AKMA service management method and communication apparatus
By receiving AKMA service shutdown notification messages and obtaining the current network information of terminal devices, the access control problem in AKMA service management is solved, enabling accurate management of AKMA services and improving user experience and communication security.
Patent Information
- Application Number
- PCT/CN2025/094965
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-20
- Filing Date
- 2025-05-14
- Publication Date
- 2025-11-27
AI Technical Summary
How to properly manage AKMA services to improve communication security and user experience, especially in the management of AKMA service usage permissions between terminal devices and application function network elements.
By receiving AKMA service shutdown notification messages and obtaining the current network information of terminal devices, it can determine whether to shut down or establish AKMA services, thereby achieving network-level management of AKMA services and avoiding unnecessary interruptions.
It enables accurate management of AKMA services, improves user experience, avoids unnecessary service interruptions, and ensures communication security.
Smart Images

Figure CN2025094965_27112025_PF_FP_ABST
Abstract
Description
Management method of AKMA service and communication device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese Patent Application No. 202410628753.0, filed on May 20, 2024, and entitled "Management method of AKMA service and communication device", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application relates to the technical field of wireless communication, and in particular to a management method of AKMA service and a communication device. BACKGROUND
[0004] In order to improve the security of communication, when a terminal device and an application function (AF) network element communicate with each other, both sides need to use the same application key to protect the authentication and key management for applications (AKMA) service. The application key used by the terminal device is generated by the terminal device, and the application key used by the AF network element can be generated by the AKMA anchor function (AAnF) network element and sent to the AF network element.
[0005] How to correctly manage the AKMA service is a problem worth considering. SUMMARY
[0006] Embodiments of the present application provide a management method of AKMA service and a communication device to correctly manage the AKMA service.
[0007] In the present application, the network in which the terminal device cannot use the AKMA service can also be referred to as the network that does not allow the terminal device to use the AKMA service. The network in which the terminal device can use the AKMA service can also be referred to as the network that allows the terminal device to use the AKMA service.
[0008] In a first aspect, an embodiment of the present application provides a method for managing AKMA service. The method can be executed by a first device. In the present application, the first device can refer to an AF network element, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the AF network element, or a logic module or software capable of realizing all or part of the functions of the AF network element. The method comprises the following steps: receiving an AKMA service closing notification message, wherein the AKMA service closing notification message comprises information of a first network, and the AKMA service closing notification message is used to notify the closing of the AKMA service of the first network; obtaining information of a current network corresponding to a first session of a terminal device, wherein the first session is used to transmit a first AKMA service between the terminal device and an application function network element; and determining whether to close the first AKMA service according to the AKMA service closing notification message and the information of the current network corresponding to the first session.
[0009] Based on the above scheme, the first device can obtain information of a network in which the terminal device is not allowed to perform AKMA service, and obtain information of a current network corresponding to a session used to carry AKMA service between the terminal device and the application function network element, so as to accurately determine whether the terminal device and the application function network element can perform AKMA service, and to determine whether to close the AKMA service, thereby realizing network granularity management of the AKMA service, and helping to improve user experience. Compared with the scheme that the AKMA service of all the networks registered by the terminal device is always closed as long as the terminal device is not allowed to perform AKMA service in a certain network, the present application can realize closing of the AKMA service based on network granularity, and can avoid interruption of the AKMA service as much as possible.
[0010] In a possible implementation method, the determining whether to close the first AKMA service according to the AKMA service closing notification message and the information of the current network corresponding to the first session comprises: in a case where the current network corresponding to the first session is the first network, closing the first AKMA service.
[0011] Based on the above scheme, when the current network corresponding to the first session of the terminal device is the first network, the first AKMA service carried by the first session is transmitted in the first network, and the terminal device cannot use the AKMA service in the first network, so the first AKMA service is closed, thereby realizing correct management of the AKMA service.
[0012] In a possible implementation method, the obtaining information of a current network corresponding to the first session of the terminal device comprises: receiving a first notification message, wherein the first notification message comprises information of the first network, and the first notification message indicates that the network corresponding to the first session changes to the first network.
[0013] Based on the above scheme, the current network information corresponding to the first session of the terminal device can be acquired in time and correctly.
[0014] In a possible implementation method, the method further includes: in a case where the current network corresponding to the second session of the terminal device is a second network, not closing a second AKMA service between the terminal device and the application function network element, the second session being used for transmitting the second AKMA service, and the second network being different from the first network.
[0015] Based on the above scheme, the current network corresponding to the second session of the terminal device is the second network, and therefore the second AKMA service carried by the second session is transmitted in the second network, and the terminal device can use the AKMA service in the second network, so that the second AKMA service is not closed, and correct management of the AKMA service is achieved.
[0016] In a possible implementation method, the method further includes: in a case where the current network corresponding to the first session is a second network, not closing the first AKMA service, the second network being different from the first network.
[0017] Based on the above scheme, the current network corresponding to the first session of the terminal device is the second network, and therefore the first AKMA service carried by the first session is transmitted in the second network, and the terminal device can use the AKMA service in the second network, so that the first AKMA service is not closed, and correct management of the AKMA service is achieved.
[0018] In a possible implementation method, the method further includes: receiving a second notification message, the second notification message including information of the second network, and the second notification message indicating that the network corresponding to the first session is the second network.
[0019] Based on the above scheme, the current network information corresponding to the first session of the terminal device can be acquired in time and correctly.
[0020] In a possible implementation method, the method further includes: sending a first subscription request message, the first subscription request message being used for subscribing to a network change corresponding to the first session.
[0021] Based on the above scheme, the current network information corresponding to the first session of the terminal device can be acquired in time and correctly through the subscription manner.
[0022] In a possible implementation, the first subscription request message includes one or more of information of the first session, an identifier of the terminal device, or a first event identifier, where the first event identifier is used to indicate a network change event.
[0023] In a possible implementation, the first notification message includes one or more of information of the first session, an identifier of the terminal device, or a first event identifier, where the first event identifier is used to indicate a network change event.
[0024] In a possible implementation, the AKMA service closing notification message further includes information of a second network.
[0025] In a second aspect, an AKMA service management method is provided. The method can be executed by a first device. Unless otherwise specified, the first device in the present application can refer to an AF network element, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the AF network element, or a logic module or software that can implement all or part of the functions of the AF network element. The method includes: receiving an application session establishment request message, where the application session establishment request message requests to establish an application session for transmitting a third AKMA service between a terminal device and an application function network element, and the application session is carried in a third session of the terminal device; obtaining information of a current network corresponding to the third session; and determining whether to allow the establishment of the application session according to the information of the current network corresponding to the third session.
[0026] Based on the above scheme, when the terminal device requests to establish an application session for transmitting an AKMA service, the first device determines whether to allow the establishment of the application session according to the information of a current network corresponding to a third session carrying the application session and networks in which the terminal device can use the AKMA service, thereby achieving network granularity management of the AKMA service and helping to improve user experience.
[0027] In a possible implementation, the determining whether to allow the establishment of the application session according to the information of the current network corresponding to the third session includes: in a case where the current network corresponding to the third session is a first network, the first network is a network in which the terminal device cannot use the AKMA service, and the establishment of the application session is rejected.
[0028] Based on the above scheme, the terminal device requests to establish an application session, which is carried in a third session, and the current network corresponding to the third session is a first network in which the terminal device cannot use the AKMA service, and it is determined that the establishment of the application session is not allowed. Therefore, the establishment of the application session is rejected, and the AKMA service can be correctly managed.
[0029] In a possible implementation, the determining whether to allow the application session to be established according to the information of the current network corresponding to the third session includes: in a case where the current network corresponding to the third session is a second network, the application session is allowed to be established, and the second network is a network in which the terminal device can use AKMA services.
[0030] Based on the foregoing scheme, the terminal device requests to establish an application session carried on a third session, the current network corresponding to the third session is a second network in which the terminal device can use AKMA services, and it is determined that the application session is allowed to be established, so that AKMA services can be correctly managed.
[0031] In a possible implementation, the obtaining the information of the current network corresponding to the third session includes: sending a second subscription request message, the second subscription request message being used to subscribe to network changes corresponding to the third session; and receiving a third notification message, the third notification message including the information of the current network corresponding to the third session.
[0032] Based on the foregoing scheme, the current network information of the third session of the terminal device can be obtained in a timely and correct manner through subscription.
[0033] In a possible implementation, the second subscription request message includes one or more of the following: information of the third session, an identifier of the terminal device, or a second event identifier, and the second event identifier is used to indicate a network change event.
[0034] In a possible implementation, the third session is the same session as the first session or the second session in any implementation method of the first aspect. In this case, any implementation method of the second aspect can be combined with any implementation method of the first aspect, for example, any implementation method of the second aspect can be executed after any implementation method of the first aspect.
[0035] In a possible implementation, the third session is different from the first session and the second session in any implementation method of the first aspect, and any implementation method of the second aspect can be implemented independently or in combination with any implementation method of the first aspect.
[0036] In a third aspect, an embodiment of the present application provides a method for managing AKMA service, which can be executed by a second device. Unless otherwise specified, the "second device" in the present application can refer to an AAnF network element, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system, etc.) in the AAnF network element, or a logic module or software capable of realizing all or part of the functions of the AAnF network element. The method comprises: determining that a terminal device cannot use AKMA service in a first network; and sending an AKMA service closing notification message to the terminal device, wherein the AKMA service closing notification message comprises information of the first network or roaming policy information, and the roaming policy information comprises information of a network in which the terminal device cannot use AKMA service, and the information of the network in which the terminal device cannot use AKMA service comprises the information of the first network.
[0037] Based on the above scheme, the terminal device can obtain the information of the network in which the terminal device is not allowed to use AKMA service, which helps the terminal device to accurately determine whether to release the corresponding application session, realizes the network granularity management of AKMA service, and helps to improve the user experience.
[0038] In a fourth aspect, an embodiment of the present application provides a method for managing AKMA service, which can be executed by a third device. Unless otherwise specified, the "third device" in the present application can refer to a terminal device, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system, etc.) in the terminal device, or a logic module or software capable of realizing all or part of the functions of the terminal device. The method comprises: sending an application session establishment request message, wherein the application session establishment request message requests to establish an application session for transmitting AKMA service between the terminal device and an application function network element; receiving an application session establishment response message, wherein the application session establishment response message indicates that the application session is successfully established; receiving an AKMA service closing notification message, wherein the AKMA service closing notification message comprises information of a first network or roaming policy information, the roaming policy information comprises information of a network in which the terminal device cannot use AKMA service, and the information of the network in which the terminal device cannot use AKMA service comprises the information of the first network; and determining whether to release the application session according to the AKMA service closing notification message and information of a network corresponding to the application session.
[0039] Based on the above scheme, the third device can obtain the information that the terminal device is not allowed to perform AKMA service in the network, and obtain the information that the application session for carrying AKMA service between the terminal device and the application function network element corresponds to the network, and then accurately determine whether the AKMA service between the terminal device and the application function network element can be performed, and decide whether to release the application session, thereby realizing the network granularity management of the AKMA service, and helping to improve the user experience. Compared with the scheme that the AKMA service of the terminal device in all networks is always closed as long as the terminal device is not allowed to perform AKMA service in a certain network, the present application can realize the closing of AKMA service based on network granularity, and can avoid the interruption of AKMA service as much as possible.
[0040] In a possible implementation method, the determining whether to release the application session according to the AKMA service closing notification message and the information of the network corresponding to the application session comprises: when the network corresponding to the application session is the first network, releasing the application session.
[0041] Based on the above scheme, since the terminal device cannot use AKMA service in the first network, and the network corresponding to the application session for transmitting AKMA service is the first network, it is determined that the application session needs to be released, and the AKMA service can be correctly managed.
[0042] In a possible implementation method, the determining whether to release the application session according to the AKMA service closing notification message and the information of the network corresponding to the application session comprises: when the network corresponding to the application session is the second network, not releasing the application session, the second network is different from the first network, and the second network is a network in which the terminal device can use AKMA service.
[0043] Based on the above scheme, since the terminal device cannot use AKMA service in the first network, and the network corresponding to the application session for transmitting AKMA service is the second network, it is determined that the application session needs to be released, and the AKMA service can be correctly managed.
[0044] In a fifth aspect, an AKMA service management method is provided. The method can be performed by a first device. The first device can refer to an AF network element, a component (e.g., a communication module, a processor, a circuit, a chip, or a chip system) in the AF network element, or a logic module or software that can implement all or part of the functions of the AF network element. The method includes receiving an application session establishment request message from a terminal device, the application session establishment request message requesting to establish an application session for transmitting AKMA service between the terminal device and an application function network element, the application session establishment request message including an AKMA key identifier, and the application session being carried on a first session; sending an application key request message to an AKMA anchor function network element, the application key request message including the AKMA key identifier; receiving an application key response message from the AKMA anchor function network element, the application key response message including an application key corresponding to the AKMA key identifier, the application key response message indicating that the terminal device is not allowed to use AKMA service in a first network and / or is allowed to use AKMA service in a second network; obtaining information of a current network corresponding to the first session; and determining whether to allow the application session based on the information of the current network corresponding to the first session and the application key response message.
[0045] In the above scheme, the first device receives an application key response message from the AKMA anchor function network element, the application key response message including an application key, and the application key response message also indicating that the terminal device is not allowed to use AKMA service in a first network and / or is allowed to use AKMA service in a second network, thereby helping the first device to more accurately determine whether to allow the application session requested by the terminal device to be established, and achieving accurate management of AKMA service between the terminal device and the application function network element.
[0046] In a possible implementation method, the obtaining of the information of the current network corresponding to the first session includes obtaining the information of the current network corresponding to the first session based on the application key response message.
[0047] Based on the above scheme, the first device obtains the information of the current network corresponding to the first session based on the application key response message, which can achieve timely and accurate obtaining of the information of the current network corresponding to the first session.
[0048] In a possible implementation, the method further includes: sending, to a session management function network element, a subscription request message, the subscription request message being used to subscribe to network information corresponding to the first session; and receiving a notification message from the session management function network element, the notification message including the information of the current network corresponding to the first session.
[0049] Based on the foregoing scheme, the current network information corresponding to the first session of the terminal device can be acquired in a timely and correct manner through subscription.
[0050] In a possible implementation, the subscription request message includes one or more of the following: information of the first session, an identifier of the terminal device, or an event identifier, the event identifier being used to indicate a network change event.
[0051] In a possible implementation, the method further includes: in a case where the current network corresponding to the first session is the first network, rejecting the application session.
[0052] Based on the foregoing scheme, the first device can correctly determine whether to reject the application session requested by the terminal device, which is helpful to correctly manage AKMA services.
[0053] In a possible implementation, the method further includes: in a case where the current network corresponding to the first session is the second network, allowing the application session.
[0054] Based on the foregoing scheme, the first device can correctly determine whether to allow the application session requested by the terminal device, which is helpful to correctly manage AKMA services.
[0055] In a sixth aspect, an AKMA service management method is provided. The method can be performed by a second device. Unless otherwise specified, the "second device" in the present application can refer to an AAnF network element, a component (for example, a communication module, a processor, a circuit, a chip, or a chip system) in the AAnF network element, or a logic module or software capable of implementing all or part of the functions of the AAnF network element. The method includes receiving an application key request message from an application function network element, the application key request message including an AKMA key identifier; and sending an application key response message to the application function network element according to whether the terminal device is allowed to use AKMA services in a first network and a second network, the application key response message indicating whether the terminal device is allowed to use AKMA services in the first network and / or the second network.
[0056] Based on the above scheme, the second device sends an application key response message to the application function network element, which indicates whether the terminal device is allowed to use AKMA services in the first network and / or the second network, thereby helping the application function network element to more accurately determine whether to allow the terminal device to request an established application session, and accurately managing AKMA services between the terminal device and the application function network element.
[0057] In a possible implementation method, the sending of the application key response message to the application function network element according to whether the terminal device is allowed to use AKMA services in the first network and the second network includes: in a case where it is determined that the terminal device is not allowed to use AKMA services in the first network and is allowed to use AKMA services in the second network, sending the application key response message to the application function network element, the application key response message including an application key generated according to an AKMA key corresponding to the AKMA key identifier, and the application key response message further including information of the first network and / or information of the second network; wherein the information of the first network indicates that the terminal device is not allowed to use AKMA services in the first network; and the information of the second network indicates that the terminal device is allowed to use AKMA services in the second network.
[0058] In a possible implementation, the sending, to the application function network element, of the application key response message according to whether the terminal device is allowed to use AKMA services in the first network and the second network includes: in a case where it is determined that the terminal device is allowed to use AKMA services in the first network and the second network, sending, to the application function network element, the application key response message, the application key response message being used to indicate that the terminal device is allowed to use AKMA services in the first network and the second network. The application key response message includes an application key, the application key being generated according to a corresponding AKMA key of the AKMA key identifier.
[0059] In a possible implementation, the sending, to the application function network element, of the application key response message according to whether the terminal device is allowed to use AKMA services in the first network and the second network includes: in a case where it is determined that the terminal device is allowed to use AKMA services in the first network and the second network, sending, to the application function network element, the application key response message, the application key response message being used to indicate that the terminal device is allowed to use AKMA services in the first network and the second network. The application key response message includes an application key, the application key being generated according to a corresponding AKMA key of the AKMA key identifier.
[0060] In a possible implementation, the application key response message further includes information of the first network and information of the second network; the information of the first network indicates that the terminal device is allowed to use AKMA services in the first network; and the information of the second network indicates that the terminal device is allowed to use AKMA services in the second network.
[0061] In a seventh aspect, an embodiment of the present application provides a communication apparatus, which has a function of implementing any implementation method of the first aspect to the second aspect and the sixth aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0062] In an eighth aspect, an embodiment of the present application provides a communication apparatus, which has a function of implementing any implementation method of the third aspect and the fifth aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0063] In a ninth aspect, an embodiment of the present application provides a communication apparatus, which has a function of implementing any implementation method of the fourth aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0064] In a tenth aspect, an embodiment of the present application provides a communication apparatus, including units or means for performing each of the steps of any of the implementation methods of the first aspect to the sixth aspect.
[0065] In an eleventh aspect, an embodiment of the present application provides a communication apparatus, including a processor and an interface circuit, the processor is configured to communicate with other apparatuses through the interface circuit, and perform any of the implementation methods of the first aspect to the sixth aspect. The processor includes one or more.
[0066] Optionally, the communication apparatus can further include a memory for storing computer instructions, the memory is coupled to the processor, and the processor executes the computer instructions stored in the memory to make the apparatus perform any of the implementation methods of the first aspect to the sixth aspect.
[0067] In a twelfth aspect, an embodiment of the present application further provides a computer program product, the computer program product includes computer programs or instructions, when the computer programs or instructions are run on the communication apparatus, any of the implementation methods of the first aspect to the sixth aspect are performed.
[0068] In a thirteenth aspect, an embodiment of the present application further provides a computer readable storage medium, the computer readable storage medium stores instructions, when the instructions are run on the communication apparatus, any of the implementation methods of the first aspect to the sixth aspect are performed.
[0069] In a fourteenth aspect, an embodiment of the present application provides a chip (or chip system), the chip includes a processor, the processor is coupled to a memory, and the memory stores computer programs; the processor is configured to invoke part or all of the computer programs in the memory, so that any of the implementation methods of the first aspect to the sixth aspect are performed.
[0070] In a fifteenth aspect, an embodiment of the present application provides a communication system, including a first apparatus and a second apparatus. The first apparatus is configured to implement any of the implementation methods of the first aspect. The second apparatus is configured to send an AKMA service off notification message to the first apparatus.
[0071] In a sixteenth aspect, an embodiment of the present application provides a communication system, including a first apparatus configured to implement any of the implementation methods of the fifth aspect, and a second apparatus configured to implement any of the implementation methods of the sixth aspect. BRIEF DESCRIPTION OF DRAWINGS
[0072] FIG. 1 is a schematic diagram of a 5G network architecture based on a service-oriented architecture;
[0073] FIG. 2 is a schematic diagram of a 5G network architecture based on a point-to-point interface;
[0074] Figure 3 is a schematic diagram of the architecture for adding AKMA-related functions in a 5G network;
[0075] Figure 4 shows a K embodiment provided in this application. AKMA A schematic diagram of the generation method;
[0076] Figure 5 shows a K embodiment provided in this application. AKMA A diagram illustrating how to use it;
[0077] Figure 6 is a schematic diagram of the AKMA service shutdown method provided in an embodiment of this application;
[0078] Figure 7 is a schematic diagram of the AKMA service shutdown method provided in an embodiment of this application;
[0079] Figure 8(a) is a flowchart illustrating the AKMA service management method provided in an embodiment of this application;
[0080] Figure 8(b) is a flowchart illustrating the AKMA service management method provided in the embodiments of this application;
[0081] Figure 8(c) is a flowchart illustrating the AKMA service management method provided in the embodiments of this application;
[0082] Figure 9(a) is an example of the relationship between session and network provided in an embodiment of this application;
[0083] Figure 9(b) shows an example of the relationship between session and network provided in an embodiment of this application;
[0084] Figure 9(c) is an example of the relationship between session and network provided in an embodiment of this application;
[0085] Figure 9(d) is an example of the relationship between session and network provided in the embodiments of this application;
[0086] Figure 10 is a flowchart illustrating the AKMA service management method provided in an embodiment of this application;
[0087] Figure 11 is a flowchart illustrating the AKMA service management method provided in an embodiment of this application;
[0088] Figure 12 is a flowchart illustrating the AKMA service management method provided in an embodiment of this application;
[0089] Figure 13 is a flowchart illustrating the AKMA service management method provided in an embodiment of this application;
[0090] Figure 14 is a schematic diagram of a communication device provided in an embodiment of this application;
[0091] Figure 15 is a schematic diagram of a communication device provided in an embodiment of this application. Detailed Implementation
[0092] To meet the challenge of wireless broadband technology, keep the leading advantage of the 3rd generation partnership project (3GPP) network, the 3GPP standard group formulates the architecture of the next generation mobile communication network system (Next Generation System), called the 5th generation (5G) network architecture. This architecture not only supports the wireless access technology defined by the 3GPP standard group (such as long term evolution (LTE) access technology, 5G radio access network (RAN) access technology, etc.) to access the 5G core network (CN), but also supports the use of non-3GPP (non-3GPP) access technology to access the core network through non-3GPP interworking function (N3IWF) or next generation packet data gateway (ngPDG).
[0093] FIG. 1 is a schematic diagram of a 5G network architecture based on a service-based architecture. The 5G network architecture shown in FIG. 1 can include access network devices and core network devices. A terminal device (for example, the terminal device is a user equipment (UE) in the figure) accesses a data network (DN) through the access network devices and the core network devices. Among them, the core network devices include but are not limited to part or all of the following network elements: an authentication server function (AUSF) network element (not shown in the figure), a unified data management (UDM) network element, a unified data repository (UDR) network element, a network repository function (NRF) network element (not shown in the figure), a network exposure function (NEF) network element (not shown in the figure), an application function (AF) network element, a policy control function (PCF) network element, an access and mobility management function (AMF) network element, a session management function (SMF) network element, and a user plane function (UPF) network element.
[0094] The terminal device can be a UE, a mobile station, a mobile terminal device, etc. The terminal device can be widely used in various scenarios, such as device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), internet of things (IOT), virtual reality, augmented reality, industrial control, autonomous driving, remote medical treatment, smart power grid, smart furniture, smart office, smart wear, smart transportation, smart city, etc. The terminal device can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device, a vehicle, an urban air vehicle (such as a pilotless plane, a helicopter, etc.), a ship, a robot, a mechanical arm, a smart home device, etc. The terminal device stores a long-term key and related functions. When performing mutual authentication with a core network element (such as an AMF network element, an AUSF network element), the terminal device uses the long-term key and the related functions to verify the authenticity of the network.
[0095] The access network device can be a wireless access network device (RAN device) or a wired access network device. Among them, the wireless access network device includes a 3GPP access network device, a non-trusted non-3GPP access network device, and a trusted non-3GPP access network device. The 3GPP access network device includes but is not limited to: an evolved NodeB (eNodeB) in LTE, a next generation NodeB (gNB) in a 5G mobile communication system, a base station in a future mobile communication system, or a module or unit that completes the base station part function, such as a centralized unit (CU), a distributed unit (DU), etc. The non-trusted non-3GPP access network device includes but is not limited to: a non-trusted non-3GPP access gateway or N3IWF device, a non-trusted wireless local area network (WLAN) access point (AP), a switch, a router. The trusted non-3GPP access network device includes but is not limited to: a trusted non-3GPP access gateway, a trusted WLAN AP, a switch, a router. The wired access network device includes but is not limited to: a wireline access gateway, a fixed telephone network device, a switch, a router.
[0096] The access network device and the terminal device can be fixed in position or mobile. The access network device and the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on the water surface; can also be deployed on aircraft, balloons and artificial satellites in the air. The embodiments of the present application do not limit the application scenarios of the access network device and the terminal device.
[0097] The AMF network element contains functions such as performing mobility management, access authentication / authorization, etc. In addition, it is also responsible for transferring user policies between the terminal device and the PCF network element.
[0098] The SMF network element contains functions such as performing session management, executing control policies issued by the PCF network element, selecting a UPF network element or allocating an internet protocol (IP) address of the terminal device, etc.
[0099] The UPF network element contains functions such as completing user plane data forwarding, session / stream level-based charging statistics or bandwidth limitation, etc.
[0100] The UDM network element contains functions such as performing management of subscription data or user access authorization, etc.
[0101] The UDR contains functions such as accessing different types of data such as subscription data, policy data or application data, etc.
[0102] NEF network element, used to support the opening of capabilities and events.
[0103] AF network element, delivering application-side requirements for network-side, such as QoS requirements or user state event subscription, etc. The AF can be a third-party functional entity, or an application service deployed by an operator, such as an IP Multimedia Subsystem (IMS) voice call service. Among them, the AF network element includes an AF network element in the core network (i.e. an AF network element of an operator) and a third-party AF network element (such as an application server of an enterprise).
[0104] PCF network element, containing policy control functions responsible for charging, QoS bandwidth guarantee, and mobility management or terminal device policy decision at the session and service flow level. The PCF network element includes an access and mobility management policy control function (AM PCF) network element and a session management PCF (SM PCF) network element. Among them, the AM PCF network element is used to formulate AM policies and user policies for terminal devices, and the AM PCF network element can also be referred to as a policy control network element for a UE (PCF for a UE). The SM PCF network element is used to formulate session management policies (SM policies) for sessions, and the SM PCF network element can also be referred to as a policy control network element for a PDU session (PCF for a PDU session).
[0105] NRF network element, which can be used to provide network element discovery functions, and provide network element information corresponding to a network element type based on a request of another network element. The NRF network element also provides network element management services, such as network element registration, update, deregistration, and network element state subscription and push, etc.
[0106] AUSF network element, responsible for authenticating users to determine whether to allow users or devices to access the network.
[0107] DN is a network located outside the operator network, the operator network can access multiple DN, and multiple services can be deployed on the DN, which can provide data and / or voice services for terminal devices. For example, the DN is a private network of a certain intelligent factory, the sensors installed in the workshop of the intelligent factory can be terminal devices, and the control server of the sensors is deployed in the DN, which can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions, etc. For another example, the DN is an internal office network of a certain company, the mobile phones or computers of the employees of the company can be terminal devices, and the mobile phones or computers of the employees can access information and data resources on the internal office network of the company.
[0108] In FIG. 1, Npcf, Nudr, Nudm, Naf, Namf and Nsmf are service interfaces provided by the PCF network element, the UDR network element, the UDM network element, the AF network element, the AMF network element and the SMF network element respectively, which are used to call corresponding service operations. N1, N2, N3, N4 and N6 are interface serial numbers, and the meanings of these interface serial numbers are as follows:
[0109] 1) N1: the interface between the AMF network element and the terminal device, which can be used to transmit non-access stratum (NAS) signaling (such as QoS rules from the AMF network element) to the terminal device, etc.
[0110] 2) N2: the interface between the AMF network element and the access network device, which can be used to transmit radio bearer control information from the core network side to the access network device, etc.
[0111] 3) N3: the interface between the access network device and the UPF network element, which is mainly used to transmit uplink and downlink user plane data between the access network device and the UPF network element.
[0112] 4) N4: the interface between the SMF network element and the UPF network element, which can be used to transmit information between the control plane and the user plane, including the downlink of the forwarding rules, QoS rules, traffic statistics rules, etc. from the control plane to the user plane, and the information reporting of the user plane.
[0113] 5) N6: the interface between the UPF network element and the DN, which is used to transmit uplink and downlink user data flow between the UPF network element and the DN.
[0114] FIG. 2 is a schematic diagram of a 5G network architecture based on a point-to-point interface. The functions of the network elements in FIG. 2 can refer to the functions of the corresponding network elements in FIG. 1, and will not be described in detail. The main difference between FIG. 2 and FIG. 1 is that the interfaces between the control plane network elements in FIG. 1 are service interfaces, and the interfaces between the control plane network elements in FIG. 2 are point-to-point interfaces.
[0115] In the architecture shown in Figure 2, the interface names and functions between various network elements are as follows:
[0116] 1) The meanings of N1, N2, N3, N4 and N6 interfaces can be referred to the foregoing description.
[0117] 2) N5: The interface between the AF network element and the PCF network element, which can be used for application service request issuance and network event reporting.
[0118] 3) N7: The interface between the PCF network element and the SMF network element, which can be used for issuing PDU session granularity and service data flow granularity control policies.
[0119] 4) N8: The interface between the AMF network element and the UDM network element, which can be used for the AMF network element to obtain access and mobility management related subscription data and authentication data from the UDM network element, and for the AMF network element to register terminal device mobility management related information to the UDM network element, etc.
[0120] 5) N9: The user plane interface between UPF network elements, which is used to transfer uplink and downlink user data flows between UPF network elements.
[0121] 6) N10: The interface between the SMF network element and the UDM network element, which can be used for the SMF network element to obtain session management related subscription data from the UDM network element, and for the SMF network element to register terminal device session related information to the UDM, etc.
[0122] 7) N11: The interface between the SMF network element and the AMF network element, which can be used to transfer PDU session tunnel information between the access network device and the UPF network element, to transfer control messages sent to the terminal device, to transfer radio resource control information sent to the access network device, etc.
[0123] 8) N15: The interface between the PCF network element and the AMF network element, which can be used to issue terminal device policies and access control related policies.
[0124] 9) N35: The interface between the UDM network element and the UDR network element, which can be used for the UDM network element to obtain user subscription data information from the UDR network element.
[0125] 10) N36: The interface between the PCF network element and the UDR network element, which can be used for the PCF network element to obtain policy related subscription data and application data related information from the UDR network element.
[0126] Figure 3 is a schematic diagram of an architecture in which AKMA related functions are added to a 5G network. This Figure 3 is an architecture in which AKMA related functions are added to the 5G architecture shown in Figure 1, and of course AKMA related functions can also be added to the 5G architecture shown in Figure 2, and the principle is similar and will not be repeated here.
[0127] Figure 3 introduces a new AAnF network element, which can request the AKMA root key (i.e., K) from the AUSF network element. AKMA Then, the AAnF network element is based on K AKMA Determine the application key (i.e., K) used by the AF network element. AF ) and K AF The effective time.
[0128] In the AKMA scenario shown in Figure 3, the AF network element obtains K from the AAnF network element through interaction with the AAnF network element. AF and K AF The effective time. AF network elements can be located inside or outside the 5G core network. If the AF network element is inside the 5G core network, it can directly interact with the PCF network element. If the AF network element is outside the 5G core network, it can interact with the PCF network element via the NEF network element; that is, the NEF network element acts as an intermediate network element between the AF network element and the PCF network element.
[0129] In the AKMA scenario shown in Figure 3, the AUSF network element supports authentication (also known as authorization) for both 3GPP and non-3GPP access, and can generate K for the AAnF network element. AKMA .
[0130] In the AKMA scenario shown in Figure 3, the AF network element can obtain services from the AAnF network element. For example, the AF network element can interact with the AAnF network element to obtain K... AF and K AF The effective time.
[0131] In the AKMA scenario shown in Figure 3, Ua* is a reference point between the UE and the AF network element, used for message interaction between the UE and the AF network element, and can support key generation in the AKMA process.
[0132] It is understood that the aforementioned network element or function can be a network component in a hardware device, a software function running on dedicated hardware, or a virtualized function instantiated on a platform (e.g., a cloud platform). Optionally, the aforementioned network element or function can be implemented by one device, multiple devices working together, or a functional module within a single device; this application embodiment does not specifically limit this.
[0133] For ease of illustration, the embodiments of the present application are described taking the UE as an example of the terminal device, and the UE described below can be replaced by the terminal device. In addition, the AUSF network element, the UDM network element, the AAnF network element, the AF network element, the NEF network element, the NRF network element, and the SMF network element are simply referred to as AUSF, UDM, AAnF, AF, NEF, NRF, and SMF respectively in the embodiments of the present application.
[0134] FIG. 4 is a schematic diagram of a method for generating the K AKMA The method includes the following steps:
[0135] In step 401, the AUSF sends an authentication request message to the UDM in a primary authentication procedure. Correspondingly, the UDM receives the authentication request message.
[0136] The authentication request message includes a subscription permanent identifier (SUPI) or a subscription concealed identifier (SUCI), and is used to request an authentication vector from the UDM, where the authentication vector is used to trigger the primary authentication between the core network and the UE.
[0137] For example, the authentication request message can be a Nudm_UEAuthentication Get Request message.
[0138] In the embodiments of the present application, the primary authentication procedure is also referred to as a primary authentication procedure, which is uniformly described here and will not be described in detail.
[0139] In step 402, the UDM sends an authentication response message to the AUSF. Correspondingly, the AUSF receives the authentication response message.
[0140] The authentication response message includes an authentication vector.
[0141] If the UDM determines that the UE supports the AKMA service according to the subscription information of the UE, the authentication response message further includes AKMA indication information. The UE supporting the AKMA service means that the UE has AKMA capability and the service of the UE can use the AKMA. The AKMA indication information is used to trigger the AUSF to generate the K AKMA .
[0142] In this application, AKMA service refers to a service or service that provides security protection between the UE and AF based on a key generated by AKMA. Specifically, it can be an application session or application service between the UE and AF. AKMA service can be implemented through an application session / connection / link established between the UE and AF. The AKMA service in this application embodiment can also be referred to as AKMA service; this will be used consistently here, and will not be repeated in other embodiments.
[0143] Optionally, the authentication response message may also include a routing identifier (RID), which is used to select AAnF, meaning that AAnF can be selected based on the RID.
[0144] For example, the authentication response message can be a Num_UEAuthentication_Get Response message.
[0145] Step 403: If AUSF receives AKMA instruction information from UDM, then after the main authentication process is successfully completed, AUSF will use the AUSF root key (K... AUSF Generate K AKMA And AKMA key identifier (A-KID).
[0146] A-KID is used to identify K. AKMA .
[0147] A-KID is the Network Access Identifier (NAI) format, i.e., username@example. The username portion includes the RID and the AKMA Temporary UE Identifier (A-TID). The RID is part of SUCI and is represented by 1 to 4 decimal digits. The A-TID is based on K... AUSF A temporary identifier is generated. The example part includes the Home Network Identifier, which can specifically be the identification information of the Home Public Land Mobile Network (HPLMN ID). The Home Public Land Mobile Network is also called the Home Public Land Mobile Network or the Home Location Public Land Mobile Network.
[0148] Accordingly, after the main authentication process, the UE also follows the same method as AUSF, based on K. AUSF Generate K AKMA And A-KID.
[0149] At step 404, the AUSF selects an AAnF and sends a key registration request message to the selected AAnF. Correspondingly, the AAnF receives the key registration request message.
[0150] The key registration request message includes SUPI, A-KID and K AKMA .
[0151] Exemplarily, the AUSF selects the AAnF according to the RID.
[0152] The key registration request message can be a Naanf_AKMA_AnchorKey_Register Request message.
[0153] At step 405, the AAnF sends a key registration response message to the AUSF. Correspondingly, the AUSF receives the key registration response message.
[0154] Exemplarily, the key registration response message can be a Naanf_AKMA_AnchorKey_RegisterResponse message.
[0155] It should be noted that the AAnF only saves the latest information sent by the AUSF. When re-authentication occurs, the AUSF sends a new A-KID and a new K AKMA to the AAnF. After that, the AAnF will delete the old A-KID and the old K AKMA , and save the new A-KID and the new K AKMA .
[0156] Through the above scheme, the UE and the AAnF save the same K AKMA , which facilitates the UE and the AAnF to use the K AKMA in subsequent processes.
[0157] FIG. 5 is a schematic diagram of a method for using K AKMA provided by an embodiment of the present application. In the method, the AF is a network element in the 3GPP core network or a network element outside the 3GPP core network. When the AF is a network element outside the 3GPP core network, the interactions between the AF and the AAnF involved below can be transferred through the NEF. Wherein, before step 501, the primary authentication process and the K AKMA generation process shown in the embodiment of FIG. 4 are completed. And, after the primary authentication process and the K AKMAAfter the generation procedure, and before step 501, the UE needs to complete registration and establish a PDU session for transmitting user plane data (e.g. AKMA service) between the UE and the AF. During the PDU session establishment procedure, the AF can obtain the IP address of the UE and the UE ID (e.g. GPSI). For example, after confirming that the PDU session authentication or authorization is successful, the AF requests the IP address of the UE for the current PDU session from the SMF, and the SMF provides the IP address of the UE and the UE ID (e.g. GPSI) to the AF. For details of this type of procedure, refer to 3GPP TS 23.502, section 4.3.2.3.
[0158] The method comprises the following steps:
[0159] Step 501, the UE sends an application session establishment request message to the AF. Correspondingly, the AF receives the application session establishment request message.
[0160] The application session establishment request message includes A-KID.
[0161] The A-KID is generated by the UE before step 501, in the K AKMA generation procedure. Wherein, the K AKMA The generation procedure can refer to the embodiment of FIG. 4.
[0162] Step 502, if there is no context related to the A-KID on the AF, the AF selects an AAnF and sends an application key request message to the AAnF. Correspondingly, the AAnF receives the application key request message.
[0163] The application key request message includes A-KID and AF ID. The A-KID comes from step 501. The AF ID is used to identify the AF. The AF ID can be used as an input parameter when calculating K AF to achieve key isolation between different AFs.
[0164] Wherein, the AF can select the AAnF according to the RID.
[0165] For example, the application key request message can be Naanf AKMA ApplicationKey Get Request message, or Naanf AKMA ApplicationKey AnonUser Get service message.
[0166] At step 503, optionally, the AAnF sends a request message to the UDM according to a local rule when the AAnF determines that the AF needs a generic public subscription identity (GPSI). Correspondingly, the UDM receives the request message.
[0167] The request message is used to request the GPSI of the UE. Illustratively, the request message can carry the SUPI of the UE to request the GPSI corresponding to the SUPI.
[0168] Illustratively, the request message can be an Nudm_SDM_Get Request message.
[0169] At step 504, optionally, the UDM sends a response message to the AAnF. Correspondingly, the AAnF receives the response message.
[0170] The response message includes the GPSI of the UE. The AAnF stores the GPSI as the AKMA context of the UE.
[0171] It should be noted that if the AAnF determines according to a local rule that the AF does not need the GPSI, steps 503 to 504 do not need to be performed.
[0172] Illustratively, the response message can be an Nudm_SDM_Get Response message.
[0173] At step 505, optionally, the AAnF sends a subscription request message to the UDM. Correspondingly, the UDM receives the subscription request message.
[0174] The subscription request message includes the SUPI or the GPSI of the UE, and the subscription request message is used to subscribe to the roaming status report or the roaming status information of the UE.
[0175] Illustratively, the subscription request message can be an Nudm_EventExposure_Subscribe Request message.
[0176] At step 506, optionally, the UDM sends a subscription response message to the AAnF. Correspondingly, the AAnF receives the subscription response message.
[0177] The subscription response message includes the roaming status information of the UE.
[0178] The roaming status information includes the public land mobile network (PLMN) information of the UE registration, and optionally, the roaming status information further includes indication information used to indicate whether the PLMN is a home network.
[0179] In the single registration scenario, the PLMN information registered by the UE can be referred to as the information of the first network. In the dual registration scenario, the PLMN information registered by the UE includes the identities of two PLMNs, which can also be referred to as the information of the first network and the information of the second network, respectively.
[0180] Subsequently, if the roaming information of the UE changes, the UDM sends a notification message to the AAnF, where the notification message carries the changed roaming state information.
[0181] Exposure_Subscribe Response message.
[0182] Step 507: The AAnF obtains K AKMA according to the A-KID, generates K AKMA according to the K AF and the AF ID, and determines the validity time of the K AF .
[0183] The AAnF obtains the A-KID and the K AKMA corresponding to the A-KID in the primary authentication process and the K AKMA generation process, and stores the A-KID and the K AKMA locally.
[0184] Step 508: The AAnF sends an application key response message to the AF. Correspondingly, the AF receives the application key response message.
[0185] The application key response message includes the K AF and the validity time of the K AF .
[0186] Exposure_Get Response message.
[0187] In one implementation method, when the application key request message in step 502 is a Naanf_AKMA_ApplicationKey_Get_Request message, the application key response message can carry the SUPI or the GPSI. When the application key request message in step 502 is a Naanf_AKMA_ApplicationKey_AnonUser_Get service message, the application key response message does not carry the SUPI or the GPSI.
[0188] At step 509, the AF sends an application session establishment response message to the UE. Accordingly, the UE receives the application session establishment response message.
[0189] It should be noted that the UE generates the K AKMA in any step after the generation process, and the K AF is generated in the same way as the AAnF. AF The validity time of the K AKMA is also determined.
[0190] In the above scheme, the UE and the AAnF determine the same K AF and the validity time of the K AF according to the K AF , and the AAnF sends the K AF and the validity time of the K AF to the AF. Subsequently, the K AF can be used to protect the transmission content between the UE and the AF, which helps to improve the communication security.
[0191] In the roaming scenario, there may be a scenario where AKMA service is not allowed. The AAnF can determine whether to allow AKMA service according to local configuration and UE roaming state information. The following is described.
[0192] FIG. 6 is a schematic diagram of an AKMA service closing method provided by an embodiment of the present application. The embodiment is for the scenario where no re-authentication (or re-authentication) occurs between the UE and the core network. The method includes the following steps:
[0193] At step 601, the UE registers with a first network.
[0194] For example, the first network can be a home public land mobile network (HPLMN).
[0195] At step 602, the UE accesses the AF, the AF obtains the K AF , and the AF provides a uniform resource identifier (URI) for service closing to the AAnF.
[0196] The specific process of the AF obtaining the K AF may refer to the method embodiment of FIG. 5, i.e., steps 501 to 509.
[0197] The URI is used for the AAnF to find the AF that needs to close the AKMA service. For example, the URI can be the IP address of the AF.
[0198] At step 603, the AAnF receives a notification message from the UDM, and the notification message includes roaming state information of the UE. According to the roaming state information of the UE, the AAnF discovers that the network registered by the UE has changed.
[0199] For example, the network registered by the UE changes from being registered to a first network to being registered to a second network, or changes from being registered to the first network to being registered to both the first network and the second network.
[0200] The first network can be a network connected by the UE through a 3GPP access mode or a network connected by the UE through a non-3GPP access mode.
[0201] The second network can be a network connected by the UE through a 3GPP access mode or a network connected by the UE through a non-3GPP access mode.
[0202] At step 604, the AAnF determines that the AF provides a URI for service closure, and a local rule shows that the UE cannot use AKMA service in the second network.
[0203] At step 605, the AAnF sends an AKMA service closure notification message to the AF. Correspondingly, the AF receives the AKMA service closure notification message.
[0204] The AKMA service closure notification message carries first information associated with the AKMA service of the UE. The AKMA service closure notification message is used to instruct the AF to close the AKMA service of the UE corresponding to the first information.
[0205] The first information includes one or more of the following information:
[0206] (1) A-KID.
[0207] (2) A second identifier of the UE. The second identifier of the UE is different from a first identifier of the UE. For example, the first identifier of the UE is SUPI, and the second identifier of the UE is GPSI. For another example, the first identifier of the UE is GSPI, and the second identifier of the UE is SUPI. The AAnF stores a corresponding relationship between the first identifier of the UE and the second identifier of the UE.
[0208] (3) A context ID. The context ID is used to indicate a context of a connection between the AAnF and the AF. The context ID can be generated by the AAnF.
[0209] Exemplarily, the AKMA service close notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0210] The AF stops or closes the AKMA service of the UE according to the first information.
[0211] The specific implementation method of the AF closing the AKMA service of the UE is described below.
[0212] Case one, the first information includes an A-KID.
[0213] For this case, the AF can pre-store a correspondence relationship between the A-KID and the AKMA service of the UE, and the AF can determine the AKMA service of the UE corresponding to the A-KID according to the correspondence relationship.
[0214] For this case, the AF can also pre-store a correspondence relationship between the A-KID and the application key, and a correspondence relationship between the application key and the AKMA service of the UE, and the AF can determine the application key corresponding to the A-KID according to the correspondence relationship between the A-KID and the application key, and then determine the AKMA service of the UE corresponding to the application key according to the correspondence relationship between the application key and the specific AKMA service.
[0215] Case two, the first information includes a second identifier of the UE.
[0216] For this case, the AF can pre-store a correspondence relationship between the second identifier of the UE and the AKMA service of the UE, and the AF can determine the AKMA service of the UE corresponding to the second identifier of the UE according to the correspondence relationship.
[0217] For this case, the AF can also pre-store a correspondence relationship between the second identifier of the UE and the A-KID and / or the application key, and a correspondence relationship between the A-KID and / or the application key and the AKMA service of the UE, and the AF can determine the A-KID and / or the application key corresponding to the second identifier of the UE according to the correspondence relationship between the second identifier of the UE and the A-KID and / or the application key, and then determine the AKMA service of the UE corresponding to the A-KID and / or the application key according to the correspondence relationship between the A-KID and / or the application key and the AKMA service of the UE.
[0218] Case three, the first information includes a context identifier.
[0219] For this case, the AF can pre-store a correspondence relationship between the context identifier and the AKMA service of the UE, and the AF can determine the AKMA service of the UE corresponding to the context identifier according to the correspondence relationship.
[0220] In this case, the AF can also pre-store the correspondence between the context identifier and the A-KID and / or application key, and the correspondence between the A-KID and / or application key and the AKMA service of the UE. The AF can determine the A-KID and / or application key corresponding to the context identifier according to the correspondence between the context identifier and the A-KID and / or application key, and then determine the AKMA service of the UE corresponding to the A-KID and / or application key according to the correspondence between the A-KID and / or application key and the AKMA service of the UE.
[0221] In the embodiments of the application, the AF closes the AKMA service, which can be one or more of the following operations: deleting a connection, a link or a session related to the AKMA service; deleting a context related to the AKMA service; deleting cached data or signaling related to the AKMA service; or sending a connection, link or session release message to the UE for disconnecting the connection, link or session with the UE.
[0222] In step 606, the AF sends an AKMA service closing response message to the AAnF. Correspondingly, the AAnF receives the AKMA service closing response message.
[0223] Exemplarily, the AKMA service closing response message can be a Naanf_AKMA_ServiceDisableNotification response message.
[0224] In the above scheme, when the UE changes from being registered to a first network to being registered to a second network, and the UE cannot use the AKMA service in the second network, the AAnF notifies the AF to close the AKMA service of the UE related to the A-KID.
[0225] FIG. 7 is a schematic diagram of another method for closing an AKMA service provided by an embodiment of the application. The method is for the scenario that the registration network of the UE changes and the UE undergoes at least two authentications, that is, the UE and the core network undergo re-authentication (or re-authentication). The method includes the following steps:
[0226] In step 701, a primary authentication process and K AKMA generation process are performed.
[0227] For specific implementation process of step 701, reference is made to steps 401 to 405 of the embodiment of FIG. 4.
[0228] In this process, the UE is registered to a first network, and after primary authentication, the registration process in the first network is completed. In the embodiments of the application, the K AKMA and A-KID generated by the AUSF are referred to as K AKMA #1 and A-KID#1.
[0229] At step 702, the UE sends an application session establishment request message to the AF, triggering the AF to obtain K AF and K AF from the AAnF corresponding to A-KID#1.
[0230] The specific implementation process of this step 702 can refer to steps 501 to 509 of the embodiment of FIG. 5.
[0231] At step 703, the UE performs primary authentication with the core network again, and the AUSF sends a key registration request message to the AAnF. Correspondingly, the AAnF receives the key registration request message.
[0232] The key registration request message includes SUPI, A-KID#2 and K AKMA #2. The A-KID#2 and K AKMA #2 are generated by the AUSF, and the UE also generates the same A-KID#2 and K AKMA #2.
[0233] The key registration request message can be a Naanf_AKMA_Key_Register Request message.
[0234] The scenario in which the UE performs primary authentication with the core network again includes any one of the following:
[0235] Scenario one, the UE moves from a first network to a second network for access (such as N2 handover), that is, the UE still maintains single registration.
[0236] Scenario two, the UE is registered to a first network through a first access method (such as 3GPP access), and the UE is also registered to a second network through a second access method (such as non-3GPP access), that is, the UE performs dual registration.
[0237] At step 704, the AAnF sends a key registration response message to the AUSF. Correspondingly, the AUSF receives the key registration response message.
[0238] Exemplarily, the key registration response message can be a Naanf_AKMA_AnchorKey_RegisterResponse message.
[0239] It should be noted that the AAnF only saves the latest information sent by the AUSF, so when the primary authentication occurs again (also referred to as secondary primary authentication, re-authentication, secondary authentication or re-authentication), the AUSF sends A-KID#2 and K AKMA #2 to the AAnF, and the AAnF deletes the old A-KID and K AKMAi.e. A-KID#1 and K AKMA #1, and save the new A-KID and K AKMA i.e. A-KID#2 and K AKMA #2.
[0240] At step 705, the UDM sends a notification message to the AAnF. Correspondingly, the AAnF receives the notification message.
[0241] The notification message carries UE ID and roaming status information, wherein the UE ID can be SUPI or SUCI, etc.
[0242] In the single registration scenario, the roaming status information includes the information of the second network. In the dual registration scenario, the roaming status information includes the information of the first network and the information of the second network.
[0243] Exemplarily, the notification message can be Nudm_EventExposure_Notification message.
[0244] At step 706, the AAnF determines that the AF provides a URI for service closing, and the local rule shows that the UE cannot use AKMA service in the second network.
[0245] At step 707, the AAnF sends an AKMA service closing notification message to the AF. Correspondingly, the AF receives the AKMA service closing notification message.
[0246] The AKMA service closing notification message carries A-KID#1, which is used to identify the AKMA key (e.g. K AF ) that cannot be used.
[0247] Exemplarily, the AKMA service closing notification message can be Naanf_AKMA_ServiceDisableNotification message.
[0248] At step 708, the AF sends an AKMA service closing response message to the AAnF. Correspondingly, the AAnF receives the AKMA service closing response message.
[0249] Exemplarily, the AKMA service closing response message can be Naanf_AKMA_ServiceDisableNotification response message.
[0250] The AF receives A-KID#2, and stops or closes the AKMA service of the UE corresponding to A-KID#1.
[0251] The above scheme, when the UE changes from being registered to the first network to being registered to the second network or changes to being registered to the first network and the second network at the same time, if the UE cannot use AKMA services in the second network, the AAnF notifies the AF to close the AKMA services of the UE. For this scheme, when the UE cannot use AKMA services in the second network, the AAnF notifies the AF to close the AKMA services of the UE, that is, all AKMA services on the network registered by the UE are closed, but in fact the UE can use AKMA services in the first network, so this scheme may cause unnecessary interruption of the AKMA services of the UE, affecting the user experience.
[0252] To solve the above problems, the embodiments of the present application provide corresponding solutions. The embodiments of the present application provide a management method of AKMA services to realize correct management of AKMA services, thereby improving user experience. It should be understood that the present application is proposed for the case of re-authentication, but is not limited to the use of the re-authentication scenario, such as the single registration scenario, which can also use the way of the present application.
[0253] The "first device" in the present application can refer to the AF, or a component (for example, a communication module, a processor, a circuit, a chip, or a chip system, etc.) in the AF, or a logical module or software capable of realizing all or part of the AF function. The "second device" in the present application can refer to the AAnF, or a component (for example, a communication module, a processor, a circuit, a chip, or a chip system, etc.) in the AAnF, or a logical module or software capable of realizing all or part of the AAnF function. The "third device" in the present application can refer to the UE, or a component (for example, a communication module, a processor, a circuit, a chip, or a chip system, etc.) in the UE, or a logical module or software capable of realizing all or part of the UE function. For ease of illustration, the AF, the AAnF, and the UE in any embodiment of the present application are taken as one example of the first device, the second device, and the third device, respectively, and the AF, the AAnF, and the UE appearing anywhere later can be replaced by the first device, the second device, and the third device, respectively. Here, it is uniformly explained, and the rest will not be repeated.
[0254] FIG. 8(a) is a flow diagram of a management method of AKMA services provided by an embodiment of the present application.
[0255] Wherein, before step 801a, at least one session has been established between the UE and the AF, for example, a first session and a second session are established, and each of the at least one session is used to carry one or more application sessions, the application session refers to an application layer session, and the application session is used to transmit AKMA service between the UE and the AF. For example, the first session is used to carry an application session #1 between the UE and the AF, and the application session #1 is used to transmit first AKMA service between the UE and the AF, in this case, it can also be understood that the first session is used to transmit the first AKMA service, that is, the first session is used to transmit user plane data of the first AKMA service. The second session is used to carry an application session #2 between the UE and the AF, and the application session #2 is used to transmit second AKMA service between the UE and the AF, in this case, it can also be understood that the second session is used to transmit the second AKMA service, that is, the second session is used to transmit user plane data of the second AKMA service.
[0256] Wherein, the at least one session herein can be a PDU session or other types of sessions, which are not limited by embodiments of the present application. Each session is transmitted through a network. For example, in a single registration scenario, the UE registers to one network (for example, a network connected through a 3GPP access method or a network connected through a non-3GPP access method), and at least one session of the UE is transmitted in the same network. For another example, in a dual registration scenario, the UE registers to two networks (for example, one is a network connected through a 3GPP access method, and the other is a network connected through a non-3GPP access method), and different sessions can be transmitted in different networks, and different sessions can also be transmitted in the same network, which is not limited by the present application.
[0257] The method comprises the following steps:
[0258] Step 801a, the AAnF sends an AKMA service closing notification message to the AF. Correspondingly, the AF receives the AKMA service closing notification message.
[0259] The AKMA service closing notification message comprises information of the first network (for example, PLMN ID #1), and the AKMA service closing notification message is used to notify the closing of AKMA service of the first network. For example, the AAnF determines that the UE cannot use AKMA service in the first network, and then sends the AKMA service closing notification message to the AF.
[0260] In a single registration scenario, the UE registers to the first network. The meaning of the AKMA service closing notification message comprising information of the first network is that the UE cannot use AKMA service in the first network.
[0261] In the dual registration scenario, the UE is registered to the first network and the second network. The meaning of the AKMA service closing notification message including the information of the first network can be that the UE cannot use the AKMA service in the first network, and the UE can use the AKMA service in the second network.
[0262] Exemplarily, as another implementation method, in the dual registration scenario, if the UE cannot use the AKMA service in the first network, the AAnF determines that the UE cannot use the AKMA in the first network and the second network. Accordingly, the AAnF sends the AKMA service closing notification message to the AF, which carries the information of the first network and the information of the second network (for example, PLMN ID#2), or does not carry the information of the first network and the information of the second network. When the AKMA service closing notification message carries the information of the first network and the information of the second network, the AKMA service closing notification message explicitly indicates to close the AKMA service in the first network and the second network. When the AKMA service closing notification message does not carry the information of the first network and the information of the second network, the AKMA service closing notification message implicitly indicates to close the AKMA service in the first network and the second network.
[0263] At step 802a, the AF obtains information of a current network corresponding to a first session of the UE.
[0264] The information of the current network corresponding to the first session can be a PLMN ID, such as PLMN ID#1 or PLMN ID#2, etc.
[0265] Exemplarily, the step 802a can be specifically that the AF sends a first subscription request message to the SMF, the first subscription request message being used to subscribe to network change corresponding to the first session. Then the SMF can send a notification message to the AF, and the AF determines the information of the current network corresponding to the first session according to the notification message.
[0266] The first session is used to transmit a first AKMA service between the UE and the AF. Exemplarily, an application session is established between the UE and the AF, the application session is used to transmit the first AKMA service between the UE and the AF, the application session is carried on a first session, and the first session is, for example, a PDU session. The first AKMA service is part or all of the AKMA service in the application session.
[0267] Optionally, the first subscription request message can include one or more of information of the first session, an identifier of the UE, or a first event identifier. The information of the first session includes, for example, an identifier and / or an IP address of the first session, etc. The identifier of the UE can be a SUPI or a GPSI, etc. The first event identifier is used to indicate a network change event, for example, the first event identifier is specifically a PLMN change event ID.
[0268] As an implementation method, after obtaining the information of the first session, the AF sends the first subscription request message to the SMF. That is, the AF actively subscribes to the SMF for the change of the network corresponding to the first session after obtaining the information of the first session.
[0269] As another implementation method, in the application key generation process shown in the foregoing FIG. 5, the application key response message in step 508 also carries an indication information, which is used to indicate the network to which the application key (i.e., K AF ) is applicable or not applicable. Then, the AF sends the first subscription request message to the SMF based on the indication information. In this implementation method, the step 802a can be performed before the step 801a. Specifically, when the AF receives the indication information indicating that in the UE dual registration scenario, the application key can be used in one of the networks to which the UE is registered, and cannot be used in the other network, that is, the UE can use the AKMA service in one of the networks, and cannot use the AKMA service in the other network. Therefore, the AF needs to pay attention to which network the first session corresponding to the AKMA service between the UE and the AF is transmitted in. In order to know which network the first session corresponds to, the AF sends the first subscription request message to the SMF.
[0270] As another implementation method, in the case that the AKMA service closing notification message received by the AF in the step 801a carries the information of the first network, the AF sends the first subscription request message to the SMF.
[0271] In an implementation method, after the AF sends the first subscription request message to the SMF, the SMF sends a response message, also referred to as a second notification message, to the AF. The second notification message carries the information of the second network, and indicates that the network corresponding to the first session is the second network. The AF determines that the current network corresponding to the first session is the second network according to the second notification message. Exemplarily, the second notification message further includes one or more of the information of the first session, the identifier of the UE, or the first event identifier.
[0272] In another implementation method, after sending the foregoing second notification message, if the network corresponding to the first session changes, for example, changes from the second network to the first network, the SMF notifies the AF of the change of the network corresponding to the first session. For example, the SMF sends a first notification message to the AF, where the first notification message carries the information of the first network, and indicates that the network corresponding to the first session changes to the first network. Exemplarily, the first notification message further includes one or more of the information of the first session, the identifier of the UE, or the first event identifier.
[0273] Therefore, the AF can know the information of the current network corresponding to the first session of the UE by subscribing to the network change corresponding to the first session to the SMF.
[0274] It should be noted that the AF can also determine the information of the current network corresponding to the first session in other ways, for example, the UE actively sends the information of the current network corresponding to the first session to the AF, or the AF requests the information of the current network corresponding to the first session from the UE, etc. The application does not limit the way the AF obtains the information of the current network corresponding to the first session.
[0275] The application does not limit the order between step 801a and step 802a.
[0276] In step 803a, the AF determines whether to close the first AKMA service according to the AKMA service closing notification message and the information of the current network corresponding to the first session.
[0277] The application embodiment takes the current network corresponding to the first session as the first network or the second network as an example for description. The first network and the second network are different. For example, the first network is a network connected by the UE through a 3GPP access mode, and the second network is a network connected by the UE through a non-3GPP access mode; or the first network is a network connected by the UE through a non-3GPP access mode, and the second network is a network connected by the UE through a 3GPP access mode.
[0278] The following describes different cases.
[0279] Case one, the UE cannot use the AKMA service in the first network, and the UE can use the AKMA service in the second network.
[0280] According to the foregoing description, when the AKMA service closing notification message carries the information of the first network, it indicates that the UE cannot use the AKMA service in the first network, and the UE can use the AKMA service in the second network.
[0281] In an implementation method, in a case that the current network corresponding to the first session is the second network, the AF does not close the first AKMA service. Specifically, when the current network corresponding to the first session of the UE is the second network, the first AKMA service carried by the first session is transmitted in the second network, and the UE can use the AKMA service in the second network, therefore the AF does not close the first AKMA service between the UE and the AF. The scenario can refer to the example diagram of FIG. 9(a). Further, if there is also a second session and the current network corresponding to the second session is the first network, the AF closes the second AKMA service. The second session is used to carry an application session between the UE and the AF, and the application session is used to transmit the second AKMA service between the UE and the AF. The scenario can refer to the example diagram of FIG. 9(b), in which the AF does not close the first AKMA service but closes the second AKMA service.
[0282] In another implementation method, in a case that the current network corresponding to the first session is the first network, the AF closes the first AKMA service. Specifically, when the current network corresponding to the first session of the UE is the first network, the first AKMA service carried by the first session is transmitted in the first network, and the UE cannot use the AKMA service in the first network, therefore the AF closes the first AKMA service between the UE and the AF. The scenario can refer to the example diagram of FIG. 9(c). Further, if there is also a second session and the current network corresponding to the second session is the second network, the AF does not close the second AKMA service. The second session is used to carry an application session between the UE and the AF, and the application session is used to transmit the second AKMA service between the UE and the AF. The scenario can refer to the example diagram of FIG. 9(d), in which the AF closes the first AKMA service but does not close the second AKMA service.
[0283] Scenario two, the UE cannot use the AKMA service in the first network and the second network.
[0284] According to the foregoing description, when the AKMA service closing notification message carries the information of the first network and the information of the second network, or the AKMA service closing notification message does not carry the information of the first network and the information of the second network, it indicates that the UE cannot use the AKMA service in the first network and the second network.
[0285] In an implementation method, in a case that the current network corresponding to the first session is the first network or the second network, the AF closes the first AKMA service. Specifically, since the UE cannot use the AKMA service in the first network and the second network, the first AKMA service carried by the first session cannot continue regardless of whether the current network corresponding to the first session is the first network or the second network, and thus the AF closes the first AKMA service. Similarly, if a second session further exists, in a case that the current network corresponding to the second session is the first network or the second network, the AF closes the second AKMA service, where the second session is used to transmit the second AKMA service between the UE and the AF.
[0286] In the embodiments of the present application, the AF closes the AKMA service, for example, closes the first AKMA service or the second AKMA service, which can be one or more of the following operations: deleting a connection, a link or a session related to the AKMA service; deleting a context related to the AKMA service; deleting cached data or signaling related to the AKMA service; or sending a connection, link or session release message to the UE for disconnecting the connection, link or session with the UE.
[0287] Based on the above scheme, the AF can obtain the information that the UE does not allow the network to perform the AKMA service, and obtain the information of the current network corresponding to the session used to carry the AKMA service between the UE and the AF, and then accurately determine whether the AKMA service between the UE and the AF can be performed, and decide whether to close the AKMA service, thereby achieving the network granularity management of the AKMA service, and helping to improve the user experience. Compared with the scheme that the AKMA service of all the networks registered by the UE is always closed as long as the UE does not allow the AKMA service in a certain network, the present application can achieve the closing of the AKMA service based on the network granularity, and can avoid the interruption of the AKMA service as much as possible.
[0288] FIG. 8(b) is a flow diagram of an AKMA service management method provided by an embodiment of the present application. The method includes the following steps:
[0289] In step 801b, the UE sends an application session establishment request message to the AF. Correspondingly, the AF receives the application session establishment request message.
[0290] The application session establishment request message requests to establish an application session for transmitting the third AKMA service between the UE and the AF, and the application session is carried in the third session of the UE. The third session is used to transmit user plane traffic of the third AKMA service. Specifically, before step 801b, the UE has established a third session (for example, a PDU session), and then the UE sends the application session establishment request message to the AF to request to establish an application session for transmitting the AKMA service between the UE and the AF, which is carried in the third session.
[0291] In step 802b, the AF obtains information of a current network corresponding to the third session.
[0292] Exemplarily, step 802b can be specifically: the AF sends a second subscription request message to the SMF, and the second subscription request message is used to subscribe to a network change corresponding to the third session. Then the SMF can send a notification message to the AF, and the AF determines the information of the current network corresponding to the third session according to the notification message.
[0293] Exemplarily, the second subscription request message can include one or more of information of the third session, an identifier of the UE, or a second event identifier. The information of the third session includes, for example, an identifier and / or an IP address of the third session, and the like. The identifier of the UE can be SUPI or GPSI, and the like. The second event identifier is used to indicate a network change event, for example, the second event identifier is specifically a PLMN change event ID.
[0294] In an implementation method, after the AF sends the first subscription request message to the SMF, the SMF sends a response message, also referred to as a third notification message, to the AF, and the third notification message carries the information of the current network corresponding to the third session. The AF determines the information of the current network corresponding to the third session according to the third notification message.
[0295] In another implementation method, in the case that the network corresponding to the third session changes, the SMF notifies the AF that the current network corresponding to the third session changes. For example, the SMF sends a third notification message to the AF, the third notification message indicates that the current network corresponding to the third session changes, and the third notification message carries information of the changed network corresponding to the third session. Exemplarily, the third notification message also includes one or more of the information of the third session, the identifier of the UE, or the second event identifier.
[0296] Therefore, the AF can obtain the information of the current network corresponding to the third session of the UE by subscribing to the network change corresponding to the third session to the SMF.
[0297] It should be noted that the AF can also determine the information of the current network corresponding to the third session in other ways, for example, the UE actively sends the information of the current network corresponding to the third session to the AF, or the AF requests the information of the current network corresponding to the third session from the UE, etc. The application does not limit the way the AF obtains the information of the current network corresponding to the third session.
[0298] In step 803b, the AF determines whether to allow the establishment of the application session according to the information of the current network corresponding to the third session.
[0299] In one implementation method, in the case that the current network corresponding to the third session is the first network, the establishment of the application session is rejected, that is, the application session establishment request message is rejected. The first network is a network in which the UE cannot use AKMA services. Based on this scheme, the application session requested by the UE to establish is carried on the third session, and the current network corresponding to the third session is the first network in which the UE cannot use AKMA services. Therefore, the AF determines that the establishment of the application session is not allowed, and thus the establishment of the application session is rejected, which can correctly manage AKMA services.
[0300] In another implementation method, in the case that the current network corresponding to the third session is the second network, the establishment of the application session is allowed, that is, the application session establishment request message is allowed. The second network is a network in which the UE can use AKMA services. Based on this scheme, the application session requested by the UE to establish is carried on the third session, and the current network corresponding to the third session is the second network in which the UE can use AKMA services. Therefore, the AF determines that the establishment of the application session is allowed, which can correctly manage AKMA services.
[0301] For example, before step 803b, the AF receives an AKMA service closing notification message, which includes the information of the first network and does not include the information of the second network, and is used to indicate that the UE cannot use AKMA services in the first network. Therefore, the AF determines that the UE cannot use AKMA services in the first network and can use AKMA services in the second network.
[0302] Alternatively, the AF can also determine that the UE cannot use AKMA services in the first network and can use AKMA services in the second network through other methods. For example, the AMF, SMF, or UDM sends indication information to the AF, which is used to indicate the information of the network registered by the UE and the network in the registered network that allows the UE to access AKMA services.
[0303] Based on the above scheme, when the UE requests to establish an application session for transmitting AKMA service, the AF judges whether to allow the establishment of the application session according to the information of the current network corresponding to the third session carrying the application session and the networks in which the UE can use the AKMA service, thereby achieving network granularity management of the AKMA service and helping to improve user experience.
[0304] It should be noted that the above embodiment of FIG. 8(a) and the above embodiment of FIG. 8(b) can be combined for implementation, or can be implemented separately, and the present application does not limit this.
[0305] In the case that the embodiment of FIG. 8(a) is combined with the embodiment of FIG. 8(b), the embodiment of FIG. 8(b) can be executed after the embodiment of FIG. 8(a). For example, it is assumed that the third session in the embodiment of FIG. 8(b) is the same session as the first session in the embodiment of FIG. 8(a), which is referred to as the first session hereinafter. In the first case, in the embodiment of FIG. 8(a), the current network corresponding to the first session is the first network, and the first network is a network in which the UE cannot use AKMA service, the AF closes the first AKMA service. Further, after step 803a, the UE executes step 801b, that is, the UE sends an application session establishment request message to the AF, the application session establishment request message requests to establish an application session for transmitting a third AKMA service between the UE and the AF, and the application session is carried in the first session of the UE. Accordingly, in step 802b, the AF obtains the information of the network corresponding to the first session, which is the information of the first network. Accordingly, in step 803b, the AF determines not to allow the establishment of the application session according to the information of the network corresponding to the first session, that is, the information of the first network. This is because the first network is a network in which the UE cannot use AKMA service, and the application session requested to be established by the UE in step 801b is carried in the first session, the network corresponding to the first session is the first network, and therefore the AF does not allow the establishment of the application session in step 803b. In the second case, in the embodiment of FIG. 8(a), the current network corresponding to the first session is the second network, and the second network is a network in which the UE can use AKMA service, the AF does not close the first AKMA service. Further, after step 803a, the UE executes step 801b, that is, the UE sends an application session establishment request message to the AF, the application session establishment request message requests to establish an application session for transmitting a third AKMA service between the UE and the AF, and the application session is carried in the first session of the UE. Accordingly, in step 802b, the AF obtains the information of the network corresponding to the first session, which is the information of the second network. Accordingly, in step 803b, the AF determines to allow the establishment of the application session according to the information of the network corresponding to the first session, that is, the information of the second network. This is because the second network is a network in which the UE can use AKMA service, and the application session requested to be established by the UE in step 801b is carried in the first session, the network corresponding to the first session is the second network, and therefore the AF allows the establishment of the application session in step 803b. In addition, if the third session in the embodiment of FIG. 8(b) is the same session as the second session in the embodiment of FIG. 8(a), there is also a similar implementation method, which is not described herein.
[0306] FIG. 8(c) is a flow diagram of an AKMA service management method according to an embodiment of the present application. The method comprises the following steps:
[0307] At step 801c, the UE sends an application session establishment request message to the AF. Accordingly, the AF receives the application session establishment request message.
[0308] The application session establishment request message requests to establish an application session for transmitting AKMA service between the UE and the AF.
[0309] At step 802c, the AF sends an application session establishment response message to the UE. Accordingly, the UE receives the application session establishment response message.
[0310] The application session establishment response message indicates that the application session is successfully established.
[0311] After the application session is established, AKMA service can be transmitted between the UE and the AF, for example, in a single registration scenario, the AKMA service is transmitted through the registered network. In a dual registration scenario, the AKMA service is transmitted through the first network or the second network.
[0312] If the AAnF determines that the UE cannot use AKMA service in the first network, the following step 803c is performed.
[0313] At step 803c, the AAnF sends an AKMA service closing notification message to the UE. Accordingly, the UE receives the AKMA service closing notification message.
[0314] In an implementation method, the AKMA service closing notification message includes information of the first network, and the AKMA service closing notification message is used to notify the UE that AKMA service cannot be used in the first network. Based on the method, the AKMA service closing notification message carries information of the network in which the UE cannot use AKMA service among the networks in which the UE is registered. For example, the UE is registered to the first network and the second network, when the UE cannot use AKMA service in the first network, and can use AKMA service in the second network, the AKMA service closing notification message carries information of the first network.
[0315] In another implementation method, the AKMA service closing notification message includes roaming policy information, and the roaming policy information includes information of a network in which the UE cannot use the AKMA service, and the information of the network in which the UE cannot use the AKMA service includes information of the first network. Based on this implementation method, the AKMA service closing notification message carries information of a network in which the UE cannot use the AKMA service, and is not limited to information of a network in which the UE cannot use the AKMA service in the network in which the UE is registered. For example, the UE is registered to the first network and the second network, and the UE cannot use the AKMA service in the first network and the third network, and can use the AKMA service in the second network. The roaming policy information is carried in the AKMA service closing notification message, and the roaming policy information includes information of the first network and information of the third network. The UE determines, according to the roaming policy information and information of the network in which the UE is registered (i.e., information of the first network and information of the second network), that the UE cannot use the AKMA service in the first network in which the UE is currently registered, and can use the AKMA service in the second network in which the UE is currently registered. Since the UE is not registered to the third network temporarily, the information of the third network can be ignored.
[0316] As an implementation method, when the AKMA service closing notification message includes roaming policy information, the step 803c can also be performed after the step 801c. That is, the step 803c does not have to be performed after the step 801c or the step 802c.
[0317] As another implementation method, the roaming policy information can also be configured on the UE. For this case, the AKMA service closing notification message can not carry the information of the first network or the roaming policy information. After receiving the AKMA service closing notification message, the UE can obtain the roaming policy information locally, and determine, according to the roaming policy information, that the UE cannot use the AKMA service in the first network in which the UE is registered, and can use the AKMA service in the second network in which the UE is registered.
[0318] In step 804c, the UE determines whether to release the application session according to the AKMA service closing notification message and information of a network corresponding to the application session.
[0319] In an implementation method, when the network corresponding to the application session is the first network, the UE releases the application session. Based on this method, since the UE cannot use the AKMA service in the first network, and the network corresponding to the application session used for transmitting the AKMA service is the first network, the UE determines that the application session needs to be released. For example, the UE sends an application session release request to the AF to trigger an application session release process.
[0320] In another implementation method, when the network corresponding to the application session is the second network, the UE does not release the application session. Based on this method, since the UE cannot use AKMA services in the first network, can use AKMA services in the second network, and the network corresponding to the application session used to transmit AKMA services is the second network, the UE determines not to release the application session.
[0321] Based on the above scheme, the UE can obtain the information of the network in which the UE is not allowed to perform AKMA services, and obtain the information of the network corresponding to the application session used to carry AKMA services between the UE and the AF, and then accurately determine whether the UE and the AF can perform AKMA services, and decide whether to release the application session, thereby realizing network granularity management of AKMA services, and helping to improve user experience. Compared with the scheme of always turning off AKMA services of the UE in all networks as long as the UE is not allowed to perform AKMA services in a certain network, the present application can realize the turning off of AKMA services based on network granularity, and can avoid the interruption of AKMA services as much as possible.
[0322] The embodiments of FIGS. 8(a)-8(c) will be described below in combination with specific examples. The following embodiment of FIG. 10 is a specific example when the embodiment of FIG. 8(a) and the embodiment of FIG. 8(b) are combined. The following embodiment of FIG. 11 is a specific example when the embodiment of FIG. 8(c) is used. The network #1 and the network #2 in the embodiments of FIGS. 10 and 11 are specific examples of the second network and the first network in the foregoing embodiments, respectively.
[0323] FIG. 10 is a flowchart of an AKMA service management method according to an embodiment of the present application. The method includes the following steps:
[0324] Step 1001, a primary authentication process and K AKMA generation process.
[0325] For specific implementation of the step 1001, refer to the steps 401-405 of the embodiment of FIG. 4.
[0326] In this process, the UE registers with the network #1, and completes the registration process in the network #1 after primary authentication. In this process, the K AKMA generated by the AUSF and the A-KID are called K AKMA #1 and A-KID #1, respectively.
[0327] Step 1002, an application session establishment process between the UE and the AF.
[0328] For specific implementation of the step 1002, refer to the steps 501-509 of the embodiment of FIG. 5.
[0329] In the procedure, the UE and the AAnF determine the same K AKMA determine the same K AF and the K AF validity time, and the AAnF sends the K AF and the K AF validity time to the AF, and the K AF can be used by the UE and the AF to protect the transmission content between the UE and the AF.
[0330] Before step 1002, the UE completes registration and establishes a PDU session for transmitting user plane data (e.g., AKMA service) between the UE and the AF. In the PDU session establishment procedure, the AF can obtain the IP address of the UE and the UE ID (e.g., GPSI). For example, after confirming that the PDU session authentication or authorization is successful, the AF requests the IP address of the UE for the current PDU session from the SMF, and the SMF provides the IP address of the UE and the UE ID (e.g., GPSI) to the AF. For details of this type of procedure, refer to 3GPP TS 23.502, section 4.3.2.3. Hereinafter, the PDU session is referred to as the first PDU session.
[0331] The first PDU session is a specific example of the first session in the foregoing embodiment of FIG. 8(a).
[0332] At step 1003, the AF sends a subscription request message to the SMF. Correspondingly, the SMF receives the subscription request message.
[0333] The subscription request message includes at least one of the UE ID, the PLMN change event ID, or the information of the first PDU session. The subscription request message is used to subscribe to the change of the PLMN identifier corresponding to the first PDU session.
[0334] The UE ID can be SUPI or GPSI, etc. The UE ID is used to identify the identity of the UE.
[0335] The PLMN change event ID is used to identify that the requested event is a PLMN change event.
[0336] The information of the PDU session can be an IP address, etc. The information of the PDU session is used to identify the session.
[0337] For example, the subscription request can be an Nsmf_EventExposure message.
[0338] In an implementation method, at step 1003, the AF can send the subscription request to the SMF through an interface between the AF and the SMF.
[0339] In another implementation method, in step 1003, the AF can send a subscription request to the NEF through an interface between the AF and the NEF, and then the NEF sends the subscription request to the SMF through an interface between the NEF and the SMF, that is, the NEF relays the subscription request.
[0340] It should be noted that step 1003 can occur before step 1002, specifically, after the PDU session establishment is completed and before the UE sends the application session establishment request message, step 1003 is performed. Or step 1003 can also occur in step 1002, for example, after the AF receives the application session establishment request message, step 1003 is performed. Or step 1003 can also occur after step 1002, for example, after the AF sends the application session establishment response message to the UE, step 1003 is performed.
[0341] Optionally, after step 1003, the SMF sends a subscription response message to the AF, and the subscription response message carries the identifier of the PLMN corresponding to the first PDU session. The PLMN is referred to as network #1 below, and the identifier of the PLMN corresponding to the first PDU session is referred to as information of network #1.
[0342] Step 1004, the UE and the core network perform main authentication again, and the AUSF sends a key registration request message to the AAnF. Correspondingly, the AAnF receives the key registration request message.
[0343] The key registration request message includes SUPI, A-KID#2 and K AKMA #2. Wherein, the A-KID#2 and K AKMA #2 are generated by the AUSF, and the UE also generates the same A-KID#2 and K AKMA #2.
[0344] The key registration request message can be Naanf_AKMA_Key_Register Request message.
[0345] Wherein, in the case that the UE and the core network perform main authentication again, the UE is registered to network #1 through a first access mode (such as 3GPP access), and the UE is also registered to network #2 through a second access mode (such as non-3GPP access), that is, the UE performs dual registration. Or, the first access mode can be non-3GPP access, and the second access mode can be 3GPP access.
[0346] Step 1005, the AAnF sends a key registration response message to the AUSF. Correspondingly, the AUSF receives the key registration response message.
[0347] Exemplarily, the key registration response message can be a Naanf_AKMA_AnchorKey_RegisterResponse message.
[0348] The AUSF sends the A-KID#2 and K AKMA #2 to the AAnF, and the AAnF saves the A-KID#2 and K AKMA #2.
[0349] In step 1006, the UDM sends notification information to the AAnF. Correspondingly, the AAnF receives the notification information.
[0350] The notification information carries UE ID and roaming state information, where the UE ID can be SUPI or SUCI, etc.
[0351] In the dual registration scenario, the roaming state information includes information of network #1 and information of network #2. The information of network #1 can be the identifier of a PLMN, and the network #2 can be the identifier of another PLMN.
[0352] Exemplarily, the notification information can be a Nudm_EventExposure_Notification message.
[0353] It should be noted that step 1006 is that the UDM sends the notification message to the AAnF in response to the subscription of the AAnF. Specifically, in the foregoing step 1002, the AAnF sends a subscription request message for subscribing to the roaming state information of the UE to the UDM, which is described in detail in step 505 of the foregoing embodiment of FIG. 5.
[0354] In step 1007, the AAnF determines that the UE cannot use AKMA service in network #2.
[0355] Exemplarily, the AAnF is locally preconfigured with a list of allowed networks and / or a list of disallowed networks of the UE. The list of allowed networks includes networks in which the UE is allowed to use AKMA service in the case of roaming, that is, if the network in which the UE roams is included in the list of allowed networks, the UE is allowed to use AKMA service in the network. The list of disallowed networks includes networks in which the UE is not allowed to use AKMA service in the case of roaming, that is, if the network in which the UE roams is included in the list of disallowed networks, the UE is not allowed to use AKMA service in the network. Based on the list of allowed networks and / or the list of disallowed networks, the AAnF can determine whether the UE can use AKMA service in network #2. For example, if network #2 is included in the list of allowed networks, the AAnF determines that the UE can use AKMA service. For another example, if network #2 is included in the list of disallowed networks, the AAnF determines that the UE cannot use AKMA service.
[0356] Exemplarily, the AAnF can also determine whether the network #2 is the HPLMN of the UE first. If the network #2 is the HPLMN, it is determined that the UE can use the AKMA service in the network #2. If the network #2 is not the HPLMN, the AAnF further determines whether the UE can use the AKMA service in the network #2.
[0357] At step 1008, the AAnF sends an AKMA service closing notification message to the AF. Correspondingly, the AF receives the AKMA service closing notification message.
[0358] In an implementation method, when the AAnF determines that the UE cannot use the AKMA service in the network #2, step 1008 is performed.
[0359] In another implementation method, when the AF provides the URI for service closing to the AAnF, and the AAnF determines that the UE cannot use the AKMA service in the network #2, step 1008 is performed.
[0360] In a possible design, in the dual registration scenario, when the UE and the AF can use the AKMA service in the network #1, and the UE and the AF cannot use the AKMA service in the network #2, the AKMA service closing notification message carries information of the network #2 or indication information, the indication information being used to indicate that the UE cannot use the AKMA service in the newly registered network (i.e., the network #2). The AKMA service closing notification message is used to indicate to close the AKMA service between the UE and the AF in the network #2.
[0361] In another possible design, in the dual registration scenario, as long as the UE and the AF cannot use the AKMA service in one of the networks, the UE and the AF cannot use the AKMA service in the other network. Therefore, when the UE and the AF cannot use the AKMA service in the network #2, the AKMA service closing notification message carries information of the network #1 and information of the network #2, or does not carry the information of the network #1 and the information of the network #2. The AKMA service closing notification message is used to indicate to close the AKMA service between the UE and the AF in the network #1 and the network #2. When the AKMA service closing notification message carries the information of the network #1 and the information of the network #2, the AKMA service closing notification message explicitly indicates to close the AKMA service between the UE and the AF in the network #1 and the network #2. When the AKMA service closing notification message does not carry the information of the network #1 and the information of the network #2, the AKMA service closing notification message implicitly indicates to close the AKMA service between the UE and the AF in the network #1 and the network #2.
[0362] Optionally, the AKMA service disable notification message further carries first information, the first information being one or more of the following:
[0363] (1) A-KID#1.
[0364] (2) A second identifier of the UE. The second identifier of the UE is different from the first identifier of the UE. For example, the first identifier of the UE is SUPI, and the second identifier of the UE is GPSI. For another example, the first identifier of the UE is GSPI, and the second identifier of the UE is SUPI. The AAnF locally stores a correspondence between the first identifier of the UE and the second identifier of the UE.
[0365] (3) A context ID. The context ID is used to indicate a context of the connection between the AAnF and the AF. The context ID can be generated by the AAnF.
[0366] As an implementation method, the AAnF locally further stores information of a network that does not allow the UE to use the AKMA service. For example, information of network #2 is stored, or information of network #1 and information of network #2 are stored.
[0367] Exemplarily, the AKMA service disable notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0368] In step 1009, the SMF sends a notification message to the AF. Correspondingly, the AF receives the notification message.
[0369] In the dual registration scenario, if the PLMN corresponding to the first PDU session changes, that is, the first PDU session is updated from being transmitted through network #1 to being transmitted through network #2, the SMF sends the notification message to the AF. The notification message includes information of network #2, and the notification message is used to notify that the network corresponding to the first PDU session changes to network #2.
[0370] In the dual registration scenario, if the PLMN corresponding to the first PDU session does not change, that is, the network through which the first PDU session passes is always network #1, step 1009 is not performed.
[0371] The notification message in step 1009 is sent in response to the subscription request in step 1003.
[0372] Exemplarily, the notification message can be a Nsmf_Event_Exposure_Notification message.
[0373] In step 1010, the AF determines whether to disable the AKMA service of the UE.
[0374] In one case, when the information of network #2 is carried in step 1008, and step 1009 is not performed, it indicates that the UE can perform AKMA service in network #1, cannot perform AKMA service in network #2, and the network corresponding to the first PDU session is network #1. The AF determines that the UE can continue to perform AKMA service, and therefore does not need to close the AKMA service of the UE. That is, although the UE cannot use AKMA service in network #2, the UE is actually performing AKMA service in network #1, and the UE is allowed to perform AKMA service in network #1.
[0375] In another case, when the information of network #2 is carried in step 1008, and step 1009 is performed, it indicates that the UE can perform AKMA service in network #1, cannot perform AKMA service in network #2, and the network corresponding to the first PDU session has changed to network #2. The AF determines that the UE cannot continue to perform AKMA service, and therefore needs to close the AKMA service of the UE. That is, the first PDU session used to transmit AKMA service between the UE and the AF migrates to network #2, but the UE cannot use AKMA service in network #2, and therefore the AKMA service of the UE needs to be closed.
[0376] In another case, when the information of network #1 and the information of network #2 are carried in step 1008, or the information of network #1 and the information of network #2 are not carried, it indicates that the UE cannot perform AKMA service in network #1 and network #2. At this time, whether step 1009 is performed or not, the AF will close the AKMA service of the UE.
[0377] As one implementation method, when it is necessary to close the AKMA service of the UE, and the first information is carried in the above step 1008, the AF can determine the AKMA service of the UE according to the first information, and close the AKMA service of the UE. For specific implementation methods of closing the corresponding AKMA service according to the first information, reference can be made to the related description in step 605 of the embodiment of FIG. 6, which will not be repeated here.
[0378] Through the above method, the AKMA service of the UE is accurately closed, avoiding the interruption of the service caused by the incorrect closing of the AKMA service of the UE, and improving the user experience.
[0379] Optionally, after step 1010, part or all of steps 1011-1014 can also be performed. It should be noted that the scheme constituted by steps 1011-1014 can be combined with the scheme constituted by steps 1001-1013 for implementation, or can also be implemented as a separate embodiment. That is, the scheme constituted by steps 1011-1014 and the scheme constituted by steps 1001-1013 can not be performed in the same flow and are not coupled to each other.
[0380] In step 1011, the UE sends an application session establishment request message to the AF. Correspondingly, the AF receives the application session establishment request message.
[0381] The application session establishment request message includes A-KID#1, A-KID#2, or other A-KIDs, which are used by the AF to find the corresponding AKMA key.
[0382] It should be noted that before step 1010, the UE completes the establishment of a second PDU session for transmitting user plane data (e.g., AKMA service) between the UE and the AF. During the PDU session establishment process, the AF can obtain the IP address of the UE and the UE ID (e.g., GPSI).
[0383] Here, the second PDU session is a specific example of the third session in the embodiment of FIG. 8(b) described above.
[0384] In step 1012, the AF sends a subscription request message to the SMF. Correspondingly, the SMF receives the subscription request message.
[0385] The subscription request message includes at least one of the UE ID, the PLMN change event ID, or the information of the second PDU session. The subscription request message is used to subscribe to the change of the PLMN identifier corresponding to the second PDU session.
[0386] The UE ID can be SUPI or GPSI, etc. The UE ID is used to identify the identity of the UE.
[0387] The PLMN change event ID is used to identify that the requested event is a PLMN change event.
[0388] The information of the PDU session can be an IP address, etc., and is used to identify the session.
[0389] Exemplarily, the subscription request can be an Nsmf_EventExposure message.
[0390] In one implementation method, in step 1012, the AF can send the subscription request to the SMF through an interface between the AF and the SMF.
[0391] In another implementation method, in step 1012, the AF can send the subscription request to the NEF through an interface between the AF and the NEF, and then the NEF sends the subscription request to the SMF through an interface between the NEF and the SMF, that is, the NEF relays the subscription request.
[0392] In step 1013, the SMF sends a subscription response message to the AF. Correspondingly, the AF receives the subscription response message.
[0393] The subscription response message carries information of the network corresponding to the second PDU session. The information of the network corresponding to the second PDU session can be information of network #1, information of network #2, or information of another network.
[0394] In step 1014, the AF determines whether to allow the establishment of the application session.
[0395] In one scenario, when the network corresponding to the second PDU session is network #2, the AF does not allow the establishment of the application session, that is, rejects the application session establishment request message.
[0396] In another scenario, when the network corresponding to the second PDU session is network #1, step 1008 carries information of network #2, and step 1009 is not performed, indicating that the UE can perform AKMA service in network #1, so the AF allows the establishment of the application session, that is, allows the application session establishment request message.
[0397] In another scenario, when the network corresponding to the second PDU session is network #1 or network #2, and step 1008 carries information of network #1 and information of network #2 (or step 1008 does not carry information of network #1 and information of network #2), the AF does not allow the establishment of the application session, that is, rejects the application session establishment request message.
[0398] Based on the above scheme, the AAnF sends the information of the network in which the UE is not allowed to perform AKMA service to the AF, so that the AF can accurately determine in which network or networks the UE cannot perform AKMA service, and then can accurately close the AKMA service of the UE in the corresponding network, instead of closing the AKMA service of the UE in all registered networks, which can reduce the interruption of AKMA service and help improve user experience.
[0399] It should be noted that not all of the steps in the above embodiment of FIG. 10 are optional, and in order to achieve the purpose of the present application, only some key steps can be retained. For example, steps 1001-1002, steps 1004-1006, and step 1009 can be optional steps for achieving the purpose of the present application.
[0400] FIG. 11 is a flowchart of a method for managing AKMA services according to an embodiment of the present application. The method comprises the following steps:
[0401] Steps 1101-1102 are the same as steps 1001-1002 in the embodiment of FIG. 10.
[0402] Further, before step 102, the UE completes registration and establishes a PDU session for transmitting user plane data (e.g., AKMA services) between the UE and the AF. During the PDU session establishment process, the AF can obtain the IP address of the UE and the UE ID (e.g., GPSI). For example, after confirming that the PDU session authentication or authorization is successful, the AF requests the IP address of the UE for the current PDU session from the SMF, and the SMF provides the IP address of the UE and the UE ID (e.g., GPSI) to the AF. For details of this type of process, refer to 3GPP TS 23.502, section 4.3.2.3. Hereinafter, the PDU session is referred to as the first PDU session.
[0403] Steps 1103-1106 are the same as steps 1004-1007 in the embodiment of FIG. 10.
[0404] In step 1107, the AAnF sends an AKMA service disablement notification message to the UE. Correspondingly, the UE receives the AKMA service disablement notification message.
[0405] As an implementation method, the AAnF can send the AKMA service disablement notification message to the AMF, and then the AMF forwards the AKMA service disablement notification message to the UE, for example, the AMF sends the AKMA service disablement notification message to the UE in a downlink NAS message (DL NAS message).
[0406] For example, the AKMA service disablement notification message can be a Naanf_AKMA_ServiceDisableNotification message.
[0407] The AKMA service disablement notification message carries information about networks in the network where the UE is registered that do not allow the UE to use AKMA services, or carries roaming policy information.
[0408] The roaming policy information includes information of a network that does not allow the UE to use AKMA service. The network that does not allow the UE to use AKMA service can include a network registered by the UE or a network not registered by the UE.
[0409] The following is described in combination with specific examples. For example, the UE is registered to network #1 and network #2, and the network that does not allow the UE to use AKMA service includes network #2 and a third network. In one example, the AKMA service closing notification message carries information of network #2. The UE determines, according to the AKMA service closing notification message, that AKMA service can be used in network #1 and AKMA service cannot be used in network #2. In another example, the AKMA service closing notification message carries roaming policy information including network #2 and the third network. The UE determines, according to the roaming policy information and information of a network registered by the UE, that AKMA service can be used in network #1 and AKMA service cannot be used in network #2.
[0410] It should be noted that the roaming policy information described above can also be pre-configured on the UE or sent to the UE by the AAnF in a step before step 1107. In this case, the roaming policy information can not be carried in step 1107.
[0411] In a possible design, the trigger occasion for triggering the AF to perform step 1107 can include, but is not limited to, one or more of the following:
[0412] 1) The UE cannot use AKMA service in network #2.
[0413] 2) The AAnF obtains a URI for service closing provided by the AF.
[0414] 3) The roaming policy information carried in step 1105 includes information of network #1 and information of network #2.
[0415] It should be noted that the AKMA service closing notification message in step 1107 can also be replaced by other messages, such as an AKMA service closing message, a closing message, an indication message, a notification message, or other messages, which are not limited in the present application.
[0416] In step 1108, the UE determines whether to close AKMA service of the UE.
[0417] For example, the UE is registered to network #1 and network #2, and determines, according to the AKMA service closing notification message, that AKMA service can be used in network #1 and AKMA service cannot be used in network #2. If a first PDU session corresponds to network #1, that is, is transmitted through network #1, it is determined that AKMA service of the UE does not need to be closed.
[0418] For another example, the UE is registered to network #1 and network #2, and it is determined according to the AKMA service closing notification message that the AKMA service can be used in network #1, and the AKMA service cannot be used in network #2, and the first PDU session corresponds to network #2, that is, it is transmitted through network #2, it is determined that the AKMA service of the UE needs to be closed. For example, the UE can initiate an application session release process to the AF.
[0419] Based on the above scheme, the AAnF sends the roaming policy information or the information of the network in which the UE is registered and in which the UE is not allowed to use the AKMA service to the UE, so that the UE can accurately determine in which network or networks the UE cannot use the AKMA service, and then can accurately close the AKMA service of the UE in the corresponding network, instead of closing the AKMA service of the UE in all the registered networks, which can reduce the interruption of the AKMA service and help improve the user experience.
[0420] It should be noted that not all the steps in the above embodiment of FIG. 11 are optional, and only some key steps can be retained to achieve the purpose of the present application. For example, steps 1101-1105 above can be optional steps for achieving the purpose of the present application.
[0421] FIG. 12 is a flowchart of an AKMA service management method provided by an embodiment of the present application. The method includes the following steps:
[0422] Step 1201, the UE sends an application session establishment request message to the AF. Correspondingly, the AF receives the application session establishment request message.
[0423] The application session establishment request message requests to establish an application session for transmitting the AKMA service between the UE and the AF. The application session is carried in a first session, which can be a PDU session or other types of sessions.
[0424] The application session establishment request message includes an AKMA key identifier (A-KID).
[0425] Among them, the UE is registered to a first network and a second network at the same time. For example, the first network is a network connected by the UE through a 3GPP access method, and the second network is a network connected by the UE through a non-3GPP access method; or the first network is a network connected by the UE through a non-3GPP access method, and the second network is a network connected by the UE through a 3GPP access method.
[0426] Step 1202, the AF sends an application key request message to the AAnF. Correspondingly, the AAnF receives the application key request message.
[0427] The application key request message includes an AKMA key identifier (A-KID), and the application key request message is used to request an application key corresponding to the A-KID.
[0428] Exemplarily, the application key request message can be a Naanf_AKMA_ApplicationKey_Get_Request message or a Naanf_AKMA_ApplicationKey_AnonUser_Get service message.
[0429] In step 1203, the AAnF sends an application key response message to the AF according to whether the UE is allowed to use AKMA services in the first network and the second network. Correspondingly, the AF receives the application key response message.
[0430] As an implementation method, the application key response message includes an application key (K AF ) used to protect AKMA services between the UE and the AF. Exemplarily, the AAnF obtains an AKMA key (K AKMA ) corresponding to the A-KID according to the A-KID in the application key request message, and then the AAnF generates the application key according to the K AKMA . Optionally, the application key request message further includes an AF ID, and the AAnF can generate the application key according to the K AKMA and the AF ID. Optionally, the AAnF generates the K AF at the same time, and also generates a validity time of the K AF , and the application key response message can further include the validity time of the K AF .
[0431] Further, the application key response message is also used to indicate whether the UE is allowed to use AKMA services in the first network and / or the second network. Optionally, the application key response message can further include information of the first network and / or information of the second network.
[0432] The UE is allowed to use the AKMA service in the first network, which can also be understood as allowing the UE to use the application key, AKMA key or AKMA key identifier corresponding to the AKMA service in the first network, or that the application key is valid in the first network. The UE is not allowed to use the AKMA service in the first network, which can also be understood as not allowing the UE to use the application key, AKMA key or AKMA key identifier corresponding to the AKMA service in the first network, or that the application key is not valid in the first network. The UE is allowed to use the AKMA service in the second network, which can also be understood as allowing the UE to use the application key, AKMA key or AKMA key identifier corresponding to the AKMA service in the second network, or that the application key is valid in the second network. The UE is not allowed to use the AKMA service in the second network, which can also be understood as not allowing the UE to use the application key, AKMA key or AKMA key identifier corresponding to the AKMA service in the second network, or that the application key is not valid in the second network.
[0433] For example, the AAnF can determine whether the UE is allowed to use the AKMA service in the first network and / or the second network according to the local configuration information. For example, the local configuration information includes information of allowed networks and / or information of disallowed networks, wherein the information of allowed networks includes information of networks that allow the UE to use the AKMA service (such as one or more PLMN IDs), and the information of disallowed networks includes information of networks that do not allow the UE to use the AKMA service (such as one or more PLMN IDs). For example, the information of allowed networks includes information of the second network but does not include information of the first network, and the AAnF determines that the UE is not allowed to use the AKMA service in the first network and is allowed to use the AKMA service in the second network. For another example, the information of disallowed networks includes information of the first network but does not include information of the second network, and the AAnF determines that the UE is not allowed to use the AKMA service in the first network and is allowed to use the AKMA service in the second network.
[0434] Three different implementation methods of the step 1203 are described below.
[0435] In the first implementation method, the AAnF indicates to the AF whether the UE is allowed to use the AKMA service in the first network and / or the second network through a whitelist. For example, if the UE is allowed to use the AKMA service in a certain network, the information of the network is carried in the application key response message, and if the UE is not allowed to use the AKMA service in a certain network, the information of the network is not carried in the application key response message.
[0436] The first implementation method is described in the following three cases.
[0437] In case 1, the AAnF sends an application key response message to the AF, the application key response message including an application key, and including information of the second network, in a case that the AAnF determines that the UE is not allowed to use AKMA service in the first network and is allowed to use AKMA service in the second network. Wherein, the information of the second network indicates that the UE is allowed to use AKMA service in the second network.
[0438] Exemplarily, the information of the second network includes a PLMN ID#2 and / or an indication information, the indication information being used to indicate that the UE is allowed to use AKMA service in the second network. Wherein, when the information of the second network includes the PLMN ID#2 but does not include the indication information, it is implicitly indicated that the UE is allowed to use AKMA service in the second network.
[0439] In case 2, the AAnF sends an application key response message to the AF, the application key response message including an application key, and including information of the first network and information of the second network, in a case that the AAnF determines that the UE is allowed to use AKMA service in the first network and is allowed to use AKMA service in the second network. Wherein, the information of the first network indicates that the UE is allowed to use AKMA service in the first network, and the information of the second network indicates that the UE is allowed to use AKMA service in the second network.
[0440] Exemplarily, the information of the first network includes a PLMN ID#1 and / or an indication information#1, the indication information#1 being used to indicate that the UE is allowed to use AKMA service in the first network. Wherein, when the information of the first network includes the PLMN ID#1 but does not include the indication information#1, it is implicitly indicated that the UE is allowed to use AKMA service in the first network.
[0441] Exemplarily, the information of the second network includes a PLMN ID#2 and / or an indication information#2, the indication information#2 being used to indicate that the UE is allowed to use AKMA service in the second network. Wherein, when the information of the second network includes the PLMN ID#2 but does not include the indication information#2, it is implicitly indicated that the UE is allowed to use AKMA service in the second network.
[0442] In case 3, the AAnF sends an application key response message to the AF, the application key response message not including an application key, and not including information of the first network and information of the second network, in a case that the AAnF determines that the UE is not allowed to use AKMA service in the first network and is not allowed to use AKMA service in the second network. The application key response message is used to indicate that the request of the application key is rejected.
[0443] For the second implementation method, the AAnF indicates to the AF whether the UE is allowed to use AKMA service in the first network and / or the second network by means of a blacklist. For example, if the UE is allowed to use AKMA service in a certain network, the information of the network is not carried in the application key response message; if the UE is not allowed to use AKMA service in a certain network, the information of the network is carried in the application key response message.
[0444] For the second implementation method, the following three cases are described.
[0445] For case A, the AAnF sends the application key response message to the AF in the case that the AAnF determines that the UE is not allowed to use AKMA service in the first network and is allowed to use AKMA service in the second network, the application key response message includes the application key and includes the information of the first network. The information of the first network indicates that the UE is not allowed to use AKMA service in the first network.
[0446] For example, the information of the first network includes the PLMN ID#1 and / or the indication information indicating that the UE is not allowed to use AKMA service in the first network. When the information of the first network includes the PLMN ID#1 but does not include the indication information, it is implicitly indicated that the UE is not allowed to use AKMA service in the first network.
[0447] For case B, the AAnF sends the application key response message to the AF in the case that the AAnF determines that the UE is allowed to use AKMA service in the first network and is allowed to use AKMA service in the second network, the application key response message includes the application key but does not include the information of the first network and the information of the second network.
[0448] Since the application key response message does not include the information of the first network and the information of the second network, the application key response message is used to implicitly indicate that the UE is allowed to use AKMA service in the first network and is allowed to use AKMA service in the second network, or is understood as being allowed to use AKMA service in the network where the UE is registered.
[0449] For case C, the AAnF sends the application key response message to the AF in the case that the AAnF determines that the UE is not allowed to use AKMA service in the first network and is not allowed to use AKMA service in the second network, the application key response message does not include the application key, and does not include the information of the first network and the information of the second network. The application key response message is used to indicate that the request for the application key is rejected.
[0450] For the third implementation method, the AAnF indicates to the AF whether the UE is allowed to use AKMA service in the first network and / or the second network by means of white list and black list. For example, the application key response message includes the information of the first network and the information of the second network, and the information of the first network indicates whether the UE is allowed to use AKMA service in the first network, and the information of the second network indicates whether the UE is allowed to use AKMA service in the second network.
[0451] For the third implementation method, the following three cases are described.
[0452] For case a, the AAnF sends the application key response message to the AF in the case that the AAnF determines that the UE is not allowed to use AKMA service in the first network and is allowed to use AKMA service in the second network, the application key response message includes the application key, and includes the information of the first network and the information of the second network. The information of the first network indicates that the UE is not allowed to use AKMA service in the first network, and the information of the second network indicates that the UE is allowed to use AKMA service in the second network.
[0453] For example, the information of the first network includes the PLMN ID#1 and / or the indication information#1, and the indication information#1 is used to indicate that the UE is not allowed to use AKMA service in the first network. When the information of the first network includes the PLMN ID#1 but does not include the indication information#1, it is implicitly indicated that the UE is not allowed to use AKMA service in the first network.
[0454] For example, the information of the second network includes the PLMN ID#2 and / or the indication information#2, and the indication information#2 is used to indicate that the UE is allowed to use AKMA service in the second network. When the information of the second network includes the PLMN ID#2 but does not include the indication information#2, it is implicitly indicated that the UE is allowed to use AKMA service in the second network.
[0455] For case b, the AAnF sends the application key response message to the AF in the case that the AAnF determines that the UE is allowed to use AKMA service in the first network and is allowed to use AKMA service in the second network, the application key response message includes the application key, and includes the information of the first network and the information of the second network. The information of the first network indicates that the UE is allowed to use AKMA service in the first network, and the information of the second network indicates that the UE is allowed to use AKMA service in the second network.
[0456] Exemplarily, the information of the first network comprises a PLMN ID #1 and / or indication information #1, the indication information #1 is used to indicate that the UE is allowed to use AKMA service in the first network. Wherein, when the information of the first network comprises the PLMN ID #1 but does not comprise the indication information #1, it is implicitly indicated that the UE is allowed to use AKMA service in the first network.
[0457] Exemplarily, the information of the second network comprises a PLMN ID #2 and / or indication information #2, the indication information #2 is used to indicate that the UE is allowed to use AKMA service in the second network. Wherein, when the information of the second network comprises the PLMN ID #2 but does not comprise the indication information #2, it is implicitly indicated that the UE is allowed to use AKMA service in the second network.
[0458] Case c, the AAnF sends an application key response message to the AF in the case that it is determined that the UE is not allowed to use AKMA service in the first network and is not allowed to use AKMA service in the second network, the application key response message does not comprise an application key, nor the information of the first network and the information of the second network. The application key response message is used to indicate that the request for the application key is rejected.
[0459] Exemplarily, the application key response message can be a Naanf_AKMA_ApplicationKey_Get Response message.
[0460] Step 1204, the AF obtains the information of the current network corresponding to the first session.
[0461] Wherein, the information of the current network corresponding to the first session can be a PLMN ID for example. The session carried by the UE in the above step 1201 is established by the request is on the first session.
[0462] In an implementation method, the AF can request the SMF to obtain the information of the current network corresponding to the first session, such as the AF sends a request message to the SMF, the request message is used to request the information of the current network corresponding to the first session, the SMF sends a notification message to the AF, the notification message comprises the information of the current network corresponding to the first session. Optionally, the request message can be a subscription request message, the subscription request message is used to subscribe to the network information corresponding to the first session, after receiving the subscription request message, the SMF sends a notification message carrying the information of the current network corresponding to the first session to the AF, or when the network corresponding to the first session changes subsequently, the SMF sends a notification message carrying the information of the current network corresponding to the first session to the AF. Optionally, the subscription request message can comprise one or more of the information of the first session, the identifier of the UE or the event identifier, the event identifier is used to indicate a network change event.
[0463] The application does not limit the implementation method of the AF obtaining the information of the current network corresponding to the first session, for example, the AF can also actively request the UE to obtain the information of the current network corresponding to the first session, or the UE can actively send the information of the current network corresponding to the first session to the AF, etc.
[0464] The triggering condition triggering the AF to perform step 1204 is introduced below.
[0465] In one possible implementation method, if the application key response message is used to indicate that the UE is not allowed to use AKMA service in the first network and / or is allowed to use AKMA service in the second network, the AF obtains the information of the current network corresponding to the first session according to the application key response message. It can also be understood that the AF obtains the information of the current network corresponding to the first session according to the indication of the application key response message that the UE is not allowed to use AKMA service in the first network and / or is allowed to use AKMA service in the second network. That is, the application key response message triggers the AF to obtain the information of the current network corresponding to the first session. For example, this implementation method corresponds to the case 1 in the implementation method one, the case A in the implementation method two and the case a in the implementation method three introduced in the above step 1203.
[0466] In another possible implementation method, if the application key response message is used to indicate that the UE is allowed to use AKMA service in the first network and the second network, the AF can obtain the information of the current network corresponding to the first session according to the application key response message, or the AF can not obtain the information of the current network corresponding to the first session according to the application key response message. For example, this implementation method corresponds to the case 2 in the implementation method one, the case B in the implementation method two and the case b in the implementation method three introduced in the above step 1203. If the AF does not obtain the information of the current network corresponding to the first session, the AF can obtain the information of the current network corresponding to the first session when it is needed in the subsequent process. For example, when the AF receives the AKMA service closing notification message from the AAnF, the AF is triggered to obtain the information of the current network corresponding to the first session, and the specific implementation of this scenario can be referred to the description in the foregoing embodiment of FIG. 8(a).
[0467] In another possible implementation method, if the application key response message is used to indicate that the request application key is rejected, the AF does not perform step 1204 and the subsequent step 1205. For example, this implementation method corresponds to the case 3 in the implementation method one, the case C in the implementation method two and the case c in the implementation method three introduced in the above step 1203.
[0468] In step 1205, the AF determines whether the application session is allowed according to the information of the current network corresponding to the first session and the application key response message.
[0469] In a possible implementation, if the application key response message is used to indicate that the UE is not allowed to use the AKMA service in the first network and / or is allowed to use the AKMA service in the second network, the AF rejects the application session in the case that the current network corresponding to the first session is the first network, that is, the AF rejects the application session establishment request message of the UE in step 1201, such as that the AF sends an application session response message to the UE to indicate that the application session is rejected; the AF allows the application session in the case that the current network corresponding to the first session is the second network, that is, the AF allows the application session establishment request message of the UE in step 1201, such as that the AF sends an application session response message to the UE to indicate that the application session is allowed. Exemplarily, the implementation corresponds to the case 1 in the implementation method one, the case A in the implementation method two, and the case a in the implementation method three in step 1203.
[0470] In a possible implementation, if the application key response message is used to indicate that the UE is allowed to use the AKMA service in the first network and is allowed to use the AKMA service in the second network, the AF allows the application session regardless of whether the current network corresponding to the first session is the first network or the second network, that is, the AF allows the application session establishment request message of the UE in step 1201, such as that the AF sends an application session response message to the UE to indicate that the application session is allowed. Alternatively, the AF directly determines to allow the application session according to the application key response message. Exemplarily, the implementation corresponds to the case 2 in the implementation method one, the case B in the implementation method two, and the case b in the implementation method three in step 1203.
[0471] In the scheme, the AF receives the application key response message from the AAnF, the application key response message includes the application key, and the application key response message further indicates whether the UE is allowed to use the AKMA service in the first network and the second network, thereby helping the AF to more accurately determine whether to allow the application session requested by the UE to be established, and achieving accurate management of the AKMA service between the UE and the AF.
[0472] FIG. 13 is a flow diagram of a method for managing an AKMA service according to an embodiment of the present application. The embodiment of FIG. 13 is a specific example of the embodiment of FIG. 12. In the method, the AF is a network element in the 3GPP core network or a network element outside the 3GPP core network. When the AF is a network element outside the 3GPP core network, the interactions between the AF and the AAnF involved below can be relayed through the NEF. Before step 1301, the primary authentication process and the K AKMA generation process shown in the embodiment of FIG. 4 are completed. AKMAAfter the generation procedure, and before step 1301, the UE needs to complete registration and establish a PDU session for transmitting user plane data (e.g. AKMA traffic) between the UE and the AF.
[0473] The method comprises the following steps:
[0474] In step 1301, the UE sends an application session establishment request message to the AF. Correspondingly, the AF receives the application session establishment request message.
[0475] The application session establishment request message requests to establish an application session for transmitting AKMA traffic between the UE and the AF. The application session is carried in a first session, which can be a PDU session or other type of session.
[0476] The application session establishment request message comprises an AKMA key identifier (A-KID). The A-KID is generated by the UE before step 1301, in the K AKMA The generation procedure is generated by the UE. Wherein, the K AKMA The generation procedure can refer to the embodiment of FIG. 4.
[0477] Wherein, the UE is registered to a first network and a second network at the same time. For example, the first network is a network connected by the UE through 3GPP access, and the second network is a network connected by the UE through non-3GPP access; or, the first network is a network connected by the UE through non-3GPP access, and the second network is a network connected by the UE through 3GPP access.
[0478] In step 1302, if there is no A-KID related context on the AF, the AF selects an AAnF and sends an application key request message to the AAnF. Correspondingly, the AAnF receives the application key request message.
[0479] The A-KID in the application key request message comes from step 1301. The AF ID is used to identify the AF. The AF ID can be used as an input parameter when calculating the K AF to achieve key isolation between different AFs.
[0480] Exemplarily, the application key request message can be a Naanf_AKMA_ApplicationKey_Get_Request message, or a Naanf_AKMA_ApplicationKey_AnonUser_Get service message.
[0481] Step 1303. Optionally, the AAnF sends a request message to the UDM according to a local rule when the AAnF determines that the GPSI is needed by the AF. Correspondingly, the UDM receives the request message.
[0482] The request message is used to request the GPSI of the UE. Illustratively, the request message can carry the SUPI of the UE to request the GPSI corresponding to the SUPI.
[0483] Illustratively, the request message can be a Nudm_SDM_Get Request message.
[0484] Step 1304. Optionally, the UDM sends a response message to the AAnF. Correspondingly, the AAnF receives the response message.
[0485] The response message includes the GPSI of the UE. The AAnF stores the GPSI as the AKMA context of the UE.
[0486] It should be noted that if the AAnF determines that the GPSI is not needed by the AF according to a local rule, steps 1303 to 1304 do not need to be performed.
[0487] Illustratively, the response message can be a Nudm_SDM_Get Response message.
[0488] Step 1305. Optionally, the AAnF sends a subscription request message to the UDM. Correspondingly, the UDM receives the subscription request message.
[0489] The subscription request message includes the SUPI or the GPSI of the UE, and the subscription request message is used to subscribe to the roaming status report or the roaming status information of the UE.
[0490] Illustratively, the subscription request message can be a Nudm_EventExposure_Subscribe Request message.
[0491] Step 1306. Optionally, the UDM sends a subscription response message to the AAnF. Correspondingly, the AAnF receives the subscription response message.
[0492] The subscription response message includes the roaming status information of the UE.
[0493] The roaming status information includes the PLMN information of the UE registration, and optionally, the roaming status information further includes indication information used to indicate whether the PLMN is a home network. The present application considers a dual registration scenario, that is, the PLMN information of the UE registration includes the identities of two PLMNs, for example, PLMN ID#1 and PLMN ID#2.
[0494] Subsequently, if the UE's roaming information changes, the UDM sends a notification message to the AAnF, which carries the changed roaming status information.
[0495] For example, the subscription response message can be a Nudm_EventExposure_Subscribe Response message.
[0496] Step 1307, AAnF obtains the AKMA key (K) based on A-KID. AKMA ), and generate an application key (K) based on the AKMA key. AF ).
[0497] For example, AAnF obtains the AKMA key (K) corresponding to the A-KID based on the A-KID in the application key request message. AKMA Then AAnF according to K AKMA Generate the application key. Optionally, the application key request message may also include an AF ID, in which case AAnF can be determined based on K. AKMA The application key is generated using the AF ID. Optionally, AAnF generates the K key. AF At the same time, K is also generated AF If the validity period is specified, the application key response message may also include K. AF The effective time.
[0498] Among them, AAnF is in the main authentication process and K AKMA The generation process obtains the A-KID and the corresponding K. AKMA and A-KID with K AKMA The mapping relationship is stored locally.
[0499] In step 1308, AAnF sends an application key response message to AF based on whether the UE is allowed to use AKMA services in the first and second networks. Accordingly, AF receives the application key response message.
[0500] Step 1308 is the same as step 1203 in the embodiment of Figure 12. Please refer to the foregoing description for details, and it will not be repeated here.
[0501] In one implementation, when the application key request message in step 1302 is Naanf_AKMA_ApplicationKey_Get_Request, the application key response message may also carry SUPI or GPSI. When the application key request message in step 1302 is Naanf_AKMA_ApplicationKey_AnonUser_Getservice, the application key response message does not carry SUPI or GPSI.
[0502] At step 1309, the AF obtains information of the current network corresponding to the first session.
[0503] The step 1309 is the same as step 1204 in the embodiment of FIG. 12, and details are referred to the foregoing description.
[0504] At step 1310, the AF determines whether to allow the application session according to the information of the current network corresponding to the first session and the application key response message.
[0505] The step 1310 is the same as step 1205 in the embodiment of FIG. 12, and details are referred to the foregoing description.
[0506] At step 1311, the AF sends an application session establishment response message to the UE. Correspondingly, the UE receives the application session establishment response message.
[0507] If the AF allows the application session, the application session establishment response message indicates that the application session is successfully established.
[0508] If the AF rejects the application session, the application session establishment response message indicates that the application session is rejected.
[0509] In an implementation method, the UE determines the K AKMA In any step after the generation process, the K AF may also be generated in the same way as the AAnF. AF Optionally, the UE also determines the validity time of the K
[0510] In the above scheme, the AF receives the application key response message from the AAnF, and the application key response message includes the application key. Meanwhile, the application key response message also indicates whether to allow the UE to use the AKMA service in the first network and the second network, thereby helping the AF to more accurately determine whether to allow the application session requested by the UE to be established, and realizing accurate management of the AKMA service between the UE and the AF.
[0511] In each of the above embodiments of the present application, the names of the messages are only described as examples. With the development of communication technology, the names of the above messages may change, but as long as the changed messages have the same or similar functions as the above messages of the present application, their corresponding messages also fall within the protection scope of the present application.
[0512] It is understood that, in order to achieve the functions in the above embodiments, AF, AAnF, or UE includes hardware structures and / or software modules corresponding to perform each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0513] Figures 14 and 15 are schematic diagrams of possible communication devices provided in embodiments of this application. These communication devices can be used to implement the functions of AF, AAnF, or UE in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments. In the embodiments of this application, the communication device can be AF, AAnF, or UE.
[0514] The communication device 1400 shown in Figure 14 includes a processing unit 1410 and a transceiver unit 1420. The communication device 1400 is used to implement the functions of AF, ANF, or UE in the above method embodiments.
[0515] When the communication device 1400 is used to implement the AF function in the above method embodiment, the transceiver unit 1420 receives an AKMA service shutdown notification message, the AKMA service shutdown notification message including information of a first network, the AKMA service shutdown notification message being used to notify the shutdown of the AKMA service of the first network; the processing unit 1410 is used to obtain information of the current network corresponding to the first session of the terminal device, the first session being used to transmit the first AKMA service between the terminal device and the application function network element; and determines whether to shut down the first AKMA service based on the AKMA service shutdown notification message and the information of the current network corresponding to the first session.
[0516] In one possible implementation, the processing unit 1410 is configured to determine whether to close the first AKMA service based on the AKMA service closure notification message and the information of the current network corresponding to the first session, including: closing the first AKMA service when the current network corresponding to the first session is the first network.
[0517] In one possible implementation, the processing unit 1410 is configured to obtain the current network information corresponding to the first session of the terminal device, including: receiving a first notification message through the transceiver unit 1420, the first notification message including information of the first network, the first notification message indicating that the network corresponding to the first session has changed to the first network.
[0518] In a possible implementation, the processing unit 1410 is further configured to, in a case where the current network corresponding to the second session of the terminal device is a second network, not close the second AKMA service between the terminal device and the application function network element, the second session being used to transmit the second AKMA service, and the second network being different from the first network.
[0519] In a possible implementation, the processing unit 1410 is configured to determine whether to close the first AKMA service according to the AKMA service closing notification message and the information about the current network corresponding to the first session, including: in a case where the current network corresponding to the first session is a second network, not closing the first AKMA service, the second network being different from the first network.
[0520] In a possible implementation, the processing unit 1410 is configured to obtain the information about the current network corresponding to the first session of the terminal device, including: receiving, by the transceiver 1420, a second notification message, the second notification message including the information about the second network, and the second notification message indicating that the network corresponding to the first session is the second network.
[0521] In a possible implementation, the transceiver 1420 is further configured to send a first subscription request message, the first subscription request message being used to subscribe to network changes corresponding to the first session.
[0522] In a possible implementation, the first subscription request message includes one or more of the following: information about the first session, an identifier of the terminal device, or a first event identifier, the first event identifier being used to indicate a network change event.
[0523] In a possible implementation, the first notification message includes one or more of the following: information about the first session, an identifier of the terminal device, or a first event identifier, the first event identifier being used to indicate a network change event.
[0524] In a possible implementation, the AKMA service closing notification message further includes information about the second network.
[0525] When the communication apparatus 1400 is configured to implement the function of the AF in the method embodiments, the transceiver 1420 is configured to receive an application session establishment request message, the application session establishment request message being used to request establishment of an application session used to transmit a third AKMA service between a terminal device and an application function network element, the application session being carried in a third session of the terminal device; and the processing unit 1410 is configured to obtain information about a current network corresponding to the third session, and determine whether to allow establishment of the application session according to the information about the current network corresponding to the third session.
[0526] In a possible implementation, the processing unit 1410 is configured to determine whether to allow the application session to be established according to information of a current network corresponding to the third session, including: in a case where the current network corresponding to the third session is a first network, the first network being a network in which the terminal device cannot use AKMA services, the processing unit 1410 is configured to reject the establishment of the application session.
[0527] In a possible implementation, the processing unit 1410 is configured to determine whether to allow the application session to be established according to information of a current network corresponding to the third session, including: in a case where the current network corresponding to the third session is a second network, the second network being a network in which the terminal device can use AKMA services, the processing unit 1410 is configured to allow the establishment of the application session.
[0528] In a possible implementation, the processing unit 1410 is configured to obtain information of a current network corresponding to the third session, including: the transceiver 1420 is configured to send a second subscription request message, the second subscription request message being used to subscribe to a network change corresponding to the third session; and the processing unit 1410 is configured to receive a third notification message, the third notification message including the information of the current network corresponding to the third session.
[0529] In a possible implementation, the second subscription request message includes one or more of information of the third session, an identifier of the terminal device, or a second event identifier, the second event identifier being used to indicate a network change event.
[0530] In a possible implementation, when the communication apparatus 1400 is configured to implement the function of the AAnF in the method embodiments, the transceiver 1420 is configured to send an application session establishment request message, the application session establishment request message being used to request the establishment of an application session used to transmit AKMA services between the terminal device and an application function network element; receive an application session establishment response message, the application session establishment response message indicating that the application session is successfully established; and receive an AKMA service closing notification message, the AKMA service closing notification message including information of a first network or roaming policy information, the roaming policy information including information of a network in which the terminal device cannot use AKMA services, and the information of the network in which the terminal device cannot use AKMA services including the information of the first network; and the processing unit 1410 is configured to determine whether to release the application session according to the AKMA service closing notification message and information of a network corresponding to the application session.
[0531] In a possible implementation, the processing unit 1410 is configured to determine whether to release the application session according to the AKMA service closing notification message and information of a network corresponding to the application session, including: in a case where the network corresponding to the application session is the first network, the processing unit 1410 is configured to release the application session.
[0532] In a possible implementation, the processing unit 1410 is configured to determine whether to release the application session according to the AKMA service closing notification message and information of a network corresponding to the application session, including: when the network corresponding to the application session is a second network, not releasing the application session, the second network being different from the first network, and the second network being a network in which the terminal device can use the AKMA service.
[0533] When the communication apparatus 1400 is configured to implement the function of the UE in the method embodiments, the processing unit 1410 is configured to determine that the terminal device cannot use the AKMA service in the first network; and the transceiver 1420 is configured to send an AKMA service closing notification message to the terminal device, the AKMA service closing notification message including information of the first network or roaming policy information, the roaming policy information including information of a network in which the terminal device cannot use the AKMA service, and the information of the network in which the terminal device cannot use the AKMA service including the information of the first network.
[0534] When the communication apparatus 1400 is configured to implement the function of the AF in the method embodiments, the transceiver 1420 is configured to receive an application session establishment request message from a terminal device, the application session establishment request message requesting to establish an application session for transmitting an AKMA service between the terminal device and an application function network element, the application session establishment request message including an AKMA key identifier, and the application session being carried on a first session; send an application key request message to an AKMA anchor function network element, the application key request message including the AKMA key identifier; receive an application key response message from the AKMA anchor function network element, the application key response message including an application key corresponding to the AKMA key identifier, and the application key response message being used to indicate that the terminal device is not allowed to use the AKMA service in a first network and / or is allowed to use the AKMA service in a second network; and the processing unit 1410 is configured to obtain information of a current network corresponding to the first session, and determine whether to allow the application session according to the information of the current network corresponding to the first session and the application key response message.
[0535] In a possible implementation, the processing unit 1410 is configured to obtain the information of the current network corresponding to the first session, including: obtaining the information of the current network corresponding to the first session according to the application key response message.
[0536] In a possible implementation, the processing unit 1410 is configured to obtain information of a current network corresponding to the first session, including: sending, by the transceiver unit 1420, a subscription request message to a session management function network element, the subscription request message being used to subscribe to network information corresponding to the first session; and receiving a notification message from the session management function network element, the notification message including the information of the current network corresponding to the first session.
[0537] In a possible implementation, the subscription request message includes one or more of information of the first session, an identifier of the terminal device, or an event identifier, the event identifier being used to indicate a network change event.
[0538] In a possible implementation, the processing unit 1410 is configured to determine whether to allow the application session according to the information of the current network corresponding to the first session and the application key response message, including: configured to reject the application session in a case where the current network corresponding to the first session is the first network.
[0539] In a possible implementation, the processing unit 1410 is configured to determine whether to allow the application session according to the information of the current network corresponding to the first session and the application key response message, including: configured to allow the application session in a case where the current network corresponding to the first session is the second network.
[0540] When the communication apparatus 1400 is configured to implement the function of the AAnF in the method embodiments, the transceiver unit 1420 is configured to receive an application key request message from an application function network element, the application key request message including an AKMA key identifier; and the processing unit 1410 is configured to send, by the transceiver unit 1420, an application key response message to the application function network element according to whether to allow a terminal device to use AKMA services in a first network and a second network, the application key response message including an application key, the application key being generated according to an AKMA key corresponding to the AKMA key identifier, the application key response message being used to indicate whether to allow the terminal device to use AKMA services in the first network and / or the second network.
[0541] In a possible implementation, the processing unit 1410 is configured to send, to the application function network element via the transceiver unit 1420, an application key response message according to whether the terminal device is allowed to use AKMA services in the first network and the second network, including: in a case where it is determined that the terminal device is not allowed to use AKMA services in the first network and is allowed to use AKMA services in the second network, sending, to the application function network element via the transceiver unit 1420, the application key response message, wherein the application key response message further includes information of the first network and / or information of the second network; the information of the first network indicates that the terminal device is not allowed to use AKMA services in the first network; and the information of the second network indicates that the terminal device is allowed to use AKMA services in the second network.
[0542] In a possible implementation, the processing unit 1410 is configured to send, to the application function network element via the transceiver unit 1420, an application key response message according to whether the terminal device is allowed to use AKMA services in the first network and the second network, including: in a case where it is determined that the terminal device is allowed to use AKMA services in the first network and the second network, sending, to the application function network element via the transceiver unit 1420, the application key response message, wherein the application key response message is used to indicate that the terminal device is allowed to use AKMA services in the first network and the second network.
[0543] In a possible implementation, the application key response message further includes information of the first network and information of the second network; the information of the first network indicates that the terminal device is allowed to use AKMA services in the first network; and the information of the second network indicates that the terminal device is allowed to use AKMA services in the second network.
[0544] For more details of the processing unit 1410 and the transceiver unit 1420, refer to the related description in the above method embodiments.
[0545] The communication apparatus 1500 shown in FIG. 15 includes a processor 1510 and an interface circuit 1520. The processor 1510 and the interface circuit 1520 are coupled to each other. It can be understood that the interface circuit 1520 can be a transceiver or an input / output interface. Optionally, the communication apparatus 1500 can further include a memory 1530, used to store instructions executed by the processor 1510 or store input data required by the processor 1510 to execute instructions or store data generated after the processor 1510 executes instructions.
[0546] When the communication apparatus 1500 is used for the method embodiments described above, the processor 1510 is configured to implement the functions of the processing unit 1410 described above, and the interface circuit 1520 is configured to implement the functions of the transceiver unit 1420 described above.
[0547] It can be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.
[0548] The method steps in the embodiments of the present application can be implemented by means of hardware, or by means of a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor, so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in an AF, an AAnF or a UE. Of course, the processor and the storage medium can also exist as discrete components in the base station or the terminal device.
[0549] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer programs or instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments are performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a base station, user equipment or other programmable apparatus. The computer programs or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another computer-readable storage medium, for example, the computer programs or instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through a wired or wireless manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center and the like integrated with one or more available media. The available medium can be a magnetic medium, for example, a floppy disk, a hard disk, a magnetic tape; an optical medium, for example, a digital video disc; and a semiconductor medium, for example, a solid-state disk. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile storage media.
[0550] In various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0551] In the present application, "at least one" means one or more, and "multiple" means two or more. The association relationship between the associated objects is described, which means that there can be three relationships, for example, A and / or B, which can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. In the textual description of the present application, the character " / ", generally represents that the associated objects before and after are in an "or" relationship; in the formula of the present application, the character " / ", represents that the associated objects before and after are in a "division" relationship.
[0552] It can be understood that the various numbers involved in the embodiments of the present application are only distinguished for convenience of description, and are not used to limit the scope of the embodiments of the present application. The size of the serial number of the above processes does not mean the execution order, and the execution order of the processes should be determined according to its function and inherent logic.
Claims
A method for managing AKMA service, characterized in that, The method comprises: receiving an authentication and key management, AKMA, service closing notification message of an application, wherein the AKMA service closing notification message comprises information of a first network, and the AKMA service closing notification message is used to notify that AKMA services of the first network are closed; obtaining information of a current network corresponding to a first session of a terminal device, wherein the first session is used to transmit first AKMA services between the terminal device and an application function network element; determining whether to close the first AKMA services according to the AKMA service closing notification message and the information of the current network corresponding to the first session. The method of claim 1, wherein The determining whether to close the first AKMA services according to the AKMA service closing notification message and the information of the current network corresponding to the first session comprises: in a case where the current network corresponding to the first session is the first network, closing the first AKMA services. The method of claim 2, wherein The obtaining the information of the current network corresponding to the first session of the terminal device comprises: receiving a first notification message, wherein the first notification message comprises information of the first network, and the first notification message indicates that a network corresponding to the first session changes to the first network. The method as claimed in claim 2 or 3, characterized in that The method further comprises: in a case where a second network corresponding to a second session of the terminal device is different from the first network, not closing second AKMA services between the terminal device and the application function network element, wherein the second session is used to transmit the second AKMA services. The method of claim 1, wherein The determining whether to close the first AKMA services according to the AKMA service closing notification message and the information of the current network corresponding to the first session comprises: in a case where the current network corresponding to the first session is a second network different from the first network, not closing the first AKMA services. The method of claim 5, wherein The obtaining the information of the current network corresponding to the first session of the terminal device comprises: receiving a second notification message, wherein the second notification message comprises information of the second network, and the second notification message indicates that the network corresponding to the first session is the second network. The method of any one of claims 1 to 6, wherein The method further comprises: sending a first subscription request message, wherein the first subscription request message is used to subscribe to network changes corresponding to the first session. The method of claim 7, wherein The first subscription request message comprises one or more of information of the first session, an identifier of the terminal device, or a first event identifier, wherein the first event identifier is used to indicate a network change event. The method of claim 3, wherein The first notification message comprises one or more of information of the first session, an identifier of the terminal device, or a first event identifier, wherein the first event identifier is used to indicate a network change event. The method according to any one of claims 1 to 3, characterized in that The AKMA service closing notification message further comprises information of a second network. The method according to any one of claims 1 to 10, characterized in that The method further comprises: receiving an application session establishment request message, wherein the application session establishment request message requests to establish an application session used to transmit third AKMA services between the terminal device and the application function network element, and the application session is carried in a third session of the terminal device; determining whether to allow the establishment of the application session according to information of a current network corresponding to the third session. The method of claim 11, wherein The third session is the same session as the first session. A method for managing AKMA service, characterized in that, Comprising: receiving an application session establishment request message, the application session establishment request message requesting to establish an application session for transmitting AKMA service between a terminal device and an application function network element, the application session being carried in a third session of the terminal device; obtaining information of a current network corresponding to the third session; determining whether to allow establishment of the application session according to the information of the current network corresponding to the third session. The method of claim 13, wherein The determination whether to allow establishment of the application session according to the information of the current network corresponding to the third session comprises: in a case where the current network corresponding to the third session is a first network, the first network being a network in which the terminal device cannot use AKMA service, the establishment of the application session is rejected. The method of claim 13, wherein The determination whether to allow establishment of the application session according to the information of the current network corresponding to the third session comprises: in a case where the current network corresponding to the third session is a second network, the second network being a network in which the terminal device can use AKMA service, the establishment of the application session is allowed. The method of claim 14 or 15, wherein The obtaining of the information of the current network corresponding to the third session comprises: sending a second subscription request message, the second subscription request message being used to subscribe to network change corresponding to the third session; receiving a third notification message, the third notification message including the information of the current network corresponding to the third session. The method of claim 16, wherein The second subscription request message includes one or more of information of the third session, an identifier of the terminal device, or a second event identifier, the second event identifier being used to indicate a network change event. A method for managing AKMA service, characterized in that, Comprising: sending an application session establishment request message, the application session establishment request message requesting to establish an application session for transmitting AKMA service between a terminal device and an application function network element; receiving an application session establishment response message, the application session establishment response message indicating that the application session is successfully established; receiving an AKMA service closing notification message, the AKMA service closing notification message including information of a first network or roaming policy information, the roaming policy information including information of a network in which the terminal device cannot use AKMA service, the information of the network in which the terminal device cannot use AKMA service including the information of the first network; determining whether to release the application session according to the AKMA service closing notification message and information of a network corresponding to the application session. The method of claim 18, wherein The determination whether to release the application session according to the AKMA service closing notification message and the information of the network corresponding to the application session comprises: when the network corresponding to the application session is the first network, the application session is released. The method of claim 18, wherein The determination whether to release the application session according to the AKMA service closing notification message and the information of the network corresponding to the application session comprises: when the network corresponding to the application session is a second network, the application session is not released, the second network being different from the first network, the second network being a network in which the terminal device can use AKMA service. A method for managing AKMA service, characterized in that, Comprising: determining that the terminal device is not allowed to use AKMA service in the first network; sending, to the terminal device, an AKMA service closing notification message, the AKMA service closing notification message comprising information of the first network or roaming policy information, the roaming policy information comprising information of a network in which the terminal device is not allowed to use AKMA service, the information of the network in which the terminal device is not allowed to use AKMA service comprising the information of the first network. A method for managing AKMA service, characterized in that, comprising: receiving, from a terminal device, an application session establishment request message, the application session establishment request message requesting establishment of an application session for transmitting AKMA service between the terminal device and an application function network element, the application session establishment request message comprising an AKMA key identifier, the application session being carried on a first session; sending, to an AKMA anchor function network element, an application key request message, the application key request message comprising the AKMA key identifier; receiving, from the AKMA anchor function network element, an application key response message, the application key response message comprising an application key corresponding to the AKMA key identifier, the application key response message being used to indicate that the terminal device is not allowed to use AKMA service in a first network and / or is allowed to use AKMA service in a second network; obtaining information of a current network corresponding to the first session; determining whether to allow the application session according to the information of the current network corresponding to the first session and the application key response message. The method of claim 22, wherein The obtaining of the information of the current network corresponding to the first session comprises: obtaining the information of the current network corresponding to the first session according to the application key response message. The method of claim 22 or 23, wherein The obtaining of the information of the current network corresponding to the first session comprises: sending, to a session management function network element, a subscription request message, the subscription request message being used to subscribe to network information corresponding to the first session; receiving, from the session management function network element, a notification message, the notification message comprising the information of the current network corresponding to the first session. The method of claim 24, wherein The subscription request message comprises one or more of information of the first session, an identifier of the terminal device, or an event identifier, the event identifier being used to indicate a network change event. The method of any one of claims 22 to 25, wherein The determining of whether to allow the application session according to the information of the current network corresponding to the first session and the application key response message comprises: in a case where the current network corresponding to the first session is the first network, rejecting the application session. The method of any one of claims 22 to 25, wherein The determining of whether to allow the application session according to the information of the current network corresponding to the first session and the application key response message comprises: in a case where the current network corresponding to the first session is the second network, allowing the application session. A communication device, characterized by comprising a processor and an interface circuit, the processor being used to communicate with other devices through the interface circuit and implement the method of any one of claims 1 to 12, or implement the method of any one of claims 13 to 17, or implement the method of any one of claims 18 to 20, or implement the method of claim 21, or implement the method of any one of claims 22 to 27. A computer program product, characterized in that The computer program product comprises instructions which, when executed on a processor, implement the method of any one of claims 1 to 27. A computer-readable storage medium, characterized by The storage medium stores a computer program or instructions which, when executed, implement the method of any one of claims 1 to 27.
Citation Information
Patent Citations
Key management method and device, equipment and storage medium
CN117413554A
Application authentication and key management AKMA application program key request method and device under user equipment UE roaming condition
CN117616789A
Key management method, device, and system
US20230086032A1
Method and apparatus for wireless communication
WO2024050692A1