Method, device and system for AKMA roaming control in communication networks

The method addresses complex AKMA service verification and key management in UE roaming by determining AKMA service allowance through A-KID, enhancing secure communication compliance and reducing delays in dual-access scenarios.

WO2025171639A1PCT designated stage Publication Date: 2025-08-21ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/077360
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-18
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing wireless communication networks face challenges in efficiently verifying and enabling AKMA (Authentication and Key Management for Applications) service, particularly in scenarios involving UE roaming, where secure communication between User Equipment (UE) and Application Function (AF) entities is required but regulatory controls and key management are complex.

Method used

The method involves network elements receiving an AKMA key identifier (A-KID) to determine if AKMA service is allowed for an application session, and if not, transmitting a failure message, ensuring secure communication by deriving and managing AKMA keys based on roaming policies and network identities.

Benefits of technology

This approach enhances secure communication by ensuring compliance with roaming agreements and regulatory policies, reducing end-to-end traffic delays, and maintaining secure communication links for UE accessing AF services, especially in dual-access scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024077360_21082025_PF_FP_ABST
    Figure CN2024077360_21082025_PF_FP_ABST
Patent Text Reader

Abstract

This disclosure generally relates to enabling AKMA in wireless communication. Performed by first network element, the method includes: receiving, from a wireless device, a first message for requesting to establish an application session, wherein the first message carries an AKMA (Authentication and Key Management for Applications) key identifier, A-KID, for identifying an AKMA key of the wireless device, and wherein the AKMA key is used for authentication and security protection between the wireless device and the first network element; determining whether an AKMA service is allowed for the application session; and in response to the AKMA service not being allowed for the application session, transmitting, to the wireless device, a second message as a response to the first message, the second message indicating a failure for establishing the application session.
Need to check novelty before this filing date? Find Prior Art

Description

METHOD, DEVICE AND SYSTEM FOR AKMA ROAMING CONTROL IN COMMUNICATION NETWORKSTECHNICAL FIELD

[0001] This disclosure relates to wireless communication, and in particular, to verifying and enabling AKMA (Authentication and Key Management for Applications) service in a wireless communication network, such as 4G, 5G, and 6G wireless communication network.BACKGROUND

[0002] In a communication network, the mutual authentication of a User Equipment (UE) and the communication network may be performed to allow only authenticated UE and the authenticated communication network to communicate with each other. Application Function (AF) entities may provide various application services to the UE once authenticated. Efficient and robust authentication mechanism involving various network elements is critical to provide secure communication between Application Function entity and the UE, and to protect the credentials of the UE and the Application Function entity.SUMMARY

[0003] This disclosure discloses methods, systems, devices, and storage medium relates to wireless communication, and in particular, to verifying and enabling AKMA (Authentication and Key Management for Applications) service in a wireless communication network, such as 4G, 5G, and 6G wireless communication network.

[0004] In one embodiment, the present disclosure describes a method for wireless communication. Performed by a first network element, the method includes: receiving, from a wireless device, a first message for requesting to establish an application session, wherein the first message carries an AKMA (Authentication and Key Management for Applications) key identifier, A-KID, for identifying an AKMA key of the wireless device,  and wherein the AKMA key is used for authentication and security protection between the wireless device and the first network element; determining whether an AKMA service is allowed for the application session; and in response to the AKMA service not being allowed for the application session, transmitting, to the wireless device, a second message as a response to the first message, the second message indicating a failure for establishing the application session.

[0005] In another embodiment, a method for wireless communication is disclosed. Performed by a first network element, the method includes: receiving, from a second network element, a first message carrying at least one of: an AKMA key identifier, A-KID, for identifying an AKMA key of a wireless device, wherein the wireless device is in a procedure to establish an application session with the second network element via a Visited Public Land Mobile Network (VPLMN) ; an Application Function identifier (AF_ID) of the second network element; or a PLMN ID of the VPLMN; determining, based on at least one of: the A-KID; or a roaming policy associated with the PLMN ID, whether an AKMA service is allowed for the application session; and transmitting, from the second network element, a second message as a response to the first message indicating whether the AKMA service is allowed for the application session.

[0006] In another embodiment, a method for wireless communication is disclosed. Performed by a wireless device, the method includes: transmitting, to a first network element, a first message for requesting to establish an application session between the wireless device and the first network element, wherein the first message carries an AKMA key identifier, A-KID, for identifying an AKMA key of the wireless device, and wherein the AKMA key is used for authentication and security protection between the wireless device and the first network element, wherein the application session is initiated by the wireless device using an access via a VPLMN; and receiving, from the first network element, a second message as a response to the first message indicating whether an AKMA service is allowed for the application session.

[0007] In another embodiment, a network element or wireless device comprising a  processor and a memory is disclosed. The processor may be configured to read computer code from the memory to implement any of the methods above.

[0008] In yet another embodiment, a computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon is disclosed. The computer code, when executed by a processor, may cause the processor to implement any one of the methods above.

[0009] The above embodiments and other aspects and alternatives of their implementations are explained in greater detail in the drawings, the descriptions, and the claims below.BRIEF DESCRIPTION OF THE DRAWINGS

[0010] FIG. 1 shows an exemplary communication network including various terminal devices, a carrier network, data network, and service applications.

[0011] FIG. 2 shows exemplary network functions or network nodes in a communication network.

[0012] FIG. 3 shows exemplary network functions or network nodes in a wireless communication network.

[0013] FIG. 4 shows an exemplary network model for an Authentication and Key Management for Applications (AKMA) framework.

[0014] FIG. 5 shows an example wireless network node (or network element, network entity, entity, application function) .

[0015] FIG. 6 shows an example user equipment.

[0016] FIG. 7 shows an exemplary key hierarchy under the AKMA framework.

[0017] FIG. 8 shows an exemplary logic flow for establishing an application session  between a UE and an AF, including deriving AKMA application key for the AF.

[0018] FIGs. 9-10 show various exemplary logic flows for establishing an application session between a UE and an AF, including a pre-check based on PLMN_ID and roaming agreement.DETAILED DESCRIPTION

[0019] An exemplary communication network, shown as 100 in FIG. 1, may include terminal devices 110 and 112, a carrier network 102, various service applications 140, and other data networks 150. The carrier network 102, for example, may include access networks 120 and a core network 130. The carrier network 102 may be configured to transmit voice, data, and other information (collectively referred to as data traffic) among terminal devices 110 and 112, between the terminal devices 110 and 112 and the service applications 140, or between the terminal devices 110 and 112 and the other data networks 150. Communication sessions and corresponding data paths may be established and configured for such data transmission. The Access networks 120 may be configured to provide terminal devices 110 and 112 network access to the core network 130. The Access network 120 may, for example, support wireless access via radio resources, or wireline access. The core network 130 may include various network nodes or network functions configured to control the communication sessions and perform network access management and data traffic routing. The service applications 140 may be hosted by various application servers that are accessible by the terminal devices 110 and 112 through the core network 130 of the carrier network 102. A service application 140 may be deployed as a data network outside of the core network 130. Likewise, the other data networks 150 may be accessible by the terminal devices 110 and 112 through the core network 130 and may appear as either data destination or data source of a particular communication session instantiated in the carrier network 102.

[0020] The core network 130 of FIG. 1 may include various network nodes or functions geographically distributed and interconnected to provide network coverage of a service  region of the carrier network 102. These network nodes or functions may be implemented as dedicated hardware network elements. Alternatively, these network nodes or functions may be virtualized and implemented as virtual machines or as software entities. A network node may each be configured with one or more types of network functions. These network nodes or network functions may collectively provide the provisioning and routing functionalities of the core network 130. The term “network nodes” and “network functions” are used interchangeably in this disclosure.

[0021] FIG. 2 further shows an exemplary division of network functions in the core network 130 of a communication network 200. While only single instances of network nodes or functions are illustrated in FIG. 2, those having ordinary skill in the art readily understand that each of these network nodes may be instantiated as multiple instances of network nodes that are distributed throughout the core network 130. As shown in FIG. 2, the core network 130 may include but is not limited to network nodes such as access management network node (AMNN) 230, authentication network node (AUNN) 260, network data management network node (NDMNN) 270, session management network node (SMNN) 240, data routing network node (DRNN) 250, policy control network node (PCNN) 220, and application data management network node (ADMNN) 210. Exemplary signaling and data exchange between the various types of network nodes through various communication interfaces are indicated by the various solid connection lines in FIG. 2. Such signaling and data exchange may be carried by signaling or data messages following predetermined formats or protocols.

[0022] The implementations described above in FIGs. 1 and 2 may be applied to both wireless and wireline communication systems. FIG. 3 illustrates an exemplary cellular wireless communication network 300 based on the general implementation of the communication network 200 of FIG. 2. FIG. 3 shows that the wireless communication network 300 may include user equipment (UE) 310 (functioning as the terminal device 110 of FIG. 2) , radio access network (RAN) 320 (functioning as the access network 120 of FIG. 2) , data network (DN) 150, and core network 130 including access management function  (AMF) 330 (functioning as the AMNN 230 of FIG. 2) , session management function (SMF) 340 (functioning as the SMNN 240 of FIG. 2) , application function (AF) 390 (functioning as the ADMNN 210 of FIG. 2) , user plane function (UPF) 350 (functioning as the DRNN 250 of FIG. 2) , policy control function 322 (functioning as the PCNN 220 of FIG. 2) , authentication server function (AUSF) 360 (functioning as the AUNN 260 of FIG. 2) , and universal data management (UDM) function 370 (functioning as the UDMNN 270 of FIG. 2) . Again, while only single instances for some network functions or nodes of the wireless communication network 300 (the core network 130 in particular) are illustrated in FIG. 3, those of ordinary skill in the art readily understand that each of these network nodes or functions may have multiple instances that are distributed throughout the wireless communication network 300. While the AF 390 is depicted as part of the core network 130 in FIG. 3, they may be considered as associated with particular service applications 140 and may be considered as being outside of the core network 140. In this disclosure, various functions deployed in the wireless network as described above may also be referred to as function entities, which may be implemented as a network node, a network element, a logical function, via hardware, software, or a combination thereof.

[0023] In FIG. 3, the UE 310 may be implemented as various types of mobile devices that are configured to access the core network 130 via the RAN 320. The UE 310 may include but is not limited to mobile phones, laptop computers, tablets, Internet-Of-Things (IoT) devices, distributed sensor network nodes, wearable devices, and the like. The UE may also be Multi-access Edge Computing (MEC) capable UE that supports edge computing. The RAN 320 for example, may include a plurality of radio base stations distributed throughout the service areas of the carrier network. The communication between the UE 310 and the RAN 320 may be carried in over-the-air (OTA) radio interfaces as indicated by 311 in FIG. 3.

[0024] Continuing with FIG. 3, the UDM 370 may form a permanent storage or database for user contract and subscription data. The UDM may further include an authentication credential repository and processing function (ARPF, as indicated in 370 of FIG. 3) for storage  of long-term security credentials for user authentication, and for using such long-term security credentials as input to perform computation of encryption keys as described in more detail below. To prevent unauthorized exposure of UDM / ARPF data, the UDM / ARPF 370 may be located in a secure network environment of a network operator or a third-party.

[0025] The AMF / SEAF 330 may communicate with the RAN 320, the SMF 340, the AUSF 360, the UDM / ARPF 370, and the Policy Control Function (PCF) 322 via communication interfaces indicated by the various solid lines connecting these network nodes or functions. The AMF / SEAF 330 may be responsible for UE to non-access stratum (NAS) signaling management, and for provisioning registration and access of the UE 310 to the core network 130 as well as allocation of SMF 340 to support communication need of a particular UE. The AMF / SEAF 330 may be further responsible for UE mobility management. The AMF may also include a security anchor function (SEAF, as indicated in 330 of FIG. 3) that, as described in more detail below, and interacts with AUSF 360 and UE 310 for user authentication and management of various levels of encryption / decryption keys. The AUSF 360 may terminate user registration / authentication / key generation requests from the AMF / SEAF 330 and interact with the UDM / ARPF 370 for completing such user registration / authentication / key generation.

[0026] The SMF 340 may be allocated by the AMF / SEAF 330 for a particular communication session instantiated in the wireless communication network 300. The SMF 340 may be responsible for allocating UPF 350 to support the communication session and data flows therein in a user data plane and for provisioning / regulating the allocated UPF 350 (e.g., for formulating packet detection and forwarding rules for the allocated UPF 350) . Alternative to being allocated by the SMF 340, the UPF 350 may be allocated by the AMF / SEAF 330 for the particular communication session and data flows. The UPF 350 allocated and provisioned by the SMF 340 and AMF / SEAF 330 may be responsible for data routing and forwarding and for reporting network usage by the particular communication session. For example, the UPF 350 may be responsible for routing end-end data flows between UE 310 and the DN 150, between UE 310 and the service applications 140. The  DN 150 and the service applications 140 may include but are not limited to data network and services provided by the operator of the wireless communication network 300 or by third-party data network and service providers.

[0027] The PCF 322 may be responsible for managing and providing various levels of policies and rules applicable to a communication session associated with the UE 310 to the AMF / SEAF 330 and SMF 340. As such, the AMF / SEAF 330, for example, may assign SMF 340 for the communication session according to policies and rules associated with the UE 310 and obtained from the PCF 322. Likewise, the SMF 340 may allocate UPF 350 to handle data routing and forwarding of the communication session according to policies and rules obtained from the PCF 322.

[0028] While FIGs. 1-3 and the various exemplary implementations described below are based on cellular wireless communication networks, the scope of this disclosure is not so limited and the underlying principles are applicable to other types of wireless and wireline communication networks.

[0029] Network identity and data security in the wireless communication network 300 of FIG. 3 may be managed via user authentication processes provided by the AMF / SEAF 330, the AUSF 360, and the UDM / ARPF 370. In particularly, the UE 310 may first communicate with AMF / SEAF 330 for network registration and may then be authenticated by the AUSF 360 according to user contract and subscription data in the UDM / ARPF 370. Communication sessions established for the UE 310 after user authentication to the wireless communication network 300 may then be protected by the various levels of encryption / decryption keys. The generation and management of the various keys may be orchestrated by the AUSF 360 and other network functions in the communication network 300.

[0030] AKMA Framework

[0031] In the wireless communication network, the Application Function (AF, or  application function entity) may provide application service to a UE. The AF may be deployed in various locations, such as a Home Public Land Mobile Network (HPLMN) of the UE, a Visited Public Land Mobile Network (VPLMN) of the UE (e.g., when the UE roams to the VPLMN) , or a Data Network (DN) which is external to the HPLMN and the VPLMN. Secure or encrypted data communication between the AF and the UE may be implemented under an Authentication and Key Management for Applications (AKMA) framework. The AKMA framework may be based on various authentication procedures such as the 5G Authentication and Key Agreement (5G-AKA) method, the Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA') method, the Extensible Authentication Protocol –Transport Layer Security (EAP-TLS) method, or the like.

[0032] FIG. 4 illustrates an exemplary network model 400 for implementing an AKMA framework. This model includes various network elements. Each network element may be implemented as a physical entity, or a logical entity providing a particular set of network functions. A logical entity may be based on software, hardware, firmware, of any combination thereof. For example, a logical entity may include a server providing the function. For another example, a logical entity may be implemented based on cloud-based service or platform, such as Software as a service (SaaS) , Platform as a service (PaaS) , etc.

[0033] The AKMA Anchor Function (AAnF) 412 provides a security anchor function in the HPLMN. The AAnF stores the AKMA Anchor Key (KAKMA) for AKMA service associated with UE 424, which is received from the Authentication Server Function (AUSF) 416 after the UE 424 completes a successful primary authentication. The AAnF may also generate the key material to be used between the UE and the Application Function (AF) 420 and maintains UE AKMA context (also referred to as AKMA security context) .

[0034] The AF 420 may provide application service to the UE. Under the AKMA framework, the AF may request for its AKMA Application Key, denoted as KAF, from the AAnF using an identifier for the KAKMA. The identifier may include an AKMA Key Identifier (A-KID) . The AAnF may only provide the KAF to the AF after the AF is  authenticated and authorized by the operator network. The AF may be located inside or outside the operator's network. In this disclosure, for simplicity, the AKMA Application Key (denoted as KAF, or KAF) may also be referred to as the AF key.

[0035] In some example implementations, the A-KID may include: A-TID (AKMA Temporary UE Identifier) , and HN-ID (identity of home network) . A-KID identifies the KAKMA key of the UE. A-KID may be in a Network Access Identifier (NAI) format, i.e., username@realm. Specifically, the username part may include the Routing Identifier (RID) of the UE and the AKMA Temporary UE Identifier (A-TID) , and the realm part may include Home Network Identifier.

[0036] A-TID may be derived from KAUSF and SUPI (Subscription Permanent Identifier) of the UE. For example, A-TID = KDF ( "A-TID" , SUPI, KAUSF) , where KDF is the key derivation function.

[0037] The Network Exposure Function (NEF) 410 may be configured to enable and authorize external AFs to access the AKMA service and forward the AKMA service request towards the AAnF. The NEF may also perform the AAnF selection in case there are multiple AAnFs.

[0038] The AUSF 416 may provide the Subscription Permanent Identifier (SUPI) and AKMA key material (e.g., A-KID, KAKMA) of the UE to the AAnF. The AUSF may also perform the AAnF selection.

[0039] The UDM may store AKMA subscription data of the subscriber (or the UE subscribed to the wireless communication network) .

[0040] Referring to FIG. 4, various interfaces may be involved in the AKMA framework. These interfaces may include Nnef, Naanf, Nudm, Uausf, and Namf and may be referred to as Service Based Interface (SBI) , as each interface corresponds to a service provided by a network element. For example, Nnef represnets the SBI utilized by the NEF; Naanf represents the SBI utilized by the AAnF; and Nudm represents the SBI utilized by the UDM.  The network elements may interact with each other via the various SBIs. The SBI may provide security protection. For example, the SBI may be confidentiality, integrity and replay protected.

[0041] FIG. 4 shows the implementation where the AAnF is deployed as a standalone function. Other deployment options may be chosen. For example, the AAnF may be co-located with the AUSF, or the AAnF may be co-located with the NEF.

[0042] FIG. 5 shows an example of electronic device 500 to implement various network nodes, network elements, network entities, such as a network base station (e.g., a radio access network node) , a core network (CN) , a core network element / entity (e.g., an AMF, a UDM, an AAnF, etc. ) , an operation and maintenance (OAM) , and the like. Optionally in one implementation, the example electronic device 500 may include radio transmitting / receiving (Tx / Rx) circuitry 508 to transmit / receive communication with UEs and / or other base stations. Optionally in one implementation, the electronic device 500 may also include network interface circuitry 509 to communicate the base station with other base stations and / or a core network, e.g., optical or wireline interconnects, Ethernet, and / or other data transmission mediums / protocols. The electronic device 500 may optionally include an input / output (I / O) interface 506 to communicate with an operator or the like.

[0043] The electronic device 500 may also include system circuitry 504. System circuitry 504 may include processor (s) 521 and / or memory 522. Memory 522 may include an operating system 524, instructions 526, and parameters 528. Instructions 526 may be configured for the one or more of the processors 521 to perform the functions of the network node. The parameters 528 may include parameters to support execution of the instructions 526. For example, parameters may include network protocol settings, bandwidth parameters, radio frequency mapping assignments, and / or other parameters.

[0044] In this disclosure, a network function / network entity / entity, such as an AMF, an AUSF, a UDM, an AAnF, an NEF, an AF, may be implemented in hardware, software, a combination of hardware and software, and may be implemented or integrated in the  electronic device 500. They may also be implemented as a logical entity hosted by the electronic device 500.

[0045] FIG. 6 shows an example of an electronic device to implement a terminal device 600 (for example, a UE) . The UE 600 may be a mobile device, for example, a smart phone or a mobile communication module disposed in a vehicle. The UE 600 may include a portion or all of the following: communication interfaces 602, a system circuitry 604, an input / output interfaces (I / O) 606, a display circuitry 608, and a storage 609. The display circuitry may include a user interface 610. The system circuitry 604 may include any combination of hardware, software, firmware, or other logic / circuitry. The system circuitry 604 may be implemented, for example, with one or more systems on a chip (SoC) , application specific integrated circuits (ASIC) , discrete analog and digital circuits, and other circuitry. The system circuitry 604 may be a part of the implementation of any desired functionality in the UE 600. In that regard, the system circuitry 604 may include logic that facilitates, as examples, decoding and playing music and video, e.g., MP3, MP4, MPEG, AVI, FLAC, AC3, or WAV decoding and playback; running applications; accepting user inputs; saving and retrieving application data; establishing, maintaining, and terminating cellular phone calls or data connections for, as one example, internet connectivity; establishing, maintaining, and terminating wireless network connections, Bluetooth connections, or other connections; and displaying relevant information on the user interface 610. The user interface 610 and the inputs / output (I / O) interfaces 606 may include a graphical user interface, touch sensitive display, haptic feedback or other haptic output, voice or facial recognition inputs, buttons, switches, speakers and other user interface elements. Additional examples of the I / O interfaces 606 may include microphones, video and still image cameras, temperature sensors, vibration sensors, rotation and orientation sensors, headset and microphone input  / output jacks, Universal Serial Bus (USB) connectors, memory card slots, radiation sensors (e.g., IR sensors) , and other types of inputs.

[0046] Referring to FIG. 6, the communication interfaces 602 may include a Radio Frequency (RF) transmit (Tx) and receive (Rx) circuitry 616 which handles transmission and  reception of signals through one or more antennas 614. The communication interface 602 may include one or more transceivers. The transceivers may be wireless transceivers that include modulation / demodulation circuitry, digital to analog converters (DACs) , shaping tables, analog to digital converters (ADCs) , filters, waveform shapers, filters, pre-amplifiers, power amplifiers and / or other logic for transmitting and receiving through one or more antennas, or (for some devices) through a physical (e.g., wireline) medium. The transmitted and received signals may adhere to any of a diverse array of formats, protocols, modulations (e.g., QPSK, 16-QAM, 64-QAM, or 256-QAM) , frequency channels, bit rates, and encodings. As one specific example, the communication interfaces 602 may include transceivers that support transmission and reception under the 2G, 3G, BT, WiFi, Universal Mobile Telecommunications System (UMTS) , High Speed Packet Access (HSPA) +, 4G  / Long Term Evolution (LTE) , 5G, and 6G standards. The techniques described below, however, are applicable to other wireless communications technologies whether arising from the 3rd Generation Partnership Project (3GPP) , GSM Association, 3GPP2, IEEE, or other partnerships or standards bodies.

[0047] Referring to FIG. 6, the system circuitry 604 may include one or more processors 621 and memories 622. The memory 622 stores, for example, an operating system 624, instructions 626, and parameters 628. The processor 621 is configured to execute the instructions 626 to carry out desired functionality for the UE 600. The parameters 628 may provide and specify configuration and operating options for the instructions 626. The memory 622 may also store any BT, WiFi, 3G, 4G, 5G, 6G or other data that the UE 600 will send, or has received, through the communication interfaces 602. In various implementations, a system power for the UE 600 may be supplied by a power storage device, such as a battery or a transformer.

[0048] Under the AKMA framework, there may be various keys involved, and these keys may be organized in a hierarchical structure as shown in FIG. 7. The example key hierarchy of FIG. 7 may include the following keys at different level: KAUSF, KAKMA, and KAF. These keys may be derived and stored in parallel on both the network side and the Mobile  Equipment (ME) side. The ME refers to a portion of a UE along with other portions of UE such as a Universal Subscriber Identity Module (USIM) .

[0049] After a successful primary authentication between the UE and the wireless communication network (e.g., UE authenticated by the operator) , the AUSF and / or the UE may derive the KAUSF based on an Integrity Key (IK) of the UE, and a Cipher Key (CK) of the UE. AUSF may alternatively derive the KAUSF based on a transformation of the Integrity Key (denoted as IK') of the UE, and a transformation of the Cipher Key (denoted as CK') of the UE.

[0050] Based on the KAUSF, the ME and the AUSF may each derive the KAKMA based on the KAUSF, and the SUPI of the UE, by using a Key Derivation Function (KDF) .

[0051] Then based on the KAKMA, the ME and the AAnF may each derive the KAF based on the KAKMA, and an identifier of the AF, also similarly by using a KDF. It is to be noted that a UE may store multiple KAF, each corresponding to an AF. Likewise, an AF may store multiple KAF, each corresponding to a UE.

[0052] The various keys described herein may each have a lifetime. For example, the KAKMA may be refreshed until the next successful primary authentication. For another example, the KAF may be provisioned with a lifetime (or expiration time) , for example, by the AAnF. In some embodiments, the lifetime of a key may be associated with a timer, such that the timer is started once a key is commissioned, and once the timer expires, the key is refreshed.

[0053] In a wireless communication network, a UE may subscribe to various application services from an AF. When invoking services provided by the AF, secure communication link needs to be established and maintained. An encryption key may be used to encrypt the data flow between the UE and the AF. Depending on use case scenarios, different key may be selected.

[0054] In one scenario, the UE is roaming in a VPLMN, and needs to invoke application  service from an AF in its HPLMN. AKMA application key (KAF) may be used for encryption. Alternatively, an encryption key derived from KAF may be used.

[0055] In another scenario, the UE is roaming in a VPLMN, and needs to invoke application service from an AF in a data network external to the HPLMN and VPLMN. In this case, KAF, encryption key derived from KAF may be used. The AF may also choose its own encryption key which is independent of KAF.

[0056] The above scenarios impose special challenges to regulatory control, especially when the UE has dual accesses –with one access from its HPLMN, and another access from a VPLMN. If UE attempts to invoke an application service with an AF via the access in VPLMN, two pre-checks may need to happen: 1) whether roaming service for the allocation session is allowed in the VPLMN; 2) whether AKMA service is allowed for the application service. In some example implementations, the AF is in the HPLMN. In other example implementations, the AF may not belong to the HPLMN.

[0057] Deriving AKMA Application Key for an AF

[0058] Before UE can start communication with an AF (e.g., start an application session, a Packet Data Unit (PDU) session, etc) , the UE and / or the AF may need to determine whether to use AKMA service (or, use AKMA, for simplicity) . The knowledge on whether to use AKMA or not may be associated with, or implied by the specific application on the UE and / or the AF. For example, a decision may be based on the specific application running on the UE that tries to start the application session. For some applications, AKMA needs to be used, whereas for some other applications, AKMA is not used. For another example, the AF may make such decision and indicate the decision to the UE via, for example, a handshake.

[0059] FIG. 8 illustrates an example flow chart for an AF to request application function specific AKMA keys from an AAnF. An exemplary method may include a portion or all of the following steps. The AF may include any type of AFs, or just AKMA capable AF (AKMA AF for simplicity) .

[0060] Step 1: UE may generate the AKMA Anchor Key (KAKMA, or KAKMA) and the A-KID (AKMA Key Identifier) from the KAUSF before initiating communication with the AF. When the UE initiates communication with the AF, it may include the derived A-KID in the Application Session Establishment Request message. The UE may derive KAF (also denoted as KAF) before or after sending the message.

[0061] Step 2: If the AF does not have a context, or an active context associated with the A-KID, the AF may select an AAnF, and send a message, such as an Naanf_AKMA_ApplicationKey_Get request message to AAnF with the A-KID, to request the KAF for the UE. The AF may also include its identity (AF_ID) in the request message.

[0062] In some example implementations, the AF_ID may include the Fully Qualified Domain Name (FQDN) of the AF and a security protocol identifier that the AF will use with the UE. As an example, the security protocol may include a Ua*security protocol.

[0063] In some example implementations, the AAnF may check whether the AAnF can provide the service to the AF based on, for example, the configured local policy, or the authorization information available in the signaling (e.g., Oauth2.0 token) . If the check fails, the AAnF may reject the request.

[0064] If the check succeeds, the AAnF may further verify whether the UE (subscriber) is authorized to use AKMA based on the presence of the UE specific KAKMA key identified by the A-KID.

[0065] If KAKMA is present in AAnF, the AAnF may continue with step 3.

[0066] If KAKMA is not present in the AAnF, the AAnF may continue with step 6 with an error response.

[0067] Step 3: After receiving the Application Session Establishment Request from the AF, if according to its local policy, the AAnF determines that this specific AF needs Generic Public Subscription Identifier (GPSI) of the UE, the AAnF may send a request, such as an Nudm_SDM_Get Request message to the UDM, to fetch the GPSI of the UE. If the  specific AF does not need GPSI, the AAnF may continue with step 5.

[0068] Step 4: The UDM responds with the GPSI of the UE. The AAnF may then store the received GPSI as part of UE’s AKMA context.

[0069] Step 5: The AAnF may derive the AKMA Application Key (KAF, or KAF) from KAKMA if it does not already have KAF.

[0070] Step 6: The AAnF may send a response message, such as an Naanf_AKMA_ApplicationKey_Get response to the AF with at least one of: SUPI / GPSI of the UE, KAF, or the KAF expiration time. In some example implementations, whether to send SUPI or GPSI may be determined by AAnF based on its local policy.

[0071] If there is a failure in this step, AAnF may send a response message indicating the failure, and the response message may further carry a failure cause.

[0072] Step 7: The AF may send a response, such as an Application Session Establishment Response message to the UE. If there is failure in step 6 (e.g., when handling AKMA key request) , the AF may reject the Application Session Establishment by including a failure cause. Afterwards, UE may trigger a new Application Session Establishment request with the latest A-KID to the AF.

[0073] Local Breakout (LBO) Roaming UE

[0074] When a UE roams in a visited network (e.g., a VPLMN) , end to end (e2e) traffic delay may be an important factor to consider for certain type of application, such as delay-sensitive applications, which may include, for example, vehicle-to-vehicle (V2V) communications, vehicle-to-everything (V2X) communications, machine-type communications, etc. Local breakout (LBO) is a technique that may be implemented to reduce e2e delay. In LBO, the core network can be bypassed for local packets, thereby avoiding additional transport delay and cost associated with backhauling traffic to the home network.

[0075] In some example implementations, an LBO roaming UE may have dual accesses / connections simultaneously. For example, UE may connect to a VPLMN via a 3GPP access, and simultaneously connect to its HPLMN via a Non-3GPP access. When the UE establishes an application session, such as a Packet Data Unit (PDU) session via the 3GPP access, the AMF / SMF of the VPLMN is selected, and the application session is treated as a roaming session. Whereas when the UE establishes an application session via a Non-3GPP access, AMF / SMF of the HPLMN is selected, and the application session is treated as a non-roaming session.

[0076] Embodiments in this disclosure apply to a UE operating in LBO mode and having dual accesses –one via its HPLMN, and another via a VPLMN. These embodiments also apply to UE operating in other modes and having dual accesses.

[0077] Embodiment 1: AKMA Roaming Agreement Checking - Using Existing AAnF Service

[0078] In this embodiment, a UE has dual connections via its HPLMN and a VPLMN. For example, the UE may be operating in an LBO mode, or other dual access mode. UE attempts to establish an application session, such as a PDU session, with an AF. In this embodiment, existing messages for interaction between AF and AAnF are extended, to add support for checking whether roaming service is allowed, or whether AKMA is generally allowed to be used between the UE and the AF, or whether AKMA is allowed for a particular application session between the UE and the AF.

[0079] This embodiment covers a scenario that UE uses the access provided by a VPLMN to initiate the application session establishment request. In some example implementations, the UE may be in an LBO mode, and the VPLMN is used for 3GPP access. In some example implementations, the UE is operating in a dual access mode, with accesses provided by a HPLMN and a VPLMN, the VPLMN is used for 3GPP access.

[0080] As the UE is roaming in the VPLMN, although AKMA protection is preferred due to the enhanced security it provides, the AKMA service (i.e., using security protection  provided under the AKMA framework) may or may not be allowed, or supported between the UE and the AF for the application session. For example, a roaming policy does not grant UE with AKMA service, or the roaming policy does not grant AKMA service to the particular application running on the UE, or the roaming policy does not allow roaming service for the UE in the VPLMN. In this case, roaming agreement checking is performed first, to determine whether the AKMA service is allowed based on, for example, the roaming policy associated with the UE. If the AKMA service is allowed, the application session between UE and AF will proceed. Otherwise the application session establishment request will be denied. The exemplary steps for a roaming UE to establish an application session are described in details below with reference to FIG. 9. An exemplary method may include a portion or all of the following steps.

[0081] Step 1: UE may generate the AKMA Anchor Key (KAKMA, or KAKMA) and the A-KID (AKMA Key Identifier) from the KAUSF before initiating communication with the AF. When the UE initiates communication with the AF, it may include the derived A-KID in the Application Session Establishment Request message. The UE may derive KAF (also denoted as KAF) before or after sending the message.

[0082] Step 2: The AF may subscribe to the PCRF / PCF (Policy and Charging Rules Function  / Policy Control Function) to be notified on update of the PLMN ID to which the UE is currently attached (i.e., UE is using a PLMN identified by the PLMN_ID for establishing the application session) . With the subscription, the AF will be notified about the initial PLMN ID, as well as updated PLMN ID whenever UE switch to another PLMN. The subscription to PLMN change is active as long as the UE is registered.

[0083] Step 3: The PCRF / PCF forwards the PLMN ID to the AF. The AF may store the PLMN_ID.

[0084] Step 4: If the AF does not have a context, or an active context associated with the A-KID, the AF may select an AAnF, and send a request message, such as an Naanf_AKMA_ApplicationKey_Get request message to the AAnF with the A-KID, to  request the KAF for the UE. The AF may also include its identity (AF_ID) in the request message

[0085] Additionally, the AF may include the PLMN ID associated with the application session in the message. The PLMN ID identifies the PLMN which provides access to the UE for the application session. The subsequent steps may check whether UE is roaming or non-roaming based on the PLMN ID. If the UE is roaming, subsequent steps may further check if roaming service is allowed based on a roaming agreement (or roaming policy) .

[0086] Step 5: Based on the PLMN_ID, the AAnF may determine the PLMN that UE uses for the current application session establishment request. The AAnF may check whether the AAnF can provide the service to the AF based on, for example, the configured local policy, the authorization information available in the signaling (e.g., Oauth2.0 token) , or the roaming agreement (if the UE is roaming in the PLMN identified by the PLMN_ID) . If the check fails, the AAnF may not serve the AF and may reject the request it received in step 4 via a response message to be sent in step 6 (see step 6 below for details) . In this step, based on the roaming agreement / roaming policy, the AAnF may determine whether roaming is allowed. Alternatively or additionally, the AAnF may determine whether AKMA is generally allowed to be used between the UE and the AF, or whether AKMA is allowed for the current requested application session between the UE and the AF.

[0087] If the check succeeds, the AAnF is allowed to provide service to the AF. The AAnF may further proceed to verify whether the UE (subscriber) is authorized to use AKMA based on, for example, the presence of the UE specific KAKMA key identified by the A-KID.

[0088] If KAKMA is present in AAnF, the AAnF may start to derive / obtain security context including the AF key (KAF) . The detailed process is outlined in steps 3-5 as illustrated in FIG. 8, which is not reiterated herein.

[0089] If KAKMA is not present in the AAnF, the AAnF may continue with step 6 with an error response indicating that AKMA service is not allowed.

[0090] Step 6: Depending on the execution result in step 5, the AAnF may send a corresponding success or error response.

[0091] If the AKMA is allowed to be used for the application session between UE and AF, the AAnF may send a success response message (to the request message in step 4) , such as an Naanf_AKMA_ApplicationKey_Get response message to the AF. The response message may carry at least one of: SUPI / GPSI of the UE, the AF key (KAF) , or the KAF expiration time. The AAnF may determine whether to send SUPI or GPSI based on the local policy.

[0092] If there is an error condition in step 5 due to, for example, that the AAnF cannot serve the AF, or if the UE is roaming in the PLMN (identified by the PLMN_ID) , and the roaming policy does not allow AKMA to be used for the application session, and / or the roaming policy does not allow AKMA to be used between the UE and the AF, the AAnF may send an error response message (to the request message in step 4) , such as an Naanf_AKMA_ApplicationKey_Get response message to the AF. The response message may carry a failure cause. For example, the failure cause may indicate that AKMA service and / or roaming service is not allowed for the roaming UE.

[0093] Step 7: The AF may send a response (to the request message in step 1) , such as an Application Session Establishment Response message to the UE.

[0094] If AF receives a success response message from AAnF in step 6, the AF may send a success response to the UE, allowing the application session establishment request.

[0095] If AF receives an error response message from AAnF, and the failure cause indicates that AAnF cannot fetch the AKMA security context (e.g., KAF) to the AF, the AF may send an error response to the UE, denying the application session establishment request and indicating the failure cause.

[0096] If AF receives an error response message from AAnF, and the failure cause indicates that roaming service is not allowed, or that AKMA service is not allowed for the  roaming UE, or that AKMA service is not allowed for this particular application session between the UE and the AF, the AF may send an error response to the UE, denying the application session establishment request and indicating the failure cause. Additionally, the AF may store the failure record for the UE. The failure record may indicate that AKMA is not allowed, or roaming service is not allowed, if UE is roaming in a VPLMN identified by the PLMN_ID. Therefore, if this UE further triggers a subsequent Application Session Establishment request using the same VPLMN identified by the PLMN ID, AF may directly reject the request by including the failure cause, without the need of further interaction with the AAnF.

[0097] Step 8: If UE receives a failure cause indicating roaming service not allowed due to, for example, that the AKMA is not allowed when UE is roaming in the VPLMN identified by the PLMN_ID, or roaming service is not allowed, UE may decide whether to initiate a new Application Session Establishment Request via a new PDU session associated with another PLMN ID.

[0098] In this embodiment, existing messages for interaction between AF and AAnF are extended, to add support for checking whether AKMA is allowed to be used between UE and AF, or for an application session between the UE and the AF. For example, the Naanf_AKMA_ApplicationKey_Get request message is extended to carry a PLMN_ID, so the AAnF may determine whether AKMA is allowed for a particular application session, or whether AKMA is allowed to be used between the UE and the AF. Meanwhile, the Naanf_AKMA_ApplicationKey_Get response message is also extended, such that if AKMA is allowed and AAnF is able to obtain AKMA security context (e.g., KAF) for the AF, the Naanf_AKMA_ApplicationKey_Get response message returns success and may carry at least one of: the AF key -KAF, KAF expiration time, or GPSI / SUPI of the UE; and if AKMA is not allowed, the Naanf_AKMA_ApplicationKey_Get response message returns a failure and may further carry a corresponding failure cause.

[0099] In this embodiment, the AF may be in the HPLMN of the UE, or a VPLMN of the UE.

[0100] Embodiment 2: AKMA Roaming Agreement Checking - Using Newly Introduced AAnF Service

[0101] In this embodiment, a UE has dual connections via its HPLMN and a VPLMN. For example, the UE may be operating in an LBO mode, or other dual access mode. UE attempts to establish an application session, such as a PDU session, with an AF. In this embodiment, instead of using existing messages, new messages are introduced for interaction between AF and AAnF, to add support for checking whether roaming service is allowed, or whether AKMA is generally allowed to be used between the UE and the AF, or whether AKMA is allowed for a particular application session between the UE and the AF.

[0102] This embodiment covers a scenario that UE uses an access provided by a VPLMN to initiate the application session establishment request. In some example implementations, the UE may be in an LBO mode, and the VPLMN is used for 3GPP access. In some example implementations, the UE is operating in a dual access mode, with accesses provided by a HPLMN and a VPLMN, and the VPLMN is used for 3GPP access.

[0103] As the UE is roaming in the VPLMN, although AKMA protection is preferred due to the enhanced security it provides, the AKMA service (i.e., using security protection provided under the AKMA framework) may or may not be allowed, or supported between the UE and the AF for the application session. For example, a roaming policy does not grant UE with AKMA service, or the roaming policy does not grant AKMA service to the particular application running on the UE, or the roaming policy does not allow roaming service for the UE in the VPLMN. In this case, AKMA agreement checking is performed first, to determine whether the AKMA service is allowed based on, for example, the roaming policy associated with the UE. If the AKMA service is allowed, the application session between UE and AF will proceed. Otherwise the application session establishment request will be denied. The exemplary steps for a roaming UE to establish an application session are described in details below with reference to FIG. 10. An exemplary method may include a portion or all of the following steps.

[0104] Step 1: UE may generate the AKMA Anchor Key (KAKMA, or KAKMA) and the A-KID (AKMA Key Identifier) from the KAUSF before initiating communication with the AF. When the UE initiates communication with the AF, it may include the derived A-KID in the Application Session Establishment Request message. The UE may derive KAF (also denoted as KAF) before or after sending the message.

[0105] Step 2: The AF may subscribe to the PCRF / PCF (Policy and Charging Rules Function  / Policy Control Function) to be notified on update of the PLMN ID to which the UE is currently attached (i.e., UE is using a PLMN identified by the PLMN_ID for establishing the application session) . With the subscription, the AF will be notified about the initial PLMN ID, as well as updated PLMN ID whenever UE switch to another PLMN. The subscription to PLMN change is active as long as the UE is registered.

[0106] Step 3: The PCRF / PCF forwards the PLMN ID to the AF. The AF may store the PLMN_ID.

[0107] Step 4: UE may have previous interaction with the AF using the same PLMN (identified by the PLMN_ID) , and the AF may keep a record thereof.

[0108] If the PLMN ID for the current UE access (for the application session) is changed from the previous interaction, the AF may need to check whether AKMA and / or roaming service is allowed to be used for the application session. AF may perform the check by sending a request message to AAnF. Exemplarily, the request message may be named as “Naanf_AKMA_RomaingAgreement_Check request” . Note that this request message is newly introduced to wireless technology and the message name described here is for exemplary purpose only, and the message may take other names. The request message may carry the PLMN ID received in step 3 from PCF / PCRF. The PLMN ID identifies the PLMN which provides access to the UE for the current requested application session. The subsequent steps may check whether UE is roaming or non-roaming based on the PLMN ID. If the UE is roaming, further check may be performed to determine whether AKMA service is allowed under the roaming agreement (or roaming policy) .

[0109] Step 5: Based on the PLMN_ID, the AAnF may determine the PLMN that UE uses for the current application session establishment request. Then based on the roaming agreement, AAnF may determine whether roaming is supported / allowed. AAnF may further determine whether AKMA is generally allowed to be used between the UE and the AF, or whether AKMA is allowed for the current requested application session between the UE and the AF. More generally speaking, AAnF may check whether the particular PLMN (from which UE initiates the application session establishment request) satisfies the roaming agreement (in order to provide roaming service and / or AKMA service) .

[0110] Step 6: AAnF may send a response message (to the request in step 4) , such as an Naanf_AKMA_RomaingAgreement_Check response message to AF. If the PLMN ID of the UE does not satisfy the roaming agreement in step 5, the AAnF responses with a failure cause indicating that roaming service is not allowed, and / or that AKMA service is not allowed, and steps 7-9 may be skipped. Otherwise the AAnF may return a success response, indicating that AKMA service is allowed and / or roaming service is allowed.

[0111] Step 7: If the AF does not have a context, or an active context associated with the A-KID, the AF may send a request message, such as an Naanf_AKMA_ApplicationKey_Get request message to the AAnF with the A-KID, to request the KAF for the UE. The AF may also include its identity (AF_ID) in the request message.

[0112] The AF_ID may include the Fully Qualified Domain Name (FQDN) of the AF and a security protocol identifier that the AF will use with the UE. As an example, the security protocol may include a Ua*security protocol.

[0113] In example implementations, the AAnF may check whether the AAnF can provide service to the AF based on, for example, the configured local policy, or the authorization information available in the signaling (e.g., Oauth2.0 token) . If the check fails, the AAnF may reject the request (e.g., Naanf_AKMA_ApplicationKey_Get request) .

[0114] If the check succeeds, the AAnF may further verify whether the UE (subscriber) is authorized to use AKMA based on the presence of the UE specific KAKMA key identified by  the A-KID.

[0115] If KAKMA is present in AAnF, the AAnF may start to derive / obtain security context including the AF key (KAF) in step 8.

[0116] If KAKMA is not present in the AAnF, the AAnF may continue with step 9 with an error response indicating that AKMA service is not allowed.

[0117] Step 8: The AAnF may derive the AKMA Application Key (KAF) from KAKMA if it does not already have KAF. The detailed process is outlined in steps 3-5 as illustrated in FIG. 8, which is not reiterated herein.

[0118] Step 9: Depending on the execution result in previous steps, the AAnF may send a corresponding success or error response.

[0119] If the AKMA is allowed to be used for the application session between UE and AF, the AAnF may send a success response message (to the request message in step 7) , such as an Naanf_AKMA_ApplicationKey_Get response message to the AF. The response message may carry at least one of: SUPI / GPSI of the UE, the AF key (KAF) , or the KAF expiration time. The AAnF may determine whether to send SUPI or GPSI based on the local policy.

[0120] If there is an error condition in step 7 due to, for example, that the AAnF cannot serve the AF; or if the UE is roaming in the PLMN (identified by the PLMN_ID) , and the roaming policy does not allow AKMA to be used for the application session, and / or the roaming policy does not allow AKMA to be used between the UE and the AF, and / or the roaming policy does not allow roaming service, the AAnF may send an error response message (to the request message in step 7) , such as an Naanf_AKMA_ApplicationKey_Get response message to the AF. The response message may carry a failure cause. For example, the failure cause may indicate that AKMA service and / or roaming service is not allowed for the roaming UE.

[0121] Step 10: The AF may send a response (to the request message in step 1) , such as an Application Session Establishment Response message to the UE.

[0122] If AF receives a success response message from AAnF in step 9, the AF may send a success response to the UE, granting the application session establishment request.

[0123] If AF receives an error response message from AAnF (either in step 6 or step 9) , and the failure cause indicates that AAnF cannot fetch the AKMA security context (e.g., KAF) to the AF, the AF may send an error response to the UE, denying the application session establishment request and indicating the failure cause.

[0124] If AF receives an error response message from AAnF, and the failure cause indicates that roaming service is not allowed, or that AKMA service is not allowed for the roaming UE, or that AKMA service is not allowed for the particular application session between the UE and the AF, the AF may send an error response to the UE, denying the application session establishment request and indicating the failure cause. Additionally, the AF may store the failure record for the UE. The failure record may indicate that AKMA is not allowed, or roaming service is not allowed, if UE is roaming in a VPLMN identified by the PLMN_ID. Therefore, if this UE further triggers a subsequent Application Session Establishment request using the same VPLMN identified by the PLMN ID, AF may directly reject the request by including the failure cause, without the need of further interaction with the AAnF.

[0125] Step 11: If UE receives a failure cause indicating roaming service not allowed due to, for example, that the AKMA is not allowed when UE is roaming in the VPLMN identified by the PLMN_ID, or roaming service is not allowed, UE may decide whether to initiate a new Application Session Establishment Request via a new PDU session associated with another PLMN ID.

[0126] In this embodiment, instead of using existing messages, new messages are introduced for interaction between AF and AAnF, to check whether AKMA and / or roaming is allowed for an application session between a UE and the AF. For example, a new message, such as an Naanf_AKMA_RomaingAgreement_Check request message is added. Initiated by the AF, this message may carry a PLMN_ID, so the AAnF may determine  whether roaming service is allowed, or whether AKMA is allowed for a particular application session, or whether AKMA is generally allowed to be used between the UE and the AF. The determination may be based on a roaming agreement (or roaming policy) . Meanwhile, a new response message, such as an Naanf_AKMA_RomaingAgreement_Check response message is added, indicating whether AKMA is allowed for the requested application session.

[0127] In this embodiment, the AF may be in the HPLMN of the UE, or a VPLMN of the UE.

[0128] It is noted that in this disclosure, the steps are listed for exemplary purpose. Some steps described in an embodiment may be optional, while some steps provide alternative, parallel solution to other steps.

[0129] Performed by a first network element, an exemplary method according to embodiments in this disclosure may include a portion or all of the following steps: step 1: receiving, from a wireless device, a first message for requesting to establish an application session, wherein the first message carries an AKMA (Authentication and Key Management for Applications) key identifier, A-KID, for identifying an AKMA key of the wireless device, and wherein the AKMA key is used for authentication and security protection between the wireless device and the first network element; step 2: determining whether an AKMA service is allowed for the application session; and step 3: in response to the AKMA service not being allowed for the application session, transmitting, to the wireless device, a second message as a response to the first message, the second message indicating a failure for establishing the application session.

[0130] In any portion or combination of the implementations above, the first network element comprises an Application Function (AF) , and the second network element comprises an AKMA Anchor Function (AAnF) .

[0131] In any portion or combination of the implementations above, the wireless device  has at least two radio accesses comprising: a first radio access via a Home PLMN (HPLMN) , and a second radio access via a VPLMN.

[0132] In any portion or combination of the implementations above, wherein the application session is initiated by the wireless device using an access via a VPLMN.

[0133] Performed by a first network element, an exemplary method according to embodiments in this disclosure may include a portion or all of the following steps: step 1: receiving, from a second network element, a first message carrying at least one of: an AKMA (Authentication and Key Management for Applications) key identifier, A-KID, for identifying an AKMA key of a wireless device, wherein the wireless device is in a procedure to establish an application session with the second network element via a Visited Public Land Mobile Network (VPLMN) ; an Application Function identifier (AF_ID) of the second network element; or a PLMN ID of the VPLMN; step 2: determining, based on at least one of: the A-KID; or a roaming policy associated with the PLMN ID, whether an AKMA service is allowed for the application session; and step 3: transmitting, from the second network element, a second message as a response to the first message indicating whether the AKMA service is allowed for the application session.

[0134] In any portion or combination of the implementations above, the wireless device has at least two radio accesses comprising: a first radio access via a Home PLMN (HPLMN) , and a second radio access via the VPLMN.

[0135] In any portion or combination of the implementations above, the application session is initiated by the wireless device using an access via a VPLMN.

[0136] In any portion or combination of the implementations above, the first network element comprises an AKMA Anchor Function (AAnF) , and wherein the second network element comprises an Application Function (AF) .

[0137] In this disclosure, message types and / or message names (e.g., as shown in FIGs.  9-11) are for exemplary purpose only. Different message types and / or message names may be chosen in implementation, and should still be covered by this disclosure, as far as the underlying principle is the same, for example, if the messages are used for a same purpose.

[0138] In this disclosure, a single information element in a message may be split into multiple information elements. Multiple information element may also be combined into a single information element.

[0139] The present disclosure describes methods, apparatus, and computer-readable medium for wireless communication. The present disclosure addressed the issues with AKMA utilization when a UE is roaming in a VPLMN. The methods, devices, and computer-readable medium described in the present disclosure may facilitate roaming regulatory control requirement and enhance security protection for application sessions. The methods, devices, and computer-readable medium described in the present disclosure may improve the overall performance of the wireless communication systems, in particular from a security protection perspective.

[0140] In this disclosure, various embodiments are disclosed for updating / refreshing security configuration in various network entities such as AF, and UE. An AF may detect a security configuration to be expired, lost, or out of sync with the other network elements. Various mechanisms are described for the AF to refresh its security configuration and synchronize the security configuration update to the UE. In exemplary embodiments, the AAnF may further check if a valid UE security context is locally configured in the AAnF, via various approaches. Based on the check result, the AAnF may bypass procedures for soliciting UE security context from the core network thus saving signaling overhead and improving efficiency.

[0141] In this disclosure, the steps in each embodiment are for illustration purposes only and other alternatives may be derived based on the disclosed embodiments as desired. For example, only part of the steps may need to be performed. For another example, the sequence of the steps may be adjusted. For another example, several steps may be combined (e.g., several messages may be combined in one message) . For yet another  example, a single step may be split (e.g., one message may be sent via two sub-messages) .

[0142] The accompanying drawings and description above provide specific example embodiments and implementations. The described subject matter may, however, be embodied in a variety of different forms and, therefore, covered or claimed subject matter is intended to be construed as not being limited to any example embodiments set forth herein. A reasonably broad scope for claimed or covered subject matter is intended. Among other things, for example, subject matter may be embodied as methods, devices, components, systems, or non-transitory computer-readable media for storing computer codes. Accordingly, embodiments may, for example, take the form of hardware, software, firmware, storage media or any combination thereof. For example, the method embodiments described above may be implemented by components, devices, or systems including memory and processors by executing computer codes stored in the memory.

[0143] Throughout the specification and claims, terms may have nuanced meanings suggested or implied in context beyond an explicitly stated meaning. Likewise, the phrase “in one embodiment / implementation” as used herein does not necessarily refer to the same embodiment and the phrase “in another embodiment / implementation” as used herein does not necessarily refer to a different embodiment. It is intended, for example, that claimed subject matter includes combinations of example embodiments in whole or in part.

[0144] In general, terminology may be understood at least in part from usage in context. For example, terms, such as “and” , “or” , or “and / or, ” as used herein may include a variety of meanings that may depend at least in part on the context in which such terms are used. Typically, “or” if used to associate a list, such as A, B or C, is intended to mean A, B, and C, here used in the inclusive sense, as well as A, B or C, here used in the exclusive sense. In addition, the term “one or more” as used herein, depending at least in part upon context, may be used to describe any feature, structure, or characteristic in a singular sense or may be used to describe combinations of features, structures or characteristics in a plural sense. Similarly, terms, such as “a, ” “an, ” or “the, ” may be understood to convey a singular usage or to convey a plural usage, depending at least in part upon context. In addition, the term  “based on” may be understood as not necessarily intended to convey an exclusive set of factors and may, instead, allow for existence of additional factors not necessarily expressly described, again, depending at least in part on context.

[0145] Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present solution should be or are included in any single implementation thereof. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present solution. Thus, discussions of the features and advantages, and similar language, throughout the specification may, but do not necessarily, refer to the same embodiment.

[0146] Furthermore, the described features, advantages and characteristics of the present solution may be combined in any suitable manner in one or more embodiments. One of ordinary skill in the relevant art will recognize, in light of the description herein, that the present solution can be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the present solution.

Claims

1.A method for wireless communication, performed by a first network element, comprising:receiving, from a wireless device, a first message for requesting to establish an application session, wherein the first message carries an AKMA (Authentication and Key Management for Applications) key identifier, A-KID, for identifying an AKMA key of the wireless device, and wherein the AKMA key is used for authentication and security protection between the wireless device and the first network element;determining whether an AKMA service is allowed for the application session; andin response to the AKMA service not being allowed for the application session, transmitting, to the wireless device, a second message as a response to the first message, the second message indicating a failure for establishing the application session.2.The method of claim 1, where the second message indicating that the AKMA service is not allowed based on a roaming policy of the wireless device.3.The method of claim 1, further comprising determining whether the AKMA service is allowed for the application session.4.The method of claim 3, wherein determining whether the AKMA service is allowed for the application session comprises:transmitting a third message to a second network element, the third message carrying at least one of:the A-KID;an Application Function identifier (AF_ID) of the first network element; ora Public Land Mobile Network identifier (PLMN ID) associated with the application session; andreceiving, from the second network element, a fourth message as a response to the third message indicating whether the AKMA service is allowed for the application session.5.The method of claim 4, wherein:the application session is initiated by the wireless device using an access via a Visited Public Land Mobile Network (VPLMN) ;a roaming policy for the wireless device in the VPLMN allows the wireless device to use the AKMA service with the first network element; andthe fourth message carries at least one of:an indication that the wireless device is allowed to use the AKMA service with the first network element;a Subscription Permanent Identifier (SUPI) of the wireless device;a Generic Public Subscription Identifier (GPSI) of the wireless device;an application function key (KAF) of the first network element; oran expiration time of the KAF.6.The method of claim 5, further comprising:in response to the AKMA service being allowed for the application session, transmitting, to the wireless device, a response to the first message to allow an establishment of the application session.7.The method of claim 5, wherein the third message comprises an  Naanf_AKMA_ApplicationKey_Get request message, and wherein the fourth message comprises an Naanf_AKMA_ApplicationKey_Get response message.8.The method of claim 5, further comprising:in response to the first network element not having a context associated with the A-KID, transmitting, to the second network element, a fifth message to request the KAF of the first network element, the fifth message carrying at least one of:the A-KID; orthe AF_ID of the first network element; andreceiving, from the second network element, a sixth message as a response to the fifth message, the sixth message comprising at least one of:the SUPI of the wireless device;the GPSI of the wireless device;the KAF of the first network element; orthe expiration time of the KAF.9.The method of claim 4, wherein:the application session is initiated by the wireless device using an access via a Visited Public Land Mobile Network (VPLMN) ;a roaming policy for the wireless device in the VPLMN does not allow the wireless device to use the AKMA service with the first network element; andthe fourth message carries a failure cause indicating that the wireless device is not allowed to use the AKMA service with the first network element based on the roaming policy.10.The method of claim 9, wherein the second message indicates at least one of:a failure to establish the application session; orthe wireless device not being allowed to use the AKMA service with the first network element.11.The method of claim 10, wherein the second message triggers the wireless device to initiate a re-attempt to establish the application session using an access via a PLMN that is different from the VPLMN.12.The method of claim 9, further comprising:storing a failure record associated with the wireless device and the VPLMN; andin response to receiving a subsequent request from the wireless device to establish another application session and the another application session is associated with the VPLMN, rejecting the subsequent request.13.The method of claim 4, wherein transmitting the third message to the second network element comprises:in response to one of:the first network element not having a context associated with the A-KID;the first network element not having a context associated with the PLMN ID; orthe PLMN ID associated with the application session being updated, transmitting the third message to the second network element.14.The method of claim 1, further comprising:transmitting, to a third network element, a subscription request to get a PLMN ID associated with the application session, wherein the first network element subscribes to the third network element via the subscription request to receive a notification on future PLMN ID change.15.The method of claim 14, further comprising:receiving, from the third network element, a response to the subscription request, the response carrying a PLMN ID associated with the application session.16.The method of claim 14, wherein the third network element comprises at least one of:a Policy Control Function (PCF) ; ora Policy and Charging Rules Function (PCRF) .17.The method of any one of claims 1-16, wherein the first network element comprises an Application Function (AF) , and the second network element comprises an AKMA Anchor Function (AAnF) .18.The method of any one of claims 1-16, wherein the wireless device has at least two radio accesses comprising: a first radio access via a Home PLMN (HPLMN) , and a second radio access via a VPLMN.19.The method of any one of claims 1-16, wherein the application session is initiated by  the wireless device using an access via a VPLMN.20.A method for wireless communication, performed by a first network element, comprising:receiving, from a second network element, a first message carrying at least one of:an AKMA (Authentication and Key Management for Applications) key identifier, A-KID, for identifying an AKMA key of a wireless device, wherein the wireless device is in a procedure to establish an application session with the second network element via a Visited Public Land Mobile Network (VPLMN) ;an Application Function identifier (AF_ID) of the second network element; ora PLMN ID of the VPLMN;determining, based on at least one of: the A-KID; or a roaming policy associated with the PLMN ID, whether an AKMA service is allowed for the application session; andtransmitting, from the second network element, a second message as a response to the first message indicating whether the AKMA service is allowed for the application session.21.The method of claim 20, wherein the first message comprises an Naanf_AKMA_ApplicationKey_Get request message, and wherein the second message comprises an Naanf_AKMA_ApplicationKey_Get response message.22.The method of claim 21, wherein:the AKMA service is allowed for the application session; andthe second message carries at least one of:an indication that the wireless device is allowed to use the AKMA service with the second network element;a Subscription Permanent Identifier (SUPI) of the wireless device;a Generic Public Subscription Identifier (GPSI) of the wireless device;an application function key (KAF) of the first network element; oran expiration time of the KAF.23.The method of claim 22, further comprising:in response to the AKMA service being allowed for the application session, deriving the KAF based on the AKMA key of the wireless device.24.The method of claim 20, wherein the AKMA service is allowed for the application session, the method further comprising:receiving, from the second network element, a third message requesting security context for the wireless device, the third message comprising at least one of: the A-KID; or the AF_ID of the second network element;in response to the AKMA service being allowed for the application session, deriving an KAF based on the AKMA key of the wireless device; andtransmitting, to the second network element, a fourth message comprising at least one of:a SUPI of the wireless device;a GPSI of the wireless device;the KAF of the first network element; oran expiration time of the KAF.25.The method of claim 24, wherein the third message comprises an Naanf_AKMA_ApplicationKey_Get request message, and wherein the fourth message comprises an Naanf_AKMA_ApplicationKey_Get response message.26.The method of claim 20, wherein determining whether the AKMA service is allowed for the application session comprises:determining that the AKMA service is not allowed for the application session as the roaming policy associated with the PLMN ID does not allow the AKMA service to be used with the second network element.27.The method of claim 26, wherein:the second message indicates that the AKMA service is not allowed for the application session; andthe second message triggers the second network element to reject the procedure to establish the application session.28.The method of claim 26, wherein the first message comprises an Naanf_AKMA_ApplicationKey_Get request message, and wherein the second message comprises an Naanf_AKMA_ApplicationKey_Get response message.29.The method of any one of claims 20-28, wherein the first network element comprises an AKMA Anchor Function (AAnF) , and wherein the second network element comprises an Application Function (AF) .30.The method of any one of claims 20-28, wherein the wireless device has at least two radio accesses comprising: a first radio access via a Home PLMN (HPLMN) , and a second radio access via the VPLMN.31.The method of any one of claims 20-28, wherein the application session is initiated by the wireless device using an access via a VPLMN.32.A method for wireless communication, performed by a wireless device, comprising:transmitting, to a first network element, a first message for requesting to establish an application session between the wireless device and the first network element, wherein the first message carries an AKMA (Authentication and Key Management for Applications) key identifier, A-KID, for identifying an AKMA key of the wireless device, and wherein the AKMA key is used for authentication and security protection between the wireless device and the first network element, wherein the application session is initiated by the wireless device using an access via a Visited Public Land Mobile Network (VPLMN) ; andreceiving, from the first network element, a second message as a response to the first message indicating whether an AKMA service is allowed for the application session.33.The method of claim 32, wherein:a roaming policy for the wireless device in the VPLMN allows the wireless device to use the AKMA service with the first network element; andreceiving the second message comprises:receiving, from the first network element, the second message as the response to the first message indicating that the AKMA service is allowed for the application session.34.The method of claim 32, wherein:a roaming policy for the wireless device in the VPLMN does not allow the wireless device to use the AKMA service with the first network element; andreceiving the second message comprises:receiving, from the first network element, the second message as the response to the first message indicating that the AKMA service is denied for the application session.35.The method of claim 34, further comprising:in response to receiving the second message, initiating a re-attempt to establish the application session using an access via a PLMN that is different from the VPLMN.36.The method of any one of claims 32-35, wherein the first network element comprises an Application Function (AF) .37.The method of any one of claims 32-35, wherein the wireless device has at least two radio accesses comprising: a first radio access via a Home PLMN (HPLMN) , and a second radio access via the VPLMN.38.The method any one of claims 32-35, wherein the first message comprises an application session establishment request message, and wherein the second message comprises an application session establishment response message.39.A device or a network element comprising a memory for storing computer instructions and a processor in communication with the memory, wherein the processor,  when executing the computer instructions, is configured to implement a method in any one of claims 1-38.40.A computer program product comprising a non-transitory computer-readable program medium with computer code stored thereupon, the computer code, when executed by one or more processors, causing the one or more processors to implement a method of any one of claims 1-38.

Citation Information

Patent Citations

  • Session establishment method and device and communication system

    CN112399412A

  • Key material generation optimization for application authentication and key management

    CN115943651A

  • Method and system of enabling AKMA service in roaming scenario

    US20220210636A1

  • Application key delivery in a roaming situation

    US20230413045A1