletes the previously stored security context and deriving a newly derived K WAGFAt least of A portion of the AUN3 terminal (1310) is stored as a security context for the AMF / SEAF (1340). The newly derived K WAGF can select n bits at a specified position or a specified portion of the key stream and store the selected n bits. For example, AMF can be derived from K WAGF A first portion corresponding to n bits from the MSB of a key stream, a second portion corresponding to n bits from the LSB, or a third portion corresponding to n bits in the middle are selected and stored as a security context. Here, the number n of bits to be selected as the security context and / or the position or portion of the key stream to be selected as the security context may be preset by a network operator and / or a business operator. The specified position or portion, and / or the value of n, are not changed after being preset. According to one embodiment, the position of the key stream to be selected as security information may be set so that n consecutive bits are selected, or may be set so that n discontinuous bits are selected. According to one embodiment, n may be set to a maximum of 8. At step S1313, AMF / SEAF (1340) sends EAP_Success and K WAGF In step S1315, the 5G-RG (1320) transmits an EAP-Success message to the AUN3 terminal (1310) using a message of layer 2. In steps S1317 and S1319, the 5G-RG (1320) and the AUN3 terminal (1310) transmit K WAGF It uses PMK as the WLAN key and derives WLAN keys from PMK. Deriving WLAN keys from PMK is because the layer 2 connection is made over WALN. The AUN3 terminal (1310) can generate or derive a PMK or obtain a PMK from the 5G-RG (1320). For example, the AUN3 terminal (1310) can generate a new K using a previously stored security context. WAGF , and the newly derived K WAGF stores at least a portion of the KDF. Specifically, by setting the input of the KDF based on the security context stored before the AUN3 terminal (1310), a new K WAGF At this time, the parameters of KDF are obtained from the previously obtained K WAGF The values ​​of the security context and access type identifier including at least a part of the AUN3 terminal (1310) may be set based on a value indicating non-3GPP access with enhanced mobility. WAGF , and the newly derived K WAGF A new K in AMF / SEAF (1340) is used to store at least part of the WAGF , and the newly derived K WAGF In step S1321, the 5G-RG (1320) and the AUN3 terminal (1310) perform four-way handshaking to establish a WLAN security connection. WLAN keys are used for the WLAN security connection. In the explanation referring to Fig. 13, the newly derived K WAGF At least part of the newly derived K was stored as security information. WAGF Security information including at least a portion of the AUN3 terminal (1310) is deleted when the 5GC is deregistrated. It is obvious that the examples of the proposed methods described above can also be included as one of the implementation methods of the present disclosure, and thus can be considered as a kind of proposed methods. In addition, the proposed methods described above can be implemented independently, but can also be implemented in the form of a combination (or merge) of some of the proposed methods. Information on whether the proposed methods are applied (or information on the rules of the proposed methods) can be defined as a rule so that the base station notifies the terminal through a predefined signal (e.g., a physical layer signal or a higher layer signal). The present disclosure may be embodied in other specific forms without departing from the technical ideas and essential features described in the present disclosure. Accordingly, the above detailed description should not be construed as limiting in all aspects but should be considered as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all changes within the equivalent scope of the present disclosure are included in the scope of the present disclosure. In addition, claims that do not have an explicit citation relationship in the patent claims may be combined to form an embodiment or may be included as a new claim by a post-filing amendment. Embodiments of the present disclosure can be applied to various wireless access systems. As examples of various wireless access systems, there are 3GPP (3rd Generation Partnership Project) or 3GPP2 systems. The embodiments of the present disclosure can be applied not only to the various wireless access systems described above, but also to all technical fields that apply the various wireless access systems described above. Furthermore, the proposed method can also be applied to mmWave and THz communication systems that utilize ultra-high frequency bands. Additionally, embodiments of the present disclosure can be applied to various applications such as autonomous vehicles and drones.

Claims

1. A method performed by a first network node in a wireless communication system, A step of receiving a message requesting registration of a terminal from a second network node; A step of obtaining a second security key based on the first security key; and A step of transmitting a message including the second security key to the second network node, The second network node is connected to the first network node via a wireline access network and supports the NAS (non-access stratum) signaling on behalf of the terminal, The above second security key is obtained based on an uplink NAS count or further based on the above-stored security information, based on whether there is previously stored security information for the terminal.

2. In claim 1, A method wherein the above-mentioned stored security information includes at least a portion of a second security key obtained during a previous registration procedure for the terminal.

3. In claim 1, The step of obtaining the second security key based on the above first security key is: If there is no previously stored security information for the terminal, a step of deriving the second security key from the first security key based on the uplink NAS count being set to 0; and A method comprising a step of deriving the second security key from the first security key based on the pre-stored security information when there is pre-stored security information for the terminal.

4. In claim 3, A method in which the above uplink NAS count or the above stored security information is used to set at least one parameter of a key derivation function that derives the second security key from the first security key.

5. In claim 4, If there is no previously stored security information for the terminal, at least one other parameter of the key derivation function is set based on the first access type identifier, If there is pre-stored security information for the terminal, at least one other parameter of the key derivation function is set based on the second access type identifier, A method wherein the first access type identifier and the second access type identifier are different values ​​set for non-3GPP access.

6. In claim 1, A step of determining whether the message requesting registration is a message for reconnection of the terminal based on network access identifier information included in the message requesting registration; and A method further comprising a step of checking whether there is security information previously stored for the terminal when the message requesting the registration is a message for reconnection of the terminal.

7. In claim 1, A method in which whether the message requesting the above registration is a message for reconnection of the terminal is determined based on whether the network access identifier includes a 5G-GUTI (5G-globally unique temporary user equipment identity).

8. In claim 1, A method further comprising the step of storing at least a portion of the second security key as security information for the terminal.

9. In claim 8, A method wherein at least one of the location and length of at least a portion of the entire stream of the second security key stored as the security information is set by the network operator.

10. In claim 1, The above terminal includes an AUN3 (authenticable non-3GPP) terminal, The above first network node includes an access and mobility management function (AMF), A method wherein the second network node comprises a 5G residential gateway (5G-RG).

11. In claim 1, A method in which security information previously stored for the above terminal is deleted when the above terminal is deregistered.

12. In claim 1, A method wherein a message including the second security key includes an authentication result message or a registration acceptance message.

13. In a method performed by a terminal in a wireless communication system, A step of transmitting an authentication-related message including network access identification information to a second network node; A step of receiving an authentication success message from the second network node; A step of establishing security with the second network node based on PMK (pairwise master key), The second network node is connected to the first network node via a wireline access network and supports NAS (non-access stratum) signaling to the first network node on behalf of the terminal, The above PMK is obtained based on the second security key, The above second security key is obtained based on an uplink NAS count or based on the presence of pre-stored security information.

14. In a first network node in a wireless communication system, Transmitter and receiver; and comprising a processor connected to the above transceiver, The above processor, Receive a message requesting registration of a terminal from a second network node, Obtain a second security key based on the first security key, Controlling to transmit a message including the second security key to the second network node, The second network node is connected to the first network node via a wireline access network and supports the NAS (non-access stratum) signaling on behalf of the terminal, The second security key is a first network node obtained based on an uplink NAS count or based on the previously stored security information, based on whether there is previously stored security information for the terminal.

15. In a wireless communication system, at a terminal, Transmitter and receiver; and comprising a processor connected to the above transceiver, The above processor, Transmitting an authentication-related message containing network access identification information to a second network node, Receive an authentication success message from the second network node, Control to establish security with the second network node based on PMK (pairwise master key), The second network node is connected to the first network node via a wireline access network and supports NAS (non-access stratum) signaling to the first network node on behalf of the terminal, The above PMK is obtained based on the second security key, The above second security key is obtained by the terminal based on the uplink NAS count or the above-mentioned stored security information, based on whether there is previously stored security information.

16. In communication devices, At least one processor; At least one computer memory coupled to said at least one processor and storing instructions that direct operations when executed by said at least one processor, The above actions are, A step of receiving a message requesting registration of a terminal from a second network node; A step of obtaining a second security key based on the first security key; and A step of transmitting a message including the second security key to the second network node, The second network node is connected to the first network node via a wireline access network and supports the NAS (non-access stratum) signaling on behalf of the terminal, The second security key is a communication device obtained based on an uplink NAS count or further based on the previously stored security information, based on whether there is previously stored security information for the terminal.

17. In a non-transitory computer-readable medium storing at least one instruction, comprising at least one instruction executable by the processor, At least one of the above commands causes the device to: Receive a message requesting registration of a terminal from a second network node, Obtain a second security key based on the first security key, Controlling to transmit a message including the second security key to the second network node, The second network node is connected to the first network node via a wireline access network and supports the NAS (non-access stratum) signaling on behalf of the terminal, The second security key is a computer-readable medium obtained based on an uplink NAS count or further based on the previously stored security information, based on whether there is previously stored security information for the terminal.

Citation Information

Patent Citations

  • Security context handling in 5g during handover

    US20210153013A1

  • KR20230160406A