Method, device and system for managing AKMA service in communication networks

The solution addresses AKMA service management inconsistencies by using network elements to detect PLMN changes and synchronize records, ensuring secure and efficient AKMA service management in wireless communication networks.

WO2025145525A1PCT designated stage Publication Date: 2025-07-10ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/099128
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-07-10

AI Technical Summary

Technical Problem

Existing wireless communication networks face challenges in managing Authentication and Key Management for Applications (AKMA) services, particularly during roaming scenarios, leading to inconsistencies and mismatches in AKMA records between network elements, which can result in improper disabling or cleanup of AKMA services.

Method used

The proposed solution involves network elements like the AKMA Anchor Function (AAnF) detecting PLMN changes and performing checks on primary authentication to ensure accurate AKMA service management, using messages like Naanf_AKMA_ServiceDisableNotification and Nnef_AKMA_ServiceDisableNotification to synchronize AKMA records across network elements.

Benefits of technology

This approach ensures proper disabling and cleanup of AKMA services, preventing service disruptions and maintaining secure communication by resolving AKMA record mismatches, thereby enhancing network security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024099128_10072025_PF_FP_ABST
    Figure CN2024099128_10072025_PF_FP_ABST
Patent Text Reader

Abstract

This disclosure generally relates to managing AKMA service in wireless communication. Performed by first network element, the method includes: transmitting, to a second network element, a first message related to an update on an AKMA service associated with a wireless device, wherein the first message carries at least one of: a Subscription Permanent Identifier (SUPI) of the wireless device; a Generic Public Subscription Identifier (GPSI) of the wireless device; or a first AKMA key identifier, A-KID of the wireless device, for identifying a first AKMA key of the wireless device, wherein the first A-KID is up-to-date for the wireless device..
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, DEVICE AND SYSTEM FOR MANAGING AKMA SERVICE IN COMMUNICATION NETWORKSTECHNICAL FIELD

[0001] This disclosure relates to wireless communication, and in particular, to managing AKMA (Authentication and Key Management for Applications) service in a wireless communication network, such as 4G, 5G, and 6G wireless communication network.BACKGROUND

[0002] In a communication network, the mutual authentication of a User Equipment (UE) and the communication network may be performed to allow only authenticated UE and the authenticated communication network to communicate with each other. Application Function (AF) entities may provide various application services to the UE once authenticated. Efficient and robust authentication mechanism involving various network elements is critical to provide secure communication between Application Function entity and the UE, and to protect the credentials of the UE and the Application Function entity.SUMMARY

[0003] This disclosure discloses methods, systems, devices, and storage medium relates to wireless communication, and in particular, to managing, including disabling, AKMA (Authentication and Key Management for Applications) service in a wireless communication network, such as 4G, 5G, and 6G wireless communication network.

[0004] In one embodiment, the present disclosure describes a method for wireless communication. Performed by a first network element, the method includes: transmitting, to a second network element, a first message related to an update on an AKMA (Authentication and Key Management for Applications) service associated with a wireless device, wherein the first message carries at least one of: a Subscription Permanent Identifier  (SUPI) of the wireless device; a Generic Public Subscription Identifier (GPSI) of the wireless device; or a first AKMA key identifier, A-KID of the wireless device, for identifying a first AKMA key of the wireless device, wherein the first A-KID is up-to-date for the wireless device.

[0005] In another embodiment, a method for wireless communication is disclosed. Performed by a first network element, the method includes: receiving, from a second network element, a first message related to an update on an AKMA (Authentication and Key Management for Applications) service associated with a wireless device, wherein the first message carries at least one of: a Subscription Permanent Identifier (SUPI) of the wireless device; a Generic Public Subscription Identifier (GPSI) of the wireless device; or a first AKMA key identifier, A-KID of the wireless device, for identifying a first AKMA key of the wireless device, wherein the first A-KID is up-to-date for the wireless device.

[0006] In another embodiment, a network element or wireless device comprising a processor and a memory is disclosed. The processor may be configured to read computer code from the memory to implement any of the methods above.

[0007] In yet another embodiment, a computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon is disclosed. The computer code, when executed by a processor, may cause the processor to implement any one of the methods above.

[0008] The above embodiments and other aspects and alternatives of their implementations are explained in greater detail in the drawings, the descriptions, and the claims below.BRIEF DESCRIPTION OF THE DRAWINGS

[0009] FIG. 1 shows an exemplary communication network including various terminal devices, a carrier network, data network, and service applications.

[0010] FIG. 2 shows exemplary network functions or network nodes in a communication network.

[0011] FIG. 3 shows exemplary network functions or network nodes in a wireless communication network.

[0012] FIG. 4 shows an exemplary network model for an Authentication and Key Management for Applications (AKMA) framework.

[0013] FIG. 5 shows an example wireless network node (or network element, network entity, entity, application function) .

[0014] FIG. 6 shows an example user equipment.

[0015] FIG. 7 shows an exemplary key hierarchy under the AKMA framework.

[0016] FIG. 8 shows an exemplary logic flow for disabling AKMA service for a UE.

[0017] FIG. 9 shows a scenario that causes A-KID mismatch between AAnF and AF.

[0018] FIG. 10-13 show exemplary logic flows for disabling AKMA service for a UE when there is an change in the PLMN serving the UE.DETAILED DESCRIPTION

[0019] An exemplary communication network, shown as 100 in FIG. 1, may include terminal devices 110 and 112, a carrier network 102, various service applications 140, and other data networks 150. The carrier network 102, for example, may include access networks 120 and a core network 130. The carrier network 102 may be configured to transmit voice, data, and other information (collectively referred to as data traffic) among terminal devices 110 and 112, between the terminal devices 110 and 112 and the service applications 140, or between the terminal devices 110 and 112 and the other data networks 150. Communication sessions and corresponding data paths may be established and configured for such data transmission. The Access networks 120 may be configured to  provide terminal devices 110 and 112 network access to the core network 130. The Access network 120 may, for example, support wireless access via radio resources, or wireline access. The core network 130 may include various network nodes or network functions configured to control the communication sessions and perform network access management and data traffic routing. The service applications 140 may be hosted by various application servers that are accessible by the terminal devices 110 and 112 through the core network 130 of the carrier network 102. A service application 140 may be deployed as a data network outside of the core network 130. Likewise, the other data networks 150 may be accessible by the terminal devices 110 and 112 through the core network 130 and may appear as either data destination or data source of a particular communication session instantiated in the carrier network 102.

[0020] The core network 130 of FIG. 1 may include various network nodes or functions geographically distributed and interconnected to provide network coverage of a service region of the carrier network 102. These network nodes or functions may be implemented as dedicated hardware network elements. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or as software entities. A network node may each be configured with one or more types of network functions. These network nodes or network functions may collectively provide the provisioning and routing functionalities of the core network 130. The term “network nodes” and “network functions” are used interchangeably in this disclosure.

[0021] FIG. 2 further shows an exemplary division of network functions in the core network 130 of a communication network 200. While only single instances of network nodes or functions are illustrated in FIG. 2, those having ordinary skill in the art readily understand that each of these network nodes may be instantiated as multiple instances of network nodes that are distributed throughout the core network 130. As shown in FIG. 2, the core network 130 may include but is not limited to network nodes such as access management network node (AMNN) 230, authentication network node (AUNN) 260, network data management network node (NDMNN) 270, session management network node  (SMNN) 240, data routing network node (DRNN) 250, policy control network node (PCNN) 220, and application data management network node (ADMNN) 210. Exemplary signaling and data exchange between the various types of network nodes through various communication interfaces are indicated by the various solid connection lines in FIG. 2. Such signaling and data exchange may be carried by signaling or data messages following predetermined formats or protocols.

[0022] The implementations described above in FIGs. 1 and 2 may be applied to both wireless and wireline communication systems. FIG. 3 illustrates an exemplary cellular wireless communication network 300 based on the general implementation of the communication network 200 of FIG. 2. FIG. 3 shows that the wireless communication network 300 may include user equipment (UE) 310 (functioning as the terminal device 110 of FIG. 2) , radio access network (RAN) 320 (functioning as the access network 120 of FIG. 2) , data network (DN) 150, and core network 130 including access management function (AMF) 330 (functioning as the AMNN 230 of FIG. 2) , session management function (SMF) 340 (functioning as the SMNN 240 of FIG. 2) , application function (AF) 390 (for example, functioning as the ADMNN 210 of FIG. 2) , user plane function (UPF) 350 (functioning as the DRNN 250 of FIG. 2) , policy control function 322 (functioning as the PCNN 220 of FIG. 2) , authentication server function (AUSF) 360 (functioning as the AUNN 260 of FIG. 2) , and universal data management (UDM) function 370 (functioning as the UDMNN 270 of FIG. 2) . Again, while only single instances for some network functions or nodes of the wireless communication network 300 (the core network 130 in particular) are illustrated in FIG. 3, those of ordinary skill in the art readily understand that each of these network nodes or functions may have multiple instances that are distributed throughout the wireless communication network 300. While the AF 390 is depicted as part of the core network 130 in FIG. 3, they may be considered as associated with particular service applications 140 and may be considered as being outside of the core network 140. In this disclosure, various functions deployed in the wireless network as described above may also be referred to as function entities, which may be implemented as a network node, a network element, a logical function, via hardware, software, or a combination thereof.

[0023] In FIG. 3, the UE 310 may be implemented as various types of mobile devices that are configured to access the core network 130 via the RAN 320. The UE 310 may include but is not limited to mobile phones, laptop computers, tablets, Internet-Of-Things (IoT) devices, distributed sensor network nodes, wearable devices, and the like. The UE may also be Multi-access Edge Computing (MEC) capable UE that supports edge computing. The RAN 320 for example, may include a plurality of radio base stations distributed throughout the service areas of the carrier network. The communication between the UE 310 and the RAN 320 may be carried in over-the-air (OTA) radio interfaces as indicated by 311 in FIG. 3.

[0024] Continuing with FIG. 3, the UDM 370 may form a permanent storage or database for user contract and subscription data. The UDM may further include an authentication credential repository and processing function (ARPF, as indicated in 370 of FIG. 3) for storage of long-term security credentials for user authentication, and for using such long-term security credentials as input to perform computation of encryption keys as described in more detail below. To prevent unauthorized exposure of UDM / ARPF data, the UDM / ARPF 370 may be located in a secure network environment of a network operator or a third-party.

[0025] The AMF / SEAF 330 may communicate with the RAN 320, the SMF 340, the AUSF 360, the UDM / ARPF 370, and the Policy Control Function (PCF) 322 via communication interfaces indicated by the various solid lines connecting these network nodes or functions. The AMF / SEAF 330 may be responsible for UE to non-access stratum (NAS) signaling management, and for provisioning registration and access of the UE 310 to the core network 130 as well as allocation of SMF 340 to support communication need of a particular UE. The AMF / SEAF 330 may be further responsible for UE mobility management. The AMF may also include a security anchor function (SEAF, as indicated in 330 of FIG. 3) that, as described in more detail below, and interacts with AUSF 360 and UE 310 for user authentication and management of various levels of encryption / decryption keys. The AUSF 360 may terminate user registration / authentication / key generation requests from the AMF / SEAF 330 and interact with the UDM / ARPF 370 for completing such user  registration / authentication / key generation.

[0026] The SMF 340 may be allocated by the AMF / SEAF 330 for a particular communication session instantiated in the wireless communication network 300. The SMF 340 may be responsible for allocating UPF 350 to support the communication session and data flows therein in a user data plane and for provisioning / regulating the allocated UPF 350 (e.g., for formulating packet detection and forwarding rules for the allocated UPF 350) . Alternative to being allocated by the SMF 340, the UPF 350 may be allocated by the AMF / SEAF 330 for the particular communication session and data flows. The UPF 350 allocated and provisioned by the SMF 340 and AMF / SEAF 330 may be responsible for data routing and forwarding and for reporting network usage by the particular communication session. For example, the UPF 350 may be responsible for routing end-end data flows between UE 310 and the DN 150, between UE 310 and the service applications 140. The DN 150 and the service applications 140 may include but are not limited to data network and services provided by the operator of the wireless communication network 300 or by third-party data network and service providers.

[0027] The PCF 322 may be responsible for managing and providing various levels of policies and rules applicable to a communication session associated with the UE 310 to the AMF / SEAF 330 and SMF 340. As such, the AMF / SEAF 330, for example, may assign SMF 340 for the communication session according to policies and rules associated with the UE 310 and obtained from the PCF 322. Likewise, the SMF 340 may allocate UPF 350 to handle data routing and forwarding of the communication session according to policies and rules obtained from the PCF 322.

[0028] In FIG. 3, the AF 390 may provide application service (s) to a subscriber (e.g., a UE) . The application service may include, for example, multimedia service, edge computing service, Vehicle-to-Everything (V2X) service, Internet of Things (IoT) service, mission-critical service such as remote healthcare, industrial control system, and public safety. The AF 390 may be deployed in the 5G Core (5GC) Network, or in an External Data Network (EDN) which may be operated by a third-party. In some example implementations,  from a security perspective, if the AF is trusted (e.g., AF deployed in the 5GC network) , it can interact directly with 5GC network functions. If the AF belongs to a third-party, it may interact with the 5GC network via a Network Exposure Function (NEF) (more details for NEF will be described in below sections) . In some other example implementations, a third-party AF may provide third-party application that has been approved by the operators to use the operator core network, either directly or indirectly (e.g., via access to exposed Application Program Interface (API) ) .

[0029] While FIGs. 1-3 and the various exemplary implementations described below are based on cellular wireless communication networks, the scope of this disclosure is not so limited and the underlying principles are applicable to other types of wireless and wireline communication networks.

[0030] Network identity and data security in the wireless communication network 300 of FIG. 3 may be managed via user authentication processes provided by the AMF / SEAF 330, the AUSF 360, and the UDM / ARPF 370. In particularly, the UE 310 may first communicate with AMF / SEAF 330 for network registration and may then be authenticated by the AUSF 360 according to user contract and subscription data in the UDM / ARPF 370. Communication sessions established for the UE 310 after user authentication to the wireless communication network 300 may then be protected by the various levels of encryption / decryption keys. The generation and management of the various keys may be orchestrated by the AUSF 360 and other network functions in the communication network 300.

[0031] AKMA Framework

[0032] In the wireless communication network, the Application Function (AF, or application function entity) may provide application service to a UE. The AF may be deployed in various locations or domains, such as a Home Public Land Mobile Network (HPLMN) of the UE, a Visited Public Land Mobile Network (VPLMN) of the UE (e.g., when the UE roams to the VPLMN) , or a Data Network (DN) which is external to the  HPLMN and the VPLMN. Secure or encrypted data communication between the AF and the UE may be implemented under an Authentication and Key Management for Applications (AKMA) framework. The AKMA framework may be based on various authentication procedures such as the 5G Authentication and Key Agreement (5G-AKA) method, the Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA') method, the Extensible Authentication Protocol –Transport Layer Security (EAP-TLS) method, or the like.

[0033] FIG. 4 illustrates an exemplary network model 400 for implementing an AKMA framework. This model includes various network elements. Each network element may be implemented as a physical entity, or a logical entity providing a particular set of network functions. A logical entity may be based on software, hardware, firmware, of any combination thereof. For example, a logical entity may include a server providing the function. For another example, a logical entity may be implemented based on cloud-based service or platform, such as Software as a service (SaaS) , Platform as a service (PaaS) , etc.

[0034] The AKMA Anchor Function (AAnF) 412 provides a security anchor function in the HPLMN. The AAnF stores the AKMA Anchor Key (KAKMA) for AKMA service associated with UE 424, which is received from the Authentication Server Function (AUSF) 416 after the UE 424 completes a successful primary authentication. The AAnF may also generate the key material to be used between the UE and the Application Function (AF) 420 and maintains UE AKMA context (also referred to as AKMA security context) .

[0035] The AF 420 may provide application service to the UE. Under the AKMA framework, the AF may request for its AKMA Application Key, denoted as KAF, from the AAnF using an identifier for the KAKMA. The AAnF may only provide the KAF to the AF after the AF is authenticated and authorized by the operator network. The AF may be located inside or outside the operator's network. In this disclosure, for simplicity, the AKMA Application Key (denoted as KAF, or KAF) may also be referred to as the AF key.

[0036] In some example implementations, after a primary authentication of the UE, the  AKMA key, KAKMA (also denoted as KAKMA) , is derived from the key KAUSF. Correspondingly, an AKMA Key ID, namely A-KID, is also generated at the UE and AUSF side. The A-KID may serve as a temporary identifier for KAKMA of the UE. Exemplarily, the A-KID may include: A-TID (AKMA Temporary UE Identifier) , and HN-ID (identity of home network) . A-KID may be in a Network Access Identifier (NAI) format, i.e., username@realm. Specifically, the username part may include the Routing Identifier (RID) of the UE and the AKMA Temporary UE Identifier (A-TID) , and the realm part may include Home Network Identifier.

[0037] A-TID may be derived from KAUSF and SUPI (Subscription Permanent Identifier) of the UE. For example, A-TID = KDF ( "A-TID" , SUPI, KAUSF) , where KDF is the key derivation function.

[0038] In this disclosure, an AKMA context may include a set of security parameters, including SUPI, KAKMA and A-KID.

[0039] In this disclosure, an AF may maintain an AKMA key material (may also be referred to as AKMA record, AKMA information, or AKMA configuration) for a UE to which a communication is established (under AKMA framework) . The AKMA key material may include, for example, at least one of: the A-KID, the AKMA key of the UE, KAKMA, AF key, KAF, and KAF expire time.

[0040] The Network Exposure Function (NEF) 410 may be configured to enable and authorize external AFs to access the AKMA service and forward the AKMA service request towards the AAnF. The NEF may also perform the AAnF selection in case there are multiple AAnFs.

[0041] The AUSF 416 may provide the Subscription Permanent Identifier (SUPI) and AKMA key material (e.g., A-KID, KAKMA) of the UE to the AAnF. The AUSF may also perform the AAnF selection.

[0042] The UDM may store AKMA subscription data of the subscriber (or the UE  subscribed to the wireless communication network) .

[0043] Referring to FIG. 4, various interfaces may be involved in the AKMA framework. These interfaces may include Nnef, Naanf, Nudm, Uausf, and Namf and may be referred to as Service Based Interface (SBI) , as each interface corresponds to a service provided by a network element. For example, Nnef represnets the SBI utilized by the NEF; Naanf represents the SBI utilized by the AAnF; and Nudm represents the SBI utilized by the UDM. The network elements may interact with each other via the various SBIs. The SBI may provide security protection. For example, the SBI may be confidentiality, integrity and replay protected.

[0044] FIG. 4 shows the implementation where the AAnF is deployed as a standalone function. Other deployment options may be chosen. For example, the AAnF may be co-located with the AUSF, or the AAnF may be co-located with the NEF.

[0045] FIG. 5 shows an example of electronic device 500 to implement various network nodes, network elements, network entities, such as a network base station (e.g., a radio access network node) , a core network (CN) , a core network element / entity (e.g., an AMF, a UDM, an AAnF, an AF, etc. ) , an operation and maintenance (OAM) , and the like. Optionally in one implementation, the example electronic device 500 may include radio transmitting / receiving (Tx / Rx) circuitry 508 to transmit / receive communication with UEs and / or other base stations. Optionally in one implementation, the electronic device 500 may also include network interface circuitry 509 to communicate the base station with other base stations and / or a core network, e.g., optical or wireline interconnects, Ethernet, and / or other data transmission mediums / protocols. The electronic device 500 may optionally include an input / output (I / O) interface 506 to communicate with an operator or the like.

[0046] The electronic device 500 may also include system circuitry 504. System circuitry 504 may include processor (s) 521 and / or memory 522. Memory 522 may include an operating system 524, instructions 526, and parameters 528. Instructions 526 may be configured for the one or more of the processors 521 to perform the functions of the network  node. The parameters 528 may include parameters to support execution of the instructions 526. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.

[0047] In this disclosure, a network function / network entity / entity, such as an AMF, an AUSF, a UDM, an AAnF, an NEF, an AF, may be implemented in hardware, software, a combination of hardware and software, and may be implemented or integrated in the electronic device 500. They may also be implemented as a logical entity hosted by the electronic device 500.

[0048] FIG. 6 shows an example of an electronic device to implement a terminal device 600 (for example, a UE) . The UE 600 may be a mobile device, for example, a smart phone or a mobile communication module disposed in a vehicle. The UE 600 may include a portion or all of the following: communication interfaces 602, a system circuitry 604, an input / output interfaces (I / O) 606, a display circuitry 608, and a storage 609. The display circuitry may include a user interface 610. The system circuitry 604 may include any combination of hardware, software, firmware, or other logic / circuitry. The system circuitry 604 may be implemented, for example, with one or more systems on a chip (SoC) , application specific integrated circuits (ASIC) , discrete analog and digital circuits, and other circuitry. The system circuitry 604 may be a part of the implementation of any desired functionality in the UE 600. In that regard, the system circuitry 604 may include logic that facilitates, as examples, decoding and playing music and video, e.g., MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user inputs; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections for, as one example, internet connectivity; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on the user interface 610. The user interface 610 and the inputs / output (I / O) interfaces 606 may include a graphical user interface, touch sensitive display, haptic feedback or other haptic output, voice or facial recognition inputs, buttons, switches, speakers and other user interface elements. Additional examples of the I / O  interfaces 606 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headset and microphone input  / output jacks, Universal Serial Bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors) , and other types of inputs.

[0049] Referring to FIG. 6, the communication interfaces 602 may include a Radio Frequency (RF) transmit (Tx) and receive (Rx) circuitry 616 which handles transmission and reception of signals through one or more antennas 614. The communication interface 602 may include one or more transceivers. The transceivers may be wireless transceivers that include modulation  / demodulation circuitry, digital to analog converters (DACs) , shaping tables, analog to digital converters (ADCs) , filters, waveform shapers, filters, pre-amplifiers, power amplifiers and / or other logic for transmitting and receiving through one or more antennas, or (for some devices) through a physical (e.g., wireline) medium. The transmitted and received signals may adhere to any of a diverse array of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM) , frequency channels, bit rates, and encodings. As one specific example, the communication interfaces 602 may include transceivers that support transmission and reception under the 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS) , High Speed Packet Access (HSPA) +, 4G  / Long Term Evolution (LTE) , 5G, and 6G standards. The techniques described below, however, are applicable to other wireless communications technologies whether arising from the 3rd Generation Partnership Project (3GPP) , GSM Association, 3GPP2, IEEE, or other partnerships or standards bodies.

[0050] Referring to FIG. 6, the system circuitry 604 may include one or more processors 621 and memories 622. The memory 622 stores, for example, an operating system 624, instructions 626, and parameters 628. The processor 621 is configured to execute the instructions 626 to carry out desired functionality for the UE 600. The parameters 628 may provide and specify configuration and operating options for the instructions 626. The memory 622 may also store any BT, WiFi, 3G, 4G, 5G, 6G or other data that the UE 600 will send, or has received, through the communication interfaces 602. In various implementations,  a system power for the UE 600 may be supplied by a power storage device, such as a battery or a transformer.

[0051] Under the AKMA framework, there may be various keys involved, and these keys may be organized in a hierarchical structure as shown in FIG. 7. The example key hierarchy of FIG. 7 may include the following keys at different level: KAUSF, KAKMA, and KAF. These keys may be derived and stored in parallel on both the network side and the Mobile Equipment (ME) side. The ME refers to a portion of a UE along with other portions of UE such as a Universal Subscriber Identity Module (USIM) .

[0052] After a successful primary authentication between the UE and the wireless communication network (e.g., UE authenticated by the operator) , the AUSF and / or the UE may derive the KAUSF based on an Integrity Key (IK) of the UE, and a Cipher Key (CK) of the UE. AUSF may alternatively derive the KAUSF based on a transformation of the Integrity Key (denoted as IK') of the UE, and a transformation of the Cipher Key (denoted as CK') of the UE.

[0053] Based on the KAUSF, the ME and the AUSF may each derive the KAKMA based on the KAUSF, and the SUPI of the UE, by using a Key Derivation Function (KDF) . As described earlier, an A-KID may be generated that can be used to identify the KAKMA.

[0054] Then based on the KAKMA, the ME and the AAnF may each derive the KAF based on the KAKMA, and an identifier of the AF, also similarly by using a KDF. It is to be noted that a UE may store multiple KAF, each corresponding to an AF. Likewise, an AF may store multiple KAF, each corresponding to a UE.

[0055] The various keys described herein may each have a lifetime. For example, the KAKMA may be refreshed or re-generated until the next successful primary authentication. For another example, the KAF may be provisioned with a lifetime (or expiration time) , for example, by the AAnF. In some embodiments, the lifetime of a key may be associated with a timer, such that the timer is started once a key is commissioned, and once the timer expires,  the key is refreshed.

[0056] In a wireless communication network, a UE may subscribe to various application services from an AF. When invoking services provided by the AF, secure communication link needs to be established and maintained. An encryption key may be used to encrypt the data flow between the UE and the AF. Depending on use case scenarios, different key may be selected.

[0057] In one scenario, the UE is roaming in a VPLMN, and needs to invoke application service from an AF in its HPLMN. AKMA application key (KAF) may be used for encryption. Alternatively, an encryption key derived from KAF may be used.

[0058] In another scenario, the UE is roaming in a VPLMN, and needs to invoke application service from an AF in a data network external to the HPLMN and VPLMN. In this case, KAF, or encryption key derived from KAF may be used. The AF may also choose its own encryption key which is independent of KAF.

[0059] In a wireless communication network, a UE may move from one PLMN to another (i.e., roaming) . For example, UE may roam from its HPLMN to a VPLMN. When served by HPLMN, AKMA service may be enabled and activated for a UE when the UE interacts with an AF. However, when the UE roams to VPLMN, the AKMA service may not be supported or allowed anymore. In this case, the AF (s) that have interactions with the UE needs to be notified, so the AF (s) may properly shut down, disable, or deactivate the AKMA service with UE, and clean up AKMA record associated with the UE.

[0060] AKMA Service Management under Roaming Scenario

[0061] A UE may roam from its HPLMN to a VPLMN. In such roaming scenarios, it is essential for the HPLMN to have the capability to govern and determine whether the AKMA service is permitted to operate within the VPLMN. When the UE is served by (or register to, attached to) its HPLMN, the AKMA service may be started / enabled / activated, and the communication between UE and various network elements, such as AF, may be security protected under the AKMA framework. At a later time, the UE may register to a VPLMN  due to roaming. As soon as the PLMN change is detected by the AAnF, the AAnF may execute following procedure as shown in FIG. 8 based on, for example, a roaming policy.

[0062] Step 1. UE registers with, or attaches to, its HPLMN. The HPLMN is now the serving PLMN for the UE.

[0063] Step 2. UE may access the AF for an application service. The key material (e.g., AKMA key material such as A-KID, KAKMA of the UE) is provided to AF. While accessing the AAnF, the AF may also provide its notification Uniform Resource Identifier (URI) to the AAnF, which may be used by the AAnF to send notification message to the AF when certain precondition is met.

[0064] Step 3. UE is getting registered in a VPLMN due to, for example, UE roaming outside of its HPLMN. AAnF may detect the PLMN change via, for example, the Nudm_EventExposure_Notification message received from UDM.

[0065] Step 4. Based on a roaming policy, the AAnF may determine whether AKMA service is restricted, prohibited, or not supported when the UE is roaming in a VPLMN. Further, AAnF may determine whether the AF has subscribed to receive notifications on AKMA service update (e.g., when AKMA service is disabled) . If the AKMA service is restricted, prohibited, or not supported while UE roaming in the VPLMN, and AF has subscribed to receive AKMA service notification, then steps 5 to 6 are executed. Otherwise, steps 5 to 6 may be skipped.

[0066] Step 5. For AF (s) which has subscribed to receive AKMA service update notification, the AAnF may send AKMA service update notifications to the subscribed AF (s) via, for example, an Naanf_AKMA_ServiceDisableNotification message. The message may carry the A-KID of the UE (used to identify the KAKMA of UE) . In this case, the message may indicate that the AKMA service is disabled, restricted, prohibited, or not supported.

[0067] Step 6. Based on the notification, the AF may stop the AKMA service for the UE, and send a response back to the AAnF.

[0068] In the above implementation, there is a potential issue that the AF may not be able to properly disable or shut down the AKMA service for the UE, due to inconsistency / mismatch on AKMA record between AAnF and AF. The following provides a high-level step by step explanation for the reasons behind the occurrence of such a record inconsistency.

[0069] Step 1. UE performs registration with PLMN#1 (e.g., HPLMN) which involves a primary authentication. The AUSF may send the generated A-KID#1 and KAKMA#1 to the AAnF.

[0070] Step 2. UE initiates communication with the AF by sending, for example, an Application Session Establishment Request which carries the derived A-KID#1.

[0071] Step 3. AAnF sends A-KID#1 and KAF (i.e., AF key) to AF. Afterwards, the AF may send the Application Session Establishment Response to the UE.

[0072] Step 4. Due to roaming, UE is getting registered in PLMN#2 (e.g., VPLMN) and performs another round of primary authentication. AUSF sends the generated A-KID#2 and KAKMA#2 to the AAnF. Note that A-KID#2 and KAKMA#2 are refreshed from previous generated A-KID#1 and KAKMA#1.

[0073] Step 5. Once AAnF detects the PLMN change, it may determine, based on for example, a roaming policy, that AKMA service is restricted, prohibited, or not supported in PLMN#2. Consequently, the AAnF may send notifications to the subscribed AF (s) (that have subscribed to receive such notifications) , the notification carrying the updated (and up-to-date) AKMA key identifier, A-KID#2. That is, the A-KID in the notification message is from AAnF’s current view.

[0074] However, on the AF side, it is still keeping the A-KID#1 without being updated. This may be due to, for example, AKMA service is restricted, not allowed, or not support, when the UE is registered with or attached to the VPLMN, and the A-KID will not be updated. Therefore, there is a discrepancy in A-KID between the AAnF and AF, as that the AF is still employing A-KID#1 for AKMA service, which is obsolete, while AAnF is  updated to use A-KID#2. Due to this discrepancy, when receiving the notification message carrying A-KID#2, the AF may not be able to identify the corresponding AKMA key (and other AKMA security parameters) based on A-KID#2 in the notification message sent by the AAnF. Consequently, it may not be able to properly stop / shutdown the AKMA service for the UE, and / or it may not be able to clean up the AKMA record associated with the UE.

[0075] FIG. 9 illustrates an example scenario that triggers the discrepancy or mismatch issue. The scenario progresses from stage 1 to stage 2, where the UE undergoes a PLMN change. In stage 2, the A-KID mismatch occurs.

[0076] In this disclosure, various embodiments are disclosed, aiming to solve the above discussed issues with respect to AKMA service in roaming environment.

[0077] Embodiment 1: AAnF Making No Judgement on whether Primary Authentication is Performed for UE

[0078] In this embodiment, once AAnF detects that there is a PLMN change for the UE, it will not perform a check on whether a primary authentication has been performed for the UE after UE has established AKMA service with the AF. As an example, referring to FIG. 9, there is a PLMN change (from PLMN#1 to PLMN#2) in stage 2. Once AAnF detects this PLMN change, it will not check whether a primary authentication has been performed for the UE after stage 1. A solution provided in this embodiment will address the above discussed issues (i.e., AF not able to stop AKMA service properly, AF not able to clean up AKMA service record due to A-KID mismatch) .

[0079] In some example implementations, the AF may be deployed in the operator’s domain.

[0080] The exemplary steps for this embodiment are described in details below with reference to FIG. 10. An exemplary method may include a portion or all of the following steps.

[0081] Step 1. UE registers with, or attaches to its HPLMN. The HPLMN is now the serving PLMN for the UE.

[0082] Step 2. UE may access the AF for an application service. The key material (e.g., AKMA key material such as A-KID, KAKMA of the UE) is provided to AF. While accessing the AAnF, the AF may also provide its URI to the AAnF, the URI may be used by the AAnF to send notification message to the corresponding AF that has subscribed to receive notification such as AKMA service disabling notification.

[0083] Step 3. UE is getting registered in a VPLMN due to, for example, UE roaming outside of its HPLMN. AAnF may detect the PLMN change via, for example, the Nudm_EventExposure_Notification message sent by the UDM.

[0084] Step 4. Based on a roaming policy, the AAnF may determine whether AKMA service is restricted, prohibited, or not supported when the UE is roaming in a VPLMN. Further, AAnF may determine whether the AF has subscribed to receive notifications on AKMA service update (e.g., when AKMA service is disabled) . If the AKMA service is restricted, prohibited, or not supported, and AF has subscribed to receive AKMA service notification, then steps 5 to 7 are executed. Otherwise, steps 5 to 7 may be skipped.

[0085] Step 5. For AF (s) which has subscribed to receive AKMA service update notification, the AAnF may send notifications to the subscribed AF (s) about AKMA service update via, for example, an Naanf_AKMA_ServiceDisableNotification message. The message may carry at least one of: the A-KID of the UE; the Subscription Permanent Identifier (SUPI) of the UE; or the Generic Public Subscription Identifier (GPSI) of the UE. The message may indicate that the AKMA service is disabled (or restricted, prohibited, not supported) . The message may further indicate or trigger the AF to delete its AKMA service related record associated with the UE.

[0086] Step 6. The AF may try to use the A-KID received from the notification message to determine the corresponding AKMA record (e.g., KAMKA, A-KID, KAF, etc. ) . If there is a  mismatch on the A-KID between AF and AAnF (e.g., AAnF processes updated A-KID after a primary authentication for the UE but AF still keeps the outdated A-KID) , AF may fail to lookup the AKMA record based on the received A-KID. In this case, AF may determine the UE and / or AKMA record for the UE based on the received SUPI or GPSI of the UE.

[0087] In some example implementations, when attempting to locate UE AKMA record, the AF may directly use the SUPI or GPSI of the UE carried in the notification message, without the need to use the A-KID included in the notification message.

[0088] Step 7. AF may send a response back to the AAnF. In some example implementations, once the AKMA record for the UE has been located, AF may proceed to disable or deactivate the AKMA service for the UE. Additionally or alternatively, AF may perform clean up operations, to delete AKMA record related to the UE.

[0089] A detailed description for an exemplary Naanf_AKMA_ServiceDisableNotification implementation is listed below.

[0090] Naanf_AKMA_ServiceDisableNotification service operation

[0091] Service operation name: Naanf_AKMA_ServiceDisableNotification

[0092] Description: AAnF notifies the NF consumer about AKMA service disable

[0093] NOTE: The AF may be implicitly subscribed to receive Naanf_AKMA_ServiceDisableNotification service operation.

[0094] Input, Required: A-KID, at least one of [SUPI or GPSI]

[0095] Input, Optional: None

[0096] Output, Required: None

[0097] Output, Optional: None

[0098] In some example implementations, the A-KID may be optional for the input.

[0099] Embodiment 2: AAnF Making No Judgement on whether Primary Authentication is Performed for UE

[0100] In this embodiment, once AAnF detects that there is a PLMN change for the UE,  it will not perform a check on whether a primary authentication has been performed for the UE after UE has established AKMA service with the AF. As an example, referring to FIG. 9, there is a PLMN change (from PLMN#1 to PLMN#2) in stage 2. Once AAnF detects this PLMN change, it will not check whether a primary authentication has been performed for the UE after stage 1. A solution provided in this embodiment will address the above discussed issues (i.e., AF not able to stop AKMA service properly, AF not able to clean up AKMA service record due to A-KID mismatch) .

[0101] In some example implementations, the AF may be deployed outside the operator’s domain.

[0102] The exemplary steps for this embodiment are described in details below with reference to FIG. 11. An exemplary method may include a portion or all of the following steps.

[0103] Step 1. UE registers with, or attaches to its HPLMN. The HPLMN is now the serving PLMN for the UE.

[0104] Step 2. UE may access the AF for an application service. The key material (e.g., AKMA key material such as A-KID, KAKMA of the UE) is provided to AF. While accessing the AAnF, the AF may also provide its URI to the AAnF, the URI may be used by the AAnF to send notification message to the corresponding AF that has subscribed to receive notification such as AKMA service disabling notification.

[0105] Step 3. UE is getting registered in a VPLMN due to, for example, scenarios such as the UE roaming outside of its HPLMN. AAnF may detect the PLMN change via, for example, the Nudm_EventExposure_Notification message sent by the UDM.

[0106] Step 4. Based on a roaming policy, the AAnF may determine whether AKMA service is restricted, prohibited, or not supported when the UE is roaming in a VPLMN. Further, AAnF may determine whether the AF has subscribed to receive notifications on AKMA service update (e.g., when AKMA service is disabled) . If the AKMA service is restricted,  prohibited, or not supported, and AF has subscribed to receive AKMA service notification, then steps 5 to 9 are executed. Otherwise, steps 5 to 9 may be skipped.

[0107] Step 5. For AF (s) which has subscribed to receive AKMA service update notification, the AAnF may send notifications to the subscribed AF (s) about AKMA service update via, for example, an Naanf_AKMA_ServiceDisableNotification message. As the AF is deployed outside of operator’s domain, the notification message may be sent using the NEF as a relay. That is, in this case, the notification message is sent indirectly to the AF. The message may carry at least one of: the A-KID of the UE; the SUPI of the UE; or the GPSI of the UE. This message may further include a list of AFs (e.g., list of AF identifiers or URIs) that have subscribed to receive the notification message. The message may indicate that the AKMA service is disabled (or restricted, prohibited, not supported) . The message may further indicate or trigger the AF to delete its AKMA service related record associated with the UE.

[0108] Step 6. The NEF may forward the notification message in step 5 to the AF via, for example, an Nnef_AKMA_ServiceDisableNotification message. As described earlier, the NEF is used as a relay here, to forward the notification message. Note that the name of notification message may be the same or different from the notification message in step 5. The message may carry at least one of: the A-KID of the UE; the SUPI of the UE; or the GPSI of the UE.

[0109] In some example implementations, the Naanf_AKMA_ServiceDisableNotification message received by the NEF may carry the SUPI of the UE but not GPSI. The NEF may translate the SUPI to GPSI, and insert GPSI into the Nnef_AKMA_ServiceDisableNotification message to be sent to the AF. In this case, SUPI of the UE is not carried in the Nnef_AKMA_ServiceDisableNotification message so it is not exposed to the AF.

[0110] Step 7. The AF may try to use the A-KID received from the notification message to determine the corresponding AKMA record (e.g., KAMKA) . If there is a mismatch between the A-KID between AF and AAnF (e.g., AAnF has updated A-KID after a primary  authentication for the UE but AF still keeps the outdated A-KID) , AF may fail to lookup the AKMA record based on the received A-KID. In this case AF may determine the UE and / or AKMA record for the UE based on the received SUPI or GPSI of the UE.

[0111] In some example implementations, when attempting to locate UE AKMA record, the AF may directly use the SUPI or GPSI of the UE carried in the notification message, without the need to use the A-KID included in the notification message.

[0112] Step 8. AF may send a response back to the NEF. In some example implementations, once the AKMA record for the UE has been located, AF may proceed to disable or deactivate the AKMA service for the UE. Additionally or alternatively, AF may perform clean up operations, to delete AKMA record related to the UE.

[0113] Step 9. The NEF may forward the response message to the AAnF.

[0114] A detailed description for an exemplary implementation for Naanf_AKMA_ServiceDisableNotification and Nnef_AKMA_ServiceDisableNotification according to this embodiment is listed below.

[0115] Naanf_AKMA_ServiceDisableNotification service operation

[0116] Service operation name: Naanf_AKMA_ServiceDisableNotification

[0117] Description: AAnF notifies the NF consumer about AKMA service disable

[0118] NOTE: The AF may be implicitly subscribed to receive Naanf_AKMA_ServiceDisableNotification service operation.

[0119] Input, Required: A-KID, at least one of [SUPI or GPSI]

[0120] Input, Optional: None

[0121] Output, Required: None

[0122] Output, Optional: None

[0123] In some example implementations, the A-KID may be optional for the input.

[0124] Nnef_AKMA_ServiceDisableNotification service operation

[0125] Service operation name: Nnef_AKMA_ServiceDisableNotification

[0126] Description: NEF notifies the NF consumer about AKMA service is disabled.

[0127] Input, Required: A-KID, GPSI

[0128] Input, Optional: None

[0129] Output, Required: None

[0130] Output, Optional: None

[0131] In some example implementations, the A-KID may be optional for the input.

[0132] Embodiment 3: AAnF Making Judgement on whether Primary Authentication is Performed for UE

[0133] In this embodiment, once AAnF detects that there is a PLMN change for the UE, it will further perform a check on whether a primary authentication has been performed for the UE after UE has established AKMA service with the AF. As an example, referring to FIG. 9, there is a PLMN change (from PLMN#1 to PLMN#2) in stage 2. Once AAnF detects this PLMN change, it will check whether a primary authentication has been performed for the UE after stage 1 (i.e., between the time frame after stage 1 and before stage 2) . The determination result will guide AAnF in parameter selection when sending notification message to the AF. Specifically, this embodiment handles the case in which the determination shows that a primary authentication has not been performed for the UE after stage 1. A solution provided in this embodiment will address the above discussed issues (i.e., AF not able to stop AKMA service properly, AF not able to clean up AKMA service record due to A-KID mismatch) .

[0134] In some example implementations, the AF may be deployed in the operator’s domain.

[0135] In some example implementations, the AF may be deployed outside the operator’s domain, and an NEF may be used as a relay for the notification message from the AAnF to the AF (s) .

[0136] The exemplary steps for this embodiment are described in details below with  reference to FIG. 12. In this example, the AF is deployed in the operator’s domain. An exemplary method may include a portion or all of the following steps.

[0137] Step 1. UE registers with, or attaches to its HPLMN. The HPLMN is the serving PLMN for the UE.

[0138] Step 2. UE may access the AF for an application service. The key material (e.g., AKMA key material such as A-KID, KAKMA of the UE) is provided to AF. While accessing the AAnF, the AF may also provide its URI to the AAnF, and the URI may be used by the AAnF to send notification message to the corresponding AF that has subscribed to receive notification such as AKMA service disabling notification.

[0139] Step 3. UE is getting registered in a VPLMN due to, for example, scenarios such as the UE roaming outside of its HPLMN. AAnF may detect the PLMN change via, for example, the Nudm_EventExposure_Notification message sent by the UDM.

[0140] The AAnF may determine whether a primary authentication was performed for the UE after step 2 (or after step 2 and before step 3) . Additionally or alternatively, the AAnF may determine whether A-KID of the UE has been updated after step 2 (or after step 2 and before step 3) . In this embodiment, the determination shows that no primary authentication was performed for the UE after step 2, and / or A-KID of the UE has not been updated after step 2.

[0141] Step 4. Based on a roaming policy, the AAnF may determine whether AKMA service is restricted, prohibited, or not supported when the UE is roaming in a VPLMN. Further, AAnF may determine whether the AF has subscribed to receive notifications on AKMA service update (e.g., when AKMA service is disabled) . If the AKMA service is restricted, prohibited, or not supported, and AF has subscribed to receive AKMA service notification, then steps 5 to 6 are executed. Otherwise, steps 5 to 6 may be skipped.

[0142] Step 5. For AF (s) which has subscribed to receive AKMA service update notification, the AAnF may send notifications to the subscribed AF (s) about AKMA service update via, for  example, an Naanf_AKMA_ServiceDisableNotification message. The message may carry the A-KID of the UE. As AAnF has determined that no primary authentication has been performed for the UE after step 2, the A-KID maintained by the AF is still current. Therefore, there is no need to insert GPSI or SUPI of the UE in the notification message. The notification message may indicate that the AKMA service is disabled (or restricted, prohibited, not supported) . The message may further indicate or trigger the AF to delete its AKMA service related record associated with the UE.

[0143] Step 6. AF may send a response back to the AAnF. In some example implementations, once the AKMA record for the UE has been located (in this case, via the A-KID that AF receives from the notification message) , AF may proceed to disable or deactivate the AKMA service for the UE. Additionally or alternatively, AF may perform clean up operations, to delete AKMA record related to the UE.

[0144] Note that the example as shown in FIG. 12 and described above may apply to the scenario that the AF is in the operator’s domain.

[0145] The underlying principles in embodiment 2 may also apply to this embodiment, if the AF is outside operator’s domain. In this case, an NEF may be used as a relay. The AAnF may send a notification message (e.g., Naanf_AKMA_ServiceDisableNotification message) to the NEF, and the NEF may forward the message (e.g., via an Nnef_AKMA_ServiceDisableNotification) to the AF. Note that if the UE identifier received by the NEF from the notification message is SUPI, the NEF may translate the SUPI into GPSI, and use GPSI when forwarding the notification message. That is, SUPI is replaced with GPSI of the UE when NEF forwarding notification to the AF.

[0146] A detailed description for an exemplary implementation for Naanf_AKMA_ServiceDisableNotification and Nnef_AKMA_ServiceDisableNotification according to this embodiment is listed below.

[0147] Naanf_AKMA_ServiceDisableNotification service operation

[0148] Service operation name: Naanf_AKMA_ServiceDisableNotification

[0149] Description: AAnF notifies the NF consumer about AKMA service disable

[0150] NOTE: The AF may be implicitly subscribed to receive Naanf_AKMA_ServiceDisableNotification service operation.

[0151] Input, Required: A-KID

[0152] Input, Optional: SUPI, GPSI of UE

[0153] Output, Required: None

[0154] Output, Optional: None

[0155] Nnef_AKMA_ServiceDisableNotification service operation

[0156] Service operation name: Nnef_AKMA_ServiceDisableNotification

[0157] Description: NEF notifies the NF consumer about AKMA service is disabled.

[0158] Input, Required: A-KID

[0159] Input, Optional: GPSI

[0160] Output, Required: None

[0161] Output, Optional: None

[0162] Embodiment 4: AAnF Making Judgement on whether Primary Authentication is Performed for UE

[0163] In this embodiment, once AAnF detects that there is a PLMN change for the UE, it will further perform a check on whether a primary authentication has been performed for the UE after UE has established AKMA service with the AF. As an example, referring to FIG. 9, there is a PLMN change (from PLMN#1 to PLMN#2) in stage 2. Once AAnF detects this PLMN change, it will check whether a primary authentication has been performed for the UE after stage 1 (i.e., between the time frame after stage 1 and before stage 2) . The determination result will guide AAnF in parameter selection when sending notification message to the AF. Specifically, this embodiment handles the case in which the determination shows that a primary authentication has been performed for the UE after stage 1. A solution provided in this embodiment will address the above discussed issues (i.e., AF not able to stop AKMA service properly, AF not able to clean up AKMA service record due  to A-KID mismatch) .

[0164] In some example implementations, the AF may be deployed in the operator’s domain.

[0165] In some example implementations, the AF may be deployed outside the operator’s domain, and an NEF may be used as a relay for the notification message from the AAnF to the AF (s) .

[0166] The exemplary steps for this embodiment are described in details below with reference to FIG. 13. In this example, the AF is deployed in the operator’s domain. An exemplary method may include a portion or all of the following steps.

[0167] Step 1. UE registers with, or attaches to its HPLMN. The HPLMN is the serving PLMN for the UE.

[0168] Step 2. UE may access the AF for an application service. The key material (e.g., AKMA key material such as A-KID, KAKMA of the UE) is provided to AF. While accessing the AAnF, the AF may also provide its URI to the AAnF, and the URI may be used by the AAnF to send notification message to the corresponding AF that has subscribed to receive notification such as AKMA service disabling notification.

[0169] Step 3. UE is getting registered in a VPLMN due to, for example, scenarios such as the UE roaming outside of its HPLMN. AAnF may detect the PLMN change via, for example, the Nudm_EventExposure_Notification message sent by the UDM.

[0170] The AAnF may determine whether a primary authentication was performed for the UE after step 2 (or after step 2 and before step 3) . Additionally or alternatively, the AAnF may determine whether A-KID of the UE has been updated after step 2 (or after step 2 and before step 3) . In this embodiment, the determination shows that a primary authentication was performed for the UE after step 2, and / or A-KID of the UE has been updated after step 2.

[0171] Step 4. Based on a roaming policy, the AAnF may determine whether AKMA service is restricted, prohibited, or not supported when the UE is roaming in a VPLMN. Further, AAnF may determine whether the AF has subscribed to receive notifications on AKMA service update (e.g., when AKMA service is disabled) . If the AKMA service is restricted, prohibited, or not supported, and AF has subscribed to receive AKMA service notification, then steps 5 to 7 are executed. Otherwise, steps 5 to 7 may be skipped.

[0172] Step 5. For AF (s) which has subscribed to receive AKMA service update notification, the AAnF may send notifications to the subscribed AF (s) about AKMA service via, for example, an Naanf_AKMA_ServiceDisableNotification message. As AAnF has determined that primary authentication has been performed for the UE after step 2, and / or the A-KID of the UE has been updated (which indicates that the A-KID maintained at AF side is out-of-date, and there is a A-KID mismatch between AAnF and AF) , there is a need to insert at least one of GPSI or SUPI of the UE into the notification message. The notification message may optionally carry the A-KID of the UE. The notification message may indicate that the AKMA service is disabled (or restricted, prohibited, not supported) , and may further indicate or trigger the AF to delete its AKMA service related record associated with the UE.

[0173] Step 6. Based on the GPSI or SUPI of the UE carries in the notification message, the AF may be able to identify the UE, and determine its AKMA record, which may include the KAKMA of the UE.

[0174] Step 7. AF may send a response back to the AAnF. In some example implementations, once the AKMA record for the UE has been located (in this case, via the GPSI or SUPI that AF receives from the notification message) , AF may proceed to disable or deactivate the AKMA service for the UE. Additionally or alternatively, AF may perform clean up operations, to delete AKMA record related to the UE.

[0175] Note that the example as shown in FIG. 13 and described above may apply to the scenario that the AF is in the operator’s domain.

[0176] The underlying principles in embodiment 2 may also apply to this embodiment, if the AF is outside operator’s domain. In this case, an NEF may be used as a relay. The AAnF may send a notification message (e.g., Naanf_AKMA_ServiceDisableNotification message) to the NEF, and the NEF may forward the message (e.g., via an Nnef_AKMA_ServiceDisableNotification) to the AF. Note that if the UE identifier received by the NEF from the notification message is SUPI, the NEF may translate the SUPI into GPSI, and use GPSI when forwarding the notification message. That is, SUPI is replaced with GPSI of the UE when NEF forwarding notification to the AF.

[0177] A detailed description for an exemplary implementation for Naanf_AKMA_ServiceDisableNotification and Nnef_AKMA_ServiceDisableNotification according to this embodiment is listed below.

[0178] Naanf_AKMA_ServiceDisableNotification service operation

[0179] Service operation name: Naanf_AKMA_ServiceDisableNotification

[0180] Description: AAnF notifies the NF consumer about AKMA service disable

[0181] NOTE: The AF may be implicitly subscribed to receive Naanf_AKMA_ServiceDisableNotification service operation.

[0182] Input, Required: SUPI and / or GPSI of UE

[0183] Input, Optional: A-KID

[0184] Output, Required: None

[0185] Output, Optional: None

[0186] Nnef_AKMA_ServiceDisableNotification service operation

[0187] Service operation name: Nnef_AKMA_ServiceDisableNotification

[0188] Description: NEF notifies the NF consumer about AKMA service is disabled.

[0189] Input, Required: GPSI

[0190] Input, Optional: A-KID

[0191] Output, Required: None

[0192] Output, Optional: None

[0193] It is noted that in this disclosure, the steps are listed for exemplary purpose. Some steps described in an embodiment may be optional, while some steps provide alternative, parallel solution to other steps.

[0194] Performed by a first network element, an exemplary method according to embodiments in this disclosure may include transmitting, to a second network element, a first message related to an update on an AKMA (Authentication and Key Management for Applications) service associated with a wireless device, wherein the first message carries at least one of: a Subscription Permanent Identifier (SUPI) of the wireless device; a Generic Public Subscription Identifier (GPSI) of the wireless device; or a first AKMA key identifier, A-KID of the wireless device, for identifying a first AKMA key of the wireless device, wherein the first A-KID is up-to-date for the wireless device.

[0195] In any portion or combination of the implementations above, the first network element comprises an AKMA Anchor Function (AAnF) , and the second network element comprises an Application Function (AF) .

[0196] In any portion or combination of the implementations above, the first message indicates the second network element to perform at least one of: deleting an AKMA record associated with the wireless device; or disabling, deactivating, or stopping an AKMA service for the wireless device.

[0197] In any portion or combination of the implementations above, the first message comprising an Naanf_AKMA_ServiceDisableNotification message.

[0198] In any portion or combination of the implementations above, before transmitting the first message, the method further comprises: detecting that a Public Land Mobile Network (PLMN) serving the wireless device is changed.

[0199] In any portion or combination of the implementations above, detecting that the PLMN serving the wireless device is changed comprises at least one of: detecting that the PLMN serving the wireless device is changed from a Home PLMN (HPLMN) to a Visited  PLMN (VPLMN) ; or detecting that the PLMN serving the wireless device is changed from the VPLMN to the HPLMN.

[0200] Performed by a first network element, another exemplary method according to embodiments in this disclosure may include receiving, from a second network element, a first message related to an update on an AKMA (Authentication and Key Management for Applications) service associated with a wireless device, wherein the first message carries at least one of: a Subscription Permanent Identifier (SUPI) of the wireless device; a Generic Public Subscription Identifier (GPSI) of the wireless device; or a first AKMA key identifier, A-KID of the wireless device, for identifying a first AKMA key of the wireless device, wherein the first A-KID is up-to-date for the wireless device.

[0201] In any portion or combination of the implementations above, the first network element comprises an Application Function (AF) , and the second network element comprises an AKMA Anchor Function (AAnF) .

[0202] In any portion or combination of the implementations above, the first message indicates the first network element to perform at least one of: deleting an AKMA record associated with the wireless device; or disabling, deactivating, or stopping an AKMA service for the wireless device.

[0203] In any portion or combination of the implementations above, wherein the first message comprises at least one of: an Naanf_AKMA_ServiceDisableNotification message; or an Nnef_AKMA_ServiceDisableNotification message.

[0204] In any portion or combination of the implementations above, when receiving the first message, the first network element stores a second A-KID for identifying a second AKMA key of the wireless device, and the second A-KID is out-of-date for the wireless device.

[0205] In any portion or combination of the implementations above, after the first network element acquires the second A-KID, the wireless device performs a primary  authentication procedure and updates its A-KID from the second A-KID to the first A-KID.

[0206] In any portion or combination of the implementations above, the primary authentication procedure is triggered by a change of a Public Land Mobile Network (PLMN) serving the wireless device.

[0207] In any portion or combination of the implementations above, wherein the change of the PLMN serving the wireless device comprises a change from a Home PLMN (HPLMN) to a Visited PLMN (VPLMN) .

[0208] In this disclosure, message types and / or message names are for exemplary purpose only. Different message types and / or message names may be chosen in implementation, and should still be covered by this disclosure, as far as the underlying principle is the same, for example, if the messages are used for a same purpose and / or carry similar parameters.

[0209] In this disclosure, a single information element in a message may be split into multiple information elements. Multiple information element may also be combined into a single information element.

[0210] In this disclosure, various embodiments are disclosed for managing AKMA service when certain AKMA identification information is mismatch between AAnF and AF. The identification information mismatch may include A-KID mismatch and may be caused by a UE roams from its HPLMN to a VPLMN, and AKMA service is restricted, not allowed, or not supported in VPLMN. Various mechanisms are described for the AF to locate AKMA record (or AKMA key material) for the UE. The AF may then further clean up the obsolete AKMA record and / or disable, deactivate, or stop the AKMA service for the UE.

[0211] In this disclosure, the steps in each embodiment are for illustration purposes only and other alternatives may be derived based on the disclosed embodiments as desired. For example, only part of the steps may need to be performed. For another example, the  sequence of the steps may be adjusted. For another example, several steps may be combined (e.g., several messages may be combined in one message) . For yet another example, a single step may be split (e.g., one message may be sent via two sub-messages) .

[0212] In this disclosure, various embodiments may be combined to form a single embodiment, if there is no conflict. For example, embodiments 3 and 4 may be combined into an integrated embodiment, which covers two scenarios: a first scenario where there exists an A-KID mismatch between AAnF and AF, and a second scenario where there is no A-KID mismatch between AAnF and AF.

[0213] The accompanying drawings and description above provide specific example embodiments and implementations. The described subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is intended to be construed as not being limited to any example embodiments set forth herein. A reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, systems, or non-transitory computer-readable media for storing computer codes. Accordingly, embodiments may, for example, take the form of hardware, software, firmware, storage media or any combination thereof. For example, the method embodiments described above may be implemented by components, devices, or systems including memory and processors by executing computer codes stored in the memory.

[0214] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase “in one embodiment / implementation” as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment / implementation” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter includes combinations of example embodiments in whole or in part.

[0215] In general, terminology may be understood at least in part from usage in context. For example, terms, such as “and” , “or” , or “and / or, ” as used herein may include a variety of  meanings that may depend at least in part on the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a, ” “an, ” or “the, ” may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for existence of additional factors not necessarily expressly described, again, depending at least in part on context.

[0216] Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present solution should be or are included in any single implementation thereof. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, discussions of the features and advantages, and similar language, throughout the specification may, but do not necessarily, refer to the same embodiment.

[0217] Furthermore, the described features, advantages and characteristics of the present solution may be combined in any suitable manner in one or more embodiments. One of ordinary skill in the relevant art will recognize, in light of the description herein, that the present solution can be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the present solution.

Claims

1.A method for wireless communication, performed by a first network element, comprising:transmitting, to a second network element, a first message related to an update on an AKMA (Authentication and Key Management for Applications) service associated with a wireless device, wherein the first message carries at least one of:a Subscription Permanent Identifier (SUPI) of the wireless device;a Generic Public Subscription Identifier (GPSI) of the wireless device; ora first AKMA key identifier, A-KID of the wireless device, for identifying a first AKMA key of the wireless device, wherein the first A-KID is up-to-date for the wireless device.2.The method of claim 1, wherein the first network element comprises an AKMA Anchor Function (AAnF) .3.The method of claim 1, wherein the second network element comprises an Application Function (AF) .4.The method of claim 1, wherein the first message indicates the second network element to perform at least one of: deleting an AKMA record associated with the wireless device; or disabling, deactivating, or stopping an AKMA service for the wireless device.5.The method of claim 4, wherein the first message comprising an Naanf_AKMA_ServiceDisableNotification message.6.The method of claim 1, wherein before transmitting the first message, the method further comprises:detecting that a Public Land Mobile Network (PLMN) serving the wireless device is changed.7.The method of claim 6, wherein detecting that the PLMN serving the wireless device is changed comprises at least one of:detecting that the PLMN serving the wireless device is changed from a Home PLMN (HPLMN) to a Visited PLMN (VPLMN) ; ordetecting that the PLMN serving the wireless device is changed from the VPLMN to the HPLMN.8.The method of any one of claim 1-7, wherein, before receiving the first message, the second network element stores a second A-KID for identifying a second AKMA key of the wireless device, wherein the second A-KID is out-of-date for the wireless device when the second network element receives the first message.9.The method of claim 8, wherein after the second network element acquires the second A-KID, the wireless device performs a primary authentication procedure and updates its A-KID from the second A-KID to the first A-KID.10.The method of claim 9, wherein the primary authentication procedure is triggered by a change of Public Land Mobile Network (PLMN) serving the wireless device.11.The method of claim 10, wherein the change of the PLMN serving the wireless device comprises at least one of:a change from a Home PLMN (HPLMN) to a Visited PLMN (VPLMN) ; ora change from the VPLMN to the HPLMN.12.The method of claim 8, wherein the first message triggers the second network element to identify the wireless device or an AKMA record associated with the wireless device based on at least one of: the SUPI of the wireless device, or the GPSI of the wireless device.13.The method of claim 12, wherein the AKMA record comprises the second A-KID of the wireless device.14.The method of any one of claim 1-7, wherein transmitting the first message comprises:in response to determining at least one of:an AKMA service for the wireless device being disabled, restricted, not allowed, or not supported; oran access to the second network element being restricted for the wireless device due to a roaming policy,transmitting the first message to the second network element.15.The method of any one of claim 1-7, further comprising determining, whether a second A-KID of the wireless device stored by the second network element is out-of-date.16.The method of any one of claim 1-7, further comprising determining, whether a second A-KID of the wireless device stored by the second network element is out-of-date based at least in part on:whether a primary authentication is performed after the second network element acquires the second A-KID; orwhether a PLMN serving the wireless device is changed from a HPLMN to a VPLMN after the second network element acquires the first A-KID.17.The method of any one of claim 1-7, wherein, in a determination that a second A-KID of the wireless device stored by the second network element is out-of-date, or a primary authentication has been performed for the wireless device after the second network element stores the second A-KID, the first message carries at least one of:the SUPI of the wireless device; orthe GPSI of the wireless device.18.The method of any one of claim 1-7, wherein, in a determination that a second A-KID of the wireless device stored by the second network element is up-to-date, the first message does not carry:the SUPI of the wireless device; andthe GPSI of the wireless device.19.The method of any one of claim 1-7, wherein transmitting the first message comprising:transmitting, via a third network element to a second network element, the first message.20.The method of claim 19, wherein the third network element comprises a Network Exposure Function (NEF) .21.The method of claim 20, wherein the first network element is in a first domain and the second network element is in a second domain that is different from the first domain.22.The method of claim 21, wherein the first domain comprises an operator domain, and the second domain comprises a third party domain.23.A method for wireless communication, performed by a first network element, comprising:receiving, from a second network element, a first message related to an update on an AKMA (Authentication and Key Management for Applications) service associated with a wireless device, wherein the first message carries at least one of:a Subscription Permanent Identifier (SUPI) of the wireless device;a Generic Public Subscription Identifier (GPSI) of the wireless device; ora first AKMA key identifier, A-KID of the wireless device, for identifying a first AKMA key of the wireless device, wherein the first A-KID is up-to-date for the wireless device.24.The method of claim 23, wherein the first network element comprises an Application Function (AF) .25.The method of claim 23, wherein the second network element comprises an AKMA Anchor Function (AAnF) .26.The method of claim 23, wherein the first message indicates the first network element to perform at least one of: deleting an AKMA record associated with the wireless device; or disabling, deactivating, or stopping an AKMA service for the wireless device.27.The method of claim 23, wherein the first message comprises at least one of:an Naanf_AKMA_ServiceDisableNotification message; oran Nnef_AKMA_ServiceDisableNotification message.28.The method of claim 23, wherein, when receiving the first message, the first network element stores a second A-KID for identifying a second AKMA key of the wireless device, and the second A-KID is out-of-date for the wireless device.29.The method of claim 28, wherein after the first network element acquires the second A-KID, the wireless device performs a primary authentication procedure and updates its A-KID from the second A-KID to the first A-KID.30.The method of claim 29, wherein the primary authentication procedure is triggered by a change of a Public Land Mobile Network (PLMN) serving the wireless device.31.The method of claim 30, wherein the change of the PLMN serving the wireless device comprises a change from a Home PLMN (HPLMN) to a Visited PLMN (VPLMN) .32.The method of claim 28, wherein, in response to the second A-KID being out-of-date, the first message comprising at least one of:the SUPI of the wireless device; orthe GPSI of the wireless device.33.The method of any one of claims 23-32, further comprising identifying the wireless device or an AKMA record associated with the wireless device based on at least one of:the SUPI of the wireless device; orthe GPSI of the wireless device.34.The method of claim 33, wherein identifying the wireless device or the AKMA record associated with the wireless device comprises:detecting a failure when attempting to identify the wireless device or the AKMA record associated with the wireless device based on the first A-KID; andin response to detecting the failure, identifying the wireless device or the AKMA record associated with the wireless device base on at least one of:the SUPI of the UE; orthe GPSI of the UE.35.The method of claim 33, further comprising at least one of:deleting the AKMA record associated with the wireless device; ordisabling, deactivating, or stopping an AKMA service with the wireless device.36.The method of claim 33, wherein the AKMA record comprises the second A-KID of the wireless device.37.The method of any one of claims 23-32, wherein before receiving the first message, the method further comprises:subscribing with the first network element to receive AKMA service update notification by using a Uniform Resource Identifier (URI) of the first network element.38.The method of any one of claims 23-32, wherein receiving the first message comprising:receiving, via a third network element, the first message initiated from the second network element.39.The method of claim 38, wherein the third network element comprises a Network Exposure Function (NEF) .40.The method of claim 39, wherein the first network element is in a first domain and the second network element is in a second domain that is different from the first domain.41.The method of claim 40, wherein the first domain comprises a third party domain, and the second domain comprises an operator domain.42.A device or a network element comprising a memory for storing computer  instructions and a processor in communication with the memory, wherein the processor, when executing the computer instructions, is configured to implement a method in any one of claims 1-41.43.A computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon, the computer code, when executed by one or more processors, causing the one or more processors to implement a method of any one of claims 1-41.

Citation Information

Patent Citations

  • Key change notification for authentication and key management of applications

    CN115066916A

  • Apparatus and method for generating application-specific keys using keys derived from network access authentication

    CN115152257A

  • Authentication server function selection in authentication and key management

    US20210392495A1

  • Secure information pushing by service applications in communication networks

    WO2023082161A1