Apparatus and method for acquiring security key in wireless communication system

The method generates a new security key using previously stored information to minimize service delay for N5CW terminals in wireless communication systems, addressing the inefficiency of repeated authentication procedures during reconnection.

WO2025127294A1PCT designated stage expired Publication Date: 2025-06-19LG ELECTRONICS INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/009766
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-07-09
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

In wireless communication systems, especially for N5CW terminals, the frequent authentication procedures required for reconnection lead to service delay and inefficiency, as they necessitate repeated security key generation and authentication processes.

Method used

A method and device for generating a new security key based on previously stored security information in a wireless communication system, allowing N5CW terminals to reconnect without performing a new authentication procedure, thereby minimizing service delay.

Benefits of technology

This approach reduces service delay by eliminating the need for repeated authentication procedures during reconnection, ensuring seamless and efficient communication for N5CW terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024009766_19062025_PF_FP_ABST
    Figure KR2024009766_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The purpose of the present disclosure is to perform authentication of a terminal in a wireless communication system. A method performed by a first network node may comprise the steps of: receiving, from a second network node, a message requesting registration of a terminal; acquiring a second security key on the basis of a first security key; and transmitting, to the second network node, a message including the second security key.
Need to check novelty before this filing date? Find Prior Art

Description

Device and method for obtaining a security key in a wireless communication system

[0001] The following description relates to a wireless communication system, and more particularly, to a device and method for obtaining a security key in a wireless communication system.

[0002] Wireless access systems are widely deployed to provide various types of communication services, such as voice and data. Typically, wireless access systems are multiple access systems that support communications with multiple users by sharing available system resources (e.g., bandwidth, transmission power). Examples of multiple access systems include code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), orthogonal frequency division multiple access (OFDMA), and single-carrier frequency division multiple access (SC-FDMA).

[0003] In particular, as numerous communication devices demand greater communication capacity, enhanced mobile broadband (eMBB) communication technologies are being proposed, improving upon existing radio access technology (RAT). Furthermore, massive machine type communications (mMTC), which connects numerous devices and objects to provide diverse services anytime and anywhere, as well as communication systems that consider reliability and latency-sensitive services / user equipment (UE), are being proposed. Various technological configurations are being proposed for these purposes.

[0004] The present disclosure relates to a device and method for effectively obtaining a security key in a wireless communication system.

[0005] The present disclosure relates to a device and method for obtaining a new security key based on previously stored security information in a wireless communication system.

[0006] The present disclosure relates to a device and method for obtaining a new security key based on at least a portion of a previously obtained security key in a wireless communication system.

[0007] The present disclosure relates to a device and method for storing at least a portion of a security key obtained during an initial registration procedure of a terminal in a wireless communication system.

[0008] The present disclosure relates to a device and method for generating a new security key based on at least a portion of a previously stored security key when a terminal reconnects in a wireless communication system.

[0009] The present disclosure relates to a device and method for generating a new security key using at least a portion of a previously stored security key and an access type identifier in a wireless communication system.

[0010] The present disclosure relates to a device and method for setting an access type identifier based on at least one of whether a terminal is reconnected and whether there is previously stored security information in a wireless communication system.

[0011] The present disclosure relates to a device and method for deleting previously stored security information when a terminal is deregistered in a wireless communication system.

[0012] The technical objectives to be achieved in the present disclosure are not limited to those mentioned above, and other technical tasks not mentioned can be considered by a person having ordinary skill in the technical field to which the technical configuration of the present disclosure is applied from the embodiments of the present disclosure described below.

[0013] As an example of the present disclosure, a method performed by a network node in a wireless communication system includes the steps of receiving a message requesting registration of a terminal from a second network node, obtaining a second security key based on a first security key, and transmitting a message including the second security key to the second network node, wherein the second network node is included in a wireless local area network (WLAN) access network and supports non-access stratum (NAS) signaling on behalf of the terminal, and the second security key can be obtained based on an uplink NAS count or further based on the stored security information based on whether there is pre-stored security information for the terminal.

[0014] As an example of the present disclosure, a method performed by a terminal in a wireless communication system includes the steps of transmitting an authentication-related message including network access identification information to a second network node, receiving an authentication success message from the second network node, and establishing security with the second network node based on a pairwise master key (PMK), wherein the second network node is included in a wireless local area network (WLAN) access network and supports non-access stratum (NAS) signaling to a first network node on behalf of the terminal, and wherein the PMK is obtained based on a second security key, and the second security key can be obtained based on an uplink NAS count or the stored security information based on whether pre-stored security information exists.

[0015] As an example of the present disclosure, in a wireless communication system, a first network node includes a transceiver and a processor connected to the transceiver, the processor controls to receive a message requesting registration of a terminal from a second network node, obtain a second security key based on a first security key, and transmit a message including the second security key to the second network node, wherein the second network node is included in a wireless local area network (WLAN) access network and supports non-access stratum (NAS) signaling on behalf of the terminal, and the second security key can be obtained based on an uplink NAS count or further based on the pre-stored security information based on whether there is pre-stored security information for the terminal.

[0016] As an example of the present disclosure, in a wireless communication system, a terminal includes a transceiver and a processor connected to the transceiver, wherein the processor controls to transmit an authentication-related message including network access identification information to a second network node, receive an authentication success message from the second network node, and establish security with the second network node based on a pairwise master key (PMK), wherein the second network node is included in a wireless local area network (WLAN) access network and supports non-access stratum (NAS) signaling to a first network node on behalf of the terminal, and wherein the PMK is obtained based on a second security key, and the second security key can be obtained based on an uplink NAS count or the stored security information based on whether pre-stored security information exists.

[0017] As an example of the present disclosure, a communication device includes at least one processor, and at least one computer memory coupled to the at least one processor and storing instructions that, when executed by the at least one processor, direct operations, the operations including: receiving a message requesting registration of a terminal from a second network node; obtaining a second security key based on a first security key; and transmitting a message including the second security key to the second network node, wherein the second network node is included in a wireless local area network (WLAN) access network and supports non-access stratum (NAS) signaling on behalf of the terminal, and wherein the second security key may be obtained based on an uplink NAS count or further based on the stored security information, based on whether there is pre-stored security information for the terminal.

[0018] As an example of the present disclosure, a non-transitory computer-readable medium storing at least one instruction includes at least one instruction executable by a processor, the at least one instruction controlling a device to receive a message requesting registration of a terminal from a second network node, obtain a second security key based on a first security key, and transmit a message including the second security key to the second network node, wherein the second network node is included in a wireless local area network (WLAN) access network and supports non-access stratum (NAS) signaling on behalf of the terminal, and the second security key may be obtained based on an uplink NAS count or further based on the pre-stored security information based on whether there is pre-stored security information for the terminal.

[0019] The following effects may be achieved by embodiments based on the present disclosure.

[0020] The present disclosure can minimize the service delay time of a terminal by preventing the authentication procedure from being repeatedly performed in a wireless communication system.

[0021] The effects that can be obtained from the embodiments of the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned can be clearly derived and understood by those skilled in the art to which the technical configuration of the present disclosure is applied, from the description of the embodiments of the present disclosure below. In other words, unintended effects that result from implementing the configuration described in the present disclosure can also be derived by those skilled in the art from the embodiments of the present disclosure.

[0022] The accompanying drawings are intended to aid in understanding the present disclosure and, together with detailed descriptions, may provide embodiments of the present disclosure. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form new embodiments. Reference numerals in each drawing may indicate structural elements.

[0023] Figure 1 illustrates an example of a communication system applicable to the present disclosure.

[0024] FIG. 2 illustrates an example of a user equipment (UE) applicable to the present disclosure.

[0025] FIG. 3 illustrates an example of functional separation of a next generation radio access network (NG-RAN) and a 5th generation core (5GC) applicable to the present disclosure.

[0026] FIG. 4 illustrates an example of a general architecture of a 5G (5th generation) system applicable to the present disclosure.

[0027] Figures 5a, 5b, and 5c illustrate the initial registration and PDU session establishment procedures of an N5CW terminal.

[0028] Figures 6a and 6b illustrate an authentication procedure for an N5CW terminal.

[0029] Figure 7 illustrates an authentication procedure for EAP-AKA applicable to the present disclosure.

[0030] Figure 8 illustrates a key hierarchy generation structure of 5GS applicable to the present disclosure.

[0031] FIG. 9a illustrates an example of a security key acquisition procedure according to one embodiment of the present disclosure.

[0032] FIG. 9b illustrates an example of a security establishment procedure according to one embodiment of the present disclosure.

[0033] FIG. 10 illustrates an example of a specific procedure for obtaining a security key according to one embodiment of the present disclosure.

[0034] FIG. 11 illustrates an example of a key derivation function according to one embodiment of the present disclosure.

[0035] FIG. 12a and FIG. 12b illustrate examples of a procedure for initial registration of an N5CW terminal according to one embodiment of the present disclosure.

[0036] FIG. 13a and FIG. 13b illustrate examples of a reconnection procedure of an N5CW terminal according to one embodiment of the present disclosure.

[0037] The following embodiments combine components and features of the present disclosure in a predetermined form. Each component or feature may be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, some components and / or features may be combined to form embodiments of the present disclosure. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment.

[0038] In the description of the drawings, procedures or steps that may obscure the gist of the present disclosure are not described, and procedures or steps that can be understood by a person skilled in the art are also not described.

[0039] Throughout the specification, when a part is said to "comprising" or "including" a component, this does not mean that other components may be included, but rather that other components may be excluded, unless otherwise specifically stated. In addition, terms such as "...part," "...unit," and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware, software, or a combination of hardware and software. In addition, the words "a" or "an," "one," "the," and similar related words may be used in the context of describing the present disclosure (especially in the context of the claims below) to include both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context.

[0040] Embodiments of the present disclosure described herein focus on the data transmission and reception relationship between a base station and a mobile station. Here, the base station is understood as a terminal node of a network that directly communicates with the mobile station. Certain operations described herein as being performed by the base station may, in some cases, be performed by an upper node of the base station.

[0041] That is, in a network consisting of multiple network nodes including a base station, various operations performed for communication with a mobile station may be performed by the base station or other network nodes other than the base station. In this case, the term 'base station' may be replaced by terms such as fixed station, Node B, eNB (eNode B), gNB (gNode B), ng-eNB, advanced base station (ABS), or access point.

[0042] Additionally, in embodiments of the present disclosure, the term terminal may be replaced with terms such as user equipment (UE), mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, or advanced mobile station (AMS).

[0043] Additionally, a transmitter refers to a fixed and / or mobile node that provides data or voice services, and a receiver refers to a fixed and / or mobile node that receives data or voice services. Therefore, for uplink, a mobile station can be the transmitter, and a base station can be the receiver. Similarly, for downlink, a mobile station can be the receiver, and a base station can be the transmitter.

[0044] Embodiments of the present disclosure are wireless access systems such as IEEE 802.xx system, 3rd Generation Partnership Project (3GPP) system, 3GPP Long Term Evolution (LTE) system, 3GPP 5G (5 th generation) NR (New Radio) system and 3GPP2 system, and in particular, embodiments of the present disclosure may be supported by 3GPP TS (technical specification) 38.211, 3GPP TS 38.212, 3GPP TS 38.213, 3GPP TS 38.321 and 3GPP TS 38.331 documents.

[0045] Furthermore, the embodiments of the present disclosure can be applied to other wireless access systems and are not limited to the aforementioned systems. For example, they can also be applied to systems implemented after the 3GPP 5G NR system, and are not limited to a specific system.

[0046] That is, obvious steps or parts not described in the embodiments of the present disclosure can be explained by referring to the above documents. In addition, all terms disclosed in this document can be explained by the above standard documents.

[0047] Hereinafter, preferred embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to illustrate exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the technical configurations of the present disclosure may be implemented.

[0048] Additionally, specific terms used in the embodiments of the present disclosure are provided to aid in understanding the present disclosure, and the use of such specific terms may be changed to other forms without departing from the technical spirit of the present disclosure.

[0049] The following technology can be applied to various wireless access systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access).

[0050]

[0051] For clarity, the following description is based on a 3GPP communication system (e.g., LTE, NR, etc.), but the technical spirit of the present invention is not limited thereto. LTE may refer to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 may be referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 may be referred to as LTE-A pro. 3GPP NR may refer to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. "xxx" refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system.

[0052] For background information, terms, abbreviations, etc. used in this disclosure, reference may be made to standard documents published prior to the present invention. For example, reference may be made to the 36.xxx and 38.xxx standard documents.

[0053] For terms, abbreviations, and other background technologies that may be used in this document, please refer to the following standard documents published prior to this document. In particular, terms, abbreviations, and other background technologies related to LTE / EPS (Evolved Packet System) can refer to the 36.xxx series, 23.xxx series, and 24.xxx series, and terms, abbreviations, and other background technologies related to NR (new radio) / 5GS (5G system) can refer to the 38.xxx series, 23.xxx series, and 24.xxx series.

[0054] Hereinafter, this specification is described based on the terms defined above.

[0055] The three key requirement areas for 5G include (1) Enhanced Mobile Broadband (eMBB), (2) Massive Machine Type Communication (mMTC), and (3) Ultra-reliable and Low Latency Communications (URLLC).

[0056] Some use cases may require optimization across multiple domains, while others may focus on just one Key Performance Indicator (KPI). 5G supports these diverse use cases in a flexible and reliable manner.

[0057]

[0058] Communication system applicable to the present disclosure

[0059] Although not limited thereto, the various descriptions, functions, procedures, proposals, methods and / or operational flowcharts of the present disclosure disclosed in this document may be applied to various fields requiring wireless communication / connectivity (e.g., 5G) between devices.

[0060] Hereinafter, more specific examples will be provided with reference to the drawings. In the drawings / descriptions below, the same drawing reference numerals may represent identical or corresponding hardware blocks, software blocks, or functional blocks, unless otherwise described.

[0061] Figure 1 illustrates an example of a communication system applied to the present disclosure.

[0062] Referring to FIG. 1, a communication system (100) applied to the present disclosure includes a wireless device, a base station, and a network. Here, the wireless device refers to a device that performs communication using a wireless access technology (e.g., 5G NR, LTE) and may be referred to as a communication / wireless / 5G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (extended reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Things) device (100f), and an AI (artificial intelligence) device / server (100g). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicles (100b-1, 100b-2) may include unmanned aerial vehicles (UAVs) (e.g., drones). The XR devices (100c) include augmented reality (AR) / virtual reality (VR) / mixed reality (MR) devices, and may be implemented in the form of head-mounted devices (HMDs), head-up displays (HUDs) installed in vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signage, vehicles, robots, etc. The portable devices (100d) may include smartphones, smart pads, wearable devices (e.g., smartwatches, smart glasses), computers (e.g., laptops, etc.), etc. The home appliances (100e) may include TVs, refrigerators, washing machines, etc. The IoT devices (100f) may include sensors, smart meters, etc. For example, the base station (120) and the network (130) may also be implemented as wireless devices, and a specific wireless device (120a) may act as a base station / network node to other wireless devices.

[0063] Wireless devices (100a to 100f) can be connected to a network (130) via a base station (120). AI technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (100g) via a network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, etc. The wireless devices (100a to 100f) can communicate with each other via the base station (120) / network (130), but can also communicate directly (e.g., sidelink communication) without going through the base station (120) / network (130). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). In addition, IoT devices (100f) (e.g., sensors) can communicate directly with other IoT devices (e.g., sensors) or other wireless devices (100a to 100f).

[0064] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a to 100f) / base stations (120), and base stations (120) / base stations (120). Here, the wireless communication / connection can be established through various wireless access technologies (e.g., 5G NR) such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and base station-to-base station communication (150c) (e.g., relay, IAB (integrated access backhaul)). Through the wireless communication / connection (150a, 150b, 150c), the wireless device and base station / wireless device, and base stations and base stations can transmit / receive wireless signals to / from each other. For example, the wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, based on various proposals of the present disclosure, at least some of various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), resource allocation processes, etc. may be performed.

[0065] Figure 2 illustrates an example of a UE applicable to the present disclosure.

[0066] Referring to FIG. 2, the UE (200) may include a processor (202), memory (204), a transceiver (206), one or more antennas (208), a power management module (241), a battery (242), a display (243), a keypad (244), a SIM (Subscriber Identification Module) card (245), a speaker (246), and a microphone (247).

[0067] The processor (202) may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed herein. The processor (202) may be configured to control one or more other components of the UE (200) to implement the descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed herein. A layer of a radio interface protocol may be implemented in the processor (202). The processor (202) may include an ASIC, other chipset, logic circuit, and / or data processing device. The processor (202) may be an application processor. The processor (202) may include at least one of a DSP, a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), and a modem (modulator and demodulator).

[0068] Memory (204) is operatively coupled to the processor (202) and can store various information for operating the processor (202). Memory (204) may include ROM, RAM, flash memory, memory cards, storage media, and / or other storage devices. When the implementation is implemented in software, the techniques described herein may be implemented using modules (e.g., procedures, functions, etc.) that perform the descriptions, functions, procedures, suggestions, methods, and / or operational flowcharts disclosed herein. The modules may be stored in memory (204) and executed by the processor (202). Memory (204) may be implemented within the processor (202) or external to the processor (202), in which case it may be communicatively coupled to the processor (202) via various methods known in the art.

[0069] A transceiver (206) is operably coupled to the processor (202) and is capable of transmitting and / or receiving wireless signals. The transceiver (206) may include a transmitter and a receiver. The transceiver (206) may include baseband circuitry for processing radio frequency signals. The transceiver (206) may control one or more antennas (208) to transmit and / or receive wireless signals.

[0070] The power management module (241) can manage the power of the processor (202) and / or the transceiver (206). The battery (242) can supply power to the power management module (241).

[0071] The display (243) can output the results processed by the processor (202). The keypad (244) can receive input to be used by the processor (202). The keypad (244) can be displayed on the display (243).

[0072] A SIM card (245) is an integrated circuit that securely stores an International Mobile Subscriber Identity (IMSI) and associated keys, and can be used to identify and authenticate subscribers in mobile devices such as mobile phones and computers. Additionally, many SIM cards can store contact information.

[0073] The speaker (246) can output sound-related results processed by the processor (202). The microphone (247) can receive sound-related input to be used by the processor (202).

[0074] In implementations of this specification, a UE may operate as a transmitter in the uplink and as a receiver in the downlink. In implementations of this specification, a base station may operate as a receiver in the uplink and as a transmitter in the downlink. In this specification, a base station may be referred to as a Node B (Node B), an eNode B (eNB), or a gNB, and may not be limited to a specific form.

[0075] In addition, for example, the UE may be implemented in various forms depending on the use case / service. The UE may be composed of various components, devices / parts, and / or modules. For example, each UE may include a communication device, a control device, a memory device, and additional components. The communication device may include a communication circuit and a transceiver. For example, the communication circuit may include one or more processors and / or one or more memories. For example, the transceiver may include one or more transceivers and / or one or more antennas. The control device is electrically connected to the communication device, the memory device, and the additional components, and may control the overall operation of each UE. For example, the control device may control the electrical / mechanical operation of each UE based on a program / code / command / information stored in the memory device. The control device may transmit information stored in the memory device to an external device (e.g., another communication device) via the communication device via a wireless / wired interface, or may store information received from an external device (e.g., another communication device) via the communication device via a wireless / wired interface in the memory device.

[0076] Additional components may be configured in various ways depending on the type of UE. For example, the additional components may include at least one of a power unit / battery, an input / output (I / O) device (e.g., an audio I / O port, a video I / O port), a driving device, and a computing device. In addition, the UE is not limited thereto, and may be implemented in the form of a robot (100a in FIG. 1), a vehicle (100b-1 and 100b-2 in FIG. 1), an XR device (100c in FIG. 1), a portable device (100d in FIG. 1), a home appliance (100e in FIG. 1), an IoT device (100f in FIG. 1), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (100g in FIG. 1), a base station (120 in FIG. 1), or a network node. UE can be used in mobile or fixed locations depending on the use case / service.

[0077] The various components, devices / parts, and / or modules of the UE may all be connected to each other via a wired interface, or at least some of them may be connected wirelessly via a communication device. In addition, each component, device / part, and / or module of the UE may further include one or more elements. For example, the control device may be configured by a set of one or more processors. For example, the control device may be configured by a set of a communication control processor, an application processor (AP), an electronic control unit (ECU), a graphics processing unit, and a memory control processor. As another example, the memory device may be configured by a random access memory (RAM), a dynamic random access memory (DRAM), a read-only memory (ROM), a flash memory, a volatile memory, a non-volatile memory, and / or a combination thereof.

[0078]

[0079] 5G system architecture applicable to the present disclosure

[0080] The 5G system is an advanced technology from the 4th generation LTE mobile communication technology. It supports new radio access technology (RAT: Radio Access Technology), extended LTE (eLTE) as an extended technology of LTE (Long Term Evolution), and non-3GPP (e.g., WLAN) access through the evolution or clean-state structure of the existing mobile communication network structure.

[0081] 5G systems are defined as service-based, and the interactions between network functions (NFs) within the architecture for 5G systems can be expressed in two ways as follows.

[0082] - Reference point representation: Represents the interaction between NF services within NFs described by a point-to-point reference point (e.g., N11) between two NFs (e.g., AMF and SMF).

[0083] Service-based representation: Network functions (e.g., AMF) within the control plane (CP) allow other authorized network functions to access their services. This representation also includes point-to-point reference points, if necessary.

[0084] 5GC (5G Core) can include various components, some of which include access and mobility management function (AMF), session management function (SMF), policy control function (PCF), user plane function (UPF), application function (AF), unified data management (UDM), and non-3GPP interworking function (N3IWF).

[0085] The UE connects to the data network via the UPF via the next-generation radio access network (NG-RAN) that includes the gNB. The UE can receive data services via untrusted non-3GPP access points, such as wireless local area networks (WLANs). To connect non-3GPP access points to the core network, an N3IWF may be deployed.

[0086] The N3IWF manages interworking between non-3GPP access and 5G systems. When a UE is connected to a non-3GPP access (e.g., WiFi, also known as IEEE 802.11), it can connect to a 5G system via the N3IWF. The N3IWF performs control signaling with the AMF and connects to the UPF via the N3 interface for data transmission.

[0087] AMF can manage access and mobility in 5G systems. It can also manage non-access stratum (NAS) security. It can also handle mobility in idle states.

[0088] The UPF functions as a gateway for transmitting and receiving user data. A UPF node can perform all or part of the user plane functions of a 4G mobile communications S-GW (serving gateway) and P-GW (packet data network gateway).

[0089] The UPF acts as a boundary point between the next generation RAN (NG-RAN) and the core network, and is an element that maintains the data path between the gNB and the SMF. In addition, the UPF acts as a mobility anchor point when the UE moves across the area served by the gNB. The UPF can perform the function of handling PDUs. For mobility within the NG-RAN (e.g., NG-RAN defined after 3GPP Release-15), the UPF can route packets. In addition, the UPF can also act as an anchor point for mobility with other 3GPP networks (e.g., RAN defined before 3GPP Release-15), such as UTRAN (UMTS (universal mobile telecommunications system) terrestrial radio access network), E-UTRAN (evolved-UTRAN), or GERAN (GSM (global system for mobile communication) / EDGE (enhanced data rates for global evolution) radio access network). A UPF may correspond to the termination point of a data interface toward a data network.

[0090] The PCF is a node that controls the operator's policies. The AF is a server that provides various services to UEs. The UDM is a server that manages subscriber information, similar to the HSS (home subscriber server) of 4G mobile communications. The UDM (460) stores and manages subscriber information in a unified data repository (UDR).

[0091] The SMF can perform the function of assigning an IP (Internet protocol) address to the UE. In addition, the SMF can control the PDU (protocol data unit) session.

[0092] For convenience of explanation below, the drawing symbols for AMF, SMF, PCF, UPF, AF, UDM, N3IWF, gNB, or UE may be omitted, and operation may be performed by referring to the matters described in standard documents published prior to this document.

[0093] Figure 3 illustrates an example of functional separation of NG-RAN and 5GC (5th generation core) applicable to the present disclosure.

[0094] Referring to Figure 3, the UE connects to a data network (DN) via a next-generation RAN. The control plane function (CPF) node performs all or part of the functions of the mobility management entity (MME) of 4G mobile communications, and all or part of the control plane functions of the serving gateway (S-GW) and the PDN gateway (P-GW). The CPF node includes the AMF and the SMF.

[0095] The UPF node functions as a gateway through which user data is transmitted and received.

[0096] The authentication server function (AUSF) authenticates and manages UEs. The Network Slice Selection Function (NSSF) is a node for network slicing, as described below.

[0097] The network exposure function (NEF) provides a mechanism to securely expose the services and functions of the 5G core.

[0098] The reference points shown in Fig. 3 are as follows. N1 represents a reference point between the UE and the AMF. N2 represents a reference point between the (R)AN and the AMF. N3 represents a reference point between the (R)AN and the UPF. N4 represents a reference point between the SMF and the UPF. N5 represents a reference point between the PCF and the AF. N6 represents a reference point between the UPF and the DN. N7 represents a reference point between the SMF and the PCF. N8 represents a reference point between the UDM and the AMF. N9 represents a reference point between the UPFs. N10 represents a reference point between the UDM and the SMF. N11 represents a reference point between the AMF and the SMF. N12 represents a reference point between the AMF and the AUSF. N13 represents a reference point between the UDM and the AUSF. N14 represents a reference point between the AMFs. N15 represents a reference point between a PCF and an AMF in a non-roaming scenario, and a reference point between an AMF and a PCF of a visited network in a roaming scenario. N16 represents a reference point between SMFs. N22 represents a reference point between an AMF and an NSSF. N30 represents a reference point between a PCF and an NEF. N33 may represent a reference point between an AF and an NEF, and the entities and interfaces described above may be configured with reference to those described in standard documents published before this document. N58 represents a reference point between an AMF and an NSSAAF. N59 represents a reference point between a UDM and an NSSAAF. N80 represents a reference point between an AMF and an NSACF. N81 represents a reference point between an SMF and an NSACF.

[0099] The radio interface protocol is based on the 3GPP radio access network standard. Horizontally, the radio interface protocol consists of the physical layer, data link layer, and network layer. Vertically, it is divided into the user plane for data information transmission and the control plane for control signaling.

[0100] Protocol layers can be divided into L1 (layer-1), L2 (layer-2), and L3 (layer-3) based on the three lower layers of the open systems interconnection (OSI) standard model, which is widely known in communication systems.

[0101] Below, the present disclosure describes each layer of the wireless protocol. Figure 4 illustrates an example of a general architecture of a 5G (5th generation) system applicable to the present disclosure.

[0102] Referring to FIG. 4, the AS (access stratum) layer may include a physical (PHY) layer, a medium access control layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, and a radio resource control (RRC) layer, and operations based on each layer may be performed by referring to matters described in standard documents published prior to this document.

[0103]

[0104] Specific embodiments of the present disclosure

[0105] The present disclosure relates to a device and method for obtaining a security key in a wireless communication system. Specifically, the present disclosure relates to a device and method for storing at least a portion of a security key obtained during a registration procedure and an authentication procedure of a terminal in a wireless communication system, and generating a new security key for reconnection of the terminal using at least a portion of the security key. The background art, terminology, and / or abbreviations used in the present disclosure may further refer to matters described in standard documents published prior to the present disclosure, such as 3GPP TS 23.501, 3GPP TS 33.501, and 3GPP TS 23.501.

[0106]

[0107] A terminal or device that does not support 5GC (5G Core) NAS signaling over WLAN access is referred to as an N5CW (non-5G-capable over WLAN) terminal. Unlike general 5G terminals that support NAS signaling, N5CW terminals do not support NAS signaling. Therefore, N5CW terminals are linked to 5GC through an NF that acts as a proxy between the N5CW terminal and the 5G system. That is, the N5CW terminal is registered with the 5G system by performing a registration procedure through the NF that acts as a proxy. In addition, the N5CW terminal can perform an authentication procedure with 5GC through the NF that acts as a proxy server during the registration procedure. When performing the authentication procedure of the N5CW terminal, a security context, which is information necessary for security, is created. The security context is used to secure future signaling or traffic data of the N5CW terminal. When an N5CW terminal attempts to reconnect to 5GC, a new authentication procedure is performed for the N5CW terminal via NF, which acts as a proxy server, thereby generating new security information. In other words, when an N5CW terminal attempts to reconnect to 5GC, even if previously generated security information exists, new security information is generated through a new authentication procedure. The present disclosure discloses a method for reusing previously generated security information without performing a new authentication procedure when an N5CW terminal reconnects to 5GC.

[0108]

[0109] According to 3GPP TS 23.501[1], the 5G system architecture is defined to support deployable data connectivity and services using technologies such as network function virtualization and software defined networking. The 5G system architecture leverages service-based interactions between identified control plane (CP) network functions. Specifically, the 5G system architecture allows each network function and its corresponding network function services to interact with other NFs and their corresponding network function services, directly or indirectly, via service communication proxies, if necessary. The 5G system architecture does not preclude the use of other intermediate functions to facilitate the routing of control plane messages. Furthermore, the 5G system architecture minimizes dependencies between the access network (AN) and the core network (CN). The 5G system architecture is defined as a converged core network with a common AN-CN interface that integrates different access types.

[0110] According to section 4.12b of TS 23.502, an N5CW terminal can access a 5GC of a PLMN or SNPN via a trusted WLAN access network that supports the trusted WLAN interworking function (TWIF). In this case, the N5CW terminal can support 5G via 3GPP access and can be treated as a 5G terminal via 3GPP access. The method for an N5CW terminal to connect to a trusted WLAN access network and simultaneously register with a 5G core network is as illustrated in FIGS. 5a, 5b, and 5c. In other words, FIGS. 5a, 5b, and 5c illustrate the initial registration and PDU session establishment procedures of an N5CW terminal, which are described as defined in section 4.12b.2.1 of TS 23.502. Steps 1-10 are procedures for initial registration of the N5CW terminal, steps 20-21 are procedures for establishing a PDU session, and step 25 is a user plane communication procedure. As illustrated in FIGS. 5a, 5b, and 5c, a single extensible authentication protocol (EAP)-based authentication procedure is performed for connection of the N5CW terminal to a trusted WLAN access network and registration of the N5CW terminal to a 5G core network. Specifically, the AMF of the 5G core network sends a request indicating the access network (AN) type to the AUSF, thereby triggering the authentication and key agreement (AKA) procedure, which is an EAP-based authentication procedure. The authentication and key agreement procedure is performed between the N5CW terminal and the AUSF, and the EAP message is encapsulated within the NAS authentication message via the N2 interface. The type of the EAP authentication procedure is as defined in TS 33.501

[0015] .If authentication is successful, the AMF obtains or derives the AN key from the SEAF key provided by the AUSF and provides the AN key to the TWIF. The TWIF derives the Pairwise Master Key (PMK) from the AN key. The PMK is used to secure WLAN air interface communications according to IEEE Std 802.11

[0048] .

[0111]

[0112] N5CW terminals can register with 5GC using 3GPP credentials and establish 5GC connectivity through a trusted WLAN access network. The reference architecture for this is as described in section 4.2.8.5 of TS 23.501[2]. 3GPP credentials are stored as defined in section 6.1.1.1. TWIF provides interworking functions that enable connection with 5GC, implements the NAS protocol stack, and exchanges NAS messages with AMF on behalf of N5CW terminals. A single EAP-AKA authentication procedure is performed to connect N5CW terminals to a trusted WLAN access network and the 5G core network.

[0113] Figures 6a and 6b illustrate the authentication procedure for an N5CW terminal. The authentication procedure for an N5CW terminal is as defined in section 7A.2.4 of TS 33.501. First, the N5CW terminal selects a PLMN and a trusted WLAN that supports "5G connectivity-without-NAS" for the PLMN using the procedure defined in "Access network selection for terminals not supporting 5GC NAS over WLAN" in section 6.3.12a of TS 23.501[2].

[0114] Steps 1 to 10 of FIGS. 6A and 6B correspond to the initial registration procedure of a terminal for 5GC. In step 1, the N5CW terminal connects to a trusted WLAN network, and the EAP-AKA authentication procedure is initiated. In steps 2a, 2b, and 2c, the N5CW terminal provides a network access identifier (NAI). A trusted WLAN access point (TWAP) selects a TWIF, for example, based on the received realm, and sends an AAA request to the selected TWIF. When the N5CW terminal first registers with 5GC via 3GPP access at the start of the procedure described above, the NAI includes a subscription concealed identifier (SUCI). The SUCI can be configured as defined in section 6.12.2 of TS 33.501. Alternatively, if the N5CW terminal is registered with 5GC via 3GPP access at the start of the aforementioned procedure, the NAI includes the 5G-GUTI (5G-globally unique temporary UE identity) assigned to the N5CW terminal via 3GPP access. This allows the TWIF to select the AMF that provides services to the N5CW terminal via 3GPP access in step 4a.

[0115] In Step 3, TWIF generates a 5GC registration request message on behalf of the N5CW terminal and fills in the parameters in the registration request message using default values. This is the same for all N5CW terminals that do not support 5G NAS. The registration type indicates 'initial registration.'

[0116] In step 4, the TWIF selects an AMF and sends an N2 message containing a registration request, user location, and AN type to the selected AMF. The AN type may indicate that the terminal is a non-3GPP terminal. For example, if an NAI containing a 5G-GUTI is provided by an N5CW terminal, the TWIF may select an AMF using the 5G-GUTI included in the NAI.

[0117] In step 5, if the AMF triggers the authentication procedure, the AMF sends a request to the AUSF by sending a Nausf_UEAuthentication_Authenticate request message. The Nausf_UEAuthentication_Authenticate request message includes a SUCI or subscription permanent identifier (SUPI). Additionally, the Nausf_UEAuthentication_Authenticate request message includes an indicator indicating that the request was received from an N5CW terminal. At this time, if a valid 5G-GUTI is received by the AMF, the Nausf_UEAuthentication_Authenticate request message may include the SUPI. Even if the AMF already has a security context identified by the 5G-GUTI, the AMF initiates primary authentication.

[0118] In step 6, AUSF sends a Nudm_UEAuthentication_Get request to UDM containing SUCI or SUPI and N5CW indication.

[0119] In step 7, upon receiving a Nudm_UEAuthentication_Get request, the UDM calls the subscription identifier de-concealing function (SIDF) if a SUCI is received. SIDF conceals the SUCI to obtain the SUPI before the UDM processes the request. The UDM selects the authentication method based on the "realm" portion of the SUPI, the N5CW terminal indicator, a combination of the "realm" portion and the N5CW terminal indicator, or the UDM local policy.

[0120] In step 8, the EAP-AKA' procedure is triggered to perform mutual authentication between the N5CW terminal and the home network. The EAP-AKA' procedure is performed as defined in section 6.1.3.1 of TS 33.501, but occurs between the N5CW terminal and the AUSF. Through the N2 interface, the EAP message is encapsulated within the NAS authentication message. The EAP-AKA' messages exchanged between the N5CW terminal and the TWIF are encapsulated in Layer 2 packets, such as IEEE 802.3 / 802.1x packets, IEEE 802.11 / 802.1x packets, PPP packets, etc.

[0121] This scenario does not require a NAS security context. In step 9, the AMF receives the K AMF K from key TWIF Key derivation. NAS security between AMF and TWIF is set up similarly to unauthenticated emergency calls. For example, NAS security can be set up using NULL encryption and NULL integrity protection. Note that N5CW terminals do not support NAS. As an EK, N5CW terminals cannot utilize NAS counts.

[0122] In step 10a, AMF sends NAS security mode command to TWIF. NAS security mode command includes EAP-success message and NULL security algorithm information. In step 10b, TWIF does not directly forward EAP-success to N5CW. TWIF stores EAP-success message and K TWIF In step 10c, TWIF sends a security mode completion message to AMF.

[0123] In step 11, AMF sends N2 initial context setup request and K TWIF The key is provided to the TWIF. In step 12, the TWIF provides K as defined in appendix A.22 of TS 33.501. TNGF TNAP key K from key TNAP and sends a TNAP key and an EAP-Success message to the TWAP, which forwards the EAP-Success to the N5CW terminal. The TNAP key corresponds to the pairwise master key (PMK) used to secure WLAN air interface communications according to IEEE 802.11

[0080] . A Layer 2 or Layer 3 connection is established between a trusted WLAN access point and the TWIF to forward all user plane traffic of the N5CW terminal to the TWIF. This connection is later bound to the N3 connection created for the N5CW terminal.

[0124] In step 13, TWIF sends an N2 Initial Context Setup Response message to AMF. Step 14 is as defined in section 4.12b.2 of TS 23.502[8].

[0125]

[0126] According to section 6.1.3.1 of TS 33.501, EAP-AKA' is defined in RFC 5448

[0012] , and the 3GPP 5G profile for EAP-AKA' is specified in normative annex F. The usage options for EAP-AKA' are as defined in section 6.1.2 of TS 33.501.

[0127] Figure 7 illustrates an authentication procedure for EAP-AKA' applicable to the present disclosure. Referring to Figure 7, in step 1, UDM / ARPF generates an authentication vector using the authentication management field (AMF) separation bit = 1, as defined in TS 33.102 [9]. UDM / ARPF calculates CK' and IK' according to normative Annex A, and replaces CK and IK with CK' and IK'.

[0128] In step 2, the UDM sends the converted authentication vector AV'(RAND, AUTN, XRES, CK', IK') to the AUSF that received the Nudm_UEAuthentication_Get request using the Nudm_UEAuthentication_Get response message along with an indication that AV' is used for EAP-AKA'. Note that the exchange of Nudm_UEAuthentication_Get request message and Nudm_UEAuthentication_Get response message between the AUSF and the UDM / ARPF is<network name> Same as trusted access using EAP-AKA' as defined in step 10 of subclause 6.2 of TS 33.402

[0011] , except for the input parameter for key derivation, which is the value of "network name". The "network name" is a concept from RFC 5448

[0012] , and is conveyed in the AT_KDF_INPUT attribute of EAP-AKA'.<network name> The value of the parameter is not defined in RFC 5448

[0012] , but is defined in the 3GPP specifications. For EPS, it is defined as "access network identity" in TS 24.302

[0071] , and for 5G, it is defined as "serving network name" in subclause 6.1.1.4 of TS 33.501.

[0129] If the Nudm_UEAuthentication_Get request includes SUCI, UDM includes SUPI in the Nudm_UEAuthentication_Get response. If the subscriber has an AKMA subscription, UDM must include an AKMA indication and routing indicator in the Nudm_UEAuthentication_Get response.

[0130] In step 3, AUSF sends an EAP-Request / AKA'-Challenge message to SEAF using the Nausf_UEAuthentication_Authenticate response message.

[0131] In step 4, SEAF transparently forwards the EAP-Request / AKA'-Challenge message to the UE using the NAS message authentication request message. The ME forwards the RAND and AUTN received via the EAP-Request / AKA'-Challenge message to the USIM. The authentication request message includes the ngKSI and ABBA parameters. In fact, SEAF includes the ngKSI and ABBA parameters in all EAP authentication request messages. The ngKSI is used to identify the partial native security context that is created when the UE and AMF successfully authenticate. SEAF sets the ABBA parameters as defined in Appendix A.7.1. During EAP authentication, the values ​​of the ngKSI and ABBA parameters sent from SEAF to the UE are not changed. Note that SEAF can determine that the authentication method being used is the EAP method by evaluating the type of authentication method based on the Nausf_UEAuthentication_Authenticate response message.

[0132] In step 5, upon receiving RAND and AUTN, the USIM verifies the freshness of AV' by checking whether the AUTN is accepted as described in TS 33.102 [9]. If so, the USIM computes the response RES. The USIM returns RES, CK, and IK to the ME. If the USIM computes Kc (i.e., GPRS Kc) from CK and IK using the conversion function c3 as described in TS 33.102 [9] and transmits it to the ME, the ME ignores such GPRS Kc and does not store GPRS Kc in the USIM or the ME. The ME derives CK' and IK' according to Annex A.3. If the AUTN verification on the USIM fails, the USIM and the ME proceed as described in subclause 6.1.3.3.

[0133] In step 6, the UE sends an EAP-Response / AKA'-Challenge message to SEAF via an NAS message Auth-Resp message.

[0134] In step 7, SEAF transparently forwards the EAP-Response / AKA'-Challenge message to AUSF via a Nausf_UEAuthentication_Authenticate request message.

[0135] In step 8, the AUSF verifies the message by comparing the XRES and RES. If the AUSF successfully verifies the message, it performs the next step; otherwise, it returns an error to the SEAF. The AUSF notifies the UDM of the authentication result. For more information on linking authentication confirmation, see subclause 6.1.4 of TS 33.501.

[0136] In step 9, the AUSF and the UE exchange EAP-Request / AKA'-Notification and EAP-Response / AKA'-Notification messages via SEAF. SEAF forwards these messages transparently. Note that EAP-Notification as described in RFC 3748

[0027] and EAP-AKA-Notification as described in RFC 4187

[0021] may be used at any time in an EAP-AKA exchange. Such notifications may be used, for example, for a protected result indication or when the EAP server detects an error in the received EAP-AKA response.

[0137] In step 10, AUSF derives EMSK from CK' and IK' as described in RFC 5448

[0012] and Annex F. AUSF converts the most significant 256 bits of EMSK to K AUSF As used in Section A.6, K AUSF In K SEAF AUSF sends an EAP success message to SEAF in the Nausf_UEAuthentication_Authenticate response, which SEAF transparently forwards to the UE. The Nausf_UEAuthentication_Authenticate response message contains K SEAF When the AUSF receives SUCI from SEAF when authentication is initiated (see subsection 6.1.2), the AUSF includes SUPI in the Nausf_UEAuthentication_Authenticate response message. The AUSF may also include K according to the home network operator's policy as per subsection 6.1.1.1. AUSF Save it.

[0138] In step 11, SEAF sends an EAP success message to the UE via an N1 message. This message includes ngKSI and ABBA parameters. SEAF sets the ABBA parameters as defined in Appendix A.7.1. Note that step 11 may be a NAS security mode command or an authentication result. The ABBA parameters are included to enable bidding down protection for security features that may be introduced later.

[0139] The key received in the Nausf_UEAuthentication_Authenticate response message is an anchor key K in the sense of the key hierarchy of subclause 6.2 of TS 33.501. SEAF SEAF is K in accordance with Appendix A.7. SEAF , K from ABBA parameters and SUPI AMF Induce and derive K AMF The UE, upon receiving the EAP-Success message, derives the EMSK from CK' and IK' as described in RFC 5448 and Appendix F. The ME converts the most significant 256 bits of the EMSK to K AUSF and used in the same way as AUSF K SEAF Calculate K according to Appendix A.7. SEAF , derive KAMF from ABBA parameters and SUPI.

[0140] As an implementation option, the UE creates a temporary security context as described in step 11 after receiving an EAP message that allows EMSK calculation. If the UE receives a successful EAP, it transitions the temporary security context to a partial security context. If EAP authentication fails, the UE removes the temporary security context.

[0141] Upon receiving a successfully validated EAP-Response / AKA'-Challenge message, the additional steps performed by the AUSF are described in subclause 6.1.4 of TS 33.501. If the EAP-Response / AKA'-Challenge message is not successfully validated, the policy of the home network determines the subsequent AUSF actions. If the AUSF and SEAF determine that authentication is successful, the SEAF sends ngKSI and K AMF provides to AMF.

[0142]

[0143] Figure 8 illustrates a key hierarchy generation structure of 5GS applicable to the present disclosure. The key hierarchy generation structure illustrated in Figure 8 is defined in Section 6.2 of TS 33.501.

[0144] Referring to Figure 8, the keys involved in authentication include the K key, the CK key, and the IK key. For EAP-AKA', the CK' key and the IK' key are derived from the CK key and the IK key as defined in 6.1.3.1 of TS 33.501. The key hierarchy is K AUSF , K SEAF , K AMF , K NASint , K NASenc , K N3IWF , K gNB , K RRCint , K RRCenc , K UPint and K UPenc Includes keys such as:

[0145] K is the key for AUSF within your home network AUSF is derived from CK' and IK', or CK and IK. That is, for EAP-AKA', K AUSF are derived from CK' and IK' by ME and AUSF. At this time, CK' and IK' are received as part of AV converted from ARPF in AUSF. For 5G AKA, K AUSFis derived from CK and IK by ME and ARPF. At this time, K AUSF is received from ARPF at AUSF as part of 5G HE AV.

[0146] K SEAF is K by ME and AUSF AUSF The anchor key is derived from and is provided to the SEAF of the serving network by the AUSF.

[0147] K is the key for AMF in the serving network AMF is K by ME and SEAF SEAF is derived from K AMF is additionally derived by the ME and source AMF during horizontal key derivation.

[0148] K is the key for NAS signaling NASint is K by ME and AMF AMF is derived from and is used to protect NAS signaling using a specific integrity algorithm. In addition, K, which is a key for NAS signaling, NASenc is K by ME and AMF AMF It is derived from and used to protect NAS signaling using a specific encryption algorithm.

[0149] K is the key for NG-RAN gNB is K by ME and AMF AMF is derived from K gNB is further derived by ME and source gNB during horizontal or vertical key derivation, and K between ME and ng-eNB gNB It is used as.

[0150] K is the key for UP traffic UPenc is K by ME and gNB gNB is derived from and is used to protect UP traffic using a specific encryption algorithm. In addition, K, the key for UP traffic, UPintis K by ME and gNB gNB It is derived from and used to protect UP traffic between ME and gNB using a specific integrity algorithm.

[0151] K is the key for RRC signaling RRCint is K by ME and gNB gNB is derived from and is used to protect RRC signaling using a specific integrity algorithm. In addition, K, which is a key for RRC signaling, RRCenc is K by ME and gNB gNB It is derived from and used to protect RRC signaling using a specific encryption algorithm.

[0152] NH, one of the intermediate keys, is derived by ME and AMF to provide forward security. In addition, K, one of the intermediate keys NG-RAN * is derived by the ME and NG-RAN (e.g. gNB or ng-eNB) during horizontal or vertical key derivation using a key derivation function (KDF) as defined in clauses A.11 and / or A.12 of TS 33.501. In addition, one of the intermediate keys, K AMF ' can be derived by the ME and the AMF when moving from one AMF to another during inter-AMF mobility using the KDF as specified in Annex A.13 of TS 33.501.

[0153] Key K for non-3GPP N3IWF is K for non-3GPP access by ME and AMF. AMF is derived from K N3IWF is not transmitted between N3IWFs.

[0154]

[0155] K AMF From K gNB , KWAGF , K TNGF , K TWIF and K N3IWF When deriving keys and NAS counts in UE and AMF, the following input parameters are used to form the input S for the key derivation function (KDF).

[0156] - FC = 0x6E

[0157] - P0 = uplink NAS count

[0158] - L0 = length of uplink NAS count (e.g. 0x00 0x04)

[0159] - P1 = access type distinguisher

[0160] - L1 = length of access type distinguisher (e.g. 0x00 0x01)

[0161] The values ​​of the access type identifiers are defined as in [Table 1]. This is the same as Table A.9-1 of Section A.9 of TS 33.501.

[0162] Access type distinguisher value 3GPP access0x01 Non 3GPP access0x02

[0163] The values ​​0x00 and 0x03~0xf0 are reserved for future use, and the values ​​0xf1~0xff are reserved for private use. K gNB The access type identifier for induction must be set to 0x01, which is the value for 3GPP, and K N3IWF , K WAGF , K TWIF , or K TNGFThe access type identifier in the induction must be set to 0x02, which is the value for non-3GPP. The input key, KEY, is a 256-bit K AMF The key derivation function is applied when a 5G wireless bearer protected by encryption is established and the key change is performed on-the-fly. Since the N5CW terminal does not support NAS via non-3GPP access, the uplink NAS count is K TWIF Must be set to 0 for key generation (see Section 7A.2.4).

[0164]

[0165] As described above, N5CW terminals can receive 5G system service support through a NF called TWIF, which acts as a proxy between non-3GPP access and the 5G system. Since N5CW terminals do not support NAS signaling, a protocol between the terminal and the 5G system, TWIF acts as a substitute to support NAS signaling. In other words, N5CW terminals can be registered with the 5G system by performing an initial registration procedure through TWIF. During the initial registration phase, security information, i.e., a security context, is generated through a mutual authentication procedure between the N5CW terminal and the 5G system.

[0166] Meanwhile, according to the prior art, when an N5CW terminal registered to a 5G system reconnects to the 5G system through the same TWIF or attempts to reconnect to the 5G system through a new TWIF due to a change in location, the mutual authentication procedure between the N5CW terminal and the 5G system is performed again. This is to prevent the N5CW terminal and the 5G system from using the same security key as before by changing the root key through the new authentication procedure. However, if the authentication procedure is performed every time the N5CW terminal reconnects to the 5G system, the terminal's service may be affected. Therefore, in Rel-19, discussions are underway to minimize the impact of the new authentication procedure on terminal service delays in situations such as the above-mentioned.

[0167] To address the aforementioned issues, the present disclosure proposes a method that utilizes existing security context, i.e., security information, without performing a new authentication procedure, thereby preventing N5CW terminals and 5G systems from using the same security key as before. In other words, the present disclosure discloses a method that minimizes terminal service delays by generating a new security key for data encryption using security information acquired during a previous registration procedure.

[0168] Specifically, the present disclosure discloses a method and device for newly generating only a security key necessary for data encryption, instead of repeatedly re-performing an authentication procedure when an N5CW terminal reconnects to a 5GC.

[0169] The scenario where an N5CW terminal wants to reconnect to a 5G system via a trusted WLAN is as follows.

[0170] 1) When the N5CW terminal is connected to TWIF and then disconnected, and then connects to a new TWIF.

[0171] 2) When the N5CW terminal is connected to TWIF, then disconnected, and then reconnected to the same TWIF.

[0172] 3) When the N5CW terminal is connected to a WLAN AP and then disconnected, and then connects to a new WLAN AP belonging to the same TWIF.

[0173] In scenarios like the above, 5GC may already have a security context for the N5CW terminal through a previous registration procedure. Therefore, the present disclosure proposes a method for generating a new security key based on the existing security context without repeatedly performing the authentication procedure between the N5CW terminal and the 5G system in scenarios like the above.

[0174]

[0175] Figure 9a illustrates an example of a security key acquisition procedure according to one embodiment of the present disclosure. Figure 9a illustrates a method performed by a first network node. The first network node may be an AMF, or an AMF and a SEAF.

[0176] Referring to FIG. 9A, in step S901, a first network node receives a registration request message. In other words, the first network node may receive an N2 message including the registration request message from a second network node acting as a proxy between the N5CW terminal and the 5GC system. The second network node may include a TWIF supporting NAS signaling. The N2 message may further include at least one of a user location or an AN type. The AN type is information indicating the access network type of the terminal requesting registration, which may indicate that the terminal is a non-3GPP terminal. The registration request message may include at least one of a registration type, an NAI, a requested NSSAI, or 5GC capability information. Here, the registration type may indicate whether the registration request is an initial registration. The NAI may include SUCI or 5G-GUTI based on whether the N5CW terminal is registered with the 5GC via 3GPP access. For example, if the N5CW terminal is not registered in the 5GC via 3GPP access, the NAI may include SUCI, and if the N5CW terminal is already registered in the 5GC via 3GPP access, the NAI may include 5G-GUTI. In other words, if the registration request message is a message for initial registration of the N5CW terminal, the registration request message may include SUCI. On the other hand, if the registration request message is a message for reconnection of the N5CW terminal, the registration request message may include 5G-GUTI assigned to the N5CW terminal during initial registration.

[0177] At step S903, the first network node obtains a second security key based on the first security key. The first security key is K AMF , and the second security key is K TWIFmay include. The first security key may be obtained based on any one of an authentication and key agreement procedure, NAS key re-keying, NAS key refresh, or an interworking procedure with EPS. Here, the authentication and key agreement procedure may include an EAP-AKA' authentication procedure performed during initial registration. For example, the first network node may obtain a K obtained according to the authentication and key agreement procedure. SEAF Based on K AMF can be obtained.

[0178] The second security key can be obtained by further utilizing the uplink NAS count or the pre-stored security information based on whether there is pre-stored security information for the N5CW terminal. If there is no pre-stored security information for the N5CW terminal, the first network node can obtain the second security key based on the first security key and the uplink NAS count. The uplink NAS count is a value related to the NAS connection, and a new K AMFWhen generated, it can be set to have a start value. For example, the start value of the uplink NAS count can be 0. In other words, if there is no pre-stored security information for the N5CW terminal, the first network node can obtain the second security key based on the first security key and the uplink NAS count set to 0. Here, the uplink NAS count is set to 0 because the N5CW terminal does not support NAS signaling. On the other hand, if there is pre-stored security information for the N5CW terminal, the first network node can obtain the second security key based on the first security key and the pre-stored security information. The pre-stored security information can include at least a portion of the second security key obtained during a previous registration procedure. When the second security key is obtained, the first network node can store at least a portion of the obtained second security key as security information for the N5CW terminal.

[0179] In step S905, the first network node transmits a message including a second security key. The first network node transmits a message including the second security key to the second network node. The message including the second security key may include an N2 initial context setup request message. The second security key is used to generate a PMK, and the PMK may be used to obtain a WALN key used for security setup for a wireless interface between the N5CW terminal and the TWAP.

[0180]

[0181] Figure 9b illustrates an example of a security establishment procedure according to one embodiment of the present disclosure. Figure 9b illustrates a method performed by a terminal. The terminal may be an N5CW terminal.

[0182] Referring to FIG. 9B, in step S911, the terminal transmits an authentication-related message. The terminal transmits the authentication-related message including an NAI to a second network node. The second network node may be included in a WLAN access network and may include a TWIF that supports NAS signaling to a first network node (e.g., AMF) on behalf of the terminal. In other words, the terminal may transmit the authentication-related message including an NAI to the TWIF via the TWAP. Specifically, the terminal initiates an EAP-based authentication procedure by connecting to the TWAP and receives an EAP-Req / Identify message requesting terminal identification information from the TAWP. Thereafter, the terminal transmits an EAP-Res / Identify message including an NAI to the TWAP, and the TWAP transmits a message including the NAI received from the terminal to the TWIF. The NAI may include SUCI or 5G-GUTI. For example, when the terminal performs initial registration with the 5GC via 3GPP access, the NAI may include SUCI. On the other hand, if the terminal is already registered with 5GC via the selected 3GPP access, i.e., performing a reconnection, the NAI may contain the 5G-GUTI assigned to the terminal via the 3GPP access.

[0183] In step S913, the terminal receives an authentication success message. The terminal receives the authentication success message from the second network. The authentication success message may include an EAP-success message. During initial registration of the terminal, the terminal may receive the authentication success message after performing the authentication key agreement procedure. Conversely, upon reconnection, the terminal may receive the authentication success message without performing the authentication key agreement procedure.

[0184] In step S915, the terminal establishes security based on the PMK. The terminal obtains a WLAN key based on the PMK and performs a security configuration procedure for the wireless interface based on the WLAN key. At this time, the TWAP performs an L2 or L3 connection between the TWIF and the terminal using the PMK. The PMK may be generated or derived by the terminal or may be received from a second network node. For example, the terminal may obtain a second security key based on the first security key and obtain the PMK based on the second security key. The first security key is K AMF , and the second security key is K TWIF may include. The first security key may be obtained based on any one of an authentication and key agreement procedure, NAS key re-keying, NAS key refresh, or an interworking procedure with EPS. Here, the authentication and key agreement procedure may include an EAP-AKA' authentication procedure performed during initial registration. For example, the terminal may obtain a K based on the authentication and key agreement procedure. SEAF From K AMF can be obtained. The terminal has the first security key, K AMF Based on the second security key, K TWIFHowever, the second security key may be obtained by further utilizing the uplink NAS count set to 0 or the pre-stored security information based on whether initial registration has been performed and / or whether pre-stored security information exists. Here, whether the initial registration has been performed may be determined based on whether 5G-GUTI has been allocated to the terminal. If the initial registration has not been performed or the pre-stored security information does not exist, the terminal may obtain the second security key based on the first security key and the uplink NAS count set to 0. Here, the uplink NAS count is set to 0 because the N5CW terminal does not support NAS signaling. On the other hand, if the initial registration has already been performed or pre-stored security information exists, the terminal may obtain the second security key based on the first security key and the pre-stored security information. The pre-stored security information may include at least a portion of the second security key obtained during a previous registration procedure of the terminal. When a second security key is obtained, the terminal can store at least a portion of the obtained second security key as security information and derive a PMK based on the second security key.

[0185]

[0186] FIG. 10 illustrates a specific procedure for obtaining a security key according to one embodiment of the present disclosure. FIG. 10 illustrates a method performed by a first network node. The first network node may be an AMF, or an AMF and a SEAF.

[0187] Referring to FIG. 10, in step S1001, the first network node detects reconnection. In other words, the first network node receives a registration request message from the second network node, and can detect reconnection of the N5CW terminal based on at least one of the registration type and NAI in the received registration request message. For example, if the NAI included in the registration request message is 5G-GUTI, the first network node can detect that a registration request message for reconnection of the N5CW terminal has been received. Here, the second network node may include a TWIF that supports NAS signaling on behalf of the N5CW terminal.

[0188] In step S1003, the first network node can check whether there is pre-stored security information. In other words, the first network node can check whether there is pre-stored security information at the time of initial registration or previous connection of the N5CW terminal. Here, the pre-stored security information is K acquired at the time of initial registration or previous connection. TWIF may include at least a portion of

[0189] If there is pre-stored security information, the first network node generates a second security key using the uplink NAS count set based on the pre-stored security information in step S1005. In other words, the first network node sets the uplink NAS count based on the pre-stored security information, and K AMFAnd the second security key can be generated using the uplink NAS count set based on the previously stored security information. The previously stored security information can be set as the uplink NAS count. The first network node can set at least one input parameter value of the KDF using the uplink NAS count set based on the previously stored security information, and set at least one other input parameter value of the KDF based on the access type identifier. The first network node can input the KDF to which the input parameter values ​​are set. AMF By entering , the newly derived K TWIF can be obtained. Here, the access type identifier can indicate non-3GPP access with enhanced mobility. Non-3GPP access with enhanced mobility is a newly defined access type identifier in the present disclosure and can be used when an N5CW terminal reconnects and there is previously stored security information.

[0190] If there is no previously stored security information, in step S1007, the first network node generates a second security key using the uplink NAS count set to 0. In other words, the first network node generates a second security key using the uplink NAS count set to 0. AMF And the second security key can be generated based on the uplink NAS count set to 0. The first network node can set at least one input parameter value of the KDF based on the uplink NAS count set to 0, and can set at least one other input parameter value of the KDF based on the access type identifier. The first network node can generate the KDF with the set input parameter values. AMF By entering , the newly derived K TWIF can be obtained. Here, the access type identifier can indicate non-3GPP access.

[0191] In step S1009, the first network node stores at least a portion of the second security key as security information. For example, the first network node may store the K generated or derived in step S1005 or step 1007. TWIF At least a portion of the second security key can be stored as security information for the N5CW terminal. In other words, the first network node can select at least a portion of the second security key as security information and store the selected security information. At this time, the uplink NAS count can be set or updated based on the stored security information. The first network node can select and store at least a portion corresponding to a designated position and / or length of the entire key stream of the second security key as security information. For example, the first network node can select and store a first portion corresponding to n bits from the MSB of the key stream of the second security key, a second portion corresponding to n bits from the LSB, or a third portion corresponding to n bits in the middle as security information. At least one of the position and the length of at least a portion of the second security key to be stored as security information among the entire key stream of the second security key can be designated or set by the network operator and / or business operator. The position and / or the length of at least a portion of the second security key to be stored as security information does not change.

[0192] In the description referring to Figure 10, the method by which the first network node derives the second security key was described. However, the N5CW terminal can also derive the second security key in the same manner as the first network node.

[0193]

[0194] FIG. 11 illustrates an example of a key derivation function according to one embodiment of the present disclosure.

[0195] Referring to Fig. 11, K TWIF The key derivation function (KDF) (1110) that derives the 256-bit KAMF (1111) is input, and the input K AMF and 256 bits of K based on the input parameters. TWIF Prints (1113).

[0196] The input parameters of KDF can be set as follows:

[0197] - FC = 0x6E

[0198] - P0 = Uplink NAS count or previously stored security information

[0199] - L0 = length of uplink NAS count or previously stored security information

[0200] - P1 = access type distinguisher

[0201] - L1 = length of access type identifier

[0202] Here, the previously stored security information is the security context acquired and stored during the previous connection procedure of the N5CW terminal, and the K acquired during the previous connection procedure of the N5CW terminal. TWIF may include at least a portion of

[0203] The values ​​of the access type identifier are defined as in [Table 2].

[0204] Access type distinguisher value 3GPP access 0x01 Non 3GPP access 0x02 Non 3GPP access with enhanced mobility 0x03

[0205] In Table 2, non-3GPP access with enhanced mobility is a newly defined access type identifier that can be used when an N5CW terminal reconnects and pre-stored security information exists. The value of non-3GPP access with enhanced mobility is set to 0x03, but can be set to another reserved value. For example, the value of non-3GPP access with enhanced mobility can be set to any of the values ​​0x00 and 0x03~0xf0, which are reserved for future use.

[0206] At the time of initial registration of the N5CW terminal, P0 is set to the uplink NAS count, L0 is set to the length of the uplink NAS count, P1 is set to 0x02, which is a non-3GPP access value, and L1 is set to the length of the non-3GPP access value. Thereafter, when the N5CW terminal reconnects, if there is security information pre-stored for the N5CW terminal in the first network node, P0 is set to the pre-stored security information, L0 is set to the length of the pre-stored security information, P1 is set to 0x03, which is a non-3GPP access value with enhanced mobility, and L1 is set to the length of the non-3GPP access value with enhanced mobility.

[0207]

[0208] The first network node and / or N5CW terminal can derive a second security key based on the first security key by setting the input parameters of the KDF (1110) as described above.

[0209] FIG. 12a and FIG. 12b illustrate examples of a procedure for initial registration of an N5CW terminal according to one embodiment of the present disclosure.

[0210] Referring to FIGS. 12A and 12B , at step S1201, the N5CW terminal (1210) and the TWAP (1220) trigger an EAP-based authentication procedure. In other words, the EAP-AKA authentication procedure is initiated when the N5CW terminal (1210) connects to the TWAP (1220). To this end, the N5CW terminal (1210) may first select a PLMN and a trusted WLAN. For example, the N5CW terminal (1210) may select a PLMN and a trusted WLAN that supports "5G connectivity-without-NAS" in the PLMN by using the procedures defined in Sections 6.3.12 and 5.30.2.15 of TS 23.501 [2] for access to the PLMN and the SNPN, respectively.

[0211] In step S1203, the TWAP (1220) transmits a message requesting terminal identification information to the N5CW terminal (1210). The message requesting terminal identification information may be an EAP-Req / Identify message. In step S1205, the N5CW terminal (1210) transmits a message including terminal identification information to the TWAP (1220). The message including terminal identification information may be an EAP-Res / Identify message. At this time, the terminal identification information may include a network access identifier (NAI). The NAI may include SUCI or 5G-GUTI. For example, if the N5CW terminal (1220) is not registered through 3GPP access for the 5GC of the selected PLMN, i.e., if the N5CW terminal (1220) is registering for 3GPP access for the first time, the NAI may include SUCI. On the other hand, if the N5CW terminal (1210) is registered in the 5GC through 3GPP access to the 5GC of the selected PLMN, the NAI may include the 5G-GUTI assigned to the N5CW terminal through the 3GPP access.

[0212] At step S1207, the TWAP (1220) transmits an AAA request message to the TWIF (1230). In other words, the TWAP (1220) selects the TWIF (1230) based on the realm information of the received terminal identification information and transmits an AAA request to the selected TWIF (1230). The AAA request may include the NAI received from the N5CW terminal (1210). For example, the AAA request may include SUCI or 5G-GUTI.

[0213] At step S1209, the TWIF (1230) generates a registration request message for 5GC on behalf of the N5CW terminal (1210). The TWIF (1230) may fill in the parameters in the registration request message using default values. At this time, the registration type indicates 'initial registration'. For example, the registration request message may include at least one of the registration type, terminal identification information (e.g., SUCI or 5G-GUTI), requested NSSAI, or 5GC capability information.

[0214] At step S1211, the TWIF (1230) selects an AMF (1240). The TWIF (1230) may select an AMF (1240) based on the terminal identification information received through step 1207. For example, if an NAI including a SUCI is provided by the N5CW terminal (1210), the TWIF (1230) may select an AMF (1240) using the SUCI included in the NAI. Through this, the TWIF (1230) may select the same AMF as the AMF that provides services to the N5CW terminal (1210) through 3GPP access.

[0215] In step S1213, the TWIF (1230) transmits an N2 message including a user location, an AN type, and a registration request message to the selected AMF (1240). The registration request message is a message generated in step S1209 and may include at least one of a registration type, terminal identification information (e.g., SUCI or 5G-GUTI), requested NSSAI, or 5GC capability information.

[0216] At step S1215, the AMF (1240) triggers an authentication procedure and transmits a Nausf_UEAuthentication_Authenticate request message to the AUSF (S1215). The Nausf_UEAuthentication_Authenticate request message includes SUCI or SUPI. In addition, the Nausf_UEAuthentication_Authenticate request message includes an N5CW indication N5CWind indicating that the request was received from the N5CW terminal (1210). Here, if the AMF (1240) receives a valid 5G-GUTI from the TWIF, the Nausf_UEAuthentication_Authenticate request message may include SUPI.

[0217] At step S1217, AUSF (1250) transmits a Nudm_UEAuthentication_Get request message to UDM (1260). The Nudm_UEAuthentication_Get request message may include SUCI or SUPI and N5CW indication.

[0218] At step S1219, UDM (1260) checks whether the received Nudm_UEAuthentication_Get request message includes SUCI, and if so, calls SIDF. SIDF obtains SUPI by hiding SUCI before UDM processes the request. UDM selects an authentication method based on the "realm" part of SUPI, N5CW indication, a combination of the "realm" part and N5CW indication, or UDM local policy.

[0219] At step S1221, an authentication and key agreement procedure is performed. The authentication key agreement procedure includes an authentication procedure for EAP-AKA. For mutual authentication between the N5CW terminal (1210) and the home network, an authentication procedure for EAP-AKA is performed, as defined in section 6.1.3.1 of TS 33.501. EAP-AKA occurs between the N5CW terminal (1210) and the AUSF (1250). Through the N2 interface, the EAP message is transmitted within the NAS authentication message.

[0220] At step S1223, AMF (1240) is K AMF From K TWIF Induce, K TWIF Stores at least a portion of the AMF (1240) in the KDF as shown in Fig. 11. AMF By entering K TWIF can be obtained. At this time, the input parameters of the KDF can be set based on the values ​​indicating non-3GPP access among the uplink NAS count and access type identifier values. For example, the input parameter P0 is set to the uplink NAS count, the input parameter L0 is set to the length of the uplink NAS count, the input parameter P1 is set to 0x02, which is the non-3GPP access value, and the input parameter L1 is set to the length of the non-3GPP access value. The uplink NAS count is a new K AMFWhen generated, it has a start value. For example, the start value of the uplink NAS count may be 0. This is because the N5CW terminal (1210) does not support NAS signaling. Since the uplink NAS count is 0 at the time of initial registration, the input parameter P0 may be set to 0. The AMF (1240) is derived K TWIF of At least a portion of it is stored as a security context for the N5CW terminal (1210). The AMF (1240) is derived K TWIF It can select n bits at a specified position or a specified part of the key stream and store the selected n bits. For example, AMF can be derived from K TWIF A first part corresponding to n bits from the MSB of the key stream, a second part corresponding to n bits from the LSB, or a third part corresponding to n bits in the middle are selected and stored as a security context. Here, the number n of bits to be selected as the security context and / or the position or part of the key stream to be selected as the security context may be preset by a network operator and / or a business operator. The value n and / or the designated position or part are not changed after being preset. According to one embodiment, the position of the key stream to be selected as the security context may be set so that n consecutive bits are selected, or may be set so that n discontinuous bits are selected. According to one embodiment, n may be set to a maximum of 8.

[0221] At step S1225, AMF (1240) transmits an N2 message NAS security mode command message to TWIF (1230). The NAS security mode command message includes an EAP-success message and NULL security algorithm information.

[0222] At step S1227, TWIF (1230) stores the EAP-success message and K TWIFWaits for the EAP-success to be generated or acquired. TWIF (1230) does not directly transmit EAP-success to N5CW terminal (1210), but transmits N2 message NAS security mode completion message to AMF (1240) at step S1229.

[0223] At step S1231, AMF (1240) transmits an N2 initial context setup request message to TWIF (1230). The N2 initial context setup request message includes the K derived at step S1223. TWIF Includes.

[0224] At step S1233, TWIF (1230) receives the received K TWIF From K TNAP Induces K TNAP is set to PMK (pairwise master key) and is used to provide security to the WLAN air interface.

[0225] At step S1235, TWIF (1230) transmits an AAA message including an EAP-success message and PMK to TWAP (1220), and at step S1237, TWAP (1220) transmits an EAP-Success message to N5CW terminal (1210).

[0226] In steps S1239 and S1241, the TWAP (1220) and the N5CW terminal (1210) each derive WLAN keys from the PMK. The N5CW terminal (1210) may generate or derive the PMK or obtain the PMK from the TWAP (1220). For example, the N5CW terminal (1210) may obtain the PMK through an authentication procedure for EAP-AKA. AMF and obtain K AMF From K TWIF Induce, K TWIFStores at least a portion of the N5CW terminal (1210) in the KDF as shown in FIG. 11. AMF By entering K TWIF can be obtained. At this time, the input parameters of the KDF can be set based on the value indicating non-3GPP access among the uplink NAS count and access type identifier values ​​set to 0. In the N5CW terminal (1210), K AMF From K TWIF Induce K TWIF A way to store at least part of the K in AMF(1240) AMF From K TWIF Induce K TWIF It is the same way as storing at least part of it.

[0227] At step S1243, the N5CW terminal (1210) and TWAP (1220) set up security for the wireless interface based on PMK, and at step S1245, the TWAP (1220) and TWIF (1230) perform L2 or L3 connection using PMK. At this time, the L2 or L3 connection is performed for each terminal.

[0228] At step S1247, the TWIF (1230) transmits an N2 initial context setup response message to the AMF (1240). The AMF (1240) transmits a registration acceptance message to the TWIF (1230). Through the procedure described above, the N5CW terminal (1210) can be connected to the WLAN access network and registered in the 5GC.

[0229] At step S1249, the N5CW terminal (1210) and the AMF (1240) can perform operations subsequent to step 9 of section 4.12b of TS 23.502. For example, a PDU session can be established by performing steps 20a to 21d of FIG. 5c.

[0230] In the description with reference to Figures 12a and 12b, the derived K TWIFAt least part of the derived K was stored as security information. TWIF Security information including at least a portion of the N5CW terminal (1210) is deleted when the 5GC is deregistrated.

[0231]

[0232] FIGS. 13A and 13B illustrate examples of a reconnection procedure for an N5CW terminal according to one embodiment of the present disclosure. FIGS. 13A and 13B illustrate a 5GC reconnection procedure for an N5CW terminal that has completed an initial registration procedure for 5GC.

[0233] Referring to FIGS. 13A and 13B , at step S1301, the N5CW terminal (1310) and the TWAP (1320) trigger an EAP-based authentication procedure. In other words, the EAP-AKA authentication procedure is initiated when the N5CW terminal (1310) connects to the TWAP (1320) for reconnection. To this end, the N5CW terminal (1310) can first select a trusted WLAN that supports 5G connectivity without a PLMN or NAS.

[0234] In step S1303, the TWAP (1320) transmits a message requesting terminal identification information to the N5CW terminal (1310). The message requesting terminal identification information may be an EAP-Req / Identify message. In step S1305, the N5CW terminal (1310) transmits a message including terminal identification information to the TWAP (1320). The message including terminal identification information may be an EAP-Res / Identify message. At this time, the terminal identification information may include a network access identifier (NAI). The NAI may include a 5G-GUTI. For example, since the N5CW terminal (1310) has completed the initial registration procedure for 5GC, the NAI may include a 5G-GUTI assigned to the N5CW terminal through 3GPP access.

[0235] At step S1307, the TWAP (1320) transmits an AAA request message to the TWIF (1330). In other words, the TWAP (1320) selects the TWIF (1330) based on the realm information of the received terminal identification information and transmits an AAA request to the selected TWIF (1330). The AAA request may include the NAI received from the N5CW terminal (1310). For example, the AAA request may include the 5G-GUTI.

[0236] At step S1309, the TWIF (1330) generates a registration request message for 5GC on behalf of the N5CW terminal (1310). The TWIF (1330) may fill in the parameters in the registration request message using default values. For example, the registration request message may include at least one of a registration type, terminal identification information (e.g., SUCI or 5G-GUTI), requested NSSAI, or 5GC capability information.

[0237] At step S1311, the TWIF (1330) selects an AMF (1340). The TWIF (1330) may select an AMF (1340) based on the terminal identification information received through step 1307. For example, if an NAI including a 5G-GUTI is provided by the N5CW terminal (1310), the TWIF (1330) may select an AMF (1340) using the 5G-GUTI included in the NAI. Through this, the TWIF (1330) may select the same AMF as the AMF that provides services to the N5CW terminal (1310) through 3GPP access.

[0238] In step S1313, the TWIF (1330) transmits an N2 message including a user location, an AN type, and a registration request message to the selected AMF (1340). The registration request message is a message generated in step S1309 and may include at least one of a registration type, terminal identification information (e.g., 5G-GUTI), requested NSSAI, or 5GC capability information.

[0239] In step S1315, the AMF (1340) checks whether there is a previously stored security context for the N5CW terminal (1310). For example, when an N2 message including a 5G-GUIT is received, the AMF (1340) checks whether there is a security context stored during an initial registration procedure or a previous reconnection procedure of the N5CW terminal (1310) having a 5G-GUTI. The security context is K acquired during the initial registration procedure or a previous reconnection procedure of the N5CW terminal (1310). TWIF If there is a previously stored security context for the N5CW terminal (1310), the AMF (1340) performs step S1317.

[0240] At step S1317, AMF (1340) uses the previously stored security context to create a new K TWIF, and the newly derived K TWIF stores at least a portion of the KDF. Specifically, AMF (1340) sets the input of the KDF based on the previously stored security context, thereby generating a new KDF. TWIF is obtained. At this time, the input parameters of KDF are the previously obtained K TWIF The input parameter P0 may be set based on a value indicating non-3GPP access with enhanced mobility among the values ​​of the security context and access type identifier including at least a portion of the security context and access type identifier. For example, the input parameter P0 may be set based on a previously stored security context, i.e., K acquired during an initial registration procedure or a previous reconnection procedure. TWIF At least part of, input parameter L0 is set to the length of a previously stored security context, input parameter P1 is set to 0x03, which is the value of a newly defined non-3GPP access with enhanced mobility, and input parameter L1 is set to the length of a non-3GPP access value with enhanced mobility. AMF (1340) deletes the previously stored security context and generates a newly derived K TWIF At least of A portion of the N5CW terminal (1310) is stored as a security context. AMF (1340) is newly derived K TWIF can select n bits at a specified position or a specified portion of the key stream and store the selected n bits. For example, AMF can be derived from K TWIFA first part corresponding to n bits from the MSB of the key stream, a second part corresponding to n bits from the LSB, or a third part corresponding to n bits in the middle are selected and stored as a security context. Here, the number n of bits to be selected as the security context and / or the position or part of the key stream to be selected as the security context may be preset by a network operator and / or a business operator. The specified position or part, and / or the value of n, are not changed after being preset. According to one embodiment, the position of the key stream to be selected as the security context may be set so that n consecutive bits are selected, or may be set so that n discontinuous bits are selected. According to one embodiment, n may be set to a maximum of 8.

[0241] At step S1319, AMF (1340) transmits an N2 message NAS security mode command message to TWIF (1330). The NAS security mode command message includes an EAP-success message and NULL security algorithm information.

[0242] At step S1321, TWIF (1330) stores the EAP-success message and K TWIF Waits for the generation or acquisition of. TWIF (1330) does not directly transmit EAP-success to N5CW terminal (1310). In step S1323, TWIF (1330) transmits N2 message NAS security mode completion message to AMF (1340).

[0243] At step S1325, AMF (1340) transmits an N2 initial context setup request message to TWIF (1330). The N2 initial context setup request message includes the newly derived K at step S1317. TWIF Includes.

[0244] At step S1327, TWIF (1330) receives the received K TWIF From K TNAP Induces K TNAP is set to PMK (pairwise master key) and is used to provide security to the WLAN air interface.

[0245] At step S1329, TWIF (1330) transmits an AAA message including an EAP-success message and PMK to TWAP (1320), and at step S1331, TWAP (1320) transmits an EAP-Success message to N5CW terminal (1310).

[0246] In steps S1333 and S1335, the TWAP (1320) and the N5CW terminal (1310) each derive WLAN keys from the PMK. The N5CW terminal (1310) may generate or derive the PMK or obtain the PMK from the TWAP (1320). For example, the N5CW terminal (1310) may use a previously stored security context to generate a new K TWIF , and the newly derived K TWIF stores at least a portion of the KDF. Specifically, the N5CW terminal (1310) sets the input of the KDF based on the previously stored security context, thereby generating a new KDF. TWIF is obtained. At this time, the input parameters of KDF are the previously obtained K TWIF The N5CW terminal (1310) may be set based on a value indicating non-3GPP access with enhanced mobility among the values ​​of the security context and access type identifier including at least a part of the N5CW terminal (1310). TWIF , and the newly derived K TWIF A way to store at least part of the new K in AMF (1340) TWIF , and the newly derived K TWIF It is the same way as storing at least part of it.

[0247] At step S1337, the N5CW terminal (1310) and TWAP (1320) set up security for the wireless interface based on PMK, and at step S1339, the TWAP (1320) and TWIF (1330) perform L2 or L3 connection using PMK. At this time, the L2 or L3 connection is performed for each terminal.

[0248] At step S1341, the TWIF (1330) transmits an N2 initial context setup response message to the AMF (1340). At step S1343, the AMF (1340) transmits an N2 message registration acceptance message to the TWIF (1330). Through the procedure described above, the N5CW terminal (1310) can be reconnected to the WLAN access network.

[0249] In the description with reference to Figures 13a and 13b, the newly derived K TWIF At least part of the newly derived K was stored as security information. TWIF Security information including at least a portion of the N5CW terminal (1310) is deleted when the 5GC is deregistrated.

[0250]

[0251] It is clear that the examples of the proposed methods described above can also be considered as a type of proposed methods, as they can be included as one of the implementation methods of the present disclosure. Furthermore, the proposed methods described above can be implemented independently, but they can also be implemented in the form of a combination (or merge) of some of the proposed methods. Information regarding the applicability of the proposed methods (or information regarding the rules of the proposed methods) can be defined by a rule such that the base station notifies the terminal of the application of the proposed methods through a predefined signal (e.g., a physical layer signal or a higher layer signal).

[0252] The present disclosure may be embodied in other specific forms without departing from the technical ideas and essential features described herein. Therefore, the above detailed description should not be construed as limiting in all respects but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the present disclosure are intended to be included within the scope of the present disclosure. Furthermore, claims that do not explicitly cite each other in the claims may be combined to form embodiments or incorporated into new claims through post-filing amendments.

[0253] Embodiments of the present disclosure can be applied to various wireless access systems. Examples of various wireless access systems include the 3rd Generation Partnership Project (3GPP) or 3GPP2 systems.

[0254] The embodiments of the present disclosure can be applied not only to the various wireless access systems described above, but also to all technical fields that utilize these various wireless access systems. Furthermore, the proposed method can also be applied to mmWave and THz communication systems utilizing ultra-high frequency bands.

[0255] Additionally, embodiments of the present disclosure can be applied to various applications such as autonomous vehicles and drones.

Claims

1. A method performed by a first network node in a wireless communication system, A step of receiving a message requesting registration of a terminal from a second network node; A step of obtaining a second security key based on the first security key; and A step of transmitting a message including the second security key to the second network node, The second network node is included in a wireless local area network (WLAN) access network and supports NAS (non-access stratum) signaling on behalf of the terminal, The above second security key is obtained based on an uplink NAS count or further based on the above-stored security information, based on whether there is previously stored security information for the terminal.

2. In claim 1, A method wherein the above-mentioned stored security information includes at least a portion of a second security key obtained during a previous registration procedure for the terminal.

3. In claim 1, The step of obtaining the second security key based on the above first security key is: If there is no previously stored security information for the terminal, a step of deriving the second security key from the first security key based on the uplink NAS count being set to 0; and A method comprising a step of deriving the second security key from the first security key based on the pre-stored security information when there is pre-stored security information for the terminal.

4. In claim 3, A method in which the above uplink NAS count or the above stored security information is used to set at least one input parameter of a key derivation function that derives the second security key from the first security key.

5. In claim 4, If there is no previously stored security information for the terminal, at least one other input parameter of the key derivation function is set based on the first access type identifier, If there is pre-stored security information for the terminal, at least one other input parameter of the key derivation function is set based on the second access type identifier, A method wherein the first access type identifier and the second access type identifier are different values ​​set for non-3GPP access.

6. In claim 1, A step of determining whether the message requesting registration is a message for reconnection of the terminal based on network access identifier information included in the message requesting registration; and A method further comprising a step of checking whether there is security information previously stored for the terminal when the message requesting the registration is a message for reconnection of the terminal.

7. In claim 1, A method in which whether the message requesting the above registration is a message for reconnection of the terminal is determined based on whether the network access identifier includes a 5G-GUTI (5G-globally unique temporary user equipment identity).

8. In claim 1, A method further comprising the step of storing at least a portion of the second security key as security information for the terminal.

9. In claim 8, A method wherein at least one of the location and length of at least a portion of the entire stream of the second security key stored as the security information is set by the network operator.

10. In claim 1, The above terminal includes an N5CW (non-5G-capable over WLAN) terminal, The above first network node includes an access and mobility management function (AMF), A method wherein the second network node comprises a trusted WLAN interworking function (TWIF).

11. In claim 1, A method in which security information previously stored for the above terminal is deleted when the above terminal is deregistered.

12. A method performed by a terminal in a wireless communication system, A step of transmitting an authentication-related message including network access identification information to a second network node; A step of receiving an authentication success message from the second network node; A step of establishing security with the second network node based on PMK (pairwise master key), The second network node is included in a wireless local area network (WLAN) access network and supports NAS (non-access stratum) signaling to the first network node on behalf of the terminal, The above PMK is obtained based on the second security key, The above second security key is obtained based on an uplink NAS count or based on the presence of pre-stored security information.

13. In a first network node in a wireless communication system, Transmitter and receiver; and comprising a processor connected to the above transceiver, The above processor, Receive a message requesting registration of a terminal from a second network node, Obtain a second security key based on the first security key, Controlling to transmit a message including the second security key to the second network node, The second network node is included in a wireless local area network (WLAN) access network and supports NAS (non-access stratum) signaling on behalf of the terminal, The second security key is a first network node obtained based on an uplink NAS count or based on the previously stored security information, based on whether there is previously stored security information for the terminal.

14. In a wireless communication system, at a terminal, Transmitter and receiver; and comprising a processor connected to the above transceiver, The above processor, Transmitting an authentication-related message containing network access identification information to a second network node, Receive an authentication success message from the second network node, Control to establish security with the second network node based on PMK (pairwise master key), The second network node is included in a wireless local area network (WLAN) access network and supports NAS (non-access stratum) signaling to the first network node on behalf of the terminal, The above PMK is obtained based on the second security key, The above second security key is obtained by the terminal based on the uplink NAS count or the above-mentioned stored security information, based on whether there is previously stored security information.

15. In communication devices, At least one processor; At least one computer memory coupled to said at least one processor and storing instructions that direct operations when executed by said at least one processor, The above actions are, A step of receiving a message requesting registration of a terminal from a second network node; A step of obtaining a second security key based on the first security key; and A step of transmitting a message including the second security key to the second network node, The second network node is included in a wireless local area network (WLAN) access network and supports NAS (non-access stratum) signaling on behalf of the terminal, The second security key is a communication device obtained based on an uplink NAS count or further based on the previously stored security information, based on whether there is previously stored security information for the terminal.

16. In a non-transitory computer-readable medium storing at least one instruction, comprising at least one instruction executable by the processor, At least one of the above commands causes the device to: Receive a message requesting registration of a terminal from a second network node, Obtain a second security key based on the first security key, Controlling to transmit a message including the second security key to the second network node, The second network node is included in a wireless local area network (WLAN) access network and supports NAS (non-access stratum) signaling on behalf of the terminal, The second security key is a computer-readable medium obtained based on an uplink NAS count or further based on the previously stored security information, based on whether there is previously stored security information for the terminal.

Citation Information

Patent Citations

  • Method for updating sidewalk on map, server and system using the same

    KR102642165B1

  • Inspection device for containment liner plate of nuclear reactor

    KR102671115B1

  • Security context handling in 5g during handover

    US20210153013A1