Key providing method and apparatus, network function, network device, and medium

Through the first network function, based on the terminal's roaming information and AKMA roaming policy information, the problem that the home network cannot control the AKMA service of the roaming user, is solved, and effective control and legal monitoring of the AKMA service of the roaming user is realized.

WO2025176033A1PCT designated stage Publication Date: 2025-08-28CHINA MOBILE COMM LTD RES INST +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/076636
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-19
Filing Date
2025-02-10
Publication Date
2025-08-28

AI Technical Summary

Technical Problem

In the prior art, the home network cannot effectively control the application layer authentication and key management (AKMA) services for roaming users.

Method used

Through the first network function, it is determined whether to provide AKMA services to the terminal according to the roaming information of the terminal, the AKMA roaming policy information and the instructions of the third network function, and realizes AKMA service control for the roaming user.

Benefits of technology

It realizes effective control of the AKMA service of roaming users, ensuring legal monitoring of the service and compliance with operator policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025076636_28082025_PF_FP_ABST
    Figure CN2025076636_28082025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a key providing method and apparatus, a network function, a network device, and a medium, applied to the technical field of security. The method comprises: upon acquisition of a first request sent by a second network function, on the basis of first information, determining whether an AKMA service can be provided to a terminal, wherein the first request is used for requesting an AKMA application key of the terminal, and the first information comprises one or more of the following: second information, sent by a third network function and used for indicating whether the AKMA service can be provided to the terminal; roaming information of the terminal; and AKMA roaming policy information.
Need to check novelty before this filing date? Find Prior Art

Description

Key providing method, device, network function, network equipment and medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese Patent Application No. 202410185579.7 filed in China on February 19, 2024, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates to the field of application security technology, and in particular to a key provision method, apparatus, network function, network equipment, and medium. Background Art

[0004] Existing application-layer authentication and key management technologies regulate whether the home operator network can provide roaming users with Authentication and Key Management for Applications (AKMA) services. This is determined based on operator policies, service development plans, and lawful interception requirements. However, how to implement home network control over roaming users' AKMA services remains a challenge. Summary of the Invention

[0005] The purpose of the technical solution disclosed in the present invention is to provide a key provision method, device, network function, network equipment and medium, which are used to solve the problem in the related art that the home network cannot realize AKMA service control for roaming users.

[0006] One embodiment of the present disclosure provides a key provision method, wherein the method is applied to a first network function, and the method includes:

[0007] After obtaining a first request sent by a second network function, determining, based on first information, whether an application layer authentication and key management (AKMA) service can be provided for the terminal; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following:

[0008] second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal;

[0009] roaming information of the terminal;

[0010] AKMA roaming policy information.

[0011] Optionally, the key providing method further comprises:

[0012] Acquire the roaming information and / or the AKMA roaming policy information sent by the third network function.

[0013] Optionally, the key providing method further comprises:

[0014] Send a second request to the third network function, where the second request is used to request at least part of the first information.

[0015] Optionally, in the key providing method, the second request includes one or more of the following information:

[0016] a user identifier of the terminal;

[0017] The IP address of the terminal;

[0018] AMF Instance ID corresponding to the terminal access network;

[0019] Public land mobile network (PLMN) identifier of the terminal's service network;

[0020] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0021] The access type of the terminal to the network.

[0022] Optionally, in the key provision method, the roaming information includes one or more of the following information:

[0023] The first indication information is used to indicate that the terminal is in a roaming state;

[0024] The second indication information is used to indicate that the terminal is not in a roaming state;

[0025] Visited location information of the terminal;

[0026] The access type of the terminal to the network.

[0027] Optionally, the key provision method, wherein determining whether application layer authentication and key management (AKMA) services can be provided for the terminal based on the first information, includes:

[0028] In the case where it is determined that the access type of the terminal to the network is the first type, it is determined whether application layer authentication and key management (AKMA) services can be provided for the terminal according to the first information.

[0029] Optionally, in the key providing method, the first type includes one or more of the following:

[0030] 3GPP access;

[0031] Non-3GPP access, and the terminal is not registered with the visited network;

[0032] Non-3GPP access, and the terminal is registered with the visited network but not accessed through the home network AMF.

[0033] Optionally, the key providing method further comprises:

[0034] sending a third request to a fourth network function, where the third request is used to request the access type;

[0035] Receive the third information sent by the fourth network function, wherein the third information includes the access type and / or the AMF Instance ID corresponding to the terminal access network function.

[0036] Optionally, the key providing method further comprises:

[0037] Sending a fourth request to the fifth network function, where the fourth request is used to request obtaining the fourth network function; wherein the fourth request includes the IP address of the terminal.

[0038] Optionally, the key provision method, wherein determining whether application layer authentication and key management (AKMA) services can be provided for the terminal based on the first information, includes:

[0039] Comparing the roaming information of the terminal with the AKMA roaming policy information to determine a roaming policy corresponding to the roaming information of the terminal;

[0040] According to the roaming policy, it is determined whether the application layer authentication and key management (AKMA) service can be provided for the terminal.

[0041] Optionally, the key providing method further comprises:

[0042] Send a first response message to the first request to the second network function, where the first response message is used to indicate whether the AKMA service can be provided for the terminal.

[0043] Optionally, in the key provision method, when it is determined that the AKMA service can be provided for the terminal, the first response message includes one or more of the following information:

[0044] AKMA application key;

[0045] Validity period of the AKMA application key;

[0046] A user permanent identifier (SUPI) of the terminal;

[0047] The universal public user identity (GPSI) of the terminal.

[0048] Optionally, the key providing method further comprises:

[0049] In a case where it is determined that the access type is not the first type, a second response message of the first request is sent to the second network function, where the second response message includes the provided AKMA application key.

[0050] Optionally, the key providing method further comprises:

[0051] Before determining whether the AKMA service can be provided for the terminal according to the first information, the IP address of the terminal is obtained.

[0052] Optionally, the key providing method further comprises:

[0053] Before obtaining the first request, the AKMA roaming policy information is obtained.

[0054] Optionally, in the key provision method, the AKMA roaming policy information includes one or more of the following:

[0055] Roaming-related agreements between the home network and the visited network;

[0056] The AKMA service list information includes a list of first terminals that can provide AKMA services when roaming to a visited network and / or a list of second terminals that cannot provide AKMA services when roaming to a visited network.

[0057] One embodiment of the present disclosure further provides a key provision method, wherein the method is applied to a third network function, and the method includes:

[0058] Sending third information to the first network function, so that the first network function can determine whether it can provide application layer authentication and key management (AKMA) services for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information:

[0059] The second information is used to indicate whether the AKMA service can be provided for the terminal;

[0060] roaming information of the terminal;

[0061] AKMA roaming policy information.

[0062] Optionally, the key providing method further comprises:

[0063] A second request sent by the first network function is received, where the second request is used to request the third information.

[0064] Optionally, in the key providing method, the second request includes one or more of the following information:

[0065] a user identifier of the terminal;

[0066] The IP address of the terminal;

[0067] AMF Instance ID corresponding to the terminal access network;

[0068] Public land mobile network (PLMN) identifier of the terminal's service network;

[0069] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0070] The access type of the terminal to the network.

[0071] Optionally, the key providing method further comprises:

[0072] The second request includes the user identifier and the AMF Instance ID corresponding to the terminal access network function, or when the second request includes the user identifier and the PLMN identifier of the service network of the terminal, determine whether AKMA service can be provided for the terminal according to the second request and the pre-obtained AKMA roaming policy information, and obtain the second information.

[0073] Optionally, in the key provision method, the roaming information includes one or more of the following information:

[0074] The first indication information is used to indicate that the terminal is in a roaming state;

[0075] The second indication information is used to indicate that the terminal is not in a roaming state;

[0076] Visited location information of the terminal;

[0077] The access type of the terminal to the network.

[0078] One embodiment of the present disclosure further provides a network function, wherein the network function is a first network function, including a processor, wherein the processor is configured to:

[0079] After obtaining a first request sent by a second network function, determining, based on first information, whether an application layer authentication and key management (AKMA) service can be provided for the terminal; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following:

[0080] second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal;

[0081] roaming information of the terminal;

[0082] AKMA roaming policy information.

[0083] One embodiment of the present disclosure further provides a network function, wherein the network function is a third network function, which includes a transceiver, and the transceiver is configured to:

[0084] Sending third information to the first network function, so that the first network function can determine whether it can provide application layer authentication and key management (AKMA) services for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information:

[0085] The second information is used to indicate whether the AKMA service can be provided for the terminal;

[0086] roaming information of the terminal;

[0087] AKMA roaming policy information.

[0088] One embodiment of the present disclosure further provides a key providing device, wherein the device is applied to a first network function, and includes:

[0089] A determination module, configured to determine, after obtaining a first request sent by a second network function, whether an application layer authentication and key management AKMA service can be provided for the terminal based on first information; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following:

[0090] second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal;

[0091] roaming information of the terminal;

[0092] AKMA roaming policy information.

[0093] One embodiment of the present disclosure further provides a key providing device, wherein the device is applied to a third network function, and the device includes:

[0094] The first sending module is configured to send third information to the first network function, so that the first network function can determine whether it can provide the application layer authentication and key management (AKMA) service for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information:

[0095] The second information is used to indicate whether the AKMA service can be provided for the terminal;

[0096] roaming information of the terminal;

[0097] AKMA roaming policy information.

[0098] One embodiment of the present disclosure further provides a network device, which includes a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program implements the key providing method as described in any one of the above items when executed by the processor.

[0099] One embodiment of the present disclosure further provides a readable storage medium, wherein the readable storage medium stores a program, and when the program is executed by a processor, the steps in any of the above key providing methods are implemented.

[0100] One embodiment of the present disclosure further provides a computer program product, which includes computer instructions, and when the computer instructions are executed by a processor, the steps in any of the above key providing methods are implemented.

[0101] At least one of the above technical solutions of the present disclosure has the following beneficial effects:

[0102] Using the key provision method described in the embodiment of the present disclosure, the first network function can determine whether the AKMA service can be provided to the terminal based on one or more of the roaming information of the terminal, the AKMA roaming policy information, and the second information sent by the third network function indicating whether the AKMA service can be provided to the terminal, so as to realize AKMA service control for the roaming user. BRIEF DESCRIPTION OF THE DRAWINGS

[0103] FIG1 is a schematic diagram of an AKMA network architecture using one implementation of the key provision method described in an embodiment of the present disclosure;

[0104] FIG2 is a schematic diagram of a process of a key providing method according to a first embodiment of the present disclosure;

[0105] FIG3 is a schematic diagram of a first embodiment of the key providing method according to an embodiment of the present disclosure;

[0106] FIG4 is a schematic diagram of a second embodiment of the key providing method according to an embodiment of the present disclosure;

[0107] FIG5 is a schematic diagram of a third embodiment of the key providing method according to an embodiment of the present disclosure;

[0108] FIG6 is a schematic diagram of a fourth embodiment of the key providing method according to an embodiment of the present disclosure;

[0109] FIG7 is a schematic diagram of a fifth embodiment of the key providing method according to an embodiment of the present disclosure;

[0110] FIG8 is a schematic diagram of a sixth embodiment of the key providing method according to an embodiment of the present disclosure;

[0111] FIG9 is a flow chart of a key providing method according to a second embodiment of the present disclosure;

[0112] FIG10 is a schematic diagram of the structure of the network function according to the first embodiment of the present disclosure;

[0113] FIG11 is a schematic diagram of the structure of the network function according to the second embodiment of the present disclosure;

[0114] FIG12 is a schematic structural diagram of a key providing device according to a first embodiment of the present disclosure;

[0115] FIG13 is a schematic structural diagram of the key providing device according to the second embodiment of the present disclosure. DETAILED DESCRIPTION

[0116] In order to make the technical problems, technical solutions and advantages to be solved by the present disclosure clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.

[0117] The terms "first", "second", etc. in the specification and claims of the present disclosure are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way are interchangeable where appropriate, so that the embodiments of the present disclosure can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.

[0118] FIG1 is a schematic diagram of an AKMA network architecture using one implementation of the key provision method described in an embodiment of the present disclosure.

[0119] Among them, AKMA Anchor Function (AAnF) is an anchor function deployed in the home operator. AAnF stores AKMA anchor keys (K AKMA ), after the User Equipment (UE) successfully completes the fifth generation mobile communication technology (5G) primary authentication, the Authentication Server Function (AUSF) sends the key to the AAnF. The AAnF also generates a key K for use between the UE and the Application Function (AF). AF , and maintain the UE's AKMA context.

[0120] AF with AKMA service can request AKMA application key K from AAnF through AKMA key identifier (A-KID) AF Optionally, AF can obtain K after passing the authentication and authorization of the operator network. AF The AUSF provides the UE's user permanent identifier (SUbscription Permanent Identifier, SUPI) and AKMA key material (A-KID, K AKMA ).

[0121] To solve the problem in the related art that a home network cannot implement AKMA service control for a roaming user, an embodiment of the present disclosure provides a key provision method, in which a first network function can determine whether AKMA service can be provided to a terminal based on one or more of the roaming information of the terminal, AKMA roaming policy information, and second information sent by a third network function indicating whether AKMA service can be provided to the terminal, so as to implement AKMA service control for the roaming user.

[0122] One embodiment of the present disclosure provides a key provision method, which is applied to a first network function. As shown in FIG1 , the method includes:

[0123] S210: After obtaining a first request sent by a second network function, determine, based on first information, whether an application layer authentication and key management (AKMA) service can be provided for the terminal; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following:

[0124] second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal;

[0125] roaming information of the terminal;

[0126] AKMA roaming policy information.

[0127] In the embodiment of the present disclosure, optionally, the first network function includes but is not limited to only being able to include an AKMA anchor function (AKMA Anchor Function, AAnF), the second network function includes but is not limited to only being able to include an application function (Application Function, AF), and the third network function includes but is not limited to only being able to include a unified data management (Unified Data Management, UDM) function.

[0128] Using the key provision method described in the embodiment of the present disclosure, after obtaining the request to obtain the AKMA application key, the AAnF can determine whether the AKMA service can be provided to the terminal based on one or more of the roaming information of the terminal, the AKMA roaming policy information, and the second information sent by the third network function indicating whether the AKMA service can be provided to the terminal, so as to control the AKMA service of the roaming user in the home network.

[0129] In one embodiment of the present disclosure, the roaming information may optionally include one or more of the following information:

[0130] The first indication information is used to indicate that the terminal is in a roaming state;

[0131] The second indication information is used to indicate that the terminal is not in a roaming state;

[0132] Visited location information of the terminal;

[0133] The access type of the terminal to the network.

[0134] Optionally, when the roaming information includes the first indication information, it also includes one or more of the terminal's visited location information and the access type of the terminal accessing the second network function.

[0135] In one embodiment, optionally, the AKMA roaming policy information includes one or more of the following:

[0136] Roaming-related agreements between the home network and the visited network;

[0137] The AKMA service list information includes a list of first terminals that can provide AKMA services when roaming to a visited network and / or a list of second terminals that cannot provide AKMA services when roaming to a visited network.

[0138] In the key provision method described in the embodiments of the present disclosure, in one implementation mode, the first network function determines whether the AKMA service can be provided to the terminal based on the roaming information and AKMA roaming policy information of the terminal. Specifically, the visited network of the terminal can be determined based on the visited location information in the roaming information, and whether the AKMA service can be provided to the terminal can be determined based on the roaming-related agreement between the home network operator and the visited network operator; and / or, the AKMA service list information is queried based on the user identifier and the visited location information in the roaming information to determine whether the AKMA service can be provided to the terminal.

[0139] In one embodiment of the present disclosure, optionally, the method further includes:

[0140] Acquire the roaming information and / or the AKMA roaming policy information sent by the third network function.

[0141] Optionally, the method further includes:

[0142] Send a second request to the third network function, where the second request is used to request at least part of the first information.

[0143] In the embodiment of the present disclosure, the information requested by the second request may be referred to as third information. The third information may be part of the first information, or may be the same as the first information.

[0144] In one embodiment, optionally, the second request includes one or more of the following information:

[0145] a user identifier of the terminal;

[0146] The Internet Protocol (IP) address of the terminal;

[0147] The access and mobility management function (AMF) instance identifier (ID) corresponding to the terminal access network function;

[0148] a Public Land Mobile Network (PLMN) identifier of the terminal's service network;

[0149] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0150] The access type of the terminal to the network.

[0151] Using the method described in the embodiment of the present disclosure, optionally, after the first network function (such as AAnF) obtains the first request sent by the second network function (such as AF), a second request can be sent to the third network function (such as UDM) to request at least part of the first information to obtain information for determining whether AKMA service can be provided for the terminal.

[0152] In one implementation manner, after the first network function (such as AAnF) obtains the first request sent by the second network function (such as AF), it sends a second request to the third network function (such as UDM) to request the roaming information of the terminal.

[0153] In this embodiment, optionally, the method further includes:

[0154] Before obtaining the first request, the AKMA roaming policy information is obtained.

[0155] In one embodiment, optionally, the first network function (e.g., AAnF) may obtain AKMA roaming policy information through network configuration. In another embodiment, optionally, the first network function (e.g., AAnF) may obtain the AKMA roaming policy information from a sixth network function. The sixth network function includes one or more of a UDM and a Policy Control Function (PCF).

[0156] In this embodiment, after receiving a first request from a second network function (e.g., AF), the first network function (e.g., AAnF) sends a second request to a third network function to obtain the terminal's roaming information. Based on the terminal's roaming information provided by the third network function and querying locally stored AKMA roaming policy information, the AAnF determines whether it can provide AKMA services for the terminal. In another embodiment, the AAnF can optionally compare the terminal's roaming information with the AKMA roaming policy information to determine a roaming policy corresponding to the terminal's roaming information; and based on the roaming policy, determine whether it can provide application layer authentication and key management (AKMA) services for the terminal.

[0157] 3 , taking the first network function as AAnF, the second network function as AF, and the third network function as UDM as an example, when the first network function obtains the AKMA roaming policy information in advance through network configuration or by the sixth network function, the specific implementation process of the key provision method described in this embodiment includes the following steps:

[0158] S301, the UE completes the primary authentication and establishes an AKMA context between the UE and the AAnF;

[0159] S302, the UE sends an application session establishment request to the AF. Optionally, the application session establishment request includes an AKMA key identifier A-KID;

[0160] S303: The AF sends a first request to the AAnF, where the first request is used to request an AKMA application key of the terminal. In this embodiment, the first request may also be referred to as a key acquisition request. Optionally, the first request includes an A-KID and an AF identifier AF_ID.

[0161] S304: The AAnF sends a second request to the UDM, where the second request is used to request or subscribe to the terminal's roaming information. In this embodiment, the second request may be referred to as a roaming information acquisition request (e.g., described as EventExposure_Get Request) or a roaming information subscription request (e.g., described as EventExposure_subscribe Request). Optionally, the second request includes a user identifier, such as a SUPI or a Generic Public Subscription Identifier (GPSI).

[0162] S305: The UDM sends a response message to the AAnF for the second request, where the response message includes the roaming information requested by the AAnF. If the second request is a roaming information acquisition request, the response message may be described as EventExposure_Get Response; if the second request is a roaming information subscription request, the response message may be described as EventExposure_subscribe Response. The UDM determines the roaming information corresponding to the terminal based on the user identifier in the second request. The roaming information is used to indicate whether the terminal is in a roaming state, such as indicating that the terminal is in a roaming state through first indication information (such as a first preset value) and indicating that the terminal is not in a roaming state through second indication information (such as a second preset value). If the terminal is in a roaming state, the roaming information also includes visited location information of the terminal (such as a public land mobile network (PLMN) identifier of the updated serving network, new Servingplmn) and / or the access type of the terminal.

[0163] S306, optionally, when the AAnF needs the GPSI of the terminal, sending a fifth request to the UDM for requesting to obtain the GPSI of the terminal; optionally, the fifth request may also be referred to as a GPSI acquisition request;

[0164] S307, UDM returns the response information of the fifth request to AAnF, where the response information includes the GPSI of the terminal;

[0165] It should be noted that, in the embodiment of the present disclosure, step S306 and step S307 may also be located before step S304, that is, before the AAnF sends the roaming information acquisition request to the UDM, it first sends the GPSI acquisition request to the UDM, and after obtaining the GPSI of the terminal, it sends the roaming information acquisition request to the UDM;

[0166] S308: The AAnF queries pre-acquired AKMA roaming policy information based on the obtained roaming information to determine whether the AKMA service can be provided for the terminal. Optionally, the AAnF queries the AKMA roaming policy information based on the visited location information and the user identifier of the terminal in the roaming information. The AKMA roaming policy information records a list of first terminals that can provide AKMA services when roaming to a visited network and / or a list of second terminals that cannot provide AKMA services when roaming to a visited network. That is, the AKMA roaming policy information records whether the AKMA service is allowed to be provided to at least one terminal roaming to the visited network. Therefore, based on the AKMA roaming policy information and the visited location information of the terminal, it can be determined whether the AKMA service can be provided to the corresponding terminal.

[0167] S309: The AAnF sends a first response message to the AF for the first request. Optionally, the first response message is a key request response, used to indicate whether the AKMA service can be provided for the terminal. In one embodiment, if it is determined in step S308 that the AKMA service can be provided for the corresponding terminal, the first response message includes one or more of the following information:

[0168] AKMA application key K AF ;

[0169] Validity period of the AKMA application key;

[0170] A user permanent identifier (SUPI) of the terminal;

[0171] The general public user identity GPSI of the terminal;

[0172] In another embodiment, when it is determined in step S308 that the AKMA service cannot be provided for the corresponding terminal, the first response message includes a denial of service indication information;

[0173] S310, AF returns an application session establishment response to the UE; wherein, when the first response message includes the AKMA application key, the application session establishment response is used to indicate that the UE's application session establishment is successful; when the first response message includes the denial of service indication information, the application session establishment response is used to indicate that the UE's application session establishment has failed.

[0174] In another embodiment of the present disclosure, the first network function (such as AAnF) sends a second request to the third network function (UDM) to request the second information sent by the third network function, that is, to request the UDM to determine whether it can provide AKMA service for the terminal based on the roaming information of the terminal.

[0175] In this implementation, when the first network function (such as AAnF) is not locally configured or has not obtained AKMA roaming policy information in advance, a second request is sent to the UDM to request the UDM to determine whether AKMA service can be provided for the terminal.

[0176] 4 , taking the first network function as AAnF, the second network function as AF, and the third network function as UDM as an example, when the first network function is not locally configured or has not obtained AKMA roaming policy information in advance, the specific implementation process of the key provision method described in this embodiment includes the following steps:

[0177] S401, the UE completes the primary authentication and establishes an AKMA context between the UE and the AAnF;

[0178] S402, the UE sends an application session establishment request to the AF. Optionally, the application session establishment request includes an AKMA key identifier A-KID;

[0179] S403: The AF sends a first request to the AAnF, where the first request is used to request an AKMA application key of the terminal. In this embodiment, the first request may also be referred to as a key acquisition request. Optionally, the first request includes an A-KID and an AF identifier AF_ID.

[0180] S404, the AAnF sends a second request to the UDM, where the second request is used to request or subscribe to second information, that is, to request or subscribe to the UDM to determine whether it can provide the AKMA service for the terminal based on the roaming information of the terminal; in this embodiment, optionally, the second request may also be referred to as a roaming service request message (such as described as AKMA_Roaming Get Request) or a roaming service subscription message (such as described as AKMA_Roaming subscribe Request). Optionally, the second request includes a user identifier, such as a SUPI or GPSI. Optionally, the second request may also include the AMF Instance ID corresponding to the AF and / or the public land mobile network PLMN identifier of the terminal's service network;

[0181] S405, the UDM determines whether the AKMA service can be provided for the terminal according to the user identifier and the AMF Instance ID or the PLMN identifier of the terminal's service network, and according to the pre-acquired AKMA roaming policy information, and obtains the second information;

[0182] S406: The UDM sends a response message to the AAnF for the second request, where the response message includes second information indicating whether to provide the AKMA service for the terminal. If the second request is a roaming service request message, the response message may be described as AKMA_Roaming Get Response; if the second request is a roaming service subscription message, the response message may be described as AKMA_Roaming Subscribe Response.

[0183] S407, optionally, when the AAnF needs the GPSI of the terminal, sending a fifth request to the UDM for requesting to obtain the GPSI of the terminal; optionally, the fifth request may also be referred to as a GPSI acquisition request;

[0184] S408, UDM returns the response information of the fifth request to AAnF, where the response information includes the GPSI of the terminal;

[0185] It should be noted that, in the embodiment of the present disclosure, step S407 and step S408 may also be located before step S404, that is, before the AAnF sends the roaming service request to the UDM, it first sends a GPSI acquisition request to the UDM, and after obtaining the GPSI of the terminal, it sends the roaming service request to the UDM;

[0186] S409, the AAnF determines whether it can provide the AKMA service for the terminal based on the second information obtained in step S406;

[0187] S410: The AAnF sends a first response message to the AF for the first request. Optionally, the first response message is a key request response, used to indicate whether the AKMA service can be provided for the terminal. In one embodiment, if it is determined in step S409 that the AKMA service can be provided for the corresponding terminal, the first response message includes one or more of the following information:

[0188] AKMA application key K AF ;

[0189] Validity period of the AKMA application key;

[0190] A user permanent identifier (SUPI) of the terminal;

[0191] The general public user identity GPSI of the terminal;

[0192] In another embodiment, when it is determined in step S409 that the AKMA service cannot be provided for the corresponding terminal, the first response message includes a denial of service indication information;

[0193] S411, AF returns an application session establishment response to the UE; wherein, when the first response message includes the AKMA application key, the application session establishment response is used to indicate that the UE's application session establishment is successful; when the first response message includes the denial of service indication information, the application session establishment response is used to indicate that the UE's application session establishment has failed.

[0194] In another implementation of the disclosed embodiment, the first network function (such as AAnF) sends a second request to the third network function (UDM) to request the roaming information and AKMA roaming policy information of the terminal.

[0195] In this implementation, when the first network function (such as AAnF) is not locally configured or has not obtained the AKMA roaming policy information in advance, a second request is sent to the UDM to request the terminal's roaming information and AKMA roaming policy information. In this way, AAnF determines whether it can provide AKMA service for the terminal based on the obtained roaming information and AKMA roaming policy information.

[0196] 5 , taking the first network function as AAnF, the second network function as AF, and the third network function as UDM as an example, when the first network function is not locally configured or has not obtained AKMA roaming policy information in advance, the specific implementation process of the key provision method described in this embodiment includes the following steps:

[0197] S501, the UE completes the primary authentication and establishes an AKMA context between the UE and the AAnF;

[0198] S502, the UE sends an application session establishment request to the AF. Optionally, the application session establishment request includes an AKMA key identifier A-KID;

[0199] S503: The AF sends a first request to the AAnF, where the first request is used to request an AKMA application key of the terminal. In this embodiment, the first request may also be referred to as a key acquisition request. Optionally, the first request includes an A-KID and an AF identifier AF_ID.

[0200] S504: The AAnF sends a second request to the UDM, where the second request is used to request or subscribe to roaming information and AKMA roaming policy information. In this embodiment, the second request may optionally be referred to as a roaming information acquisition request (e.g., described as EventExposure_Get Request) or a roaming information subscription request (e.g., described as EventExposure_subscribe Request). Optionally, the second request includes the user identifier of the terminal, such as a SUPI or GPSI. Optionally, the second request may also include a first character indicating a request to obtain the AKMA roaming policy information. For example, the first character is the string "AKMA."

[0201] S505: The UDM sends a response message to the AAnF in response to the second request, where the response message includes the roaming information requested by the AAnF. If the second request is a roaming information acquisition request, the response message may be described as EventExposure_Get Response; if the second request is a roaming information subscription request, the response message may be described as EventExposure_subscribe Response. The UDM determines the roaming information corresponding to the terminal based on the user identifier in the second request. The roaming information is used to indicate whether the terminal is in a roaming state, such as by first indication information (e.g., a first preset value) indicating that the terminal is in a roaming state, and by second indication information (e.g., a second preset value) indicating that the terminal is not in a roaming state. If the terminal is in a roaming state, the roaming information also includes visited location information of the terminal (e.g., a public land mobile network (PLMN) identifier (new Servingplmn) of the updated serving network) and / or the access type of the terminal. In addition, if the terminal is in a roaming state, the response message also includes AKMA roaming policy information.

[0202] S506, optionally, when the AAnF needs the GPSI of the terminal, sending a fifth request to the UDM for requesting to obtain the GPSI of the terminal; optionally, the fifth request may also be referred to as a GPSI acquisition request;

[0203] S507, UDM returns the response information of the fifth request to AAnF, where the response information includes the GPSI of the terminal;

[0204] It should be noted that, in the embodiment of the present disclosure, step S506 and step S507 may also be located before step S504, that is, before the AAnF sends the roaming information acquisition request to the UDM, it first sends the GPSI acquisition request to the UDM, and after obtaining the GPSI of the terminal, it sends the roaming information acquisition request to the UDM;

[0205] S508, AAnF determines whether it can provide AKMA service for the terminal based on the obtained roaming information and AKMA roaming policy information;

[0206] S509: The AAnF sends a first response message to the AF for the first request. Optionally, the first response message is a key request response, used to indicate whether the AKMA service can be provided for the terminal. In one embodiment, if it is determined in step S508 that the AKMA service can be provided for the corresponding terminal, the first response message includes one or more of the following information:

[0207] AKMA application key K AF ;

[0208] Validity period of the AKMA application key;

[0209] A user permanent identifier (SUPI) of the terminal;

[0210] The general public user identity GPSI of the terminal;

[0211] In another embodiment, when it is determined in step S508 that the AKMA service cannot be provided for the corresponding terminal, the first response message includes a denial of service indication information;

[0212] S510, AF returns an application session establishment response to the UE; wherein, when the first response message includes the AKMA application key, the application session establishment response is used to indicate that the UE's application session establishment is successful; when the first response message includes the denial of service indication information, the application session establishment response is used to indicate that the UE's application session establishment has failed.

[0213] In another embodiment of the present disclosure, optionally, in step S210, determining whether application layer authentication and key management (AKMA) services can be provided for the terminal based on the first information includes:

[0214] In the case where it is determined that the access type of the terminal to the network is the first type, it is determined whether application layer authentication and key management (AKMA) services can be provided for the terminal according to the first information.

[0215] The key provision method described in the embodiment of the present disclosure takes into account that the access type of the terminal will affect the roaming policy control of the AKMA service location. By adopting this implementation method, when it is determined that the access type of the terminal is the first type, it is determined based on the first information whether application layer authentication and key management AKMA services can be provided to the terminal to meet the roaming policy control requirements in different application scenarios.

[0216] Optionally, the first type includes one or more of the following:

[0217] 3rd Generation Partnership Project (3GPP) access;

[0218] Non-3GPP access, and the terminal is not registered with the visited network;

[0219] Non-3GPP access, and the terminal is registered with the visited network but not accessed through the home network AMF.

[0220] Using this implementation, taking into account the scenario of dual registration of the terminal, that is, the UE is registered in both 3GPP access and non-3GPP access, the access method used by the UE to access the AF will affect the roaming policy control of the AKMA service home. The key provision method described in the embodiment of the present disclosure performs roaming policy control according to the access type of the terminal in the AF and the roaming information of the terminal to adapt to the dual registration scenario requirements of the terminal.

[0221] Specifically, using this implementation, when it is determined that the access type of the terminal to the second network function is the first type, the first network function determines whether the AKMA service can be provided to the terminal based on one or more of the terminal's roaming information, AKMA roaming policy information, and the second information sent by the third network function indicating whether the AKMA service can be provided to the terminal. When it is determined that the AKMA service can be provided to the terminal, the first network function sends a first response message to the second network function, and the first response message carries the AKMA application key provided for the terminal; when it is determined that the AKMA service cannot be provided to the terminal, the first response message is sent to the second network function, and the first response message indicates that the AKMA service cannot be provided to the terminal; when it is determined that the access type of the terminal to the second network function is not the first type, the determination of whether the application layer authentication and key management AKMA service can be provided to the terminal based on the first information can be skipped, and a second response message is sent to the second network function, and the second response message provides the AKMA application key provided to the terminal.

[0222] In the embodiment of the present disclosure, optionally, the method further includes:

[0223] sending a third request to a fourth network function, where the third request is used to request the access type;

[0224] Receive the third information sent by the fourth network function, wherein the third information includes the access type and / or the AMF Instance ID corresponding to the terminal access network function.

[0225] Optionally, the method further includes:

[0226] Sending a fourth request to the fifth network function, where the fourth request is used to request obtaining the fourth network function; wherein the fourth request includes the IP address of the terminal.

[0227] In one embodiment of the present disclosure, the fourth network function includes but is not limited to only one or more of PCF and Session Management Function (SMF), and the fifth network function includes but is not limited to only Binding Support Function (BSF).

[0228] In an embodiment of the present disclosure, optionally, AAnF obtains the IP address of the terminal before determining whether it can provide AKMA service for the terminal based on the first information; optionally, the IP address of the terminal may be included in the first request sent by the second network function to the first network function, so that the first network function can obtain the IP address of the terminal based on the first request.

[0229] 6 , taking the first network function as AAnF, the second network function as AF, and the third network function as UDM as an example, when the first network function obtains the AKMA roaming policy information in advance through network configuration or by the sixth network function, the specific implementation process of the key provision method described in this embodiment includes the following steps:

[0230] S601, the UE completes the primary authentication and establishes an AKMA context between the UE and the AAnF;

[0231] S602, the UE sends an application session establishment request to the AF. Optionally, the application session establishment request includes an AKMA key identifier A-KID;

[0232] S603: The AF sends a first request to the AAnF, where the first request is used to request an AKMA application key of the terminal. In this embodiment, the first request may optionally be referred to as a key acquisition request. Optionally, the first request includes the A-KID, the AF identifier AF_ID, and the IP address of the terminal.

[0233] S604, the AAnF sends a fourth request to the BSF (fifth network function) to request information of the PCF or SMF (fourth network function) corresponding to the terminal, wherein the fourth request includes the IP address of the terminal;

[0234] S605, the BSF returns a response message of the fourth request to the AAnF, where the response message includes information of the determined PCF or SMF (fourth network function);

[0235] S606, the AAnF sends a third request to the PCF or SMF (fourth network function) to request the access type of the terminal; optionally, the third request includes a user identifier of the terminal;

[0236] S607, the PCF or SMF returns a response message to the third request to the AAnF, where the response message includes the access type of the terminal and / or the AMF Instance ID corresponding to the AF, so that the AAnF can determine the access type of the terminal according to the response message;

[0237] Among them, when the AAnF determines that the access type of the terminal is the first type (such as 3GPP access) according to the response message returned by the PCF or SMF, the following step S608 is performed. The AAnF needs to obtain the roaming information of the terminal and determine whether the AKMA service can be provided for the terminal according to the roaming information and the AKMA roaming policy information; when the AAnF determines that the access type of the terminal is not the first type according to the response message returned by the PCF or SMF, such as when the terminal is Non3gpp access and the terminal is registered with the visited network but accessed through the home network AMF, it is determined that the access type of the terminal is not the first type, then steps S608 and S609 can be skipped;

[0238] S608: The AAnF sends a second request to the UDM, where the second request is used to request the terminal's roaming information. In this embodiment, the second request may be referred to as a roaming information acquisition request (e.g., described as EventExposure_Get Request) or a roaming information subscription request (e.g., described as EventExposure_subscribe Request). Optionally, the second request includes the terminal's user identifier, such as a SUPI or GPSI.

[0239] S609: The UDM sends a response message to the AAnF for the second request, where the response message includes the roaming information requested by the AAnF. If the second request is a roaming information acquisition request, the response message may be described as EventExposure_Get Response; if the second request is a roaming information subscription request, the response message may be described as EventExposure_subscribe Response. The UDM determines the roaming information corresponding to the terminal based on the user identifier of the terminal in the second request. The roaming information is used to indicate whether the terminal is in a roaming state, such as indicating that the terminal is in a roaming state through first indication information (such as a first preset value) and indicating that the terminal is not in a roaming state through second indication information (such as a second preset value). If the terminal is in a roaming state, the roaming information also includes visited location information of the terminal (such as a public land mobile network (PLMN) identifier of the updated serving network, new Servingplmn) and / or the access type of the terminal.

[0240] S610, optionally, when the AAnF needs the GPSI of the terminal, sending a fifth request to the UDM for requesting to obtain the GPSI of the terminal; optionally, the fifth request may also be called a GPSI acquisition request;

[0241] S611, UDM returns the response information of the fifth request to AAnF, where the response information includes the GPSI of the terminal;

[0242] It should be noted that, in the embodiment of the present disclosure, step S610 and step S611 may also be located before step S608, that is, before the AAnF sends the roaming information acquisition request to the UDM, it first sends the GPSI acquisition request to the UDM, and after obtaining the GPSI of the terminal, it sends the roaming information acquisition request to the UDM;

[0243] S612, AAnF queries the pre-acquired AKMA roaming policy information based on the obtained roaming information to determine whether it can provide AKMA service for the terminal;

[0244] S613: The AAnF sends a first response message to the AF for the first request. Optionally, the first response message is a key request response, used to indicate whether the AKMA service can be provided for the terminal. In one embodiment, if it is determined in step S612 that the AKMA service can be provided for the corresponding terminal, or if it is determined in step S607 that the access type of the terminal is not the first type, the first response message includes one or more of the following information:

[0245] AKMA application key K AF ;

[0246] Validity period of the AKMA application key;

[0247] A user permanent identifier (SUPI) of the terminal;

[0248] The general public user identity GPSI of the terminal;

[0249] In another embodiment, when it is determined in step S612 that the AKMA service cannot be provided for the corresponding terminal, the first response message includes a denial of service indication information;

[0250] S614, AF returns an application session establishment response to the UE; wherein, when the first response message includes the AKMA application key, the application session establishment response is used to indicate that the UE's application session establishment is successful; when the first response message includes the denial of service indication information, the application session establishment response is used to indicate that the UE's application session establishment has failed.

[0251] 7 , taking the first network function as AAnF, the second network function as AF, and the third network function as UDM as an example, when the first network function is not locally configured or has not obtained AKMA roaming policy information in advance, the specific implementation process of the key provision method described in this embodiment includes the following steps:

[0252] S701, the UE completes the primary authentication and establishes an AKMA context between the UE and the AAnF;

[0253] S702, the UE sends an application session establishment request to the AF. Optionally, the application session establishment request includes an AKMA key identifier A-KID;

[0254] S703: The AF sends a first request to the AAnF, where the first request is used to request the terminal's AKMA application key. In this embodiment, the first request may also be referred to as a key acquisition request. Optionally, the first request includes the A-KID, the AF identifier AF_ID, and the terminal's IP address.

[0255] S704, the AAnF sends a fourth request to the BSF (fifth network function) to request information of the PCF or SMF (fourth network function) corresponding to the terminal, wherein the fourth request includes the IP address of the terminal;

[0256] S705, the BSF returns a response message of the fourth request to the AAnF, where the response message includes information of the determined PCF or SMF (fourth network function);

[0257] S706, the AAnF sends a third request to the PCF or SMF (fourth network function) to request the access type of the terminal; optionally, the third request includes a user identifier of the terminal;

[0258] S707, the PCF or SMF returns a response message to the third request to the AAnF, where the response message includes the access type of the terminal and / or the AMF Instance ID corresponding to the AF, so that the AAnF can determine the access type of the terminal according to the response message;

[0259] Among them, when the AAnF determines that the access type of the terminal is the first type (such as 3GPP access) according to the response message returned by the PCF or SMF, the following step S708 is performed. The AAnF needs to obtain the roaming information of the terminal and determine whether the AKMA service can be provided for the terminal according to the roaming information and the AKMA roaming policy information; when the AAnF determines that the access type of the terminal is not the first type according to the response message returned by the PCF or SMF, such as when the terminal is Non3gpp access and the terminal is registered with the visited network but accessed through the home network AMF, it is determined that the access type of the terminal is not the first type, then steps S708 and S709 can be skipped;

[0260] S708, AAnF sends a second request to UDM, where the second request is used to request or subscribe to second information, that is, to request or subscribe to UDM to determine whether it can provide AKMA service for the terminal based on the roaming information of the terminal; in this implementation manner, optionally, the second request may also be referred to as a roaming service request message (such as described as AKMA_Roaming Get Request) or a roaming service subscription message (such as described as AKMA_Roaming subscribe Request). Optionally, the second request includes a user identifier, such as SUPI or GPSI. Optionally, the second request may also include the AMF Instance ID corresponding to the AF and / or the public land mobile communication network PLMN identifier of the terminal's service network. Optionally, the second request may also include the access type of the terminal;

[0261] S709: The UDM determines, based on the user identifier and the AMF Instance ID or the PLMN identifier of the terminal's serving network, and the pre-acquired AKMA roaming policy information, the roaming location information corresponding to the access type of the terminal's actual access to the AF, and determines, based on the determined roaming location information, whether the AKMA service can be provided for the terminal, thereby obtaining second information.

[0262] S710: The UDM sends a response message to the AAnF for the second request, where the response message includes second information indicating whether to provide the AKMA service for the terminal. If the second request is a roaming service request message, the response message may be described as AKMA_Roaming Get Response; if the second request is a roaming service subscription message, the response message may be described as AKMA_Roaming Subscribe Response.

[0263] S711, optionally, when the AAnF needs the GPSI of the terminal, sending a fifth request to the UDM for requesting to obtain the GPSI of the terminal; optionally, the fifth request may also be called a GPSI acquisition request;

[0264] S712, the UDM returns a response message of the fifth request to the AAnF, where the response message includes the GPSI of the terminal;

[0265] It should be noted that, in the embodiment of the present disclosure, step S711 and step S712 may also be located before step S708, that is, before the AAnF sends the roaming service request to the UDM, it first sends a GPSI acquisition request to the UDM, and after obtaining the GPSI of the terminal, it sends the roaming service request to the UDM;

[0266] S713, the AAnF determines whether it can provide the AKMA service for the terminal based on the second information obtained in step S710;

[0267] S714: The AAnF sends a first response message to the AF for the first request. Optionally, the first response message is a key request response, used to indicate whether the AKMA service can be provided for the terminal. In one embodiment, if it is determined in step S713 that the AKMA service can be provided for the corresponding terminal, or if it is determined in step S707 that the access type of the terminal is not the first type, the first response message includes one or more of the following information:

[0268] AKMA application key K AF ;

[0269] Validity period of the AKMA application key;

[0270] A user permanent identifier (SUPI) of the terminal;

[0271] The general public user identity GPSI of the terminal;

[0272] In another embodiment, when it is determined in step S713 that the AKMA service cannot be provided for the corresponding terminal, the first response message includes a denial of service indication information;

[0273] S715. The AF returns an application session establishment response to the UE; wherein, when the first response message includes the AKMA application key, the application session establishment response is used to indicate that the UE's application session establishment is successful; when the first response message includes the denial of service indication information, the application session establishment response is used to indicate that the UE's application session establishment has failed.

[0274] 8 , taking the first network function as AAnF, the second network function as AF, and the third network function as UDM as an example, when the first network function is not locally configured or has not obtained AKMA roaming policy information in advance, another implementation of the embodiment of the present disclosure, the specific implementation process of the key provision method includes the following steps:

[0275] S801, the UE completes the primary authentication and establishes an AKMA context between the UE and the AAnF;

[0276] S802, the UE sends an application session establishment request to the AF. Optionally, the application session establishment request includes an AKMA key identifier A-KID;

[0277] S803, the AF sends a first request to the AAnF, where the first request is used to request to obtain the AKMA application key of the terminal; in this embodiment, optionally, the first request may also be referred to as a key acquisition request; optionally, the first request includes the A-KID, the AF identifier AF_ID, and the IP address of the terminal;

[0278] S804, the AAnF sends a fourth request to the BSF (fifth network function) to request information of the PCF or SMF (fourth network function) corresponding to the terminal, wherein the fourth request includes the IP address of the terminal;

[0279] S805, the BSF returns a response message of the fourth request to the AAnF, where the response message includes information of the determined PCF or SMF (fourth network function);

[0280] S806, the AAnF sends a third request to the PCF or SMF (fourth network function) to request the access type of the terminal; optionally, the third request includes a user identifier of the terminal;

[0281] S807, the PCF or SMF returns a response message to the third request to the AAnF, where the response message includes the access type of the terminal and / or the AMF Instance ID corresponding to the AF, so that the AAnF can determine the access type of the terminal according to the response message;

[0282] Among them, when the AAnF determines that the access type of the terminal is the first type (such as 3GPP access) according to the response message returned by the PCF or SMF, the following step S808 is performed. The AAnF needs to obtain the roaming information of the terminal and determine whether the AKMA service can be provided for the terminal according to the roaming information and the AKMA roaming policy information; when the AAnF determines that the access type of the terminal is not the first type according to the response message returned by the PCF or SMF, such as when the terminal is Non3gpp access and the terminal is registered with the visited network but accessed through the home network AMF, it is determined that the access type of the terminal is not the first type, then steps S808 and S809 can be skipped;

[0283] S808: The AAnF sends a second request to the UDM, where the second request is used to request or subscribe to roaming information and AKMA roaming policy information. In this embodiment, the second request may optionally be referred to as a roaming information acquisition request (e.g., described as EventExposure_Get Request) or a roaming information subscription request (e.g., described as EventExposure_subscribe Request). Optionally, the second request includes a user identifier, such as a SUPI or GPSI. Optionally, the second request may also include a first character indicating a request to obtain the AKMA roaming policy information. For example, the first character is the string "AKMA."

[0284] S809: The UDM sends a response message to the AAnF in response to the second request, where the response message includes the roaming information requested by the AAnF. If the second request is a roaming information acquisition request, the response message may be described as EventExposure_Get Response; if the second request is a roaming information subscription request, the response message may be described as EventExposure_subscribe Response. The UDM determines the roaming information corresponding to the terminal based on the user identifier in the second request. The roaming information is used to indicate whether the terminal is in a roaming state, such as by first indication information (e.g., a first preset value) indicating that the terminal is in a roaming state, and by second indication information (e.g., a second preset value) indicating that the terminal is not in a roaming state. If the terminal is in a roaming state, the roaming information also includes visited location information of the terminal (e.g., a public land mobile network (PLMN) identifier (new Servingplmn) of the updated serving network) and / or the access type of the terminal. In addition, if the terminal is in a roaming state, the response message also includes AKMA roaming policy information.

[0285] S810, optionally, when the AAnF needs the GPSI of the terminal, sending a fifth request to the UDM for requesting to obtain the GPSI of the terminal; optionally, the fifth request may also be called a GPSI acquisition request;

[0286] S811, UDM returns the response information of the fifth request to AAnF, where the response information includes the GPSI of the terminal;

[0287] It should be noted that, in the embodiment of the present disclosure, step S810 and step S811 may also be located before step S808, that is, before the AAnF sends the roaming information acquisition request to the UDM, it first sends the GPSI acquisition request to the UDM, and after obtaining the GPSI of the terminal, it sends the roaming information acquisition request to the UDM;

[0288] S812, AAnF determines whether it can provide AKMA service for the terminal based on the obtained roaming information and AKMA roaming policy information;

[0289] S813: The AAnF sends a first response message to the AF for the first request. Optionally, the first response message is a key request response, used to indicate whether the AKMA service can be provided for the terminal. In one embodiment, if it is determined in step S812 that the AKMA service can be provided for the corresponding terminal, or if it is determined in step S807 that the access type of the terminal is not the first type, the first response message includes one or more of the following information:

[0290] AKMA application key K AF ;

[0291] Validity period of the AKMA application key;

[0292] A user permanent identifier (SUPI) of the terminal;

[0293] The general public user identity GPSI of the terminal;

[0294] In another embodiment, when it is determined in step S812 that the AKMA service cannot be provided for the corresponding terminal, the first response message includes a denial of service indication information;

[0295] S814. The AF returns an application session establishment response to the UE; wherein, when the first response message includes the AKMA application key, the application session establishment response is used to indicate that the UE's application session establishment is successful; when the first response message includes the denial of service indication information, the application session establishment response is used to indicate that the UE's application session establishment has failed.

[0296] The key provision method described in the embodiment of the present disclosure performs roaming policy control according to the access type of the terminal in the AF and the roaming information of the terminal, and can adapt to the dual registration scenario requirements of the terminal.

[0297] One embodiment of the present disclosure further provides a key provision method, which is applied to a third network function, as shown in FIG9 , and includes:

[0298] S910: Send third information to the first network function, so that the first network function can determine whether it can provide the application layer authentication and key management (AKMA) service for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information:

[0299] The second information is used to indicate whether the AKMA service can be provided for the terminal;

[0300] roaming information of the terminal;

[0301] AKMA roaming policy information.

[0302] By adopting the key provision method described in the embodiment of the present disclosure, the third information is sent to the first network function through the third network function, so that the first network function can determine whether the AKMA service can be provided for the terminal based on one or more of the roaming information of the terminal, the AKMA roaming policy information, and the second information sent by the third network function indicating whether the AKMA service can be provided for the terminal, thereby realizing AKMA service control for the roaming user.

[0303] Optionally, the key providing method further comprises:

[0304] A second request sent by the first network function is received, where the second request is used to request the third information.

[0305] Optionally, in the key providing method, the second request includes one or more of the following information:

[0306] a user identifier of the terminal;

[0307] The IP address of the terminal;

[0308] AMF Instance ID corresponding to the terminal access network;

[0309] Public land mobile network (PLMN) identifier of the terminal's service network;

[0310] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0311] The access type of the terminal to the network.

[0312] Optionally, the key providing method further comprises:

[0313] The second request includes the user identifier and the AMF Instance ID corresponding to the terminal access network function, or when the second request includes the user identifier and the PLMN identifier of the service network of the terminal, determine whether AKMA service can be provided for the terminal according to the second request and the pre-obtained AKMA roaming policy information, and obtain the second information.

[0314] Optionally, in the key provision method, the roaming information includes one or more of the following information:

[0315] The first indication information is used to indicate that the terminal is in a roaming state;

[0316] The second indication information is used to indicate that the terminal is not in a roaming state;

[0317] Visited location information of the terminal;

[0318] The access type of the terminal to the network.

[0319] For a specific implementation of the key provision method described in the embodiment of the present disclosure when applied to the third network function, please refer to the detailed description of the specific implementation when applied to the first network function in conjunction with Figures 2 to 8, and will not be repeated here.

[0320] One embodiment of the present disclosure further provides a network function, wherein the network function is a first network function. As shown in FIG10 , the first network function 1000 includes a processor 1010 and a transceiver 1020. The processor 1010 is configured to:

[0321] After obtaining a first request sent by a second network function, determining, based on first information, whether an application layer authentication and key management (AKMA) service can be provided for the terminal; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following:

[0322] second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal;

[0323] roaming information of the terminal;

[0324] AKMA roaming policy information.

[0325] Optionally, the network function, wherein the transceiver 1020 is configured to:

[0326] Acquire the roaming information and / or the AKMA roaming policy information sent by the third network function.

[0327] Optionally, the network function, wherein the transceiver 1020 is configured to:

[0328] Send a second request to the third network function, where the second request is used to request at least part of the first information.

[0329] Optionally, in the network function, the second request includes one or more of the following information:

[0330] a user identifier of the terminal;

[0331] The IP address of the terminal;

[0332] AMF Instance ID corresponding to the terminal access network;

[0333] Public land mobile network (PLMN) identifier of the terminal's service network;

[0334] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0335] The access type of the terminal to the network.

[0336] Optionally, in the network function, the roaming information includes one or more of the following information:

[0337] The first indication information is used to indicate that the terminal is in a roaming state;

[0338] The second indication information is used to indicate that the terminal is not in a roaming state;

[0339] Visited location information of the terminal;

[0340] The access type of the terminal to the network.

[0341] Optionally, the network function, wherein the processor 1010 determines, based on the first information, whether it is possible to provide an application layer authentication and key management (AKMA) service for the terminal, includes:

[0342] In the case where it is determined that the access type of the terminal to the network is the first type, it is determined whether application layer authentication and key management (AKMA) services can be provided for the terminal according to the first information.

[0343] Optionally, in the network function, the first type includes one or more of the following:

[0344] 3GPP access;

[0345] Non-3GPP access, and the terminal is not registered with the visited network;

[0346] Non-3GPP access, and the terminal is registered with the visited network but not accessed through the home network AMF.

[0347] Optionally, in the network function, the transceiver 1020 is further configured to:

[0348] sending a third request to a fourth network function, where the third request is used to request the access type;

[0349] Receive the third information sent by the fourth network function, wherein the third information includes the access type and / or the AMF Instance ID corresponding to the terminal access network function.

[0350] Optionally, in the network function, the transceiver 1020 is further configured to:

[0351] Sending a fourth request to the fifth network function, where the fourth request is used to request obtaining the fourth network function; wherein the fourth request includes the IP address of the terminal.

[0352] Optionally, the network function, wherein the processor 1010 determines, based on the first information, whether it is possible to provide an application layer authentication and key management (AKMA) service for the terminal, includes:

[0353] Comparing the roaming information of the terminal with the AKMA roaming policy information to determine a roaming policy corresponding to the roaming information of the terminal;

[0354] According to the roaming policy, it is determined whether the application layer authentication and key management (AKMA) service can be provided for the terminal.

[0355] Optionally, in the network function, the transceiver 1020 is further configured to:

[0356] Send a first response message to the first request to the second network function, where the first response message is used to indicate whether the AKMA service can be provided for the terminal.

[0357] Optionally, in the network function, when it is determined that the AKMA service can be provided for the terminal, the first response message includes one or more of the following information:

[0358] AKMA application key;

[0359] Validity period of the AKMA application key;

[0360] A user permanent identifier (SUPI) of the terminal;

[0361] The universal public user identity (GPSI) of the terminal.

[0362] Optionally, in the network function, the transceiver 1020 is further configured to:

[0363] In a case where it is determined that the access type is not the first type, a second response message of the first request is sent to the second network function, where the second response message includes the provided AKMA application key.

[0364] Optionally, in the network function, the transceiver 1020 is further configured to:

[0365] Before determining whether the AKMA service can be provided for the terminal according to the first information, the IP address of the terminal is obtained.

[0366] Optionally, in the network function, the transceiver 1020 is further configured to:

[0367] Before obtaining the first request, the AKMA roaming policy information is obtained.

[0368] Optionally, in the network function, the AKMA roaming policy information includes one or more of the following:

[0369] Roaming-related agreements between the home network and the visited network;

[0370] The AKMA service list information includes a list of first terminals that can provide AKMA services when roaming to a visited network and / or a list of second terminals that cannot provide AKMA services when roaming to a visited network.

[0371] One embodiment of the present disclosure further provides a network function, wherein the network function is a third network function. As shown in FIG11 , the third network function 1100 includes a transceiver 1110 and a processor 1120. The transceiver 1110 is configured to:

[0372] Sending third information to the first network function, so that the first network function can determine whether it can provide application layer authentication and key management (AKMA) services for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information:

[0373] The second information is used to indicate whether the AKMA service can be provided for the terminal;

[0374] roaming information of the terminal;

[0375] AKMA roaming policy information.

[0376] Optionally, the network function, wherein the transceiver 1110 is further configured to:

[0377] A second request sent by the first network function is received, where the second request is used to request the third information.

[0378] Optionally, the network function, wherein the second request includes one or more of the following information:

[0379] a user identifier of the terminal;

[0380] The IP address of the terminal;

[0381] AMF Instance ID corresponding to the terminal access network;

[0382] Public land mobile network (PLMN) identifier of the terminal's service network;

[0383] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0384] The access type of the terminal to the network.

[0385] Optionally, the network function, wherein the processor 1120 is configured to:

[0386] The second request includes the user identifier and the AMF Instance ID corresponding to the terminal access network function, or when the second request includes the user identifier and the PLMN identifier of the service network of the terminal, determine whether AKMA service can be provided for the terminal according to the second request and the pre-obtained AKMA roaming policy information, and obtain the second information.

[0387] Optionally, the network function, wherein the roaming information includes one or more of the following information:

[0388] The first indication information is used to indicate that the terminal is in a roaming state;

[0389] The second indication information is used to indicate that the terminal is not in a roaming state;

[0390] Visited location information of the terminal;

[0391] The access type of the terminal to the network.

[0392] One embodiment of the present disclosure further provides a key providing device, which is applied to a first network function. As shown in FIG12 , the device includes:

[0393] A determination module 1201 is configured to determine, after obtaining a first request sent by a second network function, whether an application layer authentication and key management (AKMA) service can be provided for the terminal based on first information; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following:

[0394] second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal;

[0395] roaming information of the terminal;

[0396] AKMA roaming policy information.

[0397] Optionally, the key providing device further comprises:

[0398] The first obtaining module 1202 is configured to obtain the roaming information and / or the AKMA roaming policy information sent by the third network function.

[0399] Optionally, the key providing device further comprises:

[0400] The second sending module 1203 is configured to send a second request to the third network function, where the second request is used to request at least part of the first information.

[0401] Optionally, in the key providing device, the second request includes one or more of the following information:

[0402] a user identifier of the terminal;

[0403] The IP address of the terminal;

[0404] AMF Instance ID corresponding to the terminal access network;

[0405] Public land mobile network (PLMN) identifier of the terminal's service network;

[0406] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0407] The access type of the terminal to the network.

[0408] Optionally, in the key providing device, the roaming information includes one or more of the following information:

[0409] The first indication information is used to indicate that the terminal is in a roaming state;

[0410] The second indication information is used to indicate that the terminal is not in a roaming state;

[0411] Visited location information of the terminal;

[0412] An access type of the terminal to the second network function.

[0413] Optionally, in the key providing apparatus, the determining module 1201 determines whether the application layer authentication and key management (AKMA) service can be provided for the terminal according to the first information, including:

[0414] In the case where it is determined that the access type of the terminal to the network is the first type, it is determined whether application layer authentication and key management (AKMA) services can be provided for the terminal according to the first information.

[0415] Optionally, in the key providing device, the first type includes one or more of the following:

[0416] 3GPP access;

[0417] Non-3GPP access, and the terminal is not registered with the visited network;

[0418] Non-3GPP access, and the terminal is registered with the visited network but not accessed through the home network AMF.

[0419] Optionally, the key providing device further comprises:

[0420] A third sending module 1204 is configured to send a third request to a fourth network function, where the third request is used to request the access type;

[0421] The first receiving module 1205 is used to receive the third information sent by the fourth network function, wherein the third information includes the access type and / or the AMF Instance ID corresponding to the terminal access network function.

[0422] Optionally, the key providing device further comprises:

[0423] The fourth sending module 1206 is configured to send a fourth request to the fifth network function, where the fourth request is used to request obtaining the fourth network function; wherein the fourth request includes the IP address of the terminal.

[0424] Optionally, in the key providing apparatus, the determining module 1201 determines whether the application layer authentication and key management (AKMA) service can be provided for the terminal according to the first information, including:

[0425] Comparing the roaming information of the terminal with the AKMA roaming policy information to determine a roaming policy corresponding to the roaming information of the terminal;

[0426] According to the roaming policy, it is determined whether the application layer authentication and key management (AKMA) service can be provided for the terminal.

[0427] Optionally, the key providing device further comprises:

[0428] The fifth sending module 1207 is configured to send a first response message of the first request to the second network function, where the first response message is used to indicate whether the AKMA service can be provided for the terminal.

[0429] Optionally, in the key providing apparatus, when it is determined that the AKMA service can be provided for the terminal, the first response message includes one or more of the following information:

[0430] AKMA application key;

[0431] Validity period of the AKMA application key;

[0432] A user permanent identifier (SUPI) of the terminal;

[0433] The universal public user identity (GPSI) of the terminal.

[0434] Optionally, the key providing device further comprises:

[0435] The sixth sending module 1208 is configured to send a second response message of the first request to the second network function when it is determined that the access type is not the first type, where the second response message includes the provided AKMA application key.

[0436] Optionally, the key providing device further comprises:

[0437] The second obtaining module 1209 is configured to obtain the IP address of the terminal before determining whether the AKMA service can be provided for the terminal according to the first information.

[0438] Optionally, the key providing device further comprises:

[0439] The third obtaining module 1210 is configured to obtain the AKMA roaming policy information before obtaining the first request.

[0440] Optionally, in the key providing device, the AKMA roaming policy information includes one or more of the following:

[0441] Roaming-related agreements between the home network and the visited network;

[0442] The AKMA service list information includes a list of first terminals that can provide AKMA services when roaming to a visited network and / or a list of second terminals that cannot provide AKMA services when roaming to a visited network.

[0443] One embodiment of the present disclosure further provides a key providing device, which is applied to a third network function. As shown in FIG13 , the device includes:

[0444] The first sending module 1301 is configured to send third information to the first network function, so that the first network function can determine whether it can provide the application layer authentication and key management (AKMA) service for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request the AKMA application key of the terminal, and the third information includes one or more of the following information:

[0445] The second information is used to indicate whether the AKMA service can be provided for the terminal;

[0446] roaming information of the terminal;

[0447] AKMA roaming policy information.

[0448] Optionally, the key providing device further comprises:

[0449] The receiving module 1302 is configured to receive a second request sent by the first network function, where the second request is used to request the third information.

[0450] Optionally, in the key providing device, the second request includes one or more of the following information:

[0451] a user identifier of the terminal;

[0452] The IP address of the terminal;

[0453] AMF Instance ID corresponding to the terminal access network;

[0454] Public land mobile network (PLMN) identifier of the terminal's service network;

[0455] The first character is used to indicate a request to obtain the AKMA roaming policy information;

[0456] The access type of the terminal to the network.

[0457] Optionally, the key providing device further comprises:

[0458] Processing module 1303 is used to determine whether AKMA service can be provided for the terminal according to the second request and the pre-obtained AKMA roaming policy information when the second request includes the user identifier and the AMF Instance ID corresponding to the terminal access network function, or when the second request includes the user identifier and the PLMN identifier of the service network of the terminal, and obtain the second information.

[0459] Optionally, in the key providing device, the roaming information includes one or more of the following information:

[0460] The first indication information is used to indicate that the terminal is in a roaming state;

[0461] The second indication information is used to indicate that the terminal is not in a roaming state;

[0462] Visited location information of the terminal;

[0463] The access type of the terminal to the network.

[0464] One embodiment of the present disclosure further provides a network device, which includes a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program implements the key providing method as described in any one of the above items when executed by the processor.

[0465] Among them, the specific implementation method of executing the key providing method by the program running on the processor of the network device can refer to the detailed description of the key providing method when it is applied to the first network function or the second network function, and will not be repeated here.

[0466] In addition, a specific embodiment of the present disclosure further provides a readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the steps in any of the key providing methods described above.

[0467] Specifically, the readable storage medium is applied to the first network function or the second network function mentioned above. When applied to the first network function or the second network function, the execution steps in the corresponding key providing method are described in detail above and will not be repeated here.

[0468] Another embodiment of the present disclosure further provides a computer program product, which includes computer instructions. When the computer instructions are executed by a processor, the steps in any one of the key providing methods described above are implemented.

[0469] Optionally, the embodiments of the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, compact disc read-only memory (CD-ROM), optical storage, etc.) containing computer-usable program code.

[0470] The computer program product described in the embodiment of the present disclosure includes computer instructions that, when executed by a processor, implement the various processes of the key providing method embodiment shown above and can achieve the same technical effect. To avoid repetition, they are not described here.

[0471] In the several embodiments provided in the present disclosure, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection of some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0472] In addition, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, each unit may be physically included separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or hardware plus software functional units.

[0473] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute some steps of the sending and receiving methods described in various embodiments of the present disclosure. The aforementioned storage medium includes: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc., various media that can store program code.

[0474] The above is a preferred embodiment of the present disclosure. It should be pointed out that for ordinary personnel in this technical field, several improvements and modifications can be made without departing from the principles described in the present disclosure. These improvements and modifications should also be regarded as within the scope of protection of the present disclosure.

Claims

1. A key provision method, applied to a first network function, comprising: After obtaining a first request sent by a second network function, determining, based on first information, whether an application layer authentication and key management (AKMA) service can be provided for the terminal; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following: second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal; roaming information of the terminal; AKMA roaming policy information.

2. The key providing method according to claim 1, further comprising: Acquire the roaming information and / or the AKMA roaming policy information sent by the third network function.

3. The key providing method according to claim 1 or 2, further comprising: Send a second request to the third network function, where the second request is used to request at least part of the first information.

4. The key providing method according to claim 3, wherein: The second request includes one or more of the following information: a user identifier of the terminal; The Internet Protocol IP address of the terminal; The access and mobility management function AMF Instance ID corresponding to the terminal access network; Public land mobile network (PLMN) identifier of the terminal's service network; The first character is used to indicate a request to obtain the AKMA roaming policy information; The access type of the terminal to the network. The key providing method according to claim 1 , wherein: The roaming information includes one or more of the following information: The first indication information is used to indicate that the terminal is in a roaming state; The second indication information is used to indicate that the terminal is not in a roaming state; Visited location information of the terminal; The access type of the terminal to the network. The key providing method according to claim 1 , wherein: Determining, based on the first information, whether application layer authentication and key management (AKMA) services can be provided for the terminal includes: In the case where it is determined that the access type of the terminal to the network is the first type, it is determined whether application layer authentication and key management (AKMA) services can be provided for the terminal according to the first information.

7. The key providing method according to claim 6, wherein: The first type includes one or more of the following: 3rd Generation Partnership Project 3GPP access; Non-3GPP access, and the terminal is not registered with the visited network; Non-3GPP access, and the terminal is registered with the visited network but not accessed through the home network AMF.

8. The key providing method according to claim 6, further comprising: sending a third request to a fourth network function, where the third request is used to request the access type; Receive the third information sent by the fourth network function, wherein the third information includes the access type and / or the AMF Instance ID corresponding to the terminal access network function.

9. The key providing method according to claim 8, further comprising: Sending a fourth request to the fifth network function, where the fourth request is used to request obtaining the fourth network function; wherein the fourth request includes the IP address of the terminal.

10. The key providing method according to claim 1, wherein: Determining, based on the first information, whether application layer authentication and key management (AKMA) services can be provided for the terminal includes: Comparing the roaming information of the terminal with the AKMA roaming policy information to determine a roaming policy corresponding to the roaming information of the terminal; According to the roaming policy, it is determined whether the application layer authentication and key management (AKMA) service can be provided for the terminal.

11. The key providing method according to claim 1 , further comprising: Send a first response message to the first request to the second network function, where the first response message is used to indicate whether the AKMA service can be provided for the terminal.

12. The key providing method according to claim 11, wherein: When it is determined that the AKMA service can be provided for the terminal, the first response message includes one or more of the following information: AKMA application key; Validity period of the AKMA application key; A user permanent identifier (SUPI) of the terminal; The universal public user identity (GPSI) of the terminal.

13. The key providing method according to claim 6, further comprising: In a case where it is determined that the access type is not the first type, a second response message of the first request is sent to the second network function, where the second response message includes the provided AKMA application key.

14. The key providing method according to claim 4, further comprising: Before determining whether the AKMA service can be provided for the terminal according to the first information, the IP address of the terminal is obtained.

15. The key providing method according to claim 1, further comprising: Before obtaining the first request, the AKMA roaming policy information is obtained.

16. The key providing method according to claim 1, wherein: The AKMA roaming policy information includes one or more of the following: Roaming-related agreements between the home network and the visited network; The AKMA service list information includes a list of first terminals that can provide AKMA services when roaming to a visited network and / or a list of second terminals that cannot provide AKMA services when roaming to a visited network.

17. A key provision method, applied to a third network function, the method comprising: Sending third information to the first network function, so that the first network function can determine whether it can provide application layer authentication and key management (AKMA) services for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information: The second information is used to indicate whether the AKMA service can be provided for the terminal; roaming information of the terminal; AKMA roaming policy information.

18. The key providing method according to claim 17, further comprising: A second request sent by the first network function is received, where the second request is used to request the third information.

19. The key providing method according to claim 18, wherein: The second request includes one or more of the following information: a user identifier of the terminal; The IP address of the terminal; AMF Instance ID corresponding to the terminal access network; Public land mobile network (PLMN) identifier of the terminal's service network; The first character is used to indicate a request to obtain the AKMA roaming policy information; The access type of the terminal to the network.

20. The key providing method according to claim 19, further comprising: The second request includes the user identifier and the AMF Instance ID corresponding to the terminal access network function, or when the second request includes the user identifier and the PLMN identifier of the service network of the terminal, determine whether AKMA service can be provided for the terminal according to the second request and the pre-obtained AKMA roaming policy information, and obtain the second information.

21. The key providing method according to claim 17, wherein: The roaming information includes one or more of the following information: The first indication information is used to indicate that the terminal is in a roaming state; The second indication information is used to indicate that the terminal is not in a roaming state; Visited location information of the terminal; The access type of the terminal to the network.

22. A network function, the network function being a first network function, comprising a processor, the processor being configured to: After obtaining the first request sent by the second network function, determining whether the application layer authentication and key management AKMA service can be provided for the terminal according to the first information; wherein, The first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following: second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal; roaming information of the terminal; AKMA roaming policy information.

23. A network function, the network function being a third network function, comprising a transceiver, the transceiver being configured to: Sending third information to the first network function, so that the first network function can determine whether it can provide application layer authentication and key management AKMA services for the terminal after obtaining the first request sent by the second network function; wherein, The first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information: The second information is used to indicate whether the AKMA service can be provided for the terminal; roaming information of the terminal; AKMA roaming policy information.

24. A key providing device, applied to a first network function, comprising: A determination module, configured to determine, after obtaining a first request sent by a second network function, whether an application layer authentication and key management AKMA service can be provided for the terminal based on first information; wherein the first request is used to request an AKMA application key of the terminal, and the first information includes one or more of the following: second information, where the second information is sent by a third network function and is used to indicate whether an AKMA service can be provided for the terminal; roaming information of the terminal; AKMA roaming policy information.

25. A key providing device, applied to a third network function, comprising: The first sending module is configured to send third information to the first network function, so that the first network function can determine whether it can provide the application layer authentication and key management (AKMA) service for the terminal after obtaining the first request sent by the second network function; wherein the first request is used to request an AKMA application key of the terminal, and the third information includes one or more of the following information: The second information is used to indicate whether the AKMA service can be provided for the terminal; roaming information of the terminal; AKMA roaming policy information.

26. A network device comprising a processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the key providing method according to any one of claims 1 to 21 is implemented.

27. A readable storage medium having a program stored thereon, wherein when the program is executed by a processor, the steps of the key providing method according to any one of claims 1 to 21 are implemented.

28. A computer program product comprising computer instructions, wherein when the computer instructions are executed by a processor, the steps in the key providing method according to any one of claims 1 to 21 are implemented.

Citation Information

Patent Citations

  • Communication method and device, communication equipment and computer storage medium

    CN117295068A

  • Key management method and device, equipment and storage medium

    CN117413488A

  • Key management method and device, equipment and storage medium

    CN117413553A

  • Key management method and device, equipment and storage medium

    CN117413554A

  • Key providing method and device, network function, network equipment and medium

    CN118803763A