Method, device and computer program product for wireless communication

The method of generating and managing user-specific keys and identifiers in wireless communication networks addresses the need for enhanced user experience and customization by ensuring secure and efficient communication and service provision.

WO2025156442A1PCT designated stage Publication Date: 2025-07-31ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/086397
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-07
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

The implementation of user identifiers in wireless communication networks, particularly in 5G and 6G, is still a topic of discussion, and there is a need for enhanced user experience and customization through the use of user-specific identities.

Method used

A method for generating and managing user-specific keys and identifiers within the network, involving authentication nodes, anchor nodes, and application nodes to facilitate secure and efficient communication and service provision.

Benefits of technology

Enables secure and customized communication services by ensuring user authentication and authorization, allowing for optimized performance and tailored experiences for individual users or devices within the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024086397_31072025_PF_FP_ABST
    Figure CN2024086397_31072025_PF_FP_ABST
Patent Text Reader

Abstract

A wireless communication method is disclosed. The method comprises generating, by an authentication node, a first key corresponding to a user and a first key identifier identifying the first key based on a second key of the authentication node in response to user identifier information being received; and transmitting, by the authentication node to an anchor node, the first key, the first key identifier, and a user identifier list.
Need to check novelty before this filing date? Find Prior Art

Description

Method, Device and Computer Program Product for Wireless Communication

[0001] This document is directed generally to wireless communications, and in particular to 5th generation (5G) communications or 6th generation (6G) communications.

[0002] User identifiers in a communication network help an operator to provide customization and enhanced user experience for services inside and outside the network. However, the implementation of user identifiers is still a topic to be discussed.

[0003] This document relates to methods, systems, and computer program products for a wireless communication.

[0004] One aspect of the present disclosure relates to a wireless communication method. In an embodiment, the wireless communication method includes: generating, by an authentication node, a first key corresponding to a user and a first key identifier identifying the first key based on a second key of the authentication node in response to user identifier information being received; and transmitting, by the authentication node to an anchor node, at least one of the first key, the first key identifier, or a user identifier list.

[0005] Various embodiments may preferably implement the following features:

[0006] Preferably, the user identifier information comprises at least one of:

[0007] the user identifier list comprising one or more user identifiers; or

[0008] an anchor node identifier list comprising one or more identifiers of anchor nodes corresponding to the one or more user identifiers.

[0009] Preferably, the anchor node is selected based on the user identifier information.

[0010] Preferably, the anchor node is selected based on at least a part of a user identifier in the user identifier information or an identifier of anchor node corresponding to the user identifier.

[0011] Preferably, the first key identifier comprises at least one of: an identifier of the anchor node, a temporary identifier corresponding to the user , or a home network identifier.

[0012] Preferably, the temporary identifier corresponding to the user is derived based on at least one of the second key of the authentication node, a user identifier in the user identifier information, or a length of the user identifier.

[0013] Preferably, the first key is derived based on at least one of the second key of the  authentication node, a user identifier in the user identifier information, or a length of the user identifier.

[0014] Preferably, the authentication node receives the user identifier information from a data management node.

[0015] Preferably, the authentication node transmits, to an access management node , the user identifier information.

[0016] Preferably, the authentication node generates the first key and the first key identifier identifying the first key in response to an authentication for the user identifier information being successful.

[0017] Preferably, the authentication node receives, from the anchor node, a response for receiving the first key and the first key identifier.

[0018] Another aspect of the present disclosure relates to a wireless communication method. In an embodiment, the wireless communication method includes: transmitting, by an application node to an anchor node, a request for an application key for decrypting an encrypted user identifier received from a wireless communication terminal based on a first key identifier; and receiving, by the application node from the anchor node, a response comprising the application key.

[0019] Various embodiments may preferably implement the following features:

[0020] Preferably, the application node transmits the request for the application key in response to receiving, from the wireless communication terminal a first message comprising the first key identifier and the encrypted user identifier.

[0021] Preferably, the request comprises at least one of the first key identifier or an identifier of the application node.

[0022] Preferably, the response further comprises at least one of:

[0023] an expiration time of the application key; or

[0024] a subscription identifier corresponding to the wireless communication terminal.

[0025] Preferably, the application node performs at least one of:

[0026] transmitting, to the anchor node, the request via a network exposure node; or

[0027] receiving, from the anchor node, the response via a network exposure node.

[0028] Preferably, the application node selects the anchor node based on the first key identifier.

[0029] Preferably, the application node transmits, to the wireless communication terminal, a  message to accept or reject an application session for a user.

[0030] Another aspect of the present disclosure relates to a wireless communication method. In an embodiment, the wireless communication method includes: receiving, by an anchor node from an application node, a request for an application key for decrypting an encrypted user identifier; and transmitting, by the anchor node to the application node, a response comprising the application key.

[0031] Various embodiments may preferably implement the following features:

[0032] Preferably, the anchor node derives the application key based on a first key identified by a first key identifier in the request.

[0033] Preferably, the anchor node transmits the response to the application node in response to at least one of: a configured local policy or authorization information in the request.

[0034] Preferably, the anchor node transmits the response to the application node in response to a first key corresponding to a first key identifier in the request being stored in the anchor node.

[0035] Preferably, the anchor node receives, from an authentication node , at least one of: a first key identifying a first key identifier, a first key identifier, or a user identifier list comprising one or more user identifiers.

[0036] Preferably, the request comprises at least one of the first key identifier or an identifier of the application node.

[0037] Preferably, the response further comprises at least one of:

[0038] an expiration time of the application key; or

[0039] a subscription identifier corresponding to the wireless communication terminal.

[0040] Preferably, the anchor node performs at least one of:

[0041] receiving, from the application node, the request via a network exposure node; or

[0042] transmitting, to the application node, the response via a network exposure node.

[0043] Another aspect of the present disclosure relates to a wireless communication method. In an embodiment, the wireless communication method includes: transmitting, by a network exposure node to an anchor node, a first request for an application key for decrypting an encrypted user identifier based on a first key identifier; and receiving, by the network exposure node from the anchor node, a first response comprising the application key.

[0044] Various embodiments may preferably implement the following features:

[0045] Preferably, the network exposure node performs at least one of:

[0046] receiving , from an application node , a second request for the application key; or

[0047] transmitting , to an application node, a second response comprising the application key in response to receiving the first response.

[0048] Preferably, the network exposure node transmits the first request to the anchor node in response to the application node is authorized.

[0049] Preferably, the second request comprises at least one of the first key identifier or an identifier of the application node.

[0050] Preferably, the second response further comprises at least one of:

[0051] an expiration time of the application key; or

[0052] a Generic Public Subscription Identifier, GPSI.

[0053] Preferably, the first response further comprises at least one of:

[0054] an expiration time of the application key; or

[0055] a Subscription Permanent Identifier, SUPI.

[0056] Preferably, the first request comprises at least one of:

[0057] the first key identifier; or

[0058] an identifier of the application node.

[0059] Preferably, the network exposure node selects the anchor node based on the first key identifier.

[0060] Another aspect of the present disclosure relates to a wireless communication method. In an embodiment, the wireless communication method includes: transmitting, by a wireless communication terminal to an application node, a request for an application session for a user, the request comprising a first key identifier corresponding to the user and an encrypted user identifier corresponding to the user to allow the application node to obtain an application key for decrypting the encrypted user identifier.

[0061] Various embodiments may preferably implement the following features:

[0062] Preferably, the wireless communication terminal encrypts a user identifier of the user to generate the encrypted user identifier based on the application key.

[0063] Preferably, the wireless communication terminal derives the application key based on a first key corresponding to the first key identifier.

[0064] Preferably, the first key is derived based on at least one of a second key of an authentication node , the user identifier, or a length of the user identifier.

[0065] Preferably, the first key identifier comprises at least one of: an identifier of an anchor node corresponding to the user, a temporary identifier corresponding to the user , or a home network identifier.

[0066] Preferably, the temporary identifier corresponding to the user is derived based on at least one of: a second key of an authentication node, a user identifier of the user, or a length of the user identifier of the user.

[0067] Preferably, the wireless communication terminal receives, from the application node, a message to accept or reject the application session.

[0068] Another aspect of the present disclosure relates to a wireless communication node. In an embodiment, the wireless communication node includes a communication unit and a processor. The processor is configured to: generate a first key corresponding to a user and a first key identifier identifying the first key based on a second key of the authentication node in response to user identifier information being received; and transmit, via the communication unit to an anchor node, at least one of the first key, the first key identifier, or a user identifier list.

[0069] Another aspect of the present disclosure relates to a wireless communication node. In an embodiment, the wireless communication node includes a communication unit and a processor. The processor is configured to: transmit, via the communication unit to an anchor node, a request for an application key for decrypting an encrypted user identifier received from a wireless communication terminal based on a first key identifier; and receive, via the communication unit from the anchor node, a response comprising the application key.

[0070] Another aspect of the present disclosure relates to a wireless communication node. In an embodiment, the wireless communication node includes a communication unit and a processor. The processor is configured to: receive, via the communication unit from an application node, a request for an application key for decrypting an encrypted user identifier; and transmit, via the communication unit to the application node, a response comprising the application key.

[0071] Another aspect of the present disclosure relates to a wireless communication node. In an embodiment, the wireless communication node includes a communication unit and a processor. The processor is configured to: transmit, via the communication unit to an anchor node, a first  request for an application key for decrypting an encrypted user identifier based on a first key identifier; and receive, via the communication unit from the anchor node, a first response comprising the application key.

[0072] Another aspect of the present disclosure relates to a wireless communication terminal. In an embodiment, the wireless communication terminal includes a communication unit and a processor. The processor is configured to: transmit, via the communication unit to an application node, a request for an application session for a user, the request comprising a first key identifier corresponding to the user and an encrypted user identifier corresponding to the user to allow the application node to obtain an application key for decrypting the encrypted user identifier.

[0073] The present disclosure relates to a computer program product comprising a computer-readable program medium code stored thereupon, the code, when executed by a processor, causing the processor to implement a wireless communication method recited in any one of foregoing methods.

[0074] The exemplary embodiments disclosed herein are directed to providing features that will become readily apparent by reference to the following description when taken in conjunction with the accompanying drawings. In accordance with various embodiments, exemplary systems, methods, devices and computer program products are disclosed herein. It is understood, however, that these embodiments are presented by way of example and not limitation, and it will be apparent to those of ordinary skill in the art who read the present disclosure that various modifications to the disclosed embodiments can be made while remaining within the scope of the present disclosure.

[0075] Thus, the present disclosure is not limited to the exemplary embodiments and applications described and illustrated herein. Additionally, the specific order and / or hierarchy of steps or operations in the methods disclosed herein are merely exemplary approaches. Based upon design preferences, the specific order or hierarchy of steps or operations of the disclosed methods or processes can be re-arranged while remaining within the scope of the present disclosure. Thus, those of ordinary skill in the art will understand that the methods and techniques disclosed herein present various steps or operations in a sample order, and the present disclosure is not limited to the specific order or hierarchy presented unless expressly stated otherwise.

[0076] The above and other aspects and their implementations are described in greater detail in the drawings, the descriptions, and the claims.

[0077] FIG. 1 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.

[0078] FIG. 2 shows a schematic diagram of a network according to an embodiment of the present disclosure.

[0079] FIGs. 3A and 3B show a schematic diagram of a procedure according to an embodiment of the present disclosure.

[0080] FIG. 4 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.

[0081] FIG. 5 shows a schematic diagram of a procedure according to an embodiment of the present disclosure.

[0082] FIG. 6 shows an example of a schematic diagram of a wireless communication terminal according to an embodiment of the present disclosure.

[0083] FIG. 7 shows an example of a schematic diagram of a wireless communication node according to an embodiment of the present disclosure.

[0084] FIGs. 8 to 12 show flowcharts of wireless communication methods according to some embodiments of the present disclosure.

[0085] In some embodiments of the present disclosure, the 5G System may be enhanced to allow for the creation and utilization of user-specific identities to provide the enhanced user experience, the optimized performance and offer services to specific users. In some embodiments, the user to be identified could be an individual human user using a User Equipment (UE) with a certain subscription or a device behind a gateway UE. One of the identified use cases is that one or more users (e.g., humans or devices identified by user identifier) sharing one UE.

[0086] Some embodiments of the present disclosure provide a method to identify the case when user (s) is involved and provide the security mechanism for protection, authentication and authorization of user identifiers (e.g., human user) associated with a subscription and used on a UE.

[0087] Aspect 0:

[0088] FIG. 1 shows a schematic diagram of a procedure according to an embodiment of the present disclosure. In some embodiments, the procedure may include at least one of the following operations.

[0089] 1. The UE is registered and established Protocol Data Unit (PDU) Sessions without  the User Identifier. The procedure follows existing procedures.

[0090] 2. The UE sends a Non-access Stratum (NAS) message (e.g., a Registration Request by including the User Identifier of the user) .

[0091] 3. Based on the User Identifier provided by the UE, the Access and Mobility Management Function (AMF) triggers the authentication of the User Identifier.

[0092] 4. The AMF triggers a service operation (e.g., Nudm_UECM_Update) to notify the Unified Data Management (UDM) . In some embodiments, the notification may include that the User Identifier is activated, and the User Identifier is served by the UE.

[0093] In some embodiments, the UDM may check whether the User Identifier is used by the other UE (e.g., check whether the User Identifier is already activated by the other UE) . In some embodiments, if the User Identifier is used by the other UE, based on local policy, the UDM either rejects the registration or sends the notification (e.g., Nudm_UECM_DeregistrationNotification) to the other UE which is using the User Identifier to deactivate User Identifier over the UE.

[0094] 5. The AMF retrieves the User Identity Profile from the UDM by triggering a service operation (e.g., Nudm_SDM_Get) by providing the User Identifier. In some embodiments, based on the received information, the AMF may check whether the UE is allowed to be used by the User Identifier.

[0095] 6. If the User Identifier is allowed to get a service with the UE, the AMF may send the NAS message (e.g., the Registration Accept) to the UE with indication that the User Identifier is allowed. In some embodiments, the AMF stores the User Identifier in the UE Context. Otherwise, the AMF notifies the UDM that the User Identifier is deactivated and sends the NAS message (e.g., the Registration Accept) to the UE with indication that the User Identifier is not allowed, and the procedure stops.

[0096] 7. The AMF triggers a service operation (e.g., Nsmf_PDUSession_UpdateSMContext) to release existing PDU Session (s) .

[0097] 8. The UE sends a request (e.g., PDU Session Establishment Request) message to the AMF.

[0098] 9. The AMF triggers a service operation (e.g., Nsmf_PDUSession_CreateSMContext) and includes the User Identifier.

[0099] 10. The SMF retrieves a User Identity Profile from the UDM by triggering the service  operation (e.g., Nudm_SDM_Get) by providing the User Identifier. Based on the received information, the SMF may update the Quality of Service (QoS) based on operator policy.

[0100] 11. The SMF may create the SM Policy Association with the Policy Control Function (PCF) and includes the User Identifier. Based on the received User Identifier, the PCF can retrieve the User Identity Profile from the Unified Data Repository (UDR) to apply the User Identifier specific policy.

[0101] 12. The SMF may register the PDU Session to notify the UDM that the User Identifier is using the PDU Session.

[0102] 13. The SMF may provide the PDU Session Establishment Accept message to the UE.

[0103] Aspect 1:

[0104] FIG. 2 shows a schematic diagram of a network model for the User Identities and Authentication (UIA) according to an embodiment of the present disclosure.

[0105] In some embodiments of the present disclosure, the UIA Anchor Function (also referred to as UIA Anchor, UIA-Anchor Function, or UIA-Anchor in the present disclosure) is used. In some embodiments, the UIA Anchor Function is the anchor of the UIA service. Note that, in different scenarios, the name of the UIA Anchor Function might be varied, and the present disclosure is not limited thereto. In some embodiments, the UIA Anchor Function can be an independent network function or can be incorporated with another network function (s) .

[0106] Aspect 2:

[0107] FIGs. 3A and 3B show a schematic diagram of a procedure according to an embodiment of the present disclosure. In some embodiments, a user profile list provision and protection during the registration procedure are provided. In some embodiments, the procedure may include at least one of the following operations.

[0108] 1. The UE sends a registration request to the gNodeB (gNB) , including the UE 5G-Globally Unique Temporary Identity (GUTI) or Subscription Concealed Identifier (SUCI) .

[0109] 2. The Radio Access Network (RAN) selects an AMF (e.g., a new AMF) and forwards the Registration Request to the AMF (e.g., the new AMF) .

[0110] 3. [Conditional] The new AMF sends a complete Registration Request (e.g., Namf_Communication_UEContextTransfer) to the old AMF. In some embodiments, the new AMF determines the old AMF using the 5G-GUTI of the UE.

[0111] 4. [Conditional] The old AMF sends a response (e.g., Namf_Communication_UEContextTransfer) to the new AMF. In some embodiments, the response (e.g., Namf_Communication_UEContextTransfer) may include at least one of the Subscription Permanent Identifier (SUPI) and / or the UE Context in the AMF.

[0112] 5. [Conditional] The new AMF sends a request (e.g., the Identity Request) to the UE. In some embodiments, if the SUCI is not provided by the UE or the SUCI is not retrieved from the old AMF by the new AMF, the Identity Request procedure may be initiated by the AMF (e.g., the new AMF) . In some embodiments, the new AMF may send a request (e.g., the Identity Request) to the UE requesting the SUCI.

[0113] 6. [Conditional] The UE sends a response (e.g., the Identity Response) to the new AMF. In some embodiments, the UE responds with an Identity Response message including the SUCI. In some embodiments, the UE derives the SUCI by using the provisioned public key of the Home Public Land Mobile Network (HPLMN) .

[0114] 7. The AMF (e.g., the new AMF) may invoke the operation service (e.g., Nausf_UEAuthentication) by sending a request (e.g., Nausf_UEAuthentication_Authenticate Request) message to the Authentication Server Function (AUSF) . In some embodiments, whenever the AMF (e.g., the new AMF) wishes to initiate an authentication, the request (e.g., Nausf_UEAuthentication_Authenticate Request) message include the SUPI, the SUCI and / or the serving network name.

[0115] 8. The AUSF sends a request (e.g., Nudm_UEAuthentication_Get Request) to the UDM. In some embodiments, the request (e.g., Nudm_UEAuthentication_Get Request) may include the SUPI, the SUCI and / or the serving network name. In some embodiments, the request is for an authentication of the UE.

[0116] 9. The UDM may transmit a response to the AUSF. In some embodiments, the response responds the request. In some embodiments, the response comprises the user subscription (also referred to as user subscription data) . In some embodiments, the response comprises the user subscription data if the UE has a UIA subscription. In some embodiments, the user subscription comprises a user identifier list (also referred to as User_Id list or user id list) . In some embodiments, the User_Id list comprises one or more user identifiers (also referred to as User_Ids or user ids) .

[0117] In some embodiments, the UIA Anchor Identifier (also referred to as UIA-Anchor IDs  or UIA-AnchorIDs) is used (e.g., for the network) to identify a certain UIA Anchor Function.

[0118] In some embodiments, the response or the user subscription data from the UDM to the AUSF further comprises an anchor identifier list (e.g., a UIA-Anchor ID list) (also referred to as UIA-Anchor ID list or UIA-AnchorID list) . In some embodiments, the UIA-Anchor ID list comprises one or more anchor identifiers (e.g., a UIA-Anchor IDs) (also referred to as UIA-Anchor IDs or UIA Anchor Indicators) . In some embodiments, the UIA-Anchor ID list has a mapping relationship with the User_Id list. In some embodiments, UIA-Anchor ID (s) in the UIA-Anchor ID list has a mapping relationship with the User_Id (s) in the User_Id list.

[0119] In some embodiments, the response or the user subscription data comprises the anchor identifier list if a UIA-Anchor ID is not a part of a User_Id. In some embodiments, a UIA-Anchor ID may be a part of a User_Id. In such a case, the UDM may not transmit to the AUSF the UIA-Anchor ID list, but is not limited thereto.

[0120] In some embodiments, the UIA Anchor Indicator is used (e.g., for the network) to identify a certain UIA Anchor Function. In some embodiments, said certain UIA Anchor Function corresponds to a certain user id (e.g., User_Id) . In some embodiments, different user ids for a single UE may correspond to (e.g., mapped to) different UIA Anchor Indicators. In some embodiments, said different user ids may be transmitted to, register to, and / or stored by different UIA Anchor Functions.

[0121] In some embodiments, the response from the UDM to the AUSF may be a response (e.g., Nudm_UEAuthentication_Get Response) for an authentication of the UE. In some embodiments, the UDM may return the 5G Home Environment Authentication Vector (HE AV) to the AUSF together with an indication that the 5G HE AV is to be used for the 5G Authentication and Key Management (AKA) in the response (e.g., Nudm_UEAuthentication_Get Response) . In some embodiments, if the SUCI is included in the request (e.g., Nudm_UEAuthentication_Get Request) , the UDM may include the SUPI in the response (e.g., Nudm_UEAuthentication_Get Response) after the deconcealment of the SUCI.

[0122] 10. The AUSF may store the expected response (XRES*) temporarily together with the received SUCI or the SUPI.

[0123] In some embodiments, the AUSF may then generate the 5G AV from the 5G HE AV received from the UDM / Authentication credential Repository and Processing Function (ARPF) . In  some embodiments, the 5G AV may be generated by computing the expected response token (HXRES*) from the XRES*and the anchor keys (e.g., KSEAF) from the AUSF Key (KAUSF) , and replacing the XRES*with the HXRES*and the KAUSF with the KSEAF in the 5G HE AV.

[0124] In some embodiments, the AUSF may then remove the KSEAF and return the 5G SE AV (e.g., at least one of the Random Number (RAND) , the network authentication token (AUTN) , the HXRES*) to the AMF (e.g., the new AMF) in the response (e.g., Nausf_UEAuthentication_UEAuthentication Response) .

[0125] 11. The AMF (e.g., the new AMF) may send the RAND, the AUTN to the UE in a NAS message Authentication Request. In some embodiments, the NAS message Authentication Request also may include the 5G key set identifier (ngKSI) that may be used by the UE and the AMF to identify the KAMF and the partial native security context that is created if the authentication is successful. In some embodiments, the NAS message may also include the Anti-Bidding-down Between Architectures (ABBA) parameter. In some embodiments, the AMF (e.g., the new AMF) may set the ABBA parameter. The ME (mobile equipment) (e.g., UE) may forward the RAND and AUTN received in NAS message Authentication Request to the Universal Subscriber Identity Module (USIM) .

[0126] 12. At receipt of the RAND and the AUTN, the USIM may verify the freshness of the received values by checking whether the AUTN can be accepted. In some embodiments, if the AUTN can be accepted, the USIM computes a response (RES) . In some embodiments, the USIM may return the RES, the cipher key (CK) , the integrity key (IK) to the ME. In some embodiments, if the USIM computes a ciphering key (Kc) (e.g., General Packet Radio Service (GPRS) Kc) from the CK and the IK and sends the Kc to the ME, the ME may ignore such GPRS Kc and not store the GPRS Kc on USIM or in ME.

[0127] In some embodiments, the ME then may compute the RES*from the RES. In some embodiments, the ME may calculate the KAUSF from the CK and / or the IK. In some embodiments, the ME may calculate the KSEAF from the KAUSF. In some embodiments, the UE may return the RES*to the AMF (e.g., the new AMF) in a NAS message Authentication Response.

[0128] 13. The AMF (e.g., the new AMF) may compute the HRES*from the RES*. In some embodiments, the AMF (e.g., the new AMF) may compare the HRES*and the HXRES*. If they coincide, the AMF (e.g., the new AMF) may consider the authentication successful from the  serving network point of view.

[0129] In some embodiments, the AMF (e.g., the new AMF) may send the RES*, as received from the UE, in a request (e.g., Nausf_UEAuthentication_Authenticate Request) message to the AUSF.

[0130] 14. The AUSF transmits the received User_Id list to the new AMF. In some embodiments, the AUSF transmits the received User_Id list to the new AMF via a response for an authentication of the UE. In some embodiments, the AUSF transmits the received User_Id list to the new AMF via an Nausf_UEAuthentication_Authenticate Response message. In some embodiments, the response is to indicate whether the authentication is successful or not (e.g., from the home network point of view) .

[0131] Specifically, in some embodiments, when the AUSF receives an authentication confirmation, the request (e.g., Nausf_UEAuthentication_Authenticate Request) message including a RES*may be sent from the AUST to the AMF (e.g., the new AMF) . In some embodiments, the request (e.g., Nausf_UEAuthentication_Authenticate Request) may verify whether the 5G AV has expired. In some embodiments, if the 5G AV has expired, the AUSF may consider the authentication as unsuccessful from the home network point of view. Upon successful authentication, the AUSF stores the KAUSF based on the home network operator's policy. In some embodiments, the AUSF may compare the received RES*with the stored XRES*. In some embodiments, if the RES*and the XRES*are equal, the AUSF may consider the authentication as successful from the home network point of view.

[0132] In some embodiments, the AUSF may send to the AMF a response (e.g., Nausf_UEAuthentication_Authenticate Response) to indicate whether the authentication was successful or not from the home network point of view. If the authentication was successful, the KSEAF may be sent to the SEAF in the response (e.g., Nausf_UEAuthentication_Authenticate Response) . In some embodiments, if the AUSF received a SUCI from the SEAF in the authentication request, and if the authentication was successful, then the AUSF may also include the SUPI in the response (e.g., Nausf_UEAuthentication_Authenticate Response) message.

[0133] 15-16. The AMF and the UE complete the NAS security mode command procedure to establish the NAS Security context between the UE and the AMF.

[0134] 17a. The AUSF generates the UIA Anchor Key (KUIA) based on the KAUSF. In some  embodiments, the AUSF generates the UIA Anchor Key (KUIA) based on at least one of the KAUSF, the received User_Id in the User_Id list from the UDM, and / or the length of said received User_Id. Details of deriving the UIA Anchor Key (KUIA) can be ascertained by referring to Aspect 5 described below. In some embodiments, the UIA Anchor Key (KUIA) is a user-specific key. In some embodiments, the UIA Anchor Key (KUIA) corresponds to the received User_Id in the User_Id list from the UDM.

[0135] In some embodiments, the AUSF generates the UIA Anchor Key (KUIA) in response to the AUSF receives the user id (e.g., User_Id) list from the UDM. In some embodiments, the AUSF stores the KUIA and / or the User_Id list in response to the AUSF receives the User_Id list from the UDM. In some embodiments, the AUSF generates the UIA Anchor Key (KUIA) after the authentication procedure is successfully completed.

[0136] Similarly, the UE generates the UIA Anchor Key (KUIA) based on the KAUSF. In some embodiments, the AUSF generates the UIA Anchor Key (KUIA) based on at least one of the KAUSF, the User_Id, and / or the length of the User_Id. Details of deriving the UIA Anchor Key (KUIA) can be ascertained by referring to Aspect 5 described below.

[0137] In some embodiments, the UE generates the UIA Anchor Key (KUIA) before initiating communication with an UIA Application Function.

[0138] 17b. The AUSF generates the UIA-KID based on the KAUSF. In some embodiments, the UIA-KID comprises at least one of the UIA-Anchor ID of the UIA Anchor Function, a temporary identifier corresponding to the user (also referred to as UIA Temporary User Identifier or UIA-TID) , or the home network identifier of the home network. In some embodiments, the UIA-TID is derived based on at least one of KAUSF, the received User_Id in the User_Id list from the UDM, and / or the length of said received User_Id. Details of deriving the UIA-TID can be ascertained by referring to Aspect 5 described below.

[0139] In some embodiments, the AUSF generates the UIA-KID in response to the AUSF receives the user id (e.g., User_Id) list from the UDM. In some embodiments, the AUSF stores the UIA-KID in response to the AUSF receives the User_Id list from the UDM. In some embodiments, the AUSF generates the UIA-KID after the authentication procedure is successfully completed.

[0140] Similarly, the UE generates the UIA-KID based on the KAUSF. In some embodiments, the UIA-KID comprises at least one of the UIA-Anchor ID of the UIA Anchor Function, a  UIA-TID, or the home network identifier of the home network. In some embodiments, the UIA-TID is derived based on at least one of KAUSF, the User_Id, and / or the length of the User_Id. Details of deriving the UIA-TID can be ascertained by referring to Aspect 5 described below.

[0141] In some embodiments, the UE generates the UIA-KID before initiating communication with an UIA Application Function.

[0142] 17c. The AUSF transmits the generated UIA Anchor Key (KUIA) and UIA-KID to the UIA-Anchor Function. In some embodiments, the AUSF transmits the generated UIA Anchor Key (KUIA) and UIA-KID to the UIA-Anchor Function corresponding to the UIA Anchor Key (KUIA) and / or UIA-KID. In some embodiments, the AUSF selects the UIA-Anchor Function where the generated UIA Anchor Key (KUIA) and UIA-KID transmitted to base on the UIA-AnchorID and / or the User_Id. In some embodiments, the AUSF transmits the UIA Anchor Key (KUIA) and UIA-KID to the UIA-Anchor Function after the UIA Anchor Key (KUIA) and UIA-KID to the UIA-Anchor Function are generated. In some embodiments, the AUSF may transmit at least one of the SUPI or the User_Id to the UIA-Anchor Function. In some embodiments, the AUSF transmits the generated UIA Anchor Key (KUIA) and UIA-KID to the UIA-Anchor Function via a request for a UIA key registration (e.g., Nuiaa_UIA_KeyRegistration Request) . In some embodiments, in response to there are more than one User_Ids related with the same UIA-Anchor Function, the AUSF may transmits the User_Ids in a User_Id list to the UIA-Anchor Function.

[0143] In some embodiments, the UIA-Anchor Function stores the latest information (e.g., the latest UIA Anchor Key (KUIA) , UIA-KID, and / or User_Id (s) ) sent by the AUSF.

[0144] 17d. The UIA-Anchor Function sends the response for receiving the UIA Anchor Key (KUIA) and UIA-KID to the AUSF. In some embodiments, the response is sent via a response (e.g., Nuiaa_UIA_AnchorKey_Register Response service operation) for a UIA Anchor Key registration.

[0145] 18a. The AMF (e.g., the new AMF) registers with the UDM using the service operation (e.g., Nudm_UECM_Registration) for the access to be registered.

[0146] 18b. In some embodiments, after the AMF (e.g., the new AMF) has successfully completed the service operation (e.g., Nudm_UECM_Registration) and if the AMF (e.g., the new AMF) does not have subscription data for the UE, the AMF (e.g., the new AMF) retrieves the Access and Mobility Subscription data, the SMF Selection Subscription data, UE context in SMF data and LCS mobile origination using a service operation (e.g., Nudm_SDM_Get) .

[0147] 18c. After a successful response is received, the AMF (e.g., the new AMF) subscribes to be notified using a service operation (e.g., Nudm_SDM_Subscribe) when the data requested is modified.

[0148] 18d. The UDM initiates a deregistration notification (e.g., Nudm_UECM_DeregistrationNotification) to the AMF (e.g., the old AMF) corresponding to the same access, if one exists.

[0149] 18e. If the AMF (e.g., the old AMF) does not have the UE context for another access type (e.g., non-3GPP access) , the AMF (e.g., the old AMF) unsubscribes with the UDM for subscription data using a service operation (e.g., Nudm_SDM_unsubscribe) .

[0150] 19. The AMF (e.g., the new AMF) sends a message (e.g., Registration Accept) to the UE.

[0151] 20. The UE sends a message (e.g., Registration Complete) to the AMF (e.g., the new AMF) .

[0152] Aspect 3:

[0153] FIG. 4 shows a schematic diagram of a procedure according to an embodiment of the present disclosure. In some embodiments, a procedure of User ID end-to-end protection during the session establishment between the UE and the UIA Application Function (AF) (e.g., an AF inside the operator domain) is provided.

[0154] Before communication between the UE and the UIA AF starts, the UE and the UIA AF may know whether to implement the mechanism of the user identifier. The mechanism implicit to the certain application on the UE and the UIA AF or is indicated from the UIA AF to the UE. In some embodiments, the procedure may include at least one of the following operations.

[0155] 1. The UE is registered and established PDU Sessions. Afterwards, a user with a User_Id (e.g., User_Id#1) intends to use this UE, and at least one of the following operations is performed accordingly.

[0156] 2. The UE transmits a request to the UIA AF including at least one of: the UIA-KID and / or an encrypted User_Id of the user. In some embodiments, the UE transmits the request to the UIA AF in response to the user with the User_Id (e.g., User_Id#1) intends to use this UE.

[0157] In some embodiments, the UE generates the UIA Anchor Key (KUIA) and the UIA-KID based on the KAUSF. In some embodiments, the UE generates the UIA Anchor Key (KUIA) and the  UIA-KID from the KAUSF in a manner substantially the same as which is described in the operations 17a and 17b in Aspect 2. In some embodiments, the UE generates the UIA Anchor Key (KUIA) and the UIA-KID before initiating communication with the UIA AF (e.g., transmitting the request to the UIA AF) .

[0158] In some embodiments, the UE derives an application key (also referred to as UIA AF Anchor Key, UIA Application Key, or KUIAAF) based on the KUIA. Details of deriving the KUIAAF can be ascertained by referring to Aspect 5 described below. In some embodiments, the UE encrypts the User_Id of the user based on the KUIAAF to obtain the encrypted User_Id.

[0159] In some embodiments, the request from the UE to UIA AF is transmitted via a request (e.g., in the Application Session Establishment Request message) for requesting an application session establishment.

[0160] 3. The UIA AF sends a request to the UIA-Anchor Function to request the KUIAAF for the user. In some embodiments, the request may be the Nuiaa_UIA_ApplicationKey_Get request, but not limited thereto.

[0161] In some embodiments, the UIA AF sends the request in response to the UIA AF does not have an active context associated with the UIA-KID. In some embodiments, the request includes the UIA-KID. In some embodiments, UIA AF selects the UIA-Anchor Function corresponding to the user. In some embodiments, UIA AF selects the UIA-Anchor Function based on the UIA-KID (e.g., based on the UIA-Anchor ID and / or the UIA-TID therein) . In some embodiments, the request may further include the identity / identifier (e.g., UIA_AF_ID) of the UIA AF.

[0162] In some embodiments, the UIA-Anchor Function checks whether the UIA-Anchor Function can provide the service to the UIA AF based on the configured local policy and / or based on the authorization information available in the signaling (e.g., Oauth2.0 token) . If the UIA-Anchor Function can provide the service to the UIA AF, the following procedures are executed. Otherwise, the UIA-Anchor Function rejects the following procedure.

[0163] In some embodiments, the UIA-Anchor Function verifies whether the subscriber (e.g., the UE and / or the user) is authorized to use the UIA. In some embodiments, the verification is based on the UIA-KID. In some embodiments, the verification is based on whether the UE specific key KUIA identified by the UIA-KID is stored in the UIA-Anchor Function.

[0164] In some embodiments, if the KUIA is present in the UIA-Anchor Function, the UIA AF is authorized. In some embodiments, operation 4 (i.e., the UIA-Anchor Function derives the UIA Application Key (KUIAAF) based on the KUIA) is performed in response to the UIA AF is authorized. In some embodiments, if the KUIA is present in the UIA-Anchor Function, the UIA AF is unauthorized. In such a case, an error response will be transmitted from the UIA-Anchor Function to the UIA AF

[0165] 4. The UIA-Anchor Function derives the UIA Application Key (KUIAAF) based on the KUIA. In some embodiments, the KUIA is stored in the UIA-Anchor Function. In some embodiments, the KUIA is identified by the received UIA-KID. In some embodiments, the UIA-Anchor Function derives the UIA Application Key (KUIAAF) if the UIA-Anchor Function does not have KUIAAF. Details of deriving the KUIAAF can be ascertained by referring to Aspect 5 described below.

[0166] 5. The UIA-Anchor Function sends a response including the KUIAAF to the UIA AF. In some embodiments, the response may further include at least one of the KUIAAF expiration time or a subscription identifier (e.g., SUPI and / or Generic Public Subscription Identifier (GPSI) ) of the UE.In some embodiments, the UIA-Anchor Function determines whether to send the subscription identifier based on the local policy. In some embodiments, the response may respond a request for the application key (e.g., Nniaa_UIA_ApplicationKey_Get response) .

[0167] 6. The UIA AF decrypts the encrypted User_Id of the user using the received KUIAAF to get the decrypted User_Id (e.g., the plain text of the User_Id) . In some embodiments, after the decrypted User_Id is acquired, the UIA AF performs an authentication (e.g., an Extensible Authentication Protocol (EAP) authentication) based on the User_Id (e.g., with the Authentication, Authorization and Accounting Server (AAA-S) ) .

[0168] 7. The UIA AF sends a response (e.g., the Application Session Establishment Response) to the UE to respond the request (e.g., the request for requesting for an application session establishment) . In some embodiments, if the UIA AF cannot get the KUIAAF (e.g., the verification in operation 3 is failed) or the authentication in operation 6 is failed, the UIA AF rejects the request (e.g., the request for requesting for an application session establishment) . In some embodiments, the UIA AF rejects the request (e.g., the Application Session Establishment) with a failure cause.

[0169] Aspect 4:

[0170] FIG. 5 shows a schematic diagram of a procedure according to an embodiment of the present disclosure. In some embodiments, a procedure of User ID end-to-end protection during the session establishment between UE and UIA AF (e.g., an AF outside the operator domain) is provided. In some embodiments, the procedure may include at least one of the following operations.

[0171] Operations 0, 1, 5, 8 and 9 in this procedure are substantially identical to operations 1, 2, 4, 6, and 7 in Aspect 3 respectively, and will not be repeated in the following.

[0172] 2. The UIA AF transmits a request to a Network Exposure Function (NEF) to request the KUIAAF for the user. In some embodiments, the UIA AF discovers the network (e.g., HPLMN) of the UE based on the UIA-KID and sends the request to the NEF corresponding to the network. In some embodiments, the UIA AF sends the request via the Network Exposure Function (NEF) service Application Programming Interface (API) ) . In some embodiments, the UIA AF transmits the request , when the UE initiates application session establishment request. In some embodiments, the request includes at least one of the UIA-KID and / or the UIA AF Identifier (UIA_AF_ID) of the UIA AF.

[0173] 3. The NEF may select an UIA Anchor Function corresponding to the user. In some embodiments, the NEF selects the UIA-Anchor Function based on the UIA-KID (e.g., based on the UIA-Anchor ID and / or the UIA-TID therein) . In some embodiments, the NEF selects the UIA-Anchor Function if the UIA AF is authorized by the NEF to request KUIAAF. In some embodiments, the NEF performs the authorization by the verification of the UIA_AF_ID.

[0174] 4. The NEF sends a request (e.g., Nuiaa_UIA_ApplicationKey_Get request) to the selected UIA Anchor Function to request the KUIAAF for the user. In some embodiments, the request includes at least one of the UIA-KID and / or the identity / identifier (e.g., UIA_AF_ID) of the UIA AF.

[0175] In some embodiments, the UIA-Anchor Function checks whether the UIA-Anchor Function can provide the service to the UIA AF. In some embodiments, the UIA-Anchor Function verifies whether the subscriber (e.g., the UE and / or the user) is authorized to use the UIA. Details in this regard are substantially the same as which in operation 4 in operation 3 of Aspect 3, and will not be repeated herein.

[0176] 6. The UIA Anchor Function sends the response to the NEF. In some embodiments, the response includes at least one of the KUIAAF, the KUIAAF expiration time and / or the SUPI. In some embodiments, the UIA-Anchor Function determines whether to send the SUPI based on the local policy. In some embodiments, the response may respond a request for the application key (e.g., Nniaa_UIA_ApplicationKey_Get response) .

[0177] 7. The NEF sends the response to the UIA AF with at least one of the received KUIAAF, the received KUIAAF expiration time and / or a GPSI (external ID) corresponding to the SUPI. In some embodiments, the NEF determines whether to send the GPSI based on the local policy. In some embodiments, the response may respond a request for the application key (e.g., Nnef_UIA_ApplicationKey_Get response) .

[0178] Aspect 5:

[0179] In some embodiments of the present disclosure, the UIA-KID identifies the KUIA key of the user. In some embodiments, the UIA-KID includes at least one of the UIA-Anchor ID, the UIA Temporary User Identifier (UIA-TID) and / or Home Network Identifier.

[0180] In some embodiments, the KUIA may be derived based on at least one of the User_Id, the length of User_Id, and / or the KAUSF.

[0181] For example, when deriving a KUIA from the KAUSF, at least one of the following parameters can be used to form the input S to the Key Derivation Function (KDF) :

[0182] -FC = 0x8C; (an example for FC value, another value may also be used) ;

[0183] -P0 = "UIA" ; (an example for P0 value, another value may also be used) ;

[0184] -L0 = length of "UIA" ; (e.g., 0x00 0x03) ;

[0185] -P1 = User_Id; and / or

[0186] -L1 = length of User_Id.

[0187] The input key (e.g., KEY) may be the KAUSF.

[0188] In some embodiments, the UIA-TID may be derived based on at least one of the User_Id, the length of User_Id, and / or the KAUSF.

[0189] For example, when deriving the UIA-TID from the KAUSF, at least one of the following parameters can be used to form the input S to the KDF:

[0190] -FC = 0x8D; (an example for FC value, another value may also be used) ;

[0191] -P0 = "UIA-TID" ; (an example for P0 value) ;

[0192] -L0 = length of "UIA-TID" ; (e.g., 0x00 0x07) ;

[0193] -P1 = User_Id; and / or

[0194] -L1 = length of User_Id.

[0195] The input key (e.g., KEY) may be KAUSF.

[0196] In some embodiments, the KUIAAF may be derived based on at least one of the User_Id, the length of UIA_AF_ID, and / or the KUIA.

[0197] For example, when deriving a KUIAAF from the KUIA, at least one of the following parameters can be used to form the input S to the KDF:

[0198] -FC = 0x8E; (an example for FC value, another value may also be used)

[0199] -P0 = UIA_AF_ID; and / or

[0200] -L0 = length of UIA_AF_ID.

[0201] The input key (e.g., KEY) may be KUIA.

[0202] The UIA_AF_ID is obtained as follows:

[0203] UIA_AF_ID = FQDN of the AF || Ua*security protocol identifier, where the Ua*is the interface protocol between the UE and UIA_AF.

[0204] Some embodiments of the present disclosure provide a mechanism to realize user identifier protection and authentication.

[0205] In some embodiments, the UDM provides the User_Id list and / or the UIA_Anchor ID list to the AUSF.

[0206] In some embodiments, the AUSF receives the User_Id list from the UDM. In some embodiments, the AUSF provides the User_Id list to the new AMF. In some embodiments, the AUSF derives the KUIA from the KAUSF and derives the UIA-KID as described above. In some embodiments, the AUSF selects the UIA Anchor Function according to the UIA_Anchor ID received form the UDM. In some embodiments, the AUSF provides the User_Id list, the UIA-KID and / or the KUIA to the UIA Anchor Function.

[0207] In some embodiments, the UIA Anchor Function receives the User_Id list, the UIA-KID and / or the KUIA from the AUSF. In some embodiments, the UIA Anchor Function stores the User_Id list, the UIA-KID and / or the KUIA received from the AUSF. In some embodiments, the UIA Anchor Function receives the UIA-KID from the UIA AF for requesting the KUIAAF (AF in operator domain case) . In some embodiments, the UIA Anchor Function receives the UIA-KID  from the NEF for requesting KUIAAF (AF outside operator domain case) .

[0208] In some embodiments, the UIA Anchor Function derives the KUIAAF from the KUIA as described above. In some embodiments, the UIA Anchor Function provides the KUIAAF, the KUIAAF expiration time (e.g., expTime) , the SUPI and / or the GPSI to the UIA AF (AF in operator domain case) . In some embodiments, the UIA Anchor Function provides the KUIAAF, KUIAAF expiration time (e.g., expTime) , the SUPI to the NEF (AF outside operator domain case) .

[0209] In some embodiments, the UE derives the KUIA from the KAUSF. In some embodiments, the UE derives the UIA-KID. In some embodiments, the UE derives the KUIAAF from the KUIA as described above. In some embodiments, the UE encrypts the User_Id using the KUIAAF. In some embodiments, the UE sends the UIA-KID and encrypted user id (e.g., User_Id) to the UIA AF during the session establishment.

[0210] In some embodiments, the UIA AF receives the UIA-KID and encrypted user id (e.g., User_Id) from the UE during the session establishment. In some embodiments, the UIA AF sends the UIA-KID to the UIA Anchor Function to request the KUIAAF (AF in operator domain case) . In some embodiments, the UIA AF receives the KUIAAF, the KUIAAF expiration time (e.g., expTime) , the SUPI and / or the GPSI from the UIA Anchor Function (AF in operator domain case) . In some embodiments, the UIA AF sends the UIA-KID to the NEF to request the KUIAAF (AF outside operator domain case) . In some embodiments, the UIA AF receives the KUIAAF, KUIAAF expiration time (e.g., expTime) from the NEF (AF outside operator domain case) .

[0211] In some embodiments, the NEF (AF outside operator domain case) receives the UIA-KID from the UIA AF for requesting the KUIAAF. In some embodiments, the NEF selects the UIA Anchor Function according to the UIA-KID. In some embodiments, the NEF sends the UIA-KID to the UIA Anchor Function for requesting the KUIAAF. In some embodiments, the NEF receives the KUIAAF, KUIAAF expiration time (e.g., expTime) and / or the SUPI from the UIA Anchor Function. In some embodiments, the NEF provides the KUIAAF, KUIAAF expiration time (e.g., expTime) to the UIA AF.

[0212] FIG. 6 relates to a diagram of a wireless communication terminal 30 according to an embodiment of the present disclosure. The wireless communication terminal 30 may be a tag, a mobile phone, a laptop, a tablet computer, an electronic book or a portable computer system and is not limited herein. The wireless communication terminal 30 may be used to implement the UE  described in this disclosure. The wireless communication terminal 30 may include a processor 300 such as a microprocessor or Application Specific Integrated Circuit (ASIC) , a storage unit 310 and a communication unit 320. The storage unit 310 may be any data storage device that stores a program code 312, which is accessed and executed by the processor 300. Embodiments of the storage unit 310 include but are not limited to a subscriber identity module (SIM) , read-only memory (ROM) , flash memory, random-access memory (RAM) , hard-disk, and optical data storage device. The communication unit 320 may a transceiver and is used to transmit and receive signals (e.g., messages or packets) according to processing results of the processor 300. In an embodiment, the communication unit 320 transmits and receives the signals via at least one antenna 322 or via wiring.

[0213] In an embodiment, the storage unit 310 and the program code 312 may be omitted and the processor 300 may include a storage unit with stored program code.

[0214] The processor 300 may implement any one of the steps or operations in exemplified embodiments on the wireless communication terminal 30, e.g., by executing the program code 312.

[0215] The communication unit 320 may be a transceiver. The communication unit 320 may as an alternative or in addition be combining a transmitting unit and a receiving unit configured to transmit and to receive, respectively, signals to and from a wireless communication node.

[0216] In some embodiments, the wireless communication terminal 30 may be used to perform the operations of the UE described in this disclosure. In some embodiments, the processor 300 and the communication unit 320 collaboratively perform the operations described in this disclosure. For example, the processor 300 performs operations and transmit or receive signals, message, and / or information through the communication unit 320.

[0217] FIG. 7 relates to a diagram of a wireless communication node 40 according to an embodiment of the present disclosure. The wireless communication node 40 may be a satellite, a base station (BS) , a gNB, a network entity, a Domain Name System (DNS) server, a Mobility Management Entity (MME) , Serving Gateway (S-GW) , Packet Data Network (PDN) Gateway (P-GW) , a radio access network (RAN) , a next generation RAN (NG-RAN) , a data network, a core network, a communication node in the core network, or a Radio Network Controller (RNC) , and is not limited herein. In addition, the wireless communication node 40 may include (perform) at least one network function such as an access and mobility management function (AMF) , a session  management function (SMF) , a user place function (UPF) , a policy control function (PCF) , an application function (AF) , etc. The wireless communication node 40 may be used to implement the gNB, the AMF, the UIA Anchor Function, the SMF, the UDM, the UIA-Anchor, the PCF, the UIA AF, the AUSF, and / or the NEF described in this disclosure. The wireless communication node 40 may include a processor 400 such as a microprocessor or ASIC, a storage unit 410 and a communication unit 420. The storage unit 410 may be any data storage device that stores a program code 412, which is accessed and executed by the processor 400. Examples of the storage unit 410 include but are not limited to a SIM, ROM, flash memory, RAM, hard-disk, and optical data storage device. The communication unit 420 may be a transceiver and is used to transmit and receive signals (e.g., messages or packets) according to processing results of the processor 400. In an embodiment, the communication unit 420 transmits and receives the signals via at least one antenna 422 or via wiring.

[0218] In an embodiment, the storage unit 410 and the program code 412 may be omitted. The processor 400 may include a storage unit with stored program code.

[0219] The processor 400 may implement any steps or operations described in exemplified embodiments on the wireless communication node 40, e.g., via executing the program code 412.

[0220] The communication unit 420 may be a transceiver. The communication unit 420 may as an alternative or in addition be combining a transmitting unit and a receiving unit configured to transmit and to receive, respectively, signals, messages, or information to and from a wireless communication node or a wireless communication terminal.

[0221] In some embodiments, the wireless communication node 40 may be used to perform the gNB, the UIA Anchor Function, the AMF, the SMF, the UDM, the UIA-Anchor, the PCF, the UIA AF, the AUSF, the NEF described in this disclosure. In some embodiments, the processor 400 and the communication unit 420 collaboratively perform the operations described in this disclosure. For example, the processor 400 performs operations and transmit or receive signals through the communication unit 420.

[0222] A wireless communication method is also provided according to an embodiment of the present disclosure. In an embodiment, the wireless communication method may be performed by using a wireless communication node (e.g., an AUSF) . In an embodiment, the wireless communication node may be implemented by using the wireless communication node 40 described  in this disclosure, but is not limited thereto.

[0223] Referring to FIG. 8, in an embodiment, the wireless communication method includes: generating, by an authentication node, a first key corresponding to a user and a first key identifier identifying the first key based on a second key of the authentication node in response to user identifier information being received; and transmitting, by the authentication node to an anchor node, at least one of the first key, the first key identifier, or a user identifier list.

[0224] Details in this regard can be ascertained with reference to the paragraphs above, and will not be repeated herein.

[0225] Another wireless communication method is also provided according to an embodiment of the present disclosure. In an embodiment, the wireless communication method may be performed by using a wireless communication node (e.g., the UIA AF) . In an embodiment, the wireless communication node may be implemented by using the wireless communication node 40 described in this disclosure, but is not limited thereto.

[0226] Referring to FIG. 9, in an embodiment, the wireless communication method includes: transmitting, by an application node to an anchor node, a request for an application key for decrypting an encrypted user identifier received from a wireless communication terminal based on a first key identifier; and receiving, by the application node from the anchor node, a response comprising the application key.

[0227] Details in this regard can be ascertained with reference to the paragraphs above, and will not be repeated herein.

[0228] Another wireless communication method is also provided according to an embodiment of the present disclosure. In an embodiment, the wireless communication method may be performed by using a wireless communication node (e.g., the UIA Anchor Function) . In an embodiment, the wireless communication node may be implemented by using the wireless communication node 40 described in this disclosure, but is not limited thereto.

[0229] Referring to FIG. 10, in an embodiment, the wireless communication method includes: receiving, by an anchor node from an application node, a request for an application key for decrypting an encrypted user identifier; and transmitting, by the anchor node to the application node, a response comprising the application key.

[0230] Details in this regard can be ascertained with reference to the paragraphs above, and will  not be repeated herein.

[0231] Another wireless communication method is also provided according to an embodiment of the present disclosure. In an embodiment, the wireless communication method may be performed by using a wireless communication node (e.g., the NEF) . In an embodiment, the wireless communication node may be implemented by using the wireless communication node 40 described in this disclosure, but is not limited thereto.

[0232] Referring to FIG. 11, in an embodiment, the wireless communication method includes: transmitting, by a network exposure node to an anchor node, a first request for an application key for decrypting an encrypted user identifier based on a first key identifier; and receiving, by the network exposure node from the anchor node, a first response comprising the application key.

[0233] Details in this regard can be ascertained with reference to the paragraphs above, and will not be repeated herein.

[0234] Another wireless communication method is also provided according to an embodiment of the present disclosure. In an embodiment, the wireless communication method may be performed by using a wireless communication terminal (e.g., the UE) . In an embodiment, the wireless communication terminal may be implemented by using the wireless communication terminal 30 described in this disclosure, but is not limited thereto.

[0235] Referring to FIG. 12, in an embodiment, the wireless communication method includes: transmitting, by a wireless communication terminal to an application node, a request for an application session for a user, the request comprising a first key identifier corresponding to the user and an encrypted user identifier corresponding to the user to allow the application node to obtain an application key for decrypting the encrypted user identifier.

[0236] Details in this regard can be ascertained with reference to the paragraphs above, and will not be repeated herein.

[0237] In some embodiments, the wireless communication terminal used in the present disclosure may indicate the UE described above.

[0238] In some embodiments, the authentication node used in the present disclosure may indicate the AUSF described above.

[0239] In some embodiments, the anchor node used in the present disclosure may indicate the  UIA Anchor Function described above.

[0240] In some embodiments, the application node used in the present disclosure may indicate the UIA AF described above.

[0241] In some embodiments, the network exposure node used in the present disclosure may indicate the NEF described above.

[0242] In some embodiments, the data management node used in the present disclosure may indicate the UDM described above.

[0243] In some embodiments, the access management node used in the present disclosure may indicate the new AMF described above.

[0244] In some embodiments, the first key used in the present disclosure may indicate the UIA Anchor Key (KUIA) described above.

[0245] In some embodiments, the first key identifier used in the present disclosure may indicate the UIA-KID described above.

[0246] In some embodiments, the second key used in the present disclosure may indicate the KAUSF described above.

[0247] In some embodiments, the first key identifier comprises at least one of: an identifier of the anchor node, a temporary identifier corresponding to the user, or a home network identifier, and the identifier of the anchor node used in the present disclosure may indicate the UIA-Anchor ID described above, and / or the temporary identifier corresponding to the user may indicate the UIA-TID described above.

[0248] In some embodiments, the application key for decrypting an encrypted user identifier used in the present disclosure may indicate the KUIAAF described above.

[0249] In some embodiments, the identifier of the application node used in the present disclosure may indicate the UIA_AF_ID described above.

[0250] While various embodiments of the present disclosure have been described above, it should be understood that they have been presented by way of example only, and not by way of  limitation. Likewise, the various diagrams may depict an example architectural or configuration, which are provided to enable persons of ordinary skill in the art to understand exemplary features and functions of the present disclosure. Such persons would understand, however, that the present disclosure is not restricted to the illustrated example architectures or configurations, but can be implemented using a variety of alternative architectures and configurations. Additionally, as would be understood by persons of ordinary skill in the art, one or more features of one embodiment can be combined with one or more features of another embodiment described herein. Thus, the breadth and scope of the present disclosure should not be limited by any one of the above-described exemplary embodiments.

[0251] It is understood that, in the present disclosure, the term “and / or” or symbol “ / ” may include any and all combinations of one or more of the associated listed items. For example, A and / or B and / or C includes any and all combinations of one or more of A, B, and C, including A, B, C, A and B, A and C, B and C, and a combination of A and B and C. Likewise, A / B / C includes any and all combinations of one or more of A, B, and C, including A, B, C, A and B, A and C, B and C, and a combination of A and B and C.

[0252] It is also understood that any reference to an element herein using a designation such as "first, " "second, " and so forth does not generally limit the quantity or order of those elements. Rather, these designations can be used herein as a convenient means of distinguishing between two or more elements or instances of an element. Thus, a reference to first and second elements does not mean that only two elements can be employed, or that the first element must precede the second element in some manner.

[0253] Additionally, a person having ordinary skill in the art would understand that information and signals can be represented using any one of a variety of different technologies and techniques. For example, data, instructions, commands, information, signals, bits and symbols, for example, which may be referenced in the above description can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0254] A skilled person would further appreciate that any one of the various illustrative logical blocks, units, processors, means, circuits, methods and functions described in connection with the aspects disclosed herein can be implemented by electronic hardware (e.g., a digital implementation,  an analog implementation, or a combination of the two) , firmware, various forms of program or design code incorporating instructions (which can be referred to herein, for convenience, as "software" or a "software unit” ) , or any combination of these techniques.

[0255] To clearly illustrate this interchangeability of hardware, firmware and software, various illustrative components, blocks, units, circuits, operations, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware, firmware or software, or a combination of these techniques, depends upon the particular application and design constraints imposed on the overall system. Skilled artisans can implement the described functionality in various ways for each particular application, but such implementation decisions do not cause a departure from the scope of the present disclosure. In accordance with various embodiments, a processor, device, component, circuit, structure, machine, unit, etc. can be configured to perform one or more of the functions described herein. The term “configured to” or “configured for” as used herein with respect to a specified operation or function refers to a processor, device, component, circuit, structure, machine, unit, etc. that is physically constructed, programmed and / or arranged to perform the specified operation or function.

[0256] Furthermore, a skilled person would understand that various illustrative logical blocks, units, devices, components and circuits described herein can be implemented within or performed by an integrated circuit (IC) that can include a general-purpose processor, a digital signal processor (DSP) , an application specific integrated circuit (ASIC) , a field programmable gate array (FPGA) or other programmable logic device, or any combination thereof. The logical blocks, units, and circuits can further include antennas and / or transceivers to communicate with various components within the network or within the device. A general-purpose processor can be a microprocessor, but in the alternative, the processor can be any conventional processor, controller, or state machine. A processor can also be implemented as a combination of computing devices, e.g., a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other suitable configuration to perform the functions described herein. If implemented in software, the functions can be stored as one or more instructions or code on a computer-readable medium. Thus, the steps or operations of a method or algorithm disclosed herein can be implemented as software stored on a computer-readable medium.

[0257] Computer-readable media includes both computer storage media and communication  media including any medium that can be enabled to transfer a computer program or code from one place to another. A storage media can be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store desired program code in the form of instructions or data structures and that can be accessed by a computer.

[0258] In this document, the term "unit" as used herein, refers to software, firmware, hardware, and any combination of these elements for performing the associated functions described herein. Additionally, for purpose of discussion, the various units are described as discrete units; however, as would be apparent to one of ordinary skill in the art, two or more units may be combined to form a single unit that performs the associated functions according to embodiments of the present disclosure.

[0259] Additionally, memory or other storage, as well as communication components, may be employed in embodiments of the present disclosure. It will be appreciated that, for clarity purposes, the above description has described embodiments of the present disclosure with reference to different functional units and processors. However, it will be apparent that any suitable distribution of functionality between different functional units, processing logic elements or domains may be used without detracting from the present disclosure. For example, functionality illustrated to be performed by separate processing logic elements, or controllers, may be performed by the same processing logic element, or controller. Hence, references to specific functional units are only references to a suitable means for providing the described functionality, rather than indicative of a strict logical or physical structure or organization.

[0260] Various modifications to the implementations described in this disclosure will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other implementations without departing from the scope of the claims. Thus, the disclosure is not intended to be limited to the implementations shown herein, but is to be accorded the widest scope consistent with the novel features and principles disclosed herein, as recited in the claims below.

Claims

1.A wireless communication method comprising:generating, by an authentication node, a first key corresponding to a user and a first key identifier identifying the first key based on a second key of the authentication node in response to user identifier information being received; andtransmitting, by the authentication node to an anchor node, at least one of the first key, the first key identifier, or a user identifier list.2.The wireless communication method of claim 1, wherein the user identifier information comprises at least one of:the user identifier list comprising one or more user identifiers; oran anchor node identifier list comprising one or more identifiers of anchor nodes corresponding to the one or more user identifiers.3.The wireless communication method of claim 1 or 2, wherein the anchor node is selected based on the user identifier information.4.The wireless communication method of claim 3, wherein the anchor node is selected based on at least a part of a user identifier in the user identifier information or an identifier of anchor node corresponding to the user identifier.5.The wireless communication method of any of claims 1 to 4, wherein the first key identifier comprises at least one of: an identifier of the anchor node, a temporary identifier corresponding to the user, or a home network identifier.6.The wireless communication method of claim 5, wherein the temporary identifier corresponding to the user is derived based on at least one of the second key of the authentication node, a user identifier in the user identifier information, or a length of the user identifier.7.The wireless communication method of any of claims 1 to 6, wherein the first key is derived based on at least one of the second key of the authentication node, a user identifier in the user identifier information, or a length of the user identifier.8.The wireless communication method of any of claims 1 to 7, wherein the authentication node receives the user identifier information from a data management node.9.The wireless communication method of any of claims 1 to 8, wherein the authentication node transmits, to an access management node, the user identifier information.10.The wireless communication method of any of claims 1 to 9, wherein the authentication node generates the first key and the first key identifier identifying the first key in response to an authentication for the user identifier information being successful.11.The wireless communication method of any of claims 1 to 10, wherein the authentication node receives, from the anchor node, a response for receiving the first key and the first key identifier.12.A wireless communication method comprising:transmitting, by an application node to an anchor node, a request for an application key for decrypting an encrypted user identifier received from a wireless communication terminal based on a first key identifier; andreceiving, by the application node from the anchor node, a response comprising the application key.13.The wireless communication method of claim 12, wherein the application node transmits the request for the application key in response to receiving, from the wireless communication terminal a first message comprising the first key identifier and the encrypted user identifier.14.The wireless communication method of claim 12 or 13, wherein the request comprises at least one of the first key identifier or an identifier of the application node.15.The wireless communication method of any of claims 12 to 14, wherein the response further comprises at least one of:an expiration time of the application key; ora subscription identifier corresponding to the wireless communication terminal.16.The wireless communication method of any of claims 12 to 15, wherein the application node performs at least one of:transmitting, to the anchor node, the request via a network exposure node; orreceiving, from the anchor node, the response via a network exposure node.17.The wireless communication method of any of claims 12 to 16, wherein the application node selects the anchor node based on the first key identifier.18.The wireless communication method of any of claims 12 to 17, wherein the application node transmits, to the wireless communication terminal, a message to accept or reject an application session for a user.19.A wireless communication method comprising:receiving, by an anchor node from an application node, a request for an application key for decrypting an encrypted user identifier; andtransmitting, by the anchor node to the application node, a response comprising the application key.20.The wireless communication method of claim 19, wherein the anchor node derives the application key based on a first key identified by a first key identifier in the request.21.The wireless communication method of claim 19 or 20, wherein the anchor node transmits the response to the application node in response to at least one of: a configured local policy or authorization information in the request.22.The wireless communication method of any of claims 19 to 21, wherein the anchor node transmits the response to the application node in response to a first key corresponding to a first key identifier in the request being stored in the anchor node.23.The wireless communication method of any of claims 19 to 22, wherein the anchor node receives, from an authentication node, at least one of: a first key identifying a first key identifier, a first key identifier, or a user identifier list comprising one or more user identifiers.24.The wireless communication method of any of claims 19 to 23, wherein the request comprises at least one of the first key identifier or an identifier of the application node.25.The wireless communication method of any of claims 19 to 24, wherein the response further comprises at least one of:an expiration time of the application key; ora subscription identifier corresponding to the wireless communication terminal.26.The wireless communication method of any of claims 19 to 25, wherein the anchor node performs at least one of:receiving, from the application node, the request via a network exposure node; ortransmitting, to the application node, the response via a network exposure node.27.A wireless communication method comprising:transmitting, by a network exposure node to an anchor node, a first request for an application key for decrypting an encrypted user identifier based on a first key identifier; andreceiving, by the network exposure node from the anchor node, a first response comprising the application key.28.The wireless communication method of claim 27, wherein the network exposure node performs at least one of:receiving, from an application node, a second request for the application key; ortransmitting, to an application node, a second response comprising the application key in response to receiving the first response.29.The wireless communication method of claim 28, wherein the network exposure node transmits the first request to the anchor node in response to the application node is authorized.30.The wireless communication method of any of claims 28 to 29, wherein the second request comprises at least one of the first key identifier or an identifier of the application node.31.The wireless communication method of any of claims 28 to 30, wherein the second response further comprises at least one of:an expiration time of the application key; ora Generic Public Subscription Identifier, GPSI.32.The wireless communication method of any of claims 27 to 31, wherein the first response further comprises at least one of:an expiration time of the application key; ora Subscription Permanent Identifier, SUPI.33.The wireless communication method of any of claims 27 to 32, wherein the first request comprises at least one of:the first key identifier; oran identifier of the application node.34.The wireless communication method of any of claims 27 to 33, wherein the network exposure node selects the anchor node based on the first key identifier.35.A wireless communication method comprising:transmitting, by a wireless communication terminal to an application node, a request for an application session for a user, the request comprising a first key identifier corresponding to the user and an encrypted user identifier corresponding to the user to allow the application node to obtain an application key for decrypting the encrypted user identifier.36.The wireless communication method of claim 35, wherein the wireless communication terminal encrypts a user identifier of the user to generate the encrypted user identifier based on the application key.37.The wireless communication method of claim 36, wherein the wireless communication terminal derives the application key based on a first key corresponding to the first key identifier.38.The wireless communication method of claim 37, wherein the first key is derived based on at least one of a second key of an authentication node, the user identifier, or a length of the user identifier.39.The wireless communication method of any of claims 35 to 38, wherein the first key identifier comprises at least one of: an identifier of an anchor node corresponding to the user, a temporary identifier corresponding to the user, or a home network identifier.40.The wireless communication method of claim 39, wherein the temporary identifier corresponding to the user is derived based on at least one of: a second key of an  authentication node, a user identifier of the user, or a length of the user identifier of the user.41.The wireless communication method of any of claim 35 to 40, wherein the wireless communication terminal receives, from the application node, a message to accept or reject the application session.42.An authentication node, comprising:a communication unit; anda processor configured to: generate a first key corresponding to a user and a first key identifier identifying the first key based on a second key of the authentication node in response to user identifier information being received; and transmit, via the communication unit to an anchor node, at least one of the first key, the first key identifier, or a user identifier list.43.The authentication node of claim 42, wherein the processor is further configured to perform a wireless communication method of any of claims 2 to 11.44.An application node, comprising:a communication unit; anda processor configured to: transmit, via the communication unit to an anchor node, a request for an application key for decrypting an encrypted user identifier received from a wireless communication terminal based on a first key identifier; and receive, via the communication unit from the anchor node, a response comprising the application key.45.The application node of claim 44, wherein the processor is further configured to perform a wireless communication method of any of claims 13 to 18.46.An anchor node, comprising:a communication unit; anda processor configured to: receive, via the communication unit from an application node, a request for an application key for decrypting an encrypted user identifier; and transmit, via the communication unit to the application node, a response comprising the application key.47.The anchor node of claim 46, wherein the processor is further configured to perform a wireless communication method of any of claims 20 to 26.48.A network exposure node, comprising:a communication unit; anda processor configured to: transmit, via the communication unit to an anchor node, a first request for an application key for decrypting an encrypted user identifier based on a first key identifier; and receive, via the communication unit from the anchor node, a first response comprising the application key.49.The network exposure node of claim 48, wherein the processor is further configured to perform a wireless communication method of any of claims 28 to 34.50.A wireless communication terminal, comprising:a communication unit; anda processor configured to: transmit, via the communication unit to an application node, a request for an application session for a user, the request comprising a first key identifier corresponding to the user and an encrypted user identifier corresponding to the user to allow the application node to obtain an application key for decrypting the encrypted user identifier.51.The wireless communication terminal of claim 50, wherein the processor is further configured to perform a wireless communication method of any of claims 36 to 41.52.A computer program product comprising a computer-readable program medium code stored thereupon, the code, when executed by a processor, causing the processor to implement a wireless communication method recited in any one of claims 1 to 41.

Citation Information

Patent Citations

  • Authentication server function selection in authentication and key management

    US20220360982A1

  • Apparatus and method of generating application specific keys using key derived from network access authentication

    US20230068196A1

  • Authentication server function (AUSF) push of authentication and key management (AKMA) material

    WO2021209379A1

  • Method for UE-to-network relay security in proximity-based services

    WO2023155192A1