Method and apparatus for terminal authentication in non-3gpp access

The method allows terminals to authenticate efficiently by using simplified authentication processes, reducing delays and signaling in wireless communication systems.

WO2025211950A1PCT designated stage Publication Date: 2025-10-09SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/099820
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-05
Filing Date
2025-03-18
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

In wireless communication systems, terminals that do not support 5GC NAS (AUN3 devices and N5CW) experience delays and additional signaling when reconnecting to a different access point or losing connection, necessitating full primary authentication with the 3GPP core network.

Method used

A method for terminals to efficiently authenticate by receiving capability information on simplified authentication support and transmitting a MAC value based on random values, reducing the need for full primary authentication.

Benefits of technology

Enhances authentication efficiency by minimizing unnecessary signaling and delays for terminals with existing security contexts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025099820_09102025_PF_FP_ABST
    Figure KR2025099820_09102025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a 4G, 5G, or 6G communication system for supporting higher data transfer rates. The present disclosure relates to a method performed by a terminal of a wireless communication system, the method comprising the steps of: receiving a first request message including a first random value and capability information about whether an access and mobility management function (AMF) entity supports authentication simplification; and transmitting a second response message including a first message authentication code (MAC) value based on the first random value, a second random value, and capability information about whether the terminal supports authentication simplification.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for terminal authentication in NON-3GPP ACCESS

[0001] The present disclosure relates to a method and device for efficiently authenticating a terminal in a wireless communication system.

[0002] 5G mobile communication technology defines a wide frequency band to enable fast transmission speeds and new services, and can be implemented not only in the sub-6GHz frequency band such as 3.5 gigahertz (3.5GHz), but also in the ultra-high frequency band called millimeter wave (mmWave) such as 28GHz and 39GHz ('Above 6GHz'). In addition, for 6G mobile communication technology, which is called the system after 5G communication (Beyond 5G), implementation in the terahertz (THz) band (for example, 3 THz band at 95GHz) is being considered to achieve a transmission speed that is 50 times faster than 5G mobile communication technology and an ultra-low latency time that is reduced to one-tenth.

[0003] In the early stages of 5G mobile communication technology, the goal is to support services and satisfy performance requirements for enhanced Mobile Broadband (eMBB), Ultra-Reliable Low-Latency Communications (URLLC), and massive Machine-Type Communications (mMTC). These include beamforming and massive MIMO to mitigate path loss of radio waves in ultra-high frequency bands and increase the transmission distance of radio waves, support for various numerologies (such as operation of multiple subcarrier intervals) and dynamic operation of slot formats for efficient use of ultra-high frequency resources, initial access technology to support multi-beam transmission and wideband, definition and operation of BWP (Bidth Part), new channel coding methods such as LDPC (Low Density Parity Check) codes for large-capacity data transmission and Polar Code for reliable transmission of control information, and L2 pre-processing (L2). Standardization has been made for network slicing, which provides dedicated networks specialized for specific services, and pre-processing.

[0004] Currently, discussions are underway to improve and enhance the initial 5G mobile communication technology in consideration of the services that 5G mobile communication technology was intended to support, and physical layer standardization is in progress for technologies such as V2X (Vehicle-to-Everything) to help autonomous vehicles make driving decisions and increase user convenience based on their own location and status information transmitted by vehicles, NR-U (New Radio Unlicensed) for the purpose of system operation that complies with various regulatory requirements in unlicensed bands, NR terminal low power consumption technology (UE Power Saving), Non-Terrestrial Network (NTN), which is direct terminal-satellite communication to secure coverage in areas where communication with terrestrial networks is impossible, and Positioning.

[0005] In addition, standardization of wireless interface architecture / protocols is in progress for technologies such as intelligent factories (Industrial Internet of Things, IIoT) to support new services through linkage and convergence with other industries, Integrated Access and Backhaul (IAB) that provides nodes for expanding network service areas by integrating wireless backhaul links and access links, Mobility Enhancement technology including Conditional Handover and Dual Active Protocol Stack (DAPS) handover, and 2-step random access (2-step RACH for NR) that simplifies random access procedures. Standardization is also in progress for system architecture / services such as 5G baseline architecture (e.g., Service-based Architecture, Service-based Interface) for grafting Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) that provides services based on the location of the terminal.

[0006] Once these 5G mobile communication systems are commercialized, an explosive increase in connected devices will be connected to the communication network, necessitating enhanced functionality and performance of 5G mobile communication systems and integrated operation of these connected devices. To this end, new research will be conducted on improving 5G performance and reducing complexity, supporting AI services, supporting metaverse services, and drone communications by utilizing eXtended Reality (XR), Artificial Intelligence (AI), and Machine Learning (ML) to efficiently support Augmented Reality (AR), Virtual Reality (VR), and Mixed Reality (MR).

[0007] In addition, the development of these 5G mobile communication systems includes new waveforms to ensure coverage in the terahertz band of 6G mobile communication technology, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), Array Antenna, and Large Scale Antenna, metamaterial-based lenses and antennas to improve the coverage of terahertz band signals, high-dimensional spatial multiplexing technology using Orbital Angular Momentum (OAM), Reconfigurable Intelligent Surface (RIS) technology, as well as full duplex technology to improve the frequency efficiency and system network of 6G mobile communication technology, satellite, AI (Artificial Intelligence) from the design stage and AI-based communication technology that realizes system optimization by internalizing end-to-end AI support functions, and ultra-high-performance communication and computing resources to provide services with complexity that exceeds the limits of terminal computing capabilities. It can serve as a basis for the development of next-generation distributed computing technologies that can be realized by utilizing them.

[0008] In the 5G mobile communication system, various use cases have been defined for authentication by accessing the 3GPP core network via Non-3GPP access. Examples include authentication by a terminal accessing the 3GPP core network via an untrusted Non-3GPP access network, authentication by a terminal accessing the 3GPP core network via a trusted Non-3GPP access network, authentication by a terminal that does not support 5GC NAS (Non-access stratum) by accessing the 3GPP core network via WLAN, authentication by a 5G-RG (Residential Gateway) accessing the 3GPP core network via a wireline access network (W-5GAN), and authentication by a terminal that does not support 5GC NAS by accessing the core network via 5G-RG. In particular, among terminals that do not support 5GC NAS, terminals that use the 3GPP core network via WLAN are defined as N5CW (Non-5G-Capable over WLAN), and terminals that use the 3GPP core network via 5G-RG are defined as AUN3 devices (Authenticable Non-3GPP devices). When connecting to the 3GPP core network via such Non-3GPP access, the authentication process is re-performed even if the terminal and the core network have a security context through the previously performed authentication process.

[0009] Based on the discussion above, the present disclosure aims to solve the following problems. In a wireless communication system, a terminal (AUN3 device, N5CW) that cannot generate NAS messages in non-3GPP access may connect to the 3GPP core network and complete authentication, thereby establishing a shared security context with the core network. If a terminal that already has a security context must connect to a different access point (e.g., 5G-RG, Trusted WLAN Access Point) due to mobility or other reasons, or if the connection to the previously connected access point is lost and the terminal connects to the same access point, full primary authentication is performed. Full primary authentication refers to the process in which an authentication request is transmitted to the AUSF and UDM, the UDM generates an authentication vector, and this value is transmitted to the terminal. The terminal verifies this vector and calculates and transmits a value that can be used to verify the terminal to the network, which then verifies this value and authenticates the terminal. This process may induce additional signaling between the terminal and the 5GC and may cause delays in the terminal connecting to the network.

[0010] The present disclosure may have as its primary purpose a method and device for improving the above-described problem.

[0011] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by a person having ordinary skill in the technical field to which the present invention pertains from the description below.

[0012] Based on the discussion described above, embodiments according to the present disclosure present a method and device for efficiently authenticating a terminal without full primary authentication when the terminal has previously accessed 5GC and has a security context.

[0013] The present disclosure relates to a method performed by a terminal of a wireless communication system, the method comprising: receiving a first request message including capability information on whether an access and mobility management function (AMF) entity supports simplified authentication and a first random value; and transmitting a second response message including a first MAC (message authentication code) value based on the first random value, a second random value, and capability information on whether the terminal supports simplified authentication.

[0014] According to embodiments of the present disclosure, terminal authentication can be performed efficiently.

[0015] The effects that can be obtained from the present disclosure are not limited to the effects mentioned in the various embodiments, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the art to which the present disclosure belongs from the description below.

[0016] FIG. 1A illustrates a communication network including core network entities in a wireless communication system according to various embodiments of the present disclosure.

[0017] FIG. 1b illustrates a wireless environment including a core network in a wireless communication system according to various embodiments of the present disclosure.

[0018] FIG. 2a illustrates an example of a structure of a terminal according to embodiments of the present disclosure.

[0019] FIG. 2b illustrates an example of a structure of a base station according to embodiments of the present disclosure.

[0020] FIG. 2c illustrates an example of the structure of a core network object according to embodiments of the present disclosure.

[0021] FIG. 3 is a diagram illustrating an authentication process of an AUN3 terminal supporting a 5G key hierarchy according to an embodiment of the present disclosure.

[0022] FIG. 4 is a diagram illustrating an authentication process of an AUN3 terminal that does not support 5G key hierarchy according to an embodiment of the present disclosure.

[0023] FIG. 5 is a diagram illustrating an authentication process of an N5CW terminal according to an embodiment of the present disclosure.

[0024] FIG. 6 is a diagram illustrating an authentication process of an AUN3 terminal supporting a 5G key hierarchy according to an embodiment of the present disclosure.

[0025] FIG. 7 is a diagram illustrating an authentication process of an AUN3 terminal that does not support 5G key hierarchy according to an embodiment of the present disclosure.

[0026] FIG. 8 is a diagram illustrating an authentication process of an N5CW terminal according to an embodiment of the present disclosure.

[0027] FIG. 9 is a diagram illustrating a 5G key hierarchy according to an embodiment of the present disclosure.

[0028] The terms used in this disclosure are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include the plural expression unless the context clearly indicates otherwise. Terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art described in this disclosure. Terms defined in general dictionaries among the terms used in this disclosure may be interpreted as having the same or similar meaning in the context of the related technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this disclosure. In some cases, even if a term is defined in this disclosure, it cannot be interpreted to exclude embodiments of the present disclosure.

[0029] The various embodiments of the present disclosure described below illustrate a hardware-based approach as an example. However, since the various embodiments of the present disclosure include techniques utilizing both hardware and software, the various embodiments of the present disclosure do not exclude a software-based approach.

[0030] 3GPP, responsible for cellular mobile communications standards, is standardizing a new core network architecture, dubbed 5G core (5GC), to facilitate the evolution of existing 4G LTE systems into 5G systems. Compared to the evolved packet core (EPC), the network core for existing 4G systems, 5GC supports the following differentiated features:

[0031] First, 5GC introduces network slicing. As a 5G requirement, 5GC must support various terminal types and services (e.g., eMBB, URLLC, or mMTC services). Each type of service has different requirements for the core network. For example, eMBB services require high data rates, while URLLC services require high reliability and low latency. One technology proposed to meet these diverse service requirements is network slicing.

[0032] Network slicing virtualizes a single physical network to create multiple logical networks. Each network slice instance (NSI) can have different characteristics. Therefore, each NSI can satisfy diverse service requirements by possessing a network function (NF) tailored to its characteristics. If each terminal is assigned an NSI that matches the characteristics of the service it requires, multiple 5G services can be efficiently supported.

[0033] Second, 5GC can facilitate support for the network virtualization paradigm by separating mobility management and session management functions. In 4G LTE (long term evolution), services were provided through signaling exchanges with a single core device called the mobility management entity (MME), which was responsible for registration, authentication, mobility management, and session management for all terminals. However, in 5G, the number of terminals increases explosively, and the mobility and traffic / session characteristics that must be supported for each terminal type become more specialized. Therefore, supporting all functions with a single device like the MME inevitably reduces scalability by adding entities for each required function. Therefore, various functions are being developed based on a structure that separates mobility management and session management functions to improve scalability in terms of functional / implementation complexity and signaling load of the core device responsible for the control plane.

[0034] Hereinafter, various embodiments will be described in detail with reference to the attached drawings. Furthermore, when describing embodiments of the present disclosure, detailed descriptions of related known functions or configurations will be omitted if they are deemed to unnecessarily obscure the gist of the embodiments. Furthermore, the terms described below are defined based on their functions in the embodiments, and may vary depending on the intent or custom of the user or operator. Therefore, their definitions should be based on the contents throughout this specification.

[0035] For the same reason, some components in the attached drawings are exaggerated, omitted, or schematically depicted. Furthermore, the dimensions of each component do not entirely reflect its actual size. Identical or corresponding components in each drawing are assigned the same reference numbers.

[0036] The advantages and features of the present disclosure, and methods for achieving them, will become clearer with reference to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms. These embodiments are provided solely to ensure that the present disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Like reference numerals designate like elements throughout the specification.

[0037] At this time, it will be understood that each block of the processing flowchart drawings and combinations of the flowchart drawings can be performed by computer program instructions. These computer program instructions can be installed in a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, so that the instructions executed by the processor of the computer or other programmable data processing equipment create a means for performing the functions described in the flowchart block(s). These computer program instructions can also be stored in a computer-available or computer-readable memory that can direct a computer or other programmable data processing equipment to implement the functions in a specific manner, so that the instructions stored in the computer-available or computer-readable memory can also produce a manufactured item that includes an instruction means for performing the functions described in the flowchart block(s). Since the computer program instructions may be installed on a computer or other programmable data processing device, a series of operational steps may be performed on the computer or other programmable data processing device to create a computer-executable process, and the instructions that cause the computer or other programmable data processing device to perform the steps for performing the functions described in the flowchart block(s) may also provide steps for performing the functions described in the flowchart block(s).

[0038] Additionally, each block may represent a module, segment, or portion of code that contains one or more executable instructions for performing a specific logical function(s). It should also be noted that in some alternative implementation examples, the functions described in the blocks may occur out of order. For example, two blocks depicted in succession may actually be executed substantially concurrently, or the blocks may sometimes be executed in reverse order, depending on their respective functions.

[0039] Here, the term '~ unit' used in various embodiments of the present disclosure means a software or hardware component such as an FPGA or ASIC, and the '~ unit' can perform certain roles. However, the '~ unit' is not limited to software or hardware. The '~ unit' may be configured to be on an addressable storage medium and may be configured to play one or more processors. Accordingly, as an example, the '~ unit' may include components such as software components, object-oriented software components, class components, and task components, processes, functions, properties, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and '~ units' may be combined into a smaller number of components and '~ units' or further separated into additional components and '~ units'. Additionally, components and '~parts' may be implemented to regenerate one or more CPUs within a device or secure multimedia card.

[0040] Hereinafter, a base station is an entity that performs resource allocation of a terminal, and may be at least one of an eNode B (eNB), a Node B, a BS (base station), a RAN (radio access network), an AN (access network), a RAN node, a NR NB, a gNB, a wireless access unit, a base station controller, or a node on a network. The terminal may include a user equipment (UE), a mobile station (MS), a cellular phone, a smartphone, a computer, or a multimedia system capable of performing a communication function. In various embodiments of the present disclosure, a case where the terminal is a UE will be described as an example. In addition, although various embodiments of the present disclosure are described below using a system based on LTE, LTE-A, or NR as an example, various embodiments of the present disclosure may be applied to other communication systems having a similar technical background or channel type. In addition, various embodiments of the present disclosure may be applied to other communication systems with some modifications within a range that does not significantly depart from the scope thereof at the discretion of a person having skilled technical knowledge.

[0041] The terms used in the following description to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, terms referring to various identification information, etc. are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects with equivalent technical meanings may be used.

[0042] Additionally, while this disclosure describes various embodiments using terminology used in certain communication standards (e.g., 3rd Generation Partnership Project (3GPP)), these are merely illustrative examples. The various embodiments of this disclosure can be easily modified and applied to other communication systems. Below, some terms used in the core network of this disclosure are predefined.

[0043] AMF access and mobility management function

[0044] CN core network

[0045] CNF containerized network function

[0046] DNN data network name

[0047] PCF policy control function

[0048] HSS home subscriber server

[0049] SMF session management function

[0050] UDM user data management

[0051] UPF user plane function

[0052] CNF containerized network function

[0053] VNF virtual network function

[0054] FIG. 1A illustrates a communication network including core network entities in a wireless communication system according to embodiments of the present disclosure. A 5G mobile communication network may be configured to include a 5G user equipment (UE) (110), a 5G radio access network (RAN) (120), and a 5G core network.

[0055] The 5G core network may be configured to include network functions such as an access and mobility management function (AMF) (150) that provides a mobility management function of UE, a session management function (SMF) (160) that provides a session management function, a user plane function (UPF) (170) that performs a data transfer role, a policy control function (PCF) (180) that provides a policy control function, a unified data management (UDM) (153) that provides a data management function such as subscriber data and policy control data, or a unified data repository (UDR) that stores data of various network functions.

[0056] Referring to FIG. 1A, a user equipment (UE) (110) may communicate with a base station (e.g., an eNB, a gNB) via a wireless channel, i.e., an access network. In some embodiments, the UE (110) may be a device used by a user and configured to provide a user interface (UI). As an example, the UE (110) may be a terminal mounted (equipment) on a vehicle for driving. In other embodiments, the UE (110) may be a device that performs machine type communication (MTC) that operates without user intervention, or may be an autonomous vehicle. UE may be referred to as a 'terminal', 'vehicle terminal', 'user equipment (UE)', 'mobile station', 'subscriber station', 'remote terminal', 'wireless terminal', or 'user device' or other terms having equivalent technical meanings, other than electronic devices. As the terminal, in addition to the UE, a customer-premises equipment (CPE) or a dongle-type terminal may be used. The CPE, while connected to the NG-RAN node like the UE, may also provide a network to other communication devices (e.g., a laptop).

[0057] Referring to FIG. 1A, the AMF (150) provides a function for connection and mobility management per terminal (110), and basically, one AMF (150) can be connected to one terminal (110). Specifically, the AMF (150) can perform at least one of signaling between core network nodes for mobility between 3GPP access networks, an interface (N2 interface) between wireless access networks (e.g., 5G RAN) (120), NAS signaling with the terminal (110), identification of the SMF (160), and provision of transmission of session management (SM) messages between the terminal (110) and the SMF (160). Some or all of the functions of the AMF (150) can be supported within a single instance of one AMF (150).

[0058] Referring to FIG. 1A, the SMF (160) provides a session management function, and when the terminal (110) has multiple sessions, each session may be managed by a different SMF (160). Specifically, the SMF (160) may perform at least one of the following functions: session management (e.g., session establishment, modification, and release, including tunnel maintenance between the UPF (170) and the access network node), selection and control of UP (user plane) functions, traffic steering setup for routing traffic to an appropriate destination in the UPF (170), termination of the SM portion of NAS messages, downlink data notification (DDN), and initiation of AN-specific SM information (e.g., delivery to the access network via the N2 interface via the AMF (150)). Some or all of the functions of the SMF (160) may be supported within a single instance of one SMF (160).

[0059] In the 3GPP system, conceptual links connecting NFs within a 5G system may be referred to as reference points. Reference points may also be referred to as interfaces. The following exemplifies reference points (hereafter, interchangeably referred to as interfaces) included in the 5G system architecture represented throughout various embodiments of the present disclosure.

[0060] - N1: Reference point between UE (110) and AMF (150)

[0061] - N2: Reference point between (R)AN(120) and AMF(150)

[0062] - N3: Reference point between (R)AN(120) and UPF(170)

[0063] - N4: Reference point between SMF (160) and UPF (170)

[0064] - N5: Reference point between PCF (180) and AF (130)

[0065] - N6: Reference point between UPF (170) and DN (140)

[0066] - N7: Reference point between SMF (160) and PCF (180)

[0067] - N8: Reference point between UDM (153) and AMF (150)

[0068] - N9: Reference point between two core UPFs (170)

[0069] - N10: Reference point between UDM (153) and SMF (160)

[0070] - N11: Reference point between AMF (150) and SMF (160)

[0071] - N12: Reference point between AMF (150) and authentication server function (AUSF) (151)

[0072] - N13: Reference point between UDM (153) and authentication server function (151)

[0073] - N14: Reference point between two AMFs (150)

[0074] - N15: For non-roaming scenarios, reference point between PCF (180) and AMF (150), for roaming scenarios, reference point between PCF (180) and AMF (150) within the visited network.

[0075] FIG. 1B illustrates a wireless environment including a core network in a wireless communication system according to embodiments of the present disclosure. Referring to FIG. 1B, the wireless communication system may include a radio access network (RAN) (120) and a core network (CN).

[0076] The wireless access network (120) is a network that is directly connected to a user device, for example, a terminal (110), and is an infrastructure that provides wireless access to the terminal (110). The wireless access network (120) includes a set of a plurality of base stations including a base station (125), and the plurality of base stations can communicate through interfaces formed between each other. At least some of the interfaces between the plurality of base stations can be wired or wireless. The base station (125) can have a structure that is divided into a central unit (CU) and a distributed unit (DU). In this case, one CU can control a plurality of DUs. The base station (125) can be referred to as an 'access point (AP)', 'next generation node B (gNB)', '5th generation node (5G node)', 'wireless point', 'transmission / reception point (TRP)', or other terms having an equivalent technical meaning thereto in addition to the base station. The terminal (110) can connect to a wireless access network (120) and communicate with a base station (125) via a wireless channel. The terminal (110) may be referred to as a 'user equipment (UE)', a 'mobile station', a 'subscriber station', a 'remote terminal', a 'wireless terminal', a 'user device', or other terms having an equivalent technical meaning.

[0077] The core network is a network that manages the entire system, controls the wireless access network (120), and can process data and control signals for terminals (110) transmitted and received through the wireless access network (120). The core network performs various functions, such as controlling the user plane and control plane, processing mobility, managing subscriber information, billing, and interworking with other types of systems (e.g., long term evolution (LTE) system). In order to perform the various functions described above, the core network may include a number of functionally separated entities having different network functions (NFs). For example, the core network (200) may include an access and mobility management function (AMF) (150), a session management function (SMF) (160), a user plane function (UPF) (170), a policy and charging function (PCF) (180), a network repository function (NRF) (159), a unified data management (UDM) (153), a network exposure function (NEF) (155), and a unified data repository (UDR) (157).

[0078] The terminal (110) can be connected to the AMF (150) that performs the mobility management function of the core network by being connected to the wireless access network (120). The AMF (150) may be a function or device that is in charge of both the connection to the wireless access network (120) and the mobility management of the terminal (110). The SMF (160) is an NF that manages sessions. The AMF (150) is connected to the SMF (160), and the AMF (150) can route session-related messages for the terminal (110) to the SMF (160). The SMF (160) is connected to the UPF (170) to allocate user plane resources to be provided to the terminal (110), and establishes a tunnel for transmitting data between the base station (125) and the UPF (170). PCF (180) can control information related to policy and charging for the session used by the terminal (110).

[0079] The NRF (159) can store information about NFs installed in a mobile communication service provider network and perform a function of notifying the stored information. The NRF (159) can be connected to all NFs. When each NF starts operating in the service provider network, it can notify the NRF (159) that the NF is operating within the network by registering with the NRF (159). The UDM (153) is an NF that performs a role similar to the HSS (home subscriber server) of a 4G network, and can store subscription information of the terminal (110) or the context used by the terminal (110) within the network.

[0080] The NEF (155) may connect a third-party server and an NF within a 5G mobile communication system. It may also provide data to, update, or acquire data from the UDR (157). The UDR (157) may store subscription information of the terminal (110), policy information, data exposed externally, or information required by a third-party application. Furthermore, the UDR (157) may also provide stored data to other NFs.

[0081] FIG. 2A illustrates an example of the functional structure of a terminal according to embodiments of the present disclosure. The configuration illustrated in FIG. 2A can be understood as the configuration of a terminal (110). Terms such as "... unit" and "... device" used hereinafter refer to a unit that processes at least one function or operation, which can be implemented using hardware, software, or a combination of hardware and software.

[0082] Referring to FIG. 2a, the terminal may include a communication unit (205), a storage unit (210), and a control unit (215).

[0083] The communication unit (205) can perform functions for transmitting and receiving signals via a wireless channel. For example, the communication unit (205) can perform a conversion function between a baseband signal and a bit stream according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (205) can generate complex symbols by encoding and modulating a transmission bit stream. In addition, when receiving data, the communication unit (205) can restore a reception bit stream by demodulating and decoding the baseband signal. In addition, the communication unit (205) upconverts a baseband signal to an RF band signal and transmits it through an antenna, and downconverts an RF band signal received through the antenna to a baseband signal. For example, the communication unit (205) can include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC, an ADC, etc.

[0084] In addition, the communication unit (205) may include a plurality of transmit / receive paths. Furthermore, the communication unit (205) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (205) may be composed of digital circuits and analog circuits (e.g., radio frequency integrated circuits (RFIC)). Here, the digital circuits and analog circuits may be implemented in a single package. In addition, the communication unit (205) may include a plurality of RF chains. Furthermore, the communication unit (205) may perform beamforming.

[0085] The communication unit (205) can transmit and receive signals as described above. Accordingly, all or part of the communication unit (205) may be referred to as a "transmitter," a "receiver," or a "transmitting and receiving unit." Furthermore, in the following description, transmission and reception performed via a wireless channel may be used to mean that processing as described above is performed by the communication unit (205).

[0086] The storage unit (210) can store data such as basic programs, application programs, and setting information for the operation of the terminal. The storage unit (210) can be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (210) can provide stored data upon request from the control unit (215).

[0087] The control unit (215) can control the overall operations of the terminal. For example, the control unit (215) can transmit and receive signals through the communication unit (205). In addition, the control unit (215) can record and read data in the storage unit (210). In addition, the control unit (215) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (215) may include at least one processor or microprocessor, or may be a part of a processor. In addition, a part of the communication unit (205) and the control unit (215) may be referred to as a CP (communication processor). According to various embodiments, the control unit (215) can control to perform synchronization using a wireless communication network. For example, the control unit (215) can control the terminal to perform operations according to various embodiments described below.

[0088] According to various embodiments of the present disclosure, a terminal may be composed of a mobile equipment (ME) and a universal mobile telecommunications service (UMTS) subscriber identity module (USIM). The ME may include a mobile terminal (MT) and terminal equipment (TE). The MT may be a part where a wireless access protocol operates, and the TE may be a part where a control function operates. For example, in the case of a wireless communication terminal (e.g., a mobile phone), the MT and the TE may be integrated, and in the case of a laptop, the MT and the TE may be separated. The present disclosure may express the ME and the USIM as distinct entities depending on the operation of each component, but is not limited thereto, and may express the ME and the USIM as a terminal (e.g., UE) including the ME, or it is of course possible to describe various embodiments of the present disclosure by expressing the ME as a terminal.

[0089] FIG. 2B illustrates an example of the functional structure of a base station according to embodiments of the present disclosure. The configuration illustrated in FIG. 2B can be understood as the configuration of a base station (120). Terms such as "... unit" and "... unit" used hereinafter refer to a unit that processes at least one function or operation, which can be implemented using hardware, software, or a combination of hardware and software.

[0090] Referring to FIG. 2b, the base station may include a wireless communication unit (235), a backhaul communication unit (220), a storage unit (225), and a control unit (230).

[0091] The wireless communication unit (235) can perform functions for transmitting and receiving signals via a wireless channel. For example, the wireless communication unit (235) can perform a conversion function between baseband signals and bit streams according to the physical layer specifications of the system. For example, when transmitting data, the wireless communication unit (235) can generate complex symbols by encoding and modulating the transmitted bit stream. Furthermore, when receiving data, the wireless communication unit (235) can restore the received bit stream by demodulating and decoding the baseband signal.

[0092] In addition, the wireless communication unit (235) can upconvert a baseband signal into an RF (radio frequency) band signal and transmit it through an antenna, and downconvert an RF band signal received through the antenna into a baseband signal. To this end, the wireless communication unit (235) can include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a digital to analog convertor (DAC), an analog to digital convertor (ADC), etc. In addition, the wireless communication unit (235) can include a plurality of transmission and reception paths. Furthermore, the wireless communication unit (235) can include at least one antenna array composed of a plurality of antenna elements.

[0093] In terms of hardware, the wireless communication unit (235) may be composed of a digital unit and an analog unit, and the analog unit may be composed of a plurality of sub-units depending on operating power, operating frequency, etc. The digital unit may be implemented with at least one processor (e.g., a digital signal processor (DSP)).

[0094] The wireless communication unit (235) can transmit and receive signals as described above. Accordingly, all or part of the wireless communication unit (235) may be referred to as a "transmitter," a "receiver," or a "transceiver." Furthermore, in the following description, transmission and reception performed via a wireless channel may be used to mean that the wireless communication unit (235) performs the processing described above.

[0095] The backhaul communication unit (220) can provide an interface for performing communication with other nodes within the network. That is, the backhaul communication unit (220) can convert a bit string transmitted from a base station to another node, such as another access node, another base station, an upper node, a core network, etc., into a physical signal, and can convert a physical signal received from another node into a bit string.

[0096] The storage unit (225) can store data such as basic programs, application programs, and setting information for the operation of the base station. The storage unit (225) can be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (225) can provide stored data upon request from the control unit (230).

[0097] The control unit (230) can control the overall operations of the base station. For example, the control unit (230) can transmit and receive signals through the wireless communication unit (235) or the backhaul communication unit (220). In addition, the control unit (230) can record and read data in the storage unit (225). In addition, the control unit (230) can perform the functions of the protocol stack required by the communication standard. According to another implementation example, the protocol stack can be included in the wireless communication unit (235). For this purpose, the control unit (230) can include at least one processor. According to various embodiments, the control unit (230) can control to perform synchronization using a wireless communication network. For example, the control unit (230) can control the base station to perform operations according to various embodiments described below.

[0098] FIG. 2C illustrates an example of the functional structure of a core network object according to embodiments of the present disclosure. It may represent the configuration of a core network object in a wireless communication system according to various embodiments of the present disclosure. The configuration illustrated in FIG. 2C may be understood as a configuration of a device having the function of at least one of the network entities including the AMF (150) of FIG. 1. Terms such as "... unit" and "... device" used hereinafter mean a unit that processes at least one function or operation, and this may be implemented by hardware, software, or a combination of hardware and software.

[0099] Referring to the above drawing 2c, the core network object can be configured to include a communication unit (240), a storage unit (245), and a control unit (250).

[0100] The communication unit (240) may provide an interface for performing communication with other devices within the network. That is, the communication unit (240) may convert a bit string transmitted from a core network object to another device into a physical signal, and may convert a physical signal received from another device into a bit string. That is, the communication unit (240) may transmit and receive signals. Accordingly, the communication unit (240) may be referred to as a modem, a transmitter, a receiver, or a transceiver. In this case, the communication unit (240) may enable the core network object to communicate with other devices or systems via a backhaul connection (e.g., a wired backhaul or a wireless backhaul) or via a network.

[0101] The storage unit (245) can store data such as basic programs, application programs, and setting information for the operation of core network objects. The storage unit (245) can be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. In addition, the storage unit (245) can provide stored data upon request from the control unit (250).

[0102] The control unit (250) can control the overall operations of the core network object. For example, the control unit (250) can transmit and receive signals through the communication unit (240). In addition, the control unit (250) can record and read data in the storage unit (245). For this purpose, the control unit (250) can include at least one processor. According to various embodiments of the present disclosure, the control unit (250) can control synchronization using a wireless communication network. For example, the control unit (250) can control the core network object to perform operations according to various embodiments described below.

[0103] The terms used in the following description to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, and terms referring to various identification information are provided as examples for convenience of explanation. Therefore, the present disclosure is not limited to the terms described below, and other terms referring to objects with equivalent technical meanings may be used.

[0104] For convenience of explanation, this disclosure uses terms and names defined in the 5GS (5G system) and NR (new radio) standards, the most recent standards defined by the 3GPP organization among the existing communication standards. However, this disclosure is not limited to these terms and names and can be equally applied to wireless communication networks conforming to other standards. In particular, this disclosure can be applied to 3GPP 5th generation mobile communication standards (e.g., 5GS and NR).

[0105] FIG. 3 is a diagram illustrating an authentication process of an AUN3 terminal supporting a 5G key hierarchy according to an embodiment of the present disclosure.

[0106] According to FIG. 3, 5G-RG can learn whether AMF supports new functions during the process of connecting to 5GC.

[0107] At step 301, the AUN3 terminal and 5G-RG can establish an 802.11 connection.

[0108] In step 302, the 5G-RG may send an EAP-ID request to the AUN3 terminal. This message includes the Challenge message generated by the 5G-RG. 5G-RG (e.g. nonce, random number, etc.) or may contain at least one indicator indicating whether AMF supports the new feature, or that information may be included in a separate message.

[0109] In step 303, the AUN3 terminal can send an EAP-ID response to the 5G-RG. The AUN3 terminal can send an EAP-ID response to the 5G-RG. AMF or K AMF Subkeys generated from, or Challenge 5G-RG , or Challenge AMF MAC using at least one of AUN3 can also generate a value. For example, the AUN3 terminal can generate a value using a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions). In this case, the key is K AMF or K AMF is a subkey generated from , and the input value is Challenge 5G-RG or Challenge AMF It can be. Some values ​​(e.g. most significant 128bits, lease significant 128bits, etc.) or all values ​​in the generated values ​​are MAC AUN3 It can be used as AUN3 terminal Challenge AMF Using MAC AUN3 In case of generating, it may be the case that there is a value received from AMF after previously connecting to 5GC and completing authentication. If 5G-GUTI or Challenge is received from AMF AMF If you have received, AUN3 terminal is 5G-GUTI or Challenge AMF to K AMF It can be stored as a security context with the AUN3 terminal. The AUN3 terminal sends the MAC address to the EAP-ID response message. AUN3 , Challenge AUN3(e.g., a random value generated by the AUN3 terminal), 5G-GUTI, and an indicator indicating whether the AUN3 terminal supports a new function, and this information can be sent using a separate message. The AUN3 terminal may be configured to support MAC AUN3 , or Challenge AUN3 , or sending 5G-GUTI could serve as an indicator that AUN3 supports new features.

[0110] In step 304, the 5G-RG may generate a registration request message on behalf of the AUN3 terminal. The registration request message includes SUCI, AUN3 indicator, 5G-GUTI, and Challenge. AUN3 , Challenge 5G-RG , MAC AUN3 , may include at least one of the indicators indicating whether the AUN3 terminal supports the new feature.

[0111] At step 305, if AMF is MAC AUN3 , Challenge AUN3 , Challenge 5G-RG , if at least one of the AUN3 capabilities is received, the AMF can know whether the AUN3 terminal supports the new capability. The AMF can AUN3 After calculating using the same method as the AUN3 terminal, the sameness can be verified. If the verification is successful, steps 306-318 may not be performed.

[0112] AMF is K AMF or K AMF Subkeys generated from Challenge AUN3 , or Challenge 5G-RG MAC using at least one of AMF can be created.

[0113] In step 306, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include at least one of SUCI, SN-Name (Serving Network name), and AUN3 indicator (an indicator indicating that the terminal is an AUN3 terminal).

[0114] In step 307, the AUSF may send a Nudm_UEAuthentication_GetRequest message to the UDM. This message may include information received from the AMF in step 306.

[0115] In step 308, after selecting an authentication method, UDM can generate an authentication vector (AV) that can authenticate the terminal.

[0116] In step 309, the UDM may send a Nudm_UEAuthentication_Get Response message to the AUSF. This message may include at least one of SUPI, EAP-AKA', and AV.

[0117] In step 310, the AUSF may send a Nausf_UEAuthentication_AuthenticationResponse message to the AMF. This message may include an AKA challenge.

[0118] In step 311, the AMF may send an authentication request message to the 5G-RG. This message may include the value received from the AUSF in step 310.

[0119] In step 312, the 5G-RG may transmit an L2 message to AUN3. This message may include the value received from the AMF in step 311.

[0120] In step 313, the AUN3 terminal can authenticate the network by verifying the AV. If verification is successful, the AUN3 terminal can also calculate an Auth response to receive authentication from the network.

[0121] In step 314, the AUN3 terminal can transmit the value generated in step 313 to 5G-RG as an L2 message.

[0122] In step 315, the 5G-RG can send the value received in step 314 to the AMF as an authentication response message.

[0123] In step 316, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include the value received in step 315.

[0124] At step 317, AUSF can authenticate the AUN3 terminal by verifying the Auth response.

[0125] In step 318, the AUSF can send an authentication response to the AMF if the verification in step 317 is successful. This message is K SEAF , may contain at least one of SUPI, and AMF may contain K SEAF Using K AMF can also be created.

[0126] At step 319, AMF is K AMF From K WAGF can be created.

[0127] If steps 306-318 are not omitted, AMF uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key used is K AMF, and the input value is 0x6E, Uplink NAS COUNT (i.e., 0), the length of uplink NAS COUNT (i.e., 0x00 0x04), Access type distinguisher (i.e., 0x02), or the length of Access type distinguisher (i.e., 0x00 0x01). WAGF can be created.

[0128] If steps 306-318 are omitted, AMF can use horizontal key derivation (e.g., horizontal key derivation can be a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key used is the current K AMF , input values ​​are 0x72, DIRECTION, length of DIRECTION, COUNT (e.g. 0), length of COUNT, Challenge AUN3 , Challenge AUN3 Length of Challenge AMF , or Challenge AMF A new K generated using at least one of the lengths of AMF Using K WAGF can be generated. AMF uses a function (for example, HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions) and the key used is a K generated using horizontal key derivation. AMF, input value is 0x6E, Uplink NAS COUNT (i.e., 0), length of uplink NAS COUNT (i.e., 0x00 0x04), Access type distinguisher (i.e., 0x02), or length of Access type distinguisher (i.e., 0x00 0x01). WAGF can be created.

[0129] Or if steps 306-318 are omitted, AMF will be the existing K AMF Using the new K WAGF can be generated. For example, AMF uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions) and the key used is an existing K AMF , input value is 0x6E, Uplink NAS COUNT (i.e. 0), length of uplink NAS COUNT (i.e. 0x00 0x04), Access type distinguisher (i.e. 0x02), length of Access type distinguisher (i.e. 0x00 0x01), Challenge AUN3 , Challenge AUN3 Length of Challenge AMF , Challenge AMF A new K using at least one of the lengths of WAGF can be created.

[0130] AMF is a Challenge AMF or K AMF may be stored as part of the security context.

[0131] At step 320, the AMF may send an Authentication Result message to the 5G-RG. This message may be K WAGF , MAC AMF , K AMFchange indicator (AMF is the existing K AMF Using horizontal key derivation, a new K AMF If you create (K) WAGF change indicator (AMF is the existing K AMF Wow Challenge AUN3 Or Challenge AMF Using the new K WAGF ), Challenge AMF , an indicator indicating that AMF supports the new feature, or may include at least one of 5G-GUTI.

[0132] At step 321, the 5G-RG can send an L2 message to the AUN3 terminal. This message includes a MAC AMF , K AMF change indicator, K WAGF change indicator, 5G-GUTI, challenge AMF , or may include at least one indicator indicating that AMF supports the new feature.

[0133] At step 322, if the AUN3 terminal is MAC AMF , K AMF change indicator, K WAGF change indicator, challenge AMF , if the AUN3 terminal has received at least one of the indicators indicating whether the AMF supports the new function, and 5G-GUTI, the AUN3 terminal can determine whether the AMF supports the new function. The AUN3 terminal uses the same method performed by the AMF in step 305 to perform MAC AMF AMF can be authenticated by calculating the indicator (K) received by the AUN3 terminal. AMF change indicator or K WAGF Depending on the change indicator, or ChallengeAMF If the AMF knows that the new key is obtained through reception, the AUN3 terminal uses the same method performed by the AMF in step 319 to obtain the K WAGF can be generated. The AUN3 terminal is a Challenge AMF , K AMF , AMF capability, or 5G-GUTI may be stored as a security context.

[0134] If the AUN3 terminal did not receive the above information, use the same method as before to K AMF , K WAGF can be created.

[0135] At step 323, the AUN3 terminal and 5G-RG are K WAGF WLAN keys can be generated using PMK (Pairwise Master Key).

[0136] At step 324, the AUN3 terminal and 5G-RG can create WLAN security.

[0137] FIG. 4 is a diagram illustrating an authentication process of an AUN3 terminal that does not support 5G key hierarchy according to an embodiment of the present disclosure.

[0138] According to FIG. 4, 5G-RG may learn whether AMF supports new functions during the process of connecting to 5GC.

[0139] At step 401, the AUN3 terminal and 5G-RG can establish an 802.11 connection.

[0140] In step 402, the 5G-RG may send an EAP-ID request. This message contains the Challenge Receiver generated by the 5G-RG. 5G-RG (e.g. nonce, random number, etc.) or may contain at least one indicator indicating whether AMF supports the new feature, or may be included in a separate message.

[0141] In step 403, the AUN3 terminal can send an EAP-ID response to the 5G-RG. The AUN3 terminal may send an MSK (Master Session Key), a subkey generated from the MSK, or a Challenge 5G-RG , or Challenge AMF MAC using at least one of AUN3 can also be generated. For example, the AUN3 terminal can generate a value using a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions). In this case, the key is MSK (part or all) or a subkey generated from MSK (part or all), and the input value is Challenge. 5G-RG or Challenge AMF It can be. Some values ​​(e.g. most significant 128bits, lease significant 128bits, etc.) or all values ​​in the generated values ​​are MAC AUN3 It can be used as AUN3 terminal Challenge AMF Using MAC AUN3 In case of generating, it may be the case that there is a value received from AMF after previously connecting to 5GC and completing authentication. If 5G-GUTI or Challenge is received from AMF AMF If you have received, AUN3 terminal is 5G-GUTI or Challenge AMF can be stored as a security context with MSK. The AUN3 terminal may include MAC address in the EAP-ID response message. AUN3 , Challenge AUN3(e.g., a random value generated by the AUN3 terminal), 5G-GUTI, or an indicator indicating whether the AUN3 terminal supports a new feature, or this information may be sent using a separate message. The AUN3 terminal may include MAC AUN3 , or Challenge AUN3 , or sending 5G-GUTI could serve as an indicator that AUN3 supports new features.

[0142] In step 404, the 5G-RG may generate a registration request message on behalf of the AUN3 terminal. The registration request message includes SUCI, AUN3 indicator, 5G-GUTI, and Challenge. AUN3 , Challenge 5G-RG , MAC AUN3 , or may include at least one indicator indicating whether the AUN3 terminal supports the new feature.

[0143] At step 405, if AMF is MAC AUN3 , Challenge AUN3 , Challenge 5G-RG , or at least one of the AUN3 capabilities, the AMF can know whether the AUN3 terminal supports the new capability. The AMF can AUN3 After calculating using the same method as the AUN3 terminal, the same can be verified. If the verification is successful, steps 406 to 418 below may not be performed. AMF is an MSK, or a subkey generated from an MSK, or a Challenge AUN3 , or Challenge 5G-RG MAC using at least one of AMF can also be created.

[0144] In step 406, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include at least one of SUCI, SN-Name (Serving Network name), and AUN3 indicator (an indicator indicating that the terminal is an AUN3 terminal).

[0145] In step 407, the AUSF may send a Nudm_UEAuthentication_GetRequest message to the UDM. This message may include the information received from the AMF in step 406.

[0146] In step 408, after selecting an authentication method, UDM can generate an authentication vector (AV) that can authenticate the terminal.

[0147] In step 409, the UDM may send a Nudm_UEAuthentication_Get Response message to the AUSF. This message may contain at least one of SUPI, EAP-AKA', and AV.

[0148] In step 410, the AUSF may send a Nausf_UEAuthentication_AuthenticationResponse message to the AMF. This message may include an AKA challenge.

[0149] In step 411, the AMF may send an authentication request message to the 5G-RG. This message may include the value received from the AUSF in step 410.

[0150] At step 412, the 5G-RG may transmit an L2 message to AUN3. This message may include the value received from the AMF at step 11.

[0151] In step 413, the AUN3 terminal can authenticate the network by verifying the AV. If verification is successful, the AUN3 terminal can calculate an Auth response to receive authentication from the network.

[0152] In step 414, the AUN3 terminal can transmit the value generated in step 413 to the 5G-RG as an L2 message.

[0153] In step 415, the 5G-RG can send the value received in step 414 to the AMF as an authentication response message.

[0154] In step 416, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include the value received in step 415.

[0155] At step 417, AUSF can authenticate the AUN3 terminal by verifying the Auth response.

[0156] In step 418, the AUSF can send an authentication response to the AMF if the verification in step 417 is successful. This message is K SEAF , may contain at least one of SUPI, and AMF may contain K SEAF Using K AMF can also be created.

[0157] At step 419, the AMF can generate a new MSK or PMK from the MSK.

[0158] If steps 406-418 are not omitted, the AMF may transmit the MSK itself to the 5G-RG. Alternatively, if the AMF learns that the AUN3 terminal supports a new feature, it may transmit the MSK and the Challenge AUN3 or Challenge AMF You can also generate a new key using at least one of them.

[0159] For example, AMF uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), the key uses the most significant 256 bits of the MSK, and the input value is the Challenge. AMF , Challenge AMF Length of Challenge AUN3 , or Challenge AUN3 A value is generated using at least one of the lengths of , and the generated value can be used as MSK or PMK. Alternatively, AMF uses a function such as HMAC-SHA256, the key uses the least significant 256 bits of MSK, and the input value is Challenge. AMF , Challenge AMF Length of Challenge AUN3 , Challenge AUN3 A value generated using at least one of the lengths of can be used as the MSK or PMK. Alternatively, a value concatenated with the two values ​​mentioned above can be used as the MSK or PMK. If a value concatenated with the two values ​​is used as the MSK, a PMK, which is a subkey, can be generated from the MSK. In one embodiment, the AMF generates the MSK and the Challenge AUN3 or Challenge AMF Here is an example of generating a new key using at least one of:

[0160] The PRF' function is defined as follows:

[0161] PRF'(K(part or all of MSK), S(Challenge AUN3 |Challenge AMF )) = T1 | T2 | T3 | …

[0162] Here, T1, T2 and T3 can be calculated as follows.

[0163] T1 = HMAC-SHA256(K, S | 0x01)

[0164] T2 = HMAC-SHA256(K, T1 | S | 0x02)

[0165] T3 = HMAC-SHA256(K, T2 | S | 0x03)

[0166] The new key can be a portion of the result of the PRF function (for example, a total of 512 bits from bit 640 to bit 1151 of the result).

[0167] If steps 406-418 are omitted, the AMF can generate a key (MSK or PMK) to be used by the 5G-RG or W-AGF and AUN3 terminal using the MSK stored in the security context. For example, the AMF uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), the key uses the most significant 256 bits of the MSK, and the input value is the Challenge. AMF , Challenge AMF Length of Challenge AUN3 , or Challenge AUN3 A value is generated using at least one of the lengths of , and the generated value can be used as MSK or PMK. Alternatively, AMF uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), the key uses the least significant 256 bits of MSK, and the input value is Challenge. AMF , Challenge AMF Length of Challenge AUN3 , Challenge AUN3A value is generated using at least one of the lengths, and the generated value can be used as an MSK or PMK. Alternatively, a value obtained by concatenating the two values ​​mentioned above can be used as an MSK or PMK. If the value is used as an MSK, a PMK, which is a subkey, can be generated from the MSK.

[0168] As an example, AMF and MSK Challenge AUN3 or Challenge AMF Here is an example of generating a new key using at least one of:

[0169] The PRF' function is defined as follows:

[0170] PRF'(K(part or all of MSK), S(Challenge AUN3 |Challenge AMF )) = T1 | T2 | T3 | …

[0171] Here, T1, T2 and T3 can be calculated as follows.

[0172] T1 = HMAC-SHA256(K, S | 0x01)

[0173] T2 = HMAC-SHA256(K, T1 | S | 0x02)

[0174] T3 = HMAC-SHA256(K, T2 | S | 0x03)

[0175] The new key can be a portion of the result of the PRF function (for example, a total of 512 bits from bit 640 to bit 1151 of the result).

[0176] AMF is a Challenge AMF Alternatively, you may be storing the MSK as part of the security context.

[0177] At step 420, the AMF can send an Authentication Result message to the 5G-RG. This message includes MSK and MAC AMF, New key derivation indicator (indicates that a subkey should be generated and used with 5G-RG or W-AGF rather than using the MSK received from AUSF as PMK, or Challenge AMF (Sending a Challenge can replace that directive) AMF , may contain at least one of an indicator indicating whether AMF supports the new feature, a 5G-GUTI, or a PMK (if a subkey is generated from the MSK).

[0178] At step 421, the 5G-RG can send an L2 message to the AUN3 terminal. This message includes a MAC AMF , New key derivation indicator, 5G-GUTI, Challenge AMF , or may include at least one indicator indicating that AMF supports the new feature.

[0179] At step 422, if the AUN3 terminal is MAC AMF , New key derivation indicator, Challenge AMF , an indicator indicating that the AMF supports the new feature, or at least one of 5G-GUTI, the AUN3 terminal can determine whether the AMF supports the new feature. The AUN3 terminal uses the same method performed by the AMF in step 405 to determine whether the AMF supports the new feature. AMF AMF can be authenticated by calculating the AUN3 terminal when it receives a New key derivation indicator or a Challenge AMF If the AMF knows that it generates a subkey from the MSK by receiving the challenge, the AUN3 terminal can generate the MSK or PMK using the same method that the AMF performed in step 419. The AUN3 terminal AMF, MSK, AMF capability, or 5G-GUTI may be stored as security context.

[0180] If the AUN3 terminal has not received the above-mentioned information, it can generate an MSK using the same method as before and use it as a PMK.

[0181] At step 423, the AUN3 terminal and 5G-RG are K WAGF WLAN keys can be generated using PMK (Pairwise Master Key).

[0182] At step 424, the AUN3 terminal and 5G-RG can create WLAN security.

[0183] FIG. 5 is a diagram illustrating an authentication process of an N5CW terminal according to an embodiment of the present disclosure.

[0184] According to Figure 5, a Trusted WLAN Access point or TWIF may know whether AMF supports new features.

[0185] In step 501, EAP (Extensible Authentication Protocol)-based authentication is initiated between the N5CW terminal and the Trusted WLAN Access Point.

[0186] In step 502a, the Trusted WLAN Access Point can send an EAP-ID request to the N5CW terminal. This message contains a Challenge message generated by the Trusted WLAN Access Network. TWAN (e.g., nonce, random number, etc.), or may include at least one indicator indicating whether AMF supports the new feature, and that information may be included in a separate message.

[0187] In step 502b, the N5CW terminal can send an EAP-ID response to the Trusted WLAN Access Point. The N5CW terminal can send an EAP-ID response to the Trusted WLAN Access Point. AMF or K AMF Subkeys generated from Challenge TWAN , or Challenge AMF MAC using at least one of N5CW can generate. For example, the N5CW terminal uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key is K AMF or K AMF Uses a subkey generated from , and the input value is Challenge 5G-RG or Challenge AMF You can use it to generate values, and some or all of the generated values ​​(e.g. most significant 128bits, lease significant 128bits, etc.) are MAC N5CW It can be used as a Challenge N5CW terminal AMF Using MAC N5CW In case of generating, it may be the case that there is a value received from AMF after previously connecting to 5GC and completing authentication. If 5G-GUTI or Challenge is received from AMF AMF If you have received, the N5CW terminal is 5G-GUTI or Challenge AMF to K AMF It can be stored as a security context with the N5CW terminal. The N5CW terminal sends the MAC address to the EAP-ID response message. N5CW , Challenge N5CW(e.g., a random value generated by the N5CW terminal), 5G-GUTI, or an indicator indicating whether the N5CW terminal supports a new feature, or this information may be sent using a separate message. The N5CW terminal may send the MAC address. N5CW or Challenge N5CW Sending a can serve as an indicator that N5CW supports the new feature.

[0188] In step 502c, the Trusted WLAN Access Point receives some or all of the values ​​received in step 502b, or the Challenge TWAP At least one of them may be transmitted to TWIF.

[0189] In step 503, the TWIF may generate a registration request message on behalf of the N5CW terminal. The registration request message includes SUCI or 5G-GUTI, requested NSSAI (Network Slice Selection Assistance Information), 5GC capability, and Challenge. TWAN , Challenge N5CW , MAC N5CW , or may include at least one indicator indicating whether the N5CW terminal supports the new feature.

[0190] At step 504a, TWIF may select AMF.

[0191] In step 504b, TWIF may forward to AMF at least one of the registration request message generated in step 503, or the user location, or the AN (Access Network) type.

[0192] At step 505, if AMF is MAC N5CW , Challenge TWAN , Challenge N5CW, or at least one of the N5CW capabilities, the AMF can know whether the N5CW terminal supports the new capability. The AMF can N5CW After calculating using the same method as the N5CW terminal, it can be verified whether it is the same. If the verification is successful, steps 506-509 below may not be performed. AMF is K AMF or K AMF Subkeys generated from Challenge N5CW , or Challenge TWAN MAC using at least one of AMF can be created.

[0193] AMF is K AMF , K AMF Subkeys generated from Challenge N5CW , or Challenge TWAN MAC using at least one of AMF can be created.

[0194] In step 506, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include at least one of SUCI, SN-Name (Serving Network name), and N5CW indicator (an indicator indicating that the terminal is an N5CW terminal).

[0195] In step 507, the AUSF may send a Nudm_UEAuthentication_GetRequest message to the UDM. This message may include information received from the AMF in step 506.

[0196] In step 508, after selecting an authentication method, UDM can generate an authentication vector (AV) that can authenticate the terminal.

[0197] At step 509, an authentication process may be performed between the network and the N5CW terminal.

[0198] At step 510, AMF is K AMF From K TWIF can be created.

[0199] If steps 506-509 are not omitted, AMF uses, for example, a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key used is K AMF , and the input value is 0x6E, Uplink NAS COUNT (i.e., 0), the length of uplink NAS COUNT (i.e., 0x00 0x04), Access type distinguisher (i.e., 0x02), or the length of Access type distinguisher (i.e., 0x00 0x01). TWIF can be created.

[0200] If steps 506-509 are omitted, AMF can use horizontal key derivation (e.g., horizontal key derivation can be a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key used is the current K AMF , input values ​​are 0x72, DIRECTION, length of DIRECTION, COUNT (e.g. 0), length of COUNT, Challenge N5CW , Challenge N5CW Length of Challenge AMF , Challenge AMF A new K generated using at least one of the lengths of AMF Using K TWIFcan be generated. For example, AMF uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions) and the key used is a K generated using horizontal key derivation. AMF , and the input value is 0x6E, Uplink NAS COUNT (i.e., 0), the length of uplink NAS COUNT (i.e., 0x00 0x04), Access type distinguisher (i.e., 0x02), or the length of Access type distinguisher (i.e., 0x00 0x01). TWIF can be created.

[0201] Or if steps 506-509 are omitted, AMF will be the existing K AMF Using the new K TWIF can be generated. For example, AMF uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions) and the key used is an existing K AMF , and the input value is 0x6E, Uplink NAS COUNT (i.e., 0), length of uplink NAS COUNT (i.e., 0x00 0x04), Access type distinguisher (i.e., 0x02), length of Access type distinguisher (i.e., 0x00 0x01), Challenge N5CW , Challenge N5CW Length of Challenge AMF , or Challenge AMF A new K using at least one of the lengths of TWIF can be created.

[0202] AMF is a Challenge AMF or KAMF may be stored as part of the security context.

[0203] In step 511a, AMF may send a NAS Security Mode Command message to TWIF with EAP Success.

[0204] At step 511c, TWIF may store the EAP-success message.

[0205] At step 511d, TWIF may send a NAS Security Mode Complete message to AMF.

[0206] At step 512, AMF may send an N2 Initial context setup request message to TWIF. This message may be K TWIF , an indicator indicating whether AMF supports new features, New key derivation indicator(K TWIF (indicates that a new method should be used when generating) MAC AMF , or Challenge AMF May include at least one of:

[0207] At step 513a, TWIF receives K from AMF. TWIF From K TNAP can be created.

[0208] K TNAP Regarding how to generate it, the function can be used HMAC-SHA256, etc., and the input key is K TWIF , the input value can be at least one of 0x84, a usage type distinguisher (i.e., 0x02), or the length of the usage type distinguisher (i.e., 0x00 0x01). K TNAP can be used as PMK.

[0209] In step 513b, the TWIF can send an AAA message to the Trusted WLAN Access Point. This message contains EAP-Success, PMK, an indicator indicating whether the AMF supports a new feature, a New key derivation indicator, and MAC. AMF , or Challenge AMF May include at least one of:

[0210] In step 513c, the Trusted WLAN Access Point can send an EAP-Success message to the N5CW. This message includes an indicator indicating whether AMF supports the new feature, a New key derivation indicator, and a MAC AMF , or Challenge AMF It may include at least one of:

[0211] At step 514a, if the N5CW terminal has MAC AMF , New key derivation indicator, challenge AMF , or at least one of the indicators indicating that the AMF supports the new feature, the N5CW terminal can determine whether the AMF supports the new feature. The N5CW terminal uses the same method performed by the AMF in step 505 to determine whether the AMF supports the new feature. AMF AMF can be authenticated by calculating the N5CW terminal when it receives a New key derivation indicator or a Challenge AMF AMF has received a new K AMF If it is known that the subkey is generated from the N5CW terminal, it uses the same method that the AMF performed in step 510 to generate the K AMF From K TWIF can be generated. In addition, K can be generated using the same method performed by TWIF in step 513a. TWIF From KTNAP can be generated and used as PMK. N5CW terminal can be Challenge AMF , K AMF , AMF capability, or 5G-GUTI may be stored as a security context.

[0212] At step 514b, the N5CW terminal and the Trusted WLAN Access Point are K TNAP WLAN keys can be generated using PMK (Pairwise Master Key).

[0213] At step 514c, the N5CW terminal and the Trusted WLAN Access Point can create WLAN security.

[0214] At step 514d, a L2 or L3 connection may be created between the Trusted WLAN Access Point and the TWIF. This may be to send user plane traffic of the N5CW terminal to the TWIF.

[0215] At step 515, TWIF may send an N2 Initial Context Setup Response message to AMF.

[0216] FIG. 6 is a diagram illustrating an authentication process of an AUN3 terminal supporting a 5G key hierarchy according to an embodiment of the present disclosure.

[0217] At step 601, the AUN3 terminal and 5G-RG can establish an 802.11 connection.

[0218] In step 602, the 5G-RG may send an EAP-ID request to the AUN3 terminal. This message includes the Challenge message generated by the 5G-RG. 5G-RG(e.g., nonce, random number, etc.), or an indicator indicating whether 5G-RG supports a new feature, or an indicator indicating whether W-AGF supports a new feature, and such information may be included in a separate message.

[0219] In step 603, the AUN3 terminal can send an EAP-ID response to the 5G-RG. The AUN3 terminal can send an EAP-ID response to the 5G-RG. WAGF , K WAGF Subkeys generated from Challenge 5G-RG , or Challenge WAGF MAC using at least one of AUN3 can also be generated. For example, the AUN3 terminal uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key is K WAGF or K WAGF Use the subkey generated from and the input value is Challenge 5G-RG or Challenge WAGF You can use MAC to generate values, and some or all of the generated values ​​(e.g. most significant 128bits, lease significant 128bits, etc.) AUN3 It can also be used as a Challenge AUN3 terminal WAGF Using MAC AUN3 In case of generating, it may be the case that there is a value received from W-AGF after previously connecting to 5GC and completing authentication. If a new ID is received from W-AGF (an ID created by W-AGF, which may include information that can identify W-AGF, such as the address of W-AGF, or may be information used by W-AGF to find the security context of the corresponding AUN3 terminal), or ChallengeWAGF If you have received, the AUN3 terminal will be given a new ID or Challenge WAGF to K TWIF It can be stored as a security context with the AUN3 terminal. The AUN3 terminal sends the MAC address to the EAP-ID response message. AUN3 , Challenge AUN3 (e.g., a random value generated by the AUN3 terminal), a new ID, an indicator indicating whether the AUN3 terminal supports a new feature, and this information can be sent using a separate message. The AUN3 terminal can send the MAC address. AUN3 , Challenge AUN3 , or sending a new ID could serve as an indicator that AUN3 supports the new feature.

[0220] In step 604, the 5G-RG may generate a registration request message on behalf of the AUN3 terminal. The registration request message includes SUCI, AUN3 indicator, new ID, and Challenge. AUN3 , Challenge 5G-RG , MAC AUN3 , may include at least one of the indicators indicating whether the AUN3 terminal supports the new feature.

[0221] At step 605, if W-AGF is MAC AUN3 , Challenge AUN3 , Challenge 5G-RG , AUN3 capability, or at least one of the new IDs, W-AGF can tell whether the AUN3 terminal supports the new feature. W-AGF can detect whether the AUN3 terminal supports the new feature. AUN3 After calculating using the same method as the AUN3 terminal, it can be verified whether it is the same. If the verification is successful, steps 606 to 621 below may not be performed. W-AGF is K WAGF, or K WAGF Subkeys generated from, or Challenge AUN3 , or Challenge 5G-RG MAC using at least one of WAGF can also be created.

[0222] At step 606, the W-AGF may send a registration request message including a SUCI or AUN3 indicator to the AMF.

[0223] In step 607, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include at least one of SUCI, SN-Name (Serving Network name), or AUN3 indicator (an indicator indicating that the terminal is an AUN3 terminal).

[0224] In step 608, the AUSF may send a Nudm_UEAuthentication_GetRequest message to the UDM. This message may include the information received from the AMF in step 607.

[0225] In step 609, after selecting an authentication method, UDM can generate an authentication vector (AV) that can authenticate the terminal.

[0226] In step 610, the UDM may send a Nudm_UEAuthentication_Get Response message to the AUSF. This message may include at least one of SUPI, EAP-AKA', or AV.

[0227] In step 611, the AUSF may send a Nausf_UEAuthentication_AuthenticationResponse message to the AMF. This message may include an AKA challenge.

[0228] In step 612, the AMF may send an authentication request message to the 5G-RG. This message may include the value received from the AUSF in step 611.

[0229] At step 613, the 5G-RG may transmit an L2 message to AUN3. This message may include the value received from the AMF at step 612.

[0230] In step 614, the AUN3 terminal can authenticate the network by verifying the AV. If verification is successful, the AUN3 terminal can calculate an Auth response to receive authentication from the network.

[0231] In step 615, the AUN3 terminal can transmit the value generated in step 614 to the 5G-RG as an L2 message.

[0232] In step 616, the 5G-RG may send the value received in step 615 to the AMF as an authentication response message.

[0233] In step 617, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include the value received in step 616.

[0234] At step 618, AUSF can authenticate the AUN3 terminal by verifying the Auth response.

[0235] In step 619, the AUSF can send an authentication response to the AMF if the verification in step 618 is successful. This message is K SEAF , may contain at least one of SUPI, and AMF may contain K SEAF Using K AMF can also be created.

[0236] At step 620, AMF is K AMF From K WAGF can be created.

[0237] In step 621, the AMF may send an Authentication Result message to the W-AGF. This message may be K WAGF , or may include at least one of EAP-Success.

[0238] In step 622, the W-AGF may send an Authentication Result message to the 5G-RG. This message may include EAP Success, K WAGF , MAC WAGF , Challenge WAGF , New key derivation indicator (If this indicator is present, the AUN3 terminal and W-AGF are K WAGF A subkey may be generated from the generated key, and the AUN3 terminal and 5G-RG may use the generated key), and may include at least one of the new IDs. The new ID may be generated by the W-AGF so that information about the W-AGF (e.g., an address) can be inferred, or the W-AGF may use it to find the security context of the terminal.

[0239] If steps 606-621 were not omitted, W-AGF receives K from AMF in step 621. WAGF can also be transmitted to 5G-RG.

[0240] Even if steps 606-621 were not omitted, if W-AGF knew that the AUN3 terminal supports the new function, it would receive K from AMF. WAGF Create a new key (e.g. K) by creating a subkey in WAGF ) can be transmitted to 5G-RG. The received K WAGF Wow Challenge WAGF , or Challenge AUN3 At least one of them can be used to create a new key.

[0241] If steps 606-621 are omitted, W-AGF will hold KWAGF Create a new key (e.g. K) by creating a subkey from WAGF ) can be transmitted to 5G-RG. K WAGF Wow Challenge WAGF , Challenge AUN3 At least one of them can be used to create a new key.

[0242] W-AGF is a Challenge WAGF , new ID, or K WAGF may be stored as part of the security context.

[0243] At step 623, the 5G-RG can send an L2 message to the AUN3 terminal. This message includes a MAC WAGF , New key derivation indicator, K WAGF Change indicator, new ID, Challenge WAGF , or may include at least one indicator indicating that W-AGF supports a new feature.

[0244] At step 624, if the AUN3 terminal is MAC WAGF , New key derivation indicator, challenge WAGF , an indicator indicating that the W-AGF supports a new feature, or a new ID, the AUN3 terminal may determine whether the W-AGF supports the new feature. The AUN3 terminal may use the same method performed by the W-AGF in step 5 to determine whether the W-AGF supports the new feature. WAGF W-AGF can be authenticated by calculating the AUN3 terminal when it receives a New key derivation indicator or a Challenge WAGF If the AUN3 terminal knows that the W-AGF generates a new key by receiving the K , it uses the same method that the W-AGF performed in step 6022. WAGFcan be generated. The AUN3 terminal is a Challenge WAGF , K WAGF , W-AGF capability, or New ID may be stored as a security context.

[0245] If the AUN3 terminal did not receive the above information, use the same method as before to K WAGF can be created.

[0246] At step 625, the AUN3 terminal and 5G-RG are K WAGF WLAN keys can be generated using PMK (Pairwise Master Key).

[0247] At step 626, the AUN3 terminal and 5G-RG can create WLAN security.

[0248] FIG. 7 is a diagram illustrating an authentication process of an AUN3 terminal that does not support 5G key hierarchy according to an embodiment of the present disclosure.

[0249] At step 701, the AUN3 terminal and 5G-RG can establish an 802.11 connection.

[0250] In step 702, the 5G-RG may send an EAP-ID request to the AUN3 terminal. This message includes the Challenge message generated by the 5G-RG. 5G-RG (e.g., nonce, random number, etc.), an indicator indicating whether 5G-RG supports a new feature, or an indicator indicating whether W-AGF supports a new feature, and the information may be included in a separate message.

[0251] In step 703, the AUN3 terminal can send an EAP-ID response to the 5G-RG. The AUN3 terminal can send the MSK, the subkey generated from the MSK, and the Challenge 5G-RG , or Challenge WAGFMAC using at least one of AUN3 can be generated. For example, the AUN3 terminal uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key uses some or all of the least significant 256 bits of the MSK, the most significant 256 bits of the MSK, or a subkey generated from the MSK, and the input value is a Challenge. 5G-RG or Challenge WAGF You can use MAC to generate values, and some or all of the generated values ​​(e.g. most significant 128bits, lease significant 128bits, etc.) AUN3 It can be used as AUN3 terminal Challenge WAGF Using MAC AUN3 In case of generating, it may be the case that there is a value received from W-AGF after previously connecting to 5GC and completing authentication. If a new ID is received from W-AGF (an ID created by W-AGF, which includes information that can identify W-AGF, such as the address of W-AGF, or information used by W-AGF to find the security context of the corresponding AUN3 terminal), or Challenge WAGF If you have received, the AUN3 terminal will be given a new ID or Challenge WAGF to K TWIF It can be stored as a security context with the AUN3 terminal. The AUN3 terminal sends the MAC address to the EAP-ID response message. AUN3 , Challenge AUN3(e.g., a random value generated by the AUN3 terminal), a new ID, or an indicator indicating whether the AUN3 terminal supports a new feature, or this information may be sent using a separate message. The AUN3 terminal may be configured to use a MAC address. AUN3 , or Challenge AUN3 , or sending a new ID could serve as an indicator that AUN3 supports the new feature.

[0252] In step 704, the 5G-RG may generate a registration request message on behalf of the AUN3 terminal. The registration request message includes SUCI, AUN3 indicator, new ID, and Challenge. AUN3 , Challenge 5G-RG , MAC AUN3 , may include at least one of the indicators indicating whether the AUN3 terminal supports the new feature.

[0253] At step 705, if W-AGF is MAC AUN3 , Challenge AUN3 , Challenge 5G-RG , AUN3 capability, or at least one of the new IDs, W-AGF can tell whether the AUN3 terminal supports the new feature. W-AGF can detect whether the AUN3 terminal supports the new feature. AUN3 After calculating using the same method as the AUN3 terminal, it can be verified whether it is the same. If the verification is successful, steps 706 to 721 below may not be performed. W-AGF is the least significant 256 bits of MSK, or the most significant 256 bits of MSK, or some or all of the subkeys generated from MSK, Challenge AUN3 , or Challenge 5G-RG MAC using at least one of WAGFcan also be created.

[0254] At step 706, the W-AGF may send a registration request message to the AMF, including a SUCI or AUN3 indicator.

[0255] In step 707, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include at least one of SUCI, SN-Name (Serving Network name), or AUN3 indicator (an indicator indicating that the terminal is an AUN3 terminal).

[0256] In step 708, the AUSF may send a Nudm_UEAuthentication_GetRequest message to the UDM. This message may include information received from the AMF in step 707.

[0257] In step 709, after selecting an authentication method, UDM can generate an authentication vector (AV) that can authenticate the terminal.

[0258] In step 710, the UDM may send a Nudm_UEAuthentication_Get Response message to the AUSF. This message may include at least one of SUPI, EAP-AKA', AV, or MSK indicators.

[0259] In step 711, the AUSF may send a Nausf_UEAuthentication_AuthenticationResponse message to the AMF. This message may include an AKA challenge.

[0260] In step 712, the AMF may send an authentication request message to the 5G-RG. This message may include the value received from the AUSF in step 711.

[0261] At step 713, the 5G-RG may transmit an L2 message to AUN3. This message may include the value received from the AMF at step 712.

[0262] In step 714, the AUN3 terminal can authenticate the network by verifying the AV. If verification is successful, the AUN3 terminal can also compute an Auth response to receive authentication from the network.

[0263] In step 715, the AUN3 terminal can transmit the value generated in step 714 to the 5G-RG as an L2 message.

[0264] In step 716, the 5G-RG may send the value received in step 715 to the AMF as an authentication response message.

[0265] In step 717, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include the value received in step 716.

[0266] At step 718, AUSF can authenticate the AUN3 terminal by verifying the Auth response.

[0267] In step 719, the AUSF may send an authentication response to the AMF if the verification in step 718 is successful. This message may include at least one of the MSK or SUPI.

[0268] In step 720, the AMF may send an Authentication Result message to the W-AGF. This message may include at least one of MSK or EAP-Success.

[0269] In step 721, the W-AGF may send an Authentication Result message to the 5G-RG. This message includes EAP Success, MSK, and MAC. WAGF , ChallengeWAGF , a New key derivation indicator (if this indicator is present, the AUN3 terminal and the W-AGF may generate a subkey from the MSK, and the AUN3 terminal and the 5G-RG may use the generated key), or a new ID. The new ID may be generated by the W-AGF so that information about the W-AGF (e.g., an address) can be inferred, or the W-AGF can use it to find the security context of the terminal.

[0270] For example, in relation to the method of generating a new MSK or PMK from the MSK held by W-AGF, the HMAC-SHA256 function, etc. (for example, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions) can be used, the key is the most significant 256 bits of the MSK, and the input value is the Challenge. AMF , Challenge AMF Length of Challenge AUN3 , or Challenge AUN3 A value can be generated using at least one of the lengths. At this time, the generated value can be used as MSK or PMK. Or, the function used is HMAC-SHA256, etc., the key is the least significant 256 bits of MSK, and the input value is Challenge. AMF , Challenge AMF Length of Challenge AUN3 , or Challenge AUN3A value can be generated using at least one of the lengths, and the generated value can be used as the MSK or PMK. Alternatively, a value obtained by concatenating the two values ​​mentioned above can be used as the MSK or PMK. If a value obtained by concatenating the two values ​​is used as the MSK, a PMK, which is a subkey, can be generated from the MSK.

[0271] In one embodiment, W-AGF is a challenge with MSK AUN3 or Challenge TWIF Here is an example of generating a new key using at least one of the PRF' functions. The PRF' function is defined as follows:

[0272] PRF'(K(part or all of MSK), S(Challenge AUN3 |Challenge AMF )) = T1 | T2 | T3 |…

[0273] Here, T1, T2 and T3 can be calculated as follows.

[0274] T1 = HMAC-SHA256(K, S | 0x01)

[0275] T2 = HMAC-SHA256(K, T1 | S | 0x02)

[0276] T3 = HMAC-SHA256(K, T2 | S | 0x03)

[0277] The new key can be a portion of the result of the PRF function (for example, a total of 512 bits from bit 640 to bit 1151 of the result).

[0278] If steps 706-721 are not omitted, the W-AGF can transmit the MSK received in step 721 from the AMF to the 5G-RG.

[0279] Even if steps 706-721 were not omitted, if W-AGF knew that AUN3 terminal supports new function, it would generate subkey from MSK received from AMF and create new key (e.g. K WAGF) can be transmitted to 5G-RG. The received MSK and Challenge WAGF , or Challenge AUN3 At least one of them can be used to create a new key.

[0280] If steps 706-721 are omitted, the W-AGF can generate a subkey from the MSK it has and send a new key (e.g., MSK or PMK) to the 5G-RG. The MSK it has and the Challenge WAGF , Challenge AUN3 At least one of them can be used to create a new key.

[0281] W-AGF is a Challenge WAGF , new ID, or K WAGF may be stored as part of the security context.

[0282] At step 722, the 5G-RG can send an L2 message to the AUN3 terminal. This message includes a MAC WAGF , New key derivation indicator, New ID, Challenge WAGF , or may include at least one indicator indicating that W-AGF supports a new feature.

[0283] At step 723, if the AUN3 terminal is MAC WAGF , New key derivation indicator, challenge WAGF , if the AUN3 terminal receives at least one of the indicators indicating that the W-AGF supports the new feature, or a new ID, the AUN3 terminal can determine whether the W-AGF supports the new feature. The AUN3 terminal uses the same method performed by the W-AGF in step 705 to perform the MAC WAGFW-AGF can be authenticated by calculating the AUN3 terminal when it receives a New key derivation indicator or a Challenge AMF If the AUN3 terminal knows that the W-AGF generates a subkey from the MSK by receiving the Challenge, the AUN3 terminal can generate the MSK or PMK using the same method that the W-AGF performed in step 721. The AUN3 terminal WAGF , MSK, PMK, W-AGF capability, or New ID may be stored as security context.

[0284] If the AUN3 terminal does not receive the above information, the MSK can be generated using the same method as before.

[0285] In step 724, the AUN3 terminal and 5G-RG can generate WLAN keys using the MSK as a PMK (Pairwise Master Key).

[0286] At step 725, the AUN3 terminal and 5G-RG can create WLAN security.

[0287] FIG. 8 is a diagram illustrating an authentication process of an N5CW terminal according to an embodiment of the present disclosure.

[0288] According to Figure 8, a Trusted WLAN Access point may know whether TWIF supports the new feature.

[0289] In step 801, EAP (Extensible Authentication Protocol)-based authentication is initiated between the N5CW terminal and the Trusted WLAN Access Point.

[0290] In step 802a, the Trusted WLAN Access Point can send an EAP-ID request to the N5CW terminal. This message contains a Challenge message generated by the Trusted WLAN Access Network. TWAP (e.g., nonce, random number, etc.), an indicator indicating whether TWAP supports the new feature, an indicator indicating whether TWIF supports the new feature, and that information may be included in a separate message.

[0291] In step 802b, the N5CW terminal can send an EAP-ID response to the Trusted WLAN Access Point. The N5CW terminal can send an EAP-ID response to the Trusted WLAN Access Point. TWIF , or K TWIF Subkeys generated from Challenge TWAP , or Challenge TWIF MAC using at least one of N5CW can also be generated. For example, the N5CW terminal uses a function (e.g., HAMC-SHA256, 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions), and the key is K TWIF or K TWIF Use the subkey generated from and the input value is Challenge 5G-RG or Challenge AMF You can use MAC to generate values, and some or all of the generated values ​​(e.g. most significant 128bits, lease significant 128bits, etc.) N5CW It can be used as a Challenge N5CW terminal AMF Using MAC N5CWIn case of generating, it may be the case that there is a value received from TWIF after previously accessing 5GC and completing authentication. If there is a new ID from TWIF (this information is an ID generated by TWIF and may include information about TWIF (e.g. address), or it may be information used by TWIF to find the security context for the N5CW terminal), or Challenge TWIF If you have received, the N5CW terminal will be given a new ID or Challenge TWIF to K TWIF It can be stored as a security context with the N5CW terminal. The N5CW terminal sends the MAC address to the EAP-ID response message. N5CW , Challenge N5CW (e.g., a random value generated by the N5CW terminal), a new ID, or an indicator indicating whether the N5CW terminal supports a new feature, and this information may be sent using a separate message. The N5CW terminal may be configured to send a MAC address. N5CW , or Challenge N5CW Sending a may also serve as an indicator that N5CW supports the new feature.

[0292] In step 802c, the Trusted WLAN Access Point receives some or all of the values ​​received in step 802b, or the Challenge TWAP At least one of them may be transmitted to TWIF.

[0293] At step 803, if TWIF is MAC N5CW , Challenge TWAP , Challenge N5CW , N5CW capability, or at least one of the new IDs, TWIF may also know whether the N5CW terminal supports the new feature. TWIF may also know whether the N5CW terminal supports the new feature. N5CWAfter calculating using the same method as the N5CW terminal, it can be verified whether it is the same. If the verification is successful, steps 804-811 below may not be performed. TWIF is K TWIF , or K TWIF Subkeys generated from Challenge N5CW , or Challenge TWAP MAC using at least one of TWIF can be created.

[0294] In step 804, the TWIF may generate a registration request message on behalf of the N5CW terminal. The registration request message may include at least one of SUCI, 5G-GUTI, requested Network Slice Selection Assistance Information (NSSAI), or 5GC capability.

[0295] At step 805a, TWIF can select AMF.

[0296] In step 805b, the TWIF may forward at least one of the registration request message generated in step 804, the user location, or the AN (Access Network) type to the AMF.

[0297] In step 806, the AMF may send a Nausf_UEAuthentication_AuthenticationRequest message to the AUSF. This message may include at least one of SUCI, SN-Name (Serving Network name), or N5CW indicator (an indicator indicating that the terminal is an N5CW terminal).

[0298] In step 807, the AUSF may send a Nudm_UEAuthentication_GetRequest message to the UDM. This message may include information received from the AMF in step 806.

[0299] In step 808, after selecting an authentication method, UDM can generate an authentication vector (AV) that can authenticate the terminal.

[0300] At step 809, an authentication process may be performed between the network and the N5CW terminal.

[0301] At step 810a, AMF may send a NAS Security Mode Command message to TWIF with EAP Success.

[0302] At step 810c, TWIF may store the EAP-success message.

[0303] At step 810d, TWIF may send a NAS Security Mode Complete message to AMF.

[0304] At step 811, the AMF may send an N2 Initial context setup request message. This message may be K TWIF may include.

[0305] At step 812a, TWIF receives K from AMF. TWIF Or K you have TWIF From K TNAP can be created.

[0306] If steps 804-811 were not omitted, TWIF receives K from AMF. TWIF From K TNAP can be created.

[0307] Even if steps 804-811 were not omitted, if TWIF knew that the N5CW terminal supports the new feature, it would receive a K TWIF Create a new key (e.g. K) by creating a subkey in TNAP ) can also be sent to TWAP. The received K TWIF Wow Challenge TWIF , or ChallengeN5CW At least one of them can be used to create a new key.

[0308] If steps 804-811 are omitted, TWIF will hold K TWIF Create a new key by creating a subkey from (e.g. K TWIF or K TNAP ) can be sent to TWAP. K held TWIF Wow Challenge TWIF , or Challenge N5CW At least one of them may be used to create a new key.

[0309] TWIF is a Challenge TWIF , new ID, or K TWIF may be stored as part of the security context.

[0310] TWIF is K TNAP In relation to the method of generating, the HMAC-SHA256 function, etc. (for example, it can be 128-AES, SNOW3G, ZUC, 256-AES, SNOW5G, ZUC-256, or other functions, etc.) is used, and the input key is K TWIF , the input value can be at least one of 0x84, a usage type distinguisher (i.e., 0x02), or the length of the usage type distinguisher (i.e., 0x00 0x01). K TNAP This can be used as PMK.

[0311] In step 812b, the TWIF can send an AAA message to the Trusted WLAN Access Point. This message contains EAP-Success, PMK, an indicator indicating whether the TWIF supports the new feature, a New key derivation indicator, and MAC. TWIF , Challenge TWIF , or may contain at least one of the new IDs.

[0312] In step 812c, the Trusted WLAN Access Point can send an EAP-Success message to the N5CW. This message includes an indicator indicating whether TWIF supports a new feature, a New key derivation indicator, and a MAC TWIF , Challenge TWIF , or may contain at least one of the new IDs.

[0313] At step 813a, if the N5CW terminal has MAC TWIF , New key derivation indicator, challenge TWIF , or at least one of the indicators indicating that the TWIF supports the new feature, the N5CW terminal can determine whether the TWIF supports the new feature. The N5CW terminal uses the same method performed by the TWIF in step 803 to determine whether the TWIF supports the new feature. TWIF TWIF can be authenticated by calculating the N5CW terminal when it receives a New key derivation indicator or a Challenge TWIF If the N5CW terminal knows that the TWIF has generated a new key by receiving the K , the N5CW terminal uses the same method that the TWIF performed in step 812a. TWIF From K TNAP can be generated and used as PMK. N5CW terminal can be Challenge TWIF , K TWIF , TWIF capability, or at least one of the new IDs may be stored as security context.

[0314] At step 813b, the N5CW terminal and the Trusted WLAN Access Point are K TNAP WLAN keys can be generated using PMK (Pairwise Master Key).

[0315] At step 813c, the N5CW terminal and the Trusted WLAN Access Point can create WLAN security.

[0316] At step 813d, a L2 or L3 connection may be established between the Trusted WLAN Access Point and the TWIF. This may be to send user plane traffic of the N5CW terminal to the TWIF.

[0317] At step 814, TWIF may send an N2 Initial Context Setup Response message to AMF.

[0318] FIG. 9 is a diagram illustrating a 5G key hierarchy according to an embodiment of the present disclosure.

[0319] The UE (user equipment) and UDM / ARPF may possess a symmetric key K, which is a long-term key. The UE may consist of a USIM and an ME, and the long-term key K may be stored in the USIM or the ME. From the long-term key K, CK and IK are generated in the UDM and USIM, and depending on the authentication method, K is generated from CK and IK. AUSF can be generated from UDM and ME. The generated key can be transferred from UDM to AUSF. AUSF and ME can be K AUSF From K SEAF can generate and AUSF can pass it to SEAF (Security Anchor Functionality). SEAF and ME can K SEAF From K AMF can be generated, and SEAF can pass it to AMF. AMF and ME can be K AMF Key (K) used to protect NAS messages from NASint , K NASenc) can be generated and used to perform integrity protection or encryption on NAS messages. AMF and ME are K AMF From K gNB can generate a key (K) that AMF can forward to the gNB. The gNB and ME can protect the RRC message from the KgNB. RRCint , K RRCenc ) and a key (K) that protects User Plane messages UPint , K UPenc ) can be generated. As shown in Fig. 9, an AUN3 terminal capable of key derivation using the 5G key hierarchy defined in 3GPP can be referred to as an AUN3 terminal supporting the 5G key hierarchy.

[0320] The configuration diagrams, diagrams illustrating control / data signal transmission / reception methods, and diagrams illustrating operational procedures illustrated in FIGS. 1A to 9 do not limit the scope of the embodiments of the present disclosure. That is, not all components, entities, or operational steps illustrated in FIGS. 1A to 9 should be construed as essential components for implementing the disclosure, and implementations may be made within a scope that does not harm the essence of the disclosure even if only some components are included.

[0321] The operations of the embodiments described above can be realized by providing a memory device storing the corresponding program code in any component within the device. That is, the control unit within the device can execute the operations described above by reading and executing the program code stored in the memory device through a processor or a CPU (Central Processing Unit).

[0322] The various components and modules of the entity or terminal device described in the present disclosure may be operated using hardware circuits, such as logic circuits based on complementary metal oxide semiconductors, firmware, software, and / or hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates, and application-specific semiconductors.

[0323] The methods according to the embodiments described in the claims or specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.

[0324] When implemented in software, a computer-readable storage medium storing one or more programs (software modules) may be provided. The one or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. The one or more programs include instructions that cause the electronic device to execute methods according to the embodiments described in the claims or specification of the present disclosure.

[0325] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read only memory (ROM), electrically erasable programmable read only memory (EEPROM), magnetic disc storage devices, compact disc-ROMs (CD-ROMs), digital versatile discs (DVDs) or other forms of optical storage devices, magnetic cassettes, or may be stored in memories formed by a combination of some or all of these. In addition, each configuration memory may include multiple copies.

[0326] Additionally, the program may be stored on an attachable storage device that is accessible via a communication network, such as the Internet, an intranet, a local area network (LAN), a wide area network (WAN), a storage area network (SAN), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure via an external port. Additionally, a separate storage device on the communication network may be connected to a device performing an embodiment of the present disclosure.

[0327] In the specific embodiments of the present disclosure described above, components included in the disclosure are expressed in the singular or plural form, depending on the specific embodiment presented. However, the singular or plural expressions are selected to suit the presented situation for convenience of explanation, and the present disclosure is not limited to singular or plural components. Components expressed in the plural form may be composed of singular elements, or components expressed in the singular form may be composed of plural elements.

[0328] While the detailed description of this disclosure has described specific embodiments, it should be understood that various modifications are possible without departing from the scope of this disclosure. Therefore, the scope of this disclosure should not be limited to the described embodiments, but should be defined not only by the scope of the claims described below, but also by equivalents thereof.

Claims

1. In a method performed by a terminal of a wireless communication system, A step of receiving a first request message including capability information on whether an AMF (access and mobility management function) entity supports simplified authentication and a first random value; and A method comprising the step of transmitting a second response message including a first MAC (message authentication code) value based on a first random value, a second random value, and capability information on whether the terminal supports simplified authentication.

2. In paragraph 1, A step of receiving an indicator indicating a change of a first key for the above AMF and a second MAC value; A step of verifying the second MAC value; A step of generating a second key for the AMF based on the first key; and A method further comprising the step of generating a third key for a first NF (network function) entity that is a subkey of the second key based on the second key.

3. In paragraph 1, A step of receiving an indicator indicating a change of a Key for a first NF entity and a second MAC value; a step of verifying the second MAC value; and A method further comprising the step of generating a third Key for a first NF (network function) entity that is a subkey of the first Key based on the first Key for the AMF.

4. In paragraph 1, A method wherein the terminal includes an AUN3 (authenticable non-3gpp) terminal or an N5CW (non-5G-capable over WLAN) terminal.

5. In a method performed by an AMF (access and mobility management function) entity of a wireless communication system, A step of receiving a first request message including a first random value, a first MAC value based on the first random value, a second random value generated by a terminal, and capability information on whether the terminal supports simplified authentication; A step of verifying a first MAC value based on the first random value and the first Key for the AMF; and A method comprising the step of generating a second MAC value based on the second random value and the first key.

6. In paragraph 5, A step of generating a second key for the AMF from the first key; A step of generating a third key for a first NF (network function) entity that is a subkey of the second key based on the second key; and A method comprising the step of transmitting an indicator indicating a change of the second MAC value, the third Key, and the first Key.

7. In paragraph 5, A step of generating a fourth key for a first NF (network function) entity that is a subkey of the first key based on the first key; and A method comprising the step of transmitting an indicator indicating a change of the second MAC value, the fourth Key and the Key to the first NF entity.

8. In paragraph 8, A method wherein the terminal includes an AUN3 (authenticable non-3gpp) terminal or an N5CW (non-5G-capable over WLAN) terminal.

9. In the terminal of a wireless communication system, Transmitter and receiver; and Includes a control unit connected to the above transmitter and receiver, The above control unit, Receive a first request message including capability information on whether an AMF (access and mobility management function) entity supports simplified authentication and a first random value, A terminal configured to transmit a second response message including a first MAC (message authentication code) value based on a first random value, a second random value, and capability information on whether the terminal supports simplified authentication.

10. In paragraph 9, the control unit, Receive an indicator and a second MAC value indicating a change of the first key for the above AMF, Verify the above second MAC value, Generate a second key for the AMF based on the first key, and A terminal configured to generate a third key for a first NF (network function) entity that is a subkey of the second key based on the second key.

11. In paragraph 9, the control unit, Receive an indicator indicating a change of Key for the first NF entity and a second MAC value, Verify the above second MAC value, A terminal configured to generate a third Key for a first NF (network function) entity that is a subkey of the first Key based on the first Key for the above AMF.

12. In paragraph 9, The terminal includes an AUN3 (authenticable non-3gpp) terminal or an N5CW (non-5G-capable over WLAN) terminal.

13. In the AMF (access and mobility management function) entity of a wireless communication system, Transmitter and receiver; and Includes a control unit connected to the above transmitter and receiver, The above control unit, Receive a first request message including a first random value, a first MAC value based on the first random value, a second random value generated by the terminal, and capability information on whether the terminal supports simplified authentication; Verifying the first MAC value based on the first random value and the first Key for the AMF, and An AMF entity configured to generate a second MAC value based on the second random value and the first Key.

14. In the 13th paragraph, the control unit, Generate a second key for the AMF from the first key, Based on the second key, a third key is generated for the first NF (network function) entity, which is a subkey of the second key, and An AMF entity configured to transmit an indicator indicating a change of the second MAC value, the third Key and the first Key.

15. In the 13th paragraph, the control unit, Based on the first Key, a fourth Key is generated for the first NF (network function) entity, which is a subkey of the first Key, and An AMF entity configured to transmit an indicator indicating a change of the second MAC value, the fourth Key and the Key for the first NF entity.