Method and apparatus for enhancement of authentication and key management for applications anchor function selection
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NOKIA TECHNOLOGIES OY
- Filing Date
- 2024-09-30
- Publication Date
- 2026-08-06
Smart Images

Figure CN2024123117_06082026_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR ENHANCEMENT OF AUTHENTICATION AND KEY MANAGEMENT FOR APPLICATIONS ANCHOR FUNCTION SELECTIONTECHNICAL FIELD
[0001] Various example embodiments of the present disclosure relate generally to the technology of communication, and in particular to a method and apparatus for enhancement of Authentication and Key Management for Applications Anchor Function (AAnF) selection.BACKGROUND
[0002] In communication networks, many network functions / nodes with variant capacities are cooperating to provide communication services. It is important to select proper network functions / nodes for certain services.
[0003] For example, a network node / function AAnF should be selected to generate the key material to be used between the User Equipment (UE) and the Application Function (AF) and maintains UE Authentication and Key Management for Applications (AKMA) contexts.
[0004] Currently a Routing Indicator is used for identifying and selecting the proper AAnF. However, the Routing Indicator is not supported by some devices of some telecommunication operators.SUMMARY
[0005] This summary is provided to introduce some aspects in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0006] Certain aspects of the present disclosure and their embodiments may provide solutions to these or other challenges. There are, proposed herein, various embodiments which address one or more of the issues disclosed herein. Specific method and apparatus for enhancement of Authentication and Key Management for Applications Anchor Function (AAnF) selection may be provided.
[0007] A first aspect of the present disclosure provides an apparatus operating as a terminal device. The apparatus operating as the first terminal device comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus operating as the terminal device at least to perform: receiving at least one identifier related to an apparatus operating as a first network node; transmitting an identifier in the at least one identifier to an apparatus operating as a second network node, for the apparatus operating as the second network node to identify the apparatus operating as the first network node. The at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0008] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0009] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0010] In exemplary embodiments of the present disclosure, the at least one identifier includes the first identifier or the second identifier.
[0011] In exemplary embodiments of the present disclosure, the at least one identifier includes the first identifier and the second identifier; the at least one memory and the computer program code are further configured to cause the apparatus operating as the terminal device to receive an indication about whether to use the first identifier or the second identifier; and the first identifier and the second identifier are received via different messages during different procedures.
[0012] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to cause the apparatus operating as the terminal device to perform: receiving the at least one identifier and / or the indicator in a Non Access Stratum, NAS, message from an apparatus operating as a third network node; and the NAS message comprises a registration complete message, or the NAS message is for UE Parameters Update, UPU.
[0013] In exemplary embodiments of the present disclosure, when transmitting the identifier, the apparatus operating as the terminal device uses the same name tag for the first identifier and the second identifier, and the apparatus operating as the terminal device further uses a type indication for differentiating the first identifier and the second identifier; or when transmitting the identifier, the apparatus operating as the terminal device uses different name tags for the first identifier and the second identifier.
[0014] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; and the identifier is included by the apparatus operating as the terminal device in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.
[0015] A second aspect of the present disclosure provides an apparatus operating as a second network node. The apparatus operating as the first network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus operating as the second network node at least to perform: receiving, from an apparatus operating as a terminal device or an apparatus operating as a fourth network node, an identifier related to an apparatus operating as a first network node; and identifying the apparatus operating as the first network node, based at least on the received identifier; the identifier is one identifier in at least one identifier related to the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0016] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0017] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0018] In exemplary embodiments of the present disclosure, the same name tag is used by the apparatus operating as the terminal device or the apparatus operating as the fourth network node for the first identifier and the second identifier, and a type indication are further used by the apparatus operating as the termina device or the apparatus operating as the fourth network node for differentiating the first identifier and the second identifier; or different name tags are used by the apparatus operating as the terminal device or the apparatus operating as the fourth network node for the first identifier and the second identifier.
[0019] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; and the identifier is included, by the apparatus operating as the terminal device or the apparatus operating as the fourth network node, in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.
[0020] A third aspect of the present disclosure provides an apparatus operating as a third network node. The apparatus operating as the first network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus operating as the second network node at least to perform: transmitting, to an apparatus operating as a terminal device, at least one identifier related to an apparatus operating as the first network node; the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0021] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0022] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0023] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to cause the apparatus operating as the third network node to perform: transmitting, to the apparatus operating as the terminal device, an indication about whether to use the first identifier or the second identifier.
[0024] In exemplary embodiments of the present disclosure, the at least one identifier and / or the indication are included in a Non Access Stratum, NAS, message; and the NAS message comprises a registration complete message, or the NAS message is for UE Parameters Update, UPU.
[0025] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to cause the apparatus operating as the third network node to perform: receiving the at least one identifier and / or the indicator from an apparatus operating as a fourth network node during a primary authentication procedure for the apparatus operating as the terminal device; or receiving the at least one identifier and / or the indicator from an apparatus operating as a fifth network node, during a registration procedure for the apparatus operating as the terminal device or during a UPU procedure for the apparatus operating as the terminal device.
[0026] In exemplary embodiments of the present disclosure, the apparatus operating as the fourth network node has the second identifier of the apparatus operating as the first network node, when the apparatus operating as the fourth network node and the apparatus operating as the first network node are in the same group; or the apparatus operating as the fourth network node obtains the at least one identifier and / or the indicator from the apparatus operating as the fifth network node during the primary authentication procedure for the apparatus operating as the terminal device.
[0027] In exemplary embodiments of the present disclosure, the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; and the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.
[0028] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; and the apparatus operating as the third network node comprises an Access and Mobility Management Function, AMF.
[0029] A fourth aspect of the present disclosure provides an apparatus operating as a fourth network node. The apparatus operating as the first network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus operating as the second network node at least to perform: transmitting, to an apparatus operating as a third network node, at least one identifier related to an apparatus operating as a first network node; an identifier in the at least one identifier is to be used by an apparatus operating as the second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0030] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0031] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0032] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to cause the apparatus operating as the fourth network node to perform: transmitting, to the apparatus operating as the third network node, an indication about whether to use the first identifier or the second identifier.
[0033] In exemplary embodiments of the present disclosure, the apparatus operating as the fourth network node has the second identifier of the apparatus operating as the first network node, when the apparatus operating as the fourth network node and the apparatus operating as the first network node are in the same group; or the apparatus operating as the fourth network node receives the at least one identifier and / or the indicator from an apparatus operating as a fifth network node during the primary authentication procedure for the apparatus operating as the terminal device.
[0034] In exemplary embodiments of the present disclosure, the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.
[0035] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to cause the apparatus operating as the fourth network node to perform: transmitting, to the apparatus operating as the second network node, the identifier; when transmitting the identifier, the apparatus operating as the fourth network node uses the same name tag for the first identifier and the second identifier, and the fourth network node further uses a type indication for differentiating the first identifier and the second identifier; or when transmitting the identifier, the apparatus operating as the fourth network node uses different name tags for the first identifier and the second identifier.
[0036] In exemplary embodiments of the present disclosure, the identifier is included by the apparatus operating as the fourth network node in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.
[0037] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; and the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF;
[0038] the apparatus operating as the third network node comprises an Access and Mobility Management Function; and the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF.
[0039] A fifth aspect of the present disclosure provides an apparatus operating as a fifth network node. The apparatus operating as the first network node comprises at least one processor; and at least one memory including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor, cause the apparatus operating as the second network node at least to perform: transmitting, to an apparatus operating as a third network node and / or an apparatus operating as a fourth network node, at least one identifier related to an apparatus operating as a first network node; an identifier in the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0040] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0041] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0042] In exemplary embodiments of the present disclosure, the at least one memory and the computer program code are further configured to cause the apparatus operating as the fifth network node to perform: transmitting, to the apparatus operating as the third network node and / or the apparatus operating as the fourth network node, an indication about whether to use the first identifier or the second identifier.
[0043] In exemplary embodiments of the present disclosure, the apparatus operating as the fifth network node transmits the at least one identifier and / or the indication, during at least one of: a primary authentication procedure for the apparatus operating as the terminal device; a registration procedure for the apparatus operating as the terminal device; or a UPU procedure for the apparatus operating as the terminal device.
[0044] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; and the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; the apparatus operating as the third network node comprises an Access and Mobility Management Function; the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; and the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.
[0045] A sixth aspect of the present disclosure provides a method performed by an apparatus operating as a terminal device, according to any of embodiments of the first aspect.
[0046] A seventh aspect of the present disclosure provides a method performed by an apparatus operating as a second network node, according to any of embodiments of the second aspect.
[0047] An eighth aspect of the present disclosure provides a method performed by an apparatus operating as a third network node, according to any of embodiments of the fourth aspect.
[0048] A ninth aspect of the present disclosure provides a method performed by an apparatus operating as a fourth network node, according to any of embodiments of the fifth aspect.
[0049] A tenth aspect of the present disclosure provides a method performed by an apparatus operating as a fifth network node, according to any of embodiments of the sixth aspect.
[0050] An eleventh aspect of the present disclosure provides a computer-readable storage medium storing instructions, which when executed by at least one processor of the apparatus according to any of the embodiments above mentioned, cause the at least one processor of the apparatus to perform at least the method according to any of the embodiments above mentioned.
[0051] According to embodiments of the present disclosure, the exemplary embodiments of the present disclosure propose a mechanism for enhancement of Authentication and Key Management for Applications Anchor Function (AAnF) selection. It will be selectable / configurable to use different identifiers / indicators of different types related to a network node, for identifying and selecting the network node. Therefore, the applicability and compatibility for using the network node in different networks of different operators will be greatly improved.BRIEF DESCRIPTION OF DRAWINGS
[0052] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more fully apparent, by way of example, from the following detailed description with reference to the accompanying drawings, in which like reference numerals or letters are used to designate like or equivalent elements. The drawings are illustrated for facilitating better understanding of the embodiments of the disclosure and not necessarily drawn to scale, in which:
[0053] FIG. 1 is a diagram showing a procedure for Deriving KAKMA after primary authentication.
[0054] FIG. 2 is a diagram showing a procedure for KAF generation from KAKMA.
[0055] FIG. 3 is a block diagram showing an exemplary structure for an apparatus operating as a terminal device, according to exemplary embodiments of the present disclosure.
[0056] FIG. 4A is a flow chart showing a method performed by an apparatus operating as a terminal device.
[0057] FIG. 4B is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0058] FIG. 5 is a block diagram showing an exemplary structure for an apparatus operating as a second network node, according to exemplary embodiments of the present disclosure.
[0059] FIG. 6 is a flow chart showing a method performed by an apparatus operating as a second network node.
[0060] FIG. 7 is a block diagram showing an exemplary structure for an apparatus operating as a third network node, according to exemplary embodiments of the present disclosure.
[0061] FIG. 8A is a flow chart showing a method performed by an apparatus operating as a third network node.
[0062] FIG. 8B is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0063] FIG. 8C is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0064] FIG. 9 is a block diagram showing an exemplary structure for an apparatus operating as a fourth network node, according to exemplary embodiments of the present disclosure.
[0065] FIG. 10A is a flow chart showing a method performed by an apparatus operating as a fourth network node.
[0066] FIG. 10B is a flow chart showing further steps of the method as shown in FIG. 10A, according to exemplary embodiments of the present disclosure.
[0067] FIG. 10C is a flow chart showing further steps of the method as shown in FIG. 10A, according to exemplary embodiments of the present disclosure.
[0068] FIG. 11 is a block diagram showing an exemplary structure for an apparatus operating as a fifth network node, according to exemplary embodiments of the present disclosure.
[0069] FIG. 12A is a flow chart showing a method performed by an apparatus operating as a fifth network node.
[0070] FIG. 12B is a flow chart showing further steps of the method as shown in FIG. 12A, according to exemplary embodiments of the present disclosure.
[0071] FIG. 13 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.
[0072] FIG. 14 is a block diagram showing exemplary apparatus units for a terminal device, which is suitable for performing the method according to embodiments of the disclosure.
[0073] FIG. 15 is a block diagram showing exemplary apparatus units for a second network node, which is suitable for performing the method according to embodiments of the disclosure.
[0074] FIG. 16 is a block diagram showing exemplary apparatus units for a third network node, which is suitable for performing the method according to embodiments of the disclosure.
[0075] FIG. 17 is a block diagram showing exemplary apparatus units for a fourth network node, which is suitable for performing the method according to embodiments of the disclosure.
[0076] FIG. 18 is a block diagram showing exemplary apparatus units for a fifth network node, which is suitable for performing the method according to embodiments of the disclosure.
[0077] FIG. 19 is a diagram showing a procedure for passing GID to UE via Priamary Authentication, according to embodiments of the present disclsoure.
[0078] FIG. 20 is a diagram showing a procedure for notification to UE for the change of altRid and ridType, according to embodiments of the present disclsoure.
[0079] FIG. 21 is a diagram showing a procedure for deriving KAKMA after primary authentication, according to embodiments of the present disclsoure.
[0080] FIG. 22 is a diagram showing a procedure for KAF generation from KAKMA, according to embodiments of the present disclsoure.DETAILED DESCRIPTION
[0081] The embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for better understanding, rather than limitations on the scope of the present disclosure. The described features, advantages, and characteristics of the disclosure may be combined in any suitable manner in one or more embodiments.
[0082] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless clearly given and / or implied from the context. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate.
[0083] As used herein, the term “network” or “communication network” refers to a network following any suitable communication standards (such for an internet network, or any wireless network) . For example, wireless communication standards may comprise WLAN (Wireless Local Area Network) , new radio (NR) , long term evolution (LTE) , LTE-Advanced, 5G NR, 6G etc. In the following description, the terms “network” and “system” can be used interchangeably.
[0084] The term “node / network node” refers to a computing device or computing entity or computing function or any other devices (physical or virtual) in a communication network. For example, the node in the network may include a base station (BS) , an access point (AP) , or any other suitable device in a wireless communication network. The BS may be, for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , a next generation NodeB (gNodeB or gNB) , a remote radio unit (RRU) , a radio header (RH) , a remote radio head (RRH) , a relay, a low power node such as a femto, a pico, and so forth. Further, the node may include other core network node, such as an Access and Mobility Management Function, AMF, a Session Management Function, SMF, a User Plane Function, UPF, a mobility management entity, MME, or a serving gateway, S-GW, etc.
[0085] The term “terminal device” refers to any end device that can access a communication network and receive services therefrom. By way of example and not limitation, the terminal device refers to a mobile terminal, user equipment (UE) , a non-AP device (such as a non-AP Station (STA) ) , or other suitable devices. The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, a wearable device, a vehicle-mounted wireless terminal device, a vehicle, and the like.
[0086] As one example, a terminal device may represent a device configured for communication in accordance with one or more communication standards promulgated by any standard organization, such as 3rd generation partnership project, 3GPP.
[0087] As yet another example, in an Internet of Things (IoT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another terminal device and / or network equipment. Particular examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or home or personal appliances, for example refrigerators, televisions, personal wearables such as watches etc. In other scenarios, a terminal device may represent a vehicle or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0088] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.
[0089] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0090] As an example for introducing the solutions in embodiments of the present disclosure, the AAnF is used. However, it should be understood that this is not a limitation. The solutions of the embodiments of the present disclosure may be also used to identify and / or select variant kinds of network nodes / functions.
[0091] AAnF is the anchor function in the Home Public Land Mobile Network (HPLMN) . The AAnF stores the Authentication and Key Management for Applications (AKMA) Anchor Key (KAKMA) and SUbscription Permanent Identifier (SUPI) for AKMA service, which is received from the AUthentication Server Function (AUSF) after the user equipment (UE) completes a successful 5th generation (5G) primary authentication. The AAnF also generates the key material to be used between the UE and the Application Function (AF) and maintains UE AKMA contexts. The AAnF sends SUPI of the UE to application function (AF) located inside the operator's network according to the AF request or sends to Network Exposure Function (NEF) .
[0092] FIG. 1 is a diagram showing a procedure for Deriving KAKMA after primary authentication.
[0093] FIG. 1 is the Figure 6.1-1: Deriving KAKMA after primary authentication, 3GPP TS 33.535 V18.2.0 (2023-12) .
[0094] FIG. 1 shows following main steps, as cited from the 3GPP TS 33.535 V18.2.0 (2023-12) .
[0095] 1) During the primary authentication procedure, the AUSF interacts with the UDM in order to fetch authentication information such as subscription credentials (e.g. AKA Authentication vectors) and the authentication method using the Nudm_UEAuthentication_Get Request service operation.
[0096] 2) In the response, the UDM may also indicate to the AUSF whether the AKMA Anchor key needs to be generated for the UE. If the AKMA indication is included, the UDM shall also include the RID of the UE.
[0097] 3) If the AUSF receives the AKMA indication from the UDM, the AUSF shall store the KAUSF and generate the AKMA Anchor Key (KAKMA) and the A-KID from KAUSF after the primary authentication procedure is successfully completed.
[0098] The UE shall generate the AKMA Anchor Key (KAKMA) and the A-KID from the KAUSF before initiating communication with an AKMA Application Function.
[0099] 4) After AKMA key material is generated, the AUSF selects the AAnF as defined in clause 6.7, and shall send the generated A-KID and KAKMA to the AAnF together with the SUPI of the UE using the Naanf_AKMA_KeyRegistration Request service operation. The AAnF shall store the latest information sent by the AUSF.
[0100] NOTE 1: The AUSF need not store any AKMA key material after delivery to the AAnF.
[0101] NOTE 1a: When re-authentication runs, the AUSF generates a new A-KID, and a new KAKMA and sends the new generated A-KID and KAKMA to the AAnF. After receiving the new generated A-KID and KAKMA, the AAnF deletes the old A-KID and KAKMA and stores the new generated A-KID and KAKMA.
[0102] 5) The AAnF sends the response to the AUSF using the Naanf_AKMA_AnchorKey_Register Response service operation.
[0103] FIG. 2 is a diagram showing a procedure for KAF generation from KAKMA.
[0104] FIG. 2 is the Figure 6.2-1: KAF generation from KAKMA, 3GPP TS 33.535 V18.2.0 (2023-12) .
[0105] FIG. 2 shows following main steps, as cited from the 3GPP TS 33.535 V18.2.0 (2023-12) .
[0106] 1. The UE shall generate the AKMA Anchor Key (KAKMA) and the A-KID from the KAUSF before initiating communication with an AKMA Application Function. When the UE initiates communication with the AKMA AF, it shall include the derived A-KID (see clause 6.1) in the Application Session Establishment Request message. The UE may derive KAF before sending the message or afterwards.
[0107] 2. If the AF does not have an active context associated with the A-KID, then the AF selects the AAnF as defined in clause 6.7, and sends a Naanf_AKMA_ApplicationKey_Get request to AAnF with the A-KID to request the KAF for the UE. The AF also includes its identity (AF_ID) in the request.
[0108] AF_ID consists of the FQDN of the AF and the Ua*security protocol identifier (see Annex A.4) . The latter parameter identifies the security protocol that the AF will use with the UE.
[0109] The AAnF shall check whether the AAnF can provide the service to the AF based on the configured local policy or based on the authorization information available in the signalling (i.e., Oauth2.0 token) . If it succeeds, the following procedures are executed. Otherwise, the AAnF shall reject the procedure.
[0110] The AAnF shall verify whether the subscriber is authorized to use AKMA based on the presence of the UE specific KAKMA key identified by the A-KID.
[0111] If KAKMA is present in AAnF, the AAnF shall continue with step 3.
[0112] If KAKMA is not present in the AAnF, the AAnF shall continue with step 6 with an error response.
[0113] 3. Once receiving the request from the AF, if the AAnF determines this specific AF needs GPSI, according to its local policy, the AAnF sends a Nudm_SDM_Get Request to the UDM to fetch the GPSI of the UE. If the specific AF does not need GPSI, the AAnF shall continue with step 5.
[0114] 4. The UDM responds with the GPSI of the UE. The AAnF shall store the received GPSI as part of UE’s AKMA context.
[0115] 5. The AAnF derives the AKMA Application Key (KAF) from KAKMA if it does not already have KAF. The key derivation of KAF shall be performed as specified in Annex A. 4.
[0116] 6. The AAnF sends Naanf_AKMA_ApplicationKey_Get response to the AF with SUPI / GPSI, KAF and the KAF expiration time. Whether to send SUPI or GPSI is determined by AAnF based on the local policy.
[0117] 7. The AF sends the Application Session Establishment Response to the UE. If the information in step 6 indicates failure of AKMA key request, the AF shall reject the Application Session Establishment by including a failure cause. Afterwards, UE may trigger a new Application Session Establishment request with the latest A-KID to the AKMA AF.
[0118] In some implementations, the AAnF selection functionality in NF consumer only consider using the UE's Routing Indicator. The AF / NEF obtains the Routing Indicator as part of the A-KID in the AKMA request. The AUSF obtains the Routing Indicator within the Nudm_UEAuthentication_Get Response from the UDM. Internal AFs, the NEF and the AUSF shall select the same AAnF set based on the UE’s Routing Indicator.
[0119] The problem is that devices of some operators don’t use Routing Indicator at all. They use other kinds of Ids, for example Group Id, to do the 5g core segmentation. All the 5g NFs, like Unified Data Management (UDM) , AUSF, AAnF, in the same group will use the same and unique Group Id for network repository function (NRF) Registration and service discovery.
[0120] If the Group Id isn’t available in the Discovery request, the NRF retrieves the Group Id based on the subscriber identity (for example SUPI) via 5G Unified Data Repository (UDR) GroupIDmap service.
[0121] In this situation, AF / NEF doesn’t have the Group Id information (since not included in the A-KID) and is not able to select correct AAnF. It should be noted that AF / NEF don’t have the subscriber identity.
[0122] However, AKMA feature is possible only via routing ID. There is no support for group Id based solution. Due to this, this feature cannot be used in some operators.
[0123] Replacing the segmentation mechanism with RID is huge change for such operators. There are also a lot of concerns using RID (only for AKMA use case) along with Group ID, like how to provision and later to keep the Routing-Id stored in the UE in synch with the respective Subscriber Data Management (SDM) group, and how to handle the migration case, etc.
[0124] Embodiments of the present disclosure are to provide solutions about how to use Ids of different types. For example, how to use Group ID in AKMA solution.
[0125] FIG. 3 is a block diagram showing an exemplary structure for an apparatus operating as a terminal device, according to exemplary embodiments of the present disclosure.
[0126] As shown in FIG. 3, the apparatus 30 for a terminal device comprises at least one processor 302, and at least one memory 304 including computer program code. The at least one memory 304 and the computer program code are configured to, with the at least one processor 302, cause the apparatus 30 operating as the terminal device at least to perform the method according to any of the following embodiments, such as shown in FIG. 4A-FIG. 4B, FIG. 19-22.
[0127] FIG. 4A is a flow chart showing a method performed by an apparatus operating as a terminal device.
[0128] As shown in FIG. 4A, the method 400 comprises: a step S402, receiving at least one identifier related to an apparatus operating as a first network node; a step S404, transmitting an identifier in the at least one identifier to an apparatus operating as a second network node, for the apparatus operating as the second network node to identify the apparatus operating as the first network node. The at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0129] According to embodiments of the present disclosure, it will be selectable / configurable to use different identifiers / indicators of different types related to a network node, for identifying and selecting the network node. Therefore, the applicability and compatibility for using the network node in different networks of different operators will be greatly improved.
[0130] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0131] According to embodiments of the present disclosure, candidate identifiers to be selected / configured may be routing identifier and group identifier. For example, when a routing identifier is not supported, a group identifier may be used. It should be noted that, more than two identifiers may be also supported by embodiments of the present disclosure.
[0132] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0133] According to embodiments of the present disclosure, any kind of group identifier, such as for a SDM group, may be used.
[0134] In exemplary embodiments of the present disclosure, the at least one identifier includes the first identifier or the second identifier.
[0135] According to embodiments of the present disclosure, the terminal device may receive any one identifier and then use it.
[0136] In exemplary embodiments of the present disclosure, the at least one identifier includes the first identifier and the second identifier; the at least one memory and the computer program code are further configured to cause the apparatus operating as the terminal device to receive an indication about whether to use the first identifier or the second identifier; and the first identifier and the second identifier are received via different messages during different procedures.
[0137] According to embodiments of the present disclosure, the terminal device may receive both identifier and then use one of them selectively. Further, these two identifiers may be received in the same message, or in different messages, even during different procedures, such as authentication procedure, parameter update procedure, etc.
[0138] FIG. 4B is a flow chart showing further steps of the method as shown in FIG. 4A, according to exemplary embodiments of the present disclosure.
[0139] In exemplary embodiments of the present disclosure, the method 400 further comprises: a step S406, receiving the at least one identifier and / or the indicator in a Non Access Stratum, NAS, message from an apparatus operating as a third network node; and the NAS message comprises a registration complete message, or the NAS message is for UE Parameters Update, UPU.
[0140] According to embodiments of the present disclosure, the identifier may be received during registration, or UE Parameters Update.
[0141] In exemplary embodiments of the present disclosure, when transmitting the identifier, the apparatus operating as the terminal device uses the same name tag for the first identifier and the second identifier, and the apparatus operating as the terminal device further uses a type indication for differentiating the first identifier and the second identifier; or when transmitting the identifier, the apparatus operating as the terminal device uses different name tags for the first identifier and the second identifier.
[0142] According to embodiments of the present disclosure, the same name tag may be used for providing compatibility. Alternatively, the different name tags may be used for providing easier understanding.
[0143] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; and the identifier is included by the apparatus operating as the terminal device in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.
[0144] According to embodiments of the present disclosure, the solutions may be applicable in AAnF selection / discovery by AF / NEF using the identifier included in the A-KID. It should be noted that this procedure is an example, not limitation.
[0145] FIG. 5 is a block diagram showing an exemplary structure for an apparatus operating as a second network node, according to exemplary embodiments of the present disclosure.
[0146] As shown in FIG. 5, the apparatus 50 operating as a second network node comprises at least one processor 502, and at least one memory 504 including computer program code. The at least one memory and the computer program code are configured to, with the at least one processor 502, cause the apparatus 50 operating as the second network node at least to perform the method according to any of the following embodiments, such as shown in FIG. 6, FIG. 19-22.
[0147] FIG. 6 is a flow chart showing a method performed by an apparatus operating as a second network node.
[0148] As shown in FIG. 6, the method 600 comprises: a step S602, receiving, from an apparatus operating as a terminal device or an apparatus operating as a fourth network node, an identifier related to an apparatus operating as a first network node; and a step S604, identifying the apparatus operating as the first network node, based at least on the received identifier; the identifier is one identifier in at least one identifier related to the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0149] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0150] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0151] In exemplary embodiments of the present disclosure, the same name tag is used by the apparatus operating as the terminal device or the apparatus operating as the fourth network node for the first identifier and the second identifier, and a type indication are further used by the apparatus operating as the termina device or the apparatus operating as the fourth network node for differentiating the first identifier and the second identifier; or different name tags are used by the apparatus operating as the terminal device or the apparatus operating as the fourth network node for the first identifier and the second identifier.
[0152] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; and the identifier is included, by the apparatus operating as the terminal device or the apparatus operating as the fourth network node, in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.
[0153] FIG. 7 is a block diagram showing an exemplary structure for an apparatus operating as a third network node, according to exemplary embodiments of the present disclosure.
[0154] As shown in FIG. 7, the apparatus70 operating as a third network node comprises at least one processor 702, and at least one memory 704 including computer program code. The at least one memory 704 and the computer program code are configured to, with the at least one processor 702, cause the apparatus 70 operating as the third network node at least to perform the method according to any of the following embodiments, such as shown in FIG. 8A-FIG. 8C, FIG. 19-22.
[0155] FIG. 8A is a flow chart showing a method performed by an apparatus operating as a third network node.
[0156] As shown in FIG. 8A, the method 800 comprises: a step S802, transmitting, to an apparatus operating as a terminal device, at least one identifier related to an apparatus operating as the first network node; the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0157] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0158] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0159] FIG. 8B is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0160] As shown in FIG. 8B, the method 800 further comprises: a step S804, transmitting, to the apparatus operating as the terminal device, an indication about whether to use the first identifier or the second identifier.
[0161] In exemplary embodiments of the present disclosure, the at least one identifier and / or the indication are included in a Non Access Stratum, NAS, message; and the NAS message comprises a registration complete message, or the NAS message is for UE Parameters Update, UPU.
[0162] FIG. 8C is a flow chart showing further steps of the method as shown in FIG. 8A, according to exemplary embodiments of the present disclosure.
[0163] As shown in FIG. 8C, the method 800 further comprises: a step S806, receiving the at least one identifier and / or the indicator from an apparatus operating as a fourth network node during a primary authentication procedure for the apparatus operating as the terminal device; or a step S808, receiving the at least one identifier and / or the indicator from an apparatus operating as a fifth network node, during a registration procedure for the apparatus operating as the terminal device or during a UPU procedure for the apparatus operating as the terminal device.
[0164] In exemplary embodiments of the present disclosure, the apparatus operating as the fourth network node has the second identifier of the apparatus operating as the first network node, when the apparatus operating as the fourth network node and the apparatus operating as the first network node are in the same group; or the apparatus operating as the fourth network node obtains the at least one identifier and / or the indicator from the apparatus operating as the fifth network node during the primary authentication procedure for the apparatus operating as the terminal device.
[0165] In exemplary embodiments of the present disclosure, the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; and the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.
[0166] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; and the apparatus operating as the third network node comprises an Access and Mobility Management Function, AMF.
[0167] FIG. 9 is a block diagram showing an exemplary structure for an apparatus operating as a fourth network node, according to exemplary embodiments of the present disclosure.
[0168] As shown in FIG. 9, the apparatus 90 operating as a fourth network node comprises at least one processor 902, and at least one memory 904 including computer program code. The at least one memory 904 and the computer program code are configured to, with the at least one processor 902, cause the apparatus90 operating as the fourth network node at least to perform the method according to any of the following embodiments, such as shown in FIG. 10A-FIG. 10C, FIG. 19-22.
[0169] FIG. 10A is a flow chart showing a method performed by an apparatus operating as a fourth network node.
[0170] As shown in FIG. 10A, the method 1000 comprises: a step S1002, transmitting, to an apparatus operating as a third network node, at least one identifier related to an apparatus operating as a first network node; an identifier in the at least one identifier is to be used by an apparatus operating as the second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0171] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0172] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0173] FIG. 10B is a flow chart showing further steps of the method as shown in FIG. 10A, according to exemplary embodiments of the present disclosure.
[0174] As shown in FIG. 10B, the method 1000 further comprises: a step S1004, transmitting, to the apparatus operating as the third network node, an indication about whether to use the first identifier or the second identifier.
[0175] In exemplary embodiments of the present disclosure, the apparatus operating as the fourth network node has the second identifier of the apparatus operating as the first network node, when the apparatus operating as the fourth network node and the apparatus operating as the first network node are in the same group; or the apparatus operating as the fourth network node receives the at least one identifier and / or the indicator from an apparatus operating as a fifth network node during the primary authentication procedure for the apparatus operating as the terminal device.
[0176] In exemplary embodiments of the present disclosure, the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.
[0177] FIG. 10C is a flow chart showing further steps of the method as shown in FIG. 10A, according to exemplary embodiments of the present disclosure.
[0178] As shown in FIG. 10C, the method 1000 further comprises: a step S1006, transmitting, to the apparatus operating as the second network node, the identifier; when transmitting the identifier, the apparatus operating as the fourth network node uses the same name tag for the first identifier and the second identifier, and the fourth network node further uses a type indication for differentiating the first identifier and the second identifier; or when transmitting the identifier, the apparatus operating as the fourth network node uses different name tags for the first identifier and the second identifier.
[0179] In exemplary embodiments of the present disclosure, the identifier is included by the apparatus operating as the fourth network node in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.
[0180] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; and the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; the apparatus operating as the third network node comprises an Access and Mobility Management Function; and the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF.
[0181] FIG. 11 is a block diagram showing an exemplary structure for an apparatus operating as a fifth network node, according to exemplary embodiments of the present disclosure.
[0182] As shown in FIG. 11, the apparatus 110 operating as a fifth network node comprises at least one processor 1102, and at least one memory 1104 including computer program code. The at least one memory 1104 and the computer program code are configured to, with the at least one processor 1102, cause the apparatus 110 operating as the fifth network node at least to perform the method according to any of the following embodiments, such as shown in FIG. 12, FIG. 19-22.
[0183] FIG. 12A is a flow chart showing a method performed by an apparatus operating as a fifth network node.
[0184] As shown in FIG. 12A, the method 1200 comprises: a step S1202, transmitting, to an apparatus operating as a third network node and / or an apparatus operating as a fourth network node, at least one identifier related to an apparatus operating as a first network node; an identifier in the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0185] In exemplary embodiments of the present disclosure, the first identifier is a routing identifier; and the second identifier is a group identifier.
[0186] In exemplary embodiments of the present disclosure, the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.
[0187] FIG. 12B is a flow chart showing further steps of the method as shown in FIG. 12A, according to exemplary embodiments of the present disclosure.
[0188] As shown in FIG. 12B, the method 1200 further comprises: a step S1204, transmitting, to the apparatus operating as the third network node and / or the apparatus operating as the fourth network node, an indication about whether to use the first identifier or the second identifier.
[0189] In exemplary embodiments of the present disclosure, the apparatus operating as the fifth network node transmits the at least one identifier and / or the indication, during at least one of: a primary authentication procedure for the apparatus operating as the terminal device; a registration procedure for the apparatus operating as the terminal device; or a UPU procedure for the apparatus operating as the terminal device.
[0190] In exemplary embodiments of the present disclosure, the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; and the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; the apparatus operating as the third network node comprises an Access and Mobility Management Function; the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; and the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.
[0191] The processor 302, 502, 702, 902, 1102 may be any kind of processing component, such as one or more microprocessor or microcontrollers, as well as other digital hardware, which may include digital signal processors (DSPs) , special-purpose digital logic, and the like. The memory 304, 504, 704, 904, 1104 may be any kind of storage component, such as read-only memory (ROM) , random-access memory, cache memory, flash memory devices, optical storage devices, etc.
[0192] FIG. 13 is a block diagram showing an apparatus / computer readable storage medium, according to embodiments of the present disclosure.
[0193] As shown in FIG. 13, a computer-readable storage medium 130 storing instructions 131, which when executed by at least one processor of a network node or a terminal device, cause the at least one processor of the network node or the terminal device to perform the method according to any of the embodiments above mentioned, such as shown in FIG. 4A-FIG. 4B, FIG. 6, FIG. 8A-FIG. 8C, FIG. 10A-FIG. 10C, FIG. 12A-FIG. 12B, FIG. 19-22.
[0194] In addition, the present disclosure may also provide a carrier containing the computer program / instructions as mentioned above. The carrier is one of an electronic signal, optical signal, radio signal, or the above computer readable storage medium. The computer readable storage medium can be, for example, an optical compact disk or an electronic memory device like a RAM (random access memory) , a ROM (read only memory) , Flash memory, magnetic tape, CD-ROM, DVD, Blue-ray disc and the like.
[0195] FIG. 14 is a block diagram showing exemplary apparatus units for a terminal device, which is suitable for performing the method according to embodiments of the disclosure.
[0196] As shown in FIG. 14, the terminal device 140 may include: a receiving unit 1402, configured for receiving at least one identifier related to an apparatus operating as a first network node; a transmitting unit 1404, configured for transmitting an identifier in the at least one identifier to an apparatus operating as a second network node, for the apparatus operating as the second network node to identify the apparatus operating as the first network node. The at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0197] [Rectified under Rule 91, 05.11.2024]In exemplary embodiments of the present disclosure, the first terminal device 140 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 4A-FIG. 4B, 19-22.
[0198] FIG. 15 is a block diagram showing exemplary apparatus units for a second network node, which is suitable for performing the method according to embodiments of the disclosure.
[0199] As shown in FIG. 15, the second network node 15 may include: a receiving unit 1502, configured for receiving, from an apparatus operating as a terminal device or an apparatus operating as a fourth network node, an identifier related to an apparatus operating as a first network node; and a identifying unit 1504, configured for identifying the apparatus operating as the first network node, based at least on the received identifier.
[0200] In exemplary embodiments of the present disclosure, the second network node 360 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 6, FIG. 19-22.
[0201] FIG. 16 is a block diagram showing exemplary apparatus units for a third network node, which is suitable for performing the method according to embodiments of the disclosure.
[0202] As shown in FIG. 16, the third network node 160 may include: a transmitting unit 1602, configured for transmitting, to an apparatus operating as a terminal device, at least one identifier related to an apparatus operating as the first network node; the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0203] In exemplary embodiments of the present disclosure, the third network node 370 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 8A-FIG. 8C, FIG. 19-22.
[0204] FIG. 17 is a block diagram showing exemplary apparatus units for a fourth network node, which is suitable for performing the method according to embodiments of the disclosure.
[0205] As shown in FIG. 17, the fourth network node 170 may include: a transmitting unit 1702, configured for transmitting, to an apparatus operating as a third network node, at least one identifier related to an apparatus operating as a first network node; an identifier in the at least one identifier is to be used by an apparatus operating as the second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0206] In exemplary embodiments of the present disclosure, the fourth network node 380 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 10A-FIG. 10C, FIG. 19-22.
[0207] FIG. 18 is a block diagram showing exemplary apparatus units for a fifth network node, which is suitable for performing the method according to embodiments of the disclosure.
[0208] As shown in FIG. 18, the fifth network node 180 may include: a transmitting unit 1802, configured for transmitting, to an apparatus operating as a third network node and / or an apparatus operating as a fourth network node, at least one identifier related to an apparatus operating as a first network node; an identifier in the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; and the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.
[0209] In exemplary embodiments of the present disclosure, the fifth network node 390 is further configured for performing the method according to any of the embodiments above mentioned, such as shown in FIG. 12, FIG. 19-22.
[0210] The term ‘unit’ may have conventional meaning in the field of electronics, electrical devices and / or electronic devices and may include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.
[0211] As used in the present disclosure, the term “circuitry” may refer to one or more or all of the following:
[0212] (a) hardware-only circuit implementations (such as implementations in only analogy and / or digital circuitry) and
[0213] (b) combinations of hardware circuits and software, such as (as applicable) :
[0214] (i) a combination of analogy and / or digital hardware circuit (s) with software / firmware and
[0215] (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[0216] (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. ”
[0217] This definition of circuitry applies to all uses of this term in the present disclosure, including in any claims. As a further example, as used in the present disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0218] With these units, the apparatus may not need a fixed processor or memory, any kind of computing resource and storage resource may be arranged from at least one node / device / entity / apparatus relating to the communication system. The virtualization technology and network computing technology (e.g., cloud computing) may be further introduced, so as to improve the usage efficiency of the network resources and the flexibility of the network.
[0219] The techniques described herein may be implemented by various means so that an apparatus implementing one or more functions of a corresponding apparatus described with an embodiment comprises not only prior art means, but also means for implementing the one or more functions of the corresponding apparatus described with the embodiment and it may comprise separate means for each separate function, or means that may be configured to perform two or more functions. For example, these techniques may be implemented in hardware (one or more apparatuses) , firmware (one or more apparatuses) , software (one or more modules / units) , or combinations thereof. For a firmware or software, implementation may be made through modules (e.g., procedures, functions, and so on) that perform the functions described herein.
[0220] In certain embodiments, some or all of the functionality described herein may be provided by processing circuitry executing instructions stored on in memory, which in certain embodiments may be a computer program product in the form of a non-transitory computer-readable storage medium. In alternative embodiments, some or all of the functionalities may be provided by the processing circuitry without executing instructions stored on a separate or discrete device-readable storage medium, such as in a hard-wired manner. In any of those particular embodiments, whether executing instructions stored on a non-transitory computer-readable storage medium or not, the processing circuitry can be configured to perform the described functionality. The benefits provided by such functionality are not limited to the processing circuitry alone or to other components of the computing device, but are enjoyed by the computing device as a whole, and / or by end users and a wireless network generally.
[0221] The term “non-transitory, ” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM) .
[0222] According to above embodiments, some further detailed solutions may be provided as follows.
[0223] In an example solution1, a new header “3gpp-5gcore-group-id” may be introduced in the response of primary authentication from AUSF to UE. A new configuration parameter (for example, the identifier to be used and / or an indication about Id type of the identifier to be used) can be introduced to decide whether Group ID (GID) or RID is to be used. If GID is to be used, when AAnF can be co-located with AUSF / UDM in the same segment, AUSF is aware of the group id of AAnF, or alternatively UDM provides the group id details to AUSF, then AUSF set AAnF group id to “3gpp-5gcore-group-id” in the response of primary authentication from AUSF to AMF. AMF provides it to UE via non-access-stratum (NAS) message, mostly in registration complete message. If “3gpp-5gcore-group-id” is not present, RID will be used to generate A-KID.
[0224] In an example solution2, GID may be provisioned in UDR.
[0225] For example, two new fields may be introduced: altRid (alternative Routing Indicator) and ridType (Routing Indicator Type) , in authentication-subscription stored in UDR. It should be noted that the above names of such fields are only examples, not limitation.
[0226] 1. When UDM detects altRid and ridType are provisioned in UDR, it shall inform UE with altRid and ridType information via UE Parameters Update (UPU) . UE shall check ridType to determine if using RID (Routing Indicator) to construct A-KID or altRid (Group Id as example) . Alternative, if operators are not using the RID, then they can provision the Subscriber Identity Module (SIM) to construct the A-KID with altRid.
[0227] 2. The AUSF may obtain altRid and ridType within the Nudm_UEAuthentication_Get Response from the UDM. AUSF shall check ridType to determine if using RID to construct A-KID or altRid (Group Id as example) .
[0228] Either with solution1 or solution2, both UE and AUSF can generate the GID-based A-KID by using the similar mechanism. When UE establishes session to AF with A-KID, AF / NEF can use the GID in A-KID to discover the correct AAnF.
[0229] Further, here are two example options to enhance the generation of A-KID, namely the manner to include the RID, or altRid in the A-KID.
[0230] In an example option1, an optional tag ridType (as a type indication) may be introduced in the username part of A-KID. AF / NEF obtains altRid and ridType in addition to RID as part of the A-KID in the AKMA request. AF / NEF shall check ridType to determine if using RID to construct A-KID or altRid (Group Id as example) . In this case, AAnF registers in the NRF with group Id, and AAnF discovery is also supported via group Id.
[0231] This option may provide a backward compatibility. For previous release with only RID, ridType is not added in the A-KID, so NF / AF will use RID based solution. No change is needed in devices of the previous release.
[0232] In an example option2, a new tag gid is introduced in the username part of A-KID. If AUSF decides to use GID, it will generate the A-KID with gid, like gid123. atid1234@realm. If RID is decided to be used, AUSF will generate the A-KID with rid, like rid123. atid1234@realm. If UE receives GID information, UE will use the same mechanism as AUSF to generate A-KID, otherwise, it will use rid to generate A-KID as AUSF does. When AF / NEF receives the request with A-KID for session establish, it will check the username of A-KID. If rid tag is present, it will discover AAnF by using RID. If gid tag is present, it will discover AAnF by using GID.
[0233] Additional, since UE stores the GID, it can be used for other subsequent requests in addition to AKMA use case.
[0234] Further details of the example solutions in the embodiments will be illustrated below with figures.
[0235] FIG. 19 is a diagram showing a procedure for passing GID to UE via Priamary Authentication, according to embodiments of the present disclsoure.
[0236] As shown in FIG. 19, a procedure to create AKMA context adopting example solution 1 is illustrated. Compared to FIG. 1, the enhancement as underlined in FIG. 19 is that, AUSF gives the group Id via the response of primary authentication by including “3gpp-5gcore-group-id” header to AMF in step1, if the configuration parameter indicates GID shall be used for AKAM solution. Alternatively, UDM can provide the group id details in step 3a. AMF will pass the “3gpp-5gcore-group-id” header to UE over NAS message in step3. Then AUSF and UE will use GID to generate A-KID.
[0237] Further, enhancement for A-KID Generation may be also provided.
[0238] For A-KID generation, it is formatted as the following string defined in 3GPP TS 29.522 V19.0.0 (2024-09) . "<username>@<realm>" , wherein, <username> shall include Routing Indicator and the A-TID in the format "rid<value>. atid<value>" , where "rid" and "atid" are labels indicating Routing Indicator and AKMA Temporary Identifier (A-TID) and <realm> shall include Home Network Id.
[0239] There are two options to enhance it to support GID in addition to RID.
[0240] Option1: Extend the usage of rid and introduce a new optional tag ridtype in username part of A-KID. The format shall be "rid<value>. atid<value>. ridtype<value>" .
[0241] If RID is decided to be used, UE and AUSF shall use RID to construct the username part of A-KID without ridtype or with ridtype 00. For example: rid012. atid123456 or rid012. atid123456. ridtype00
[0242] If GID is decided to be used, UE and AUSF shall use the GID as the value of rid tag and ridtype001 to construct the username part of A-KID. For example: the username of A-KID in GID use case shall be rid1234. atid123456. ridtype01
[0243] Note: the specific values, 00, 01, of ridtype are only examples, not limitation.
[0244] Option2: Simply introduce a new filed gid to support group id based AAnF selection. The format shall be "gid<value>. atid<value>”
[0245] If RID is decided to be used, rid tag will be used to construct the username part of A-KID. For example: rid012. atid123456
[0246] If GID is decided to be used, gid tag will be used to construct the username part of A-KID. For example: gid1234. atid123456
[0247] Note: the specific name, gid, is only examples, not limitation.
[0248] As in example solution 2, two new fields, altRid and ridType, may be introduced as below in Table 5.4.2.2-1: Definition of type AuthenticationSubscription defined in 3GPP TS 29.505 V19.0.0 (2024-09) . It should be noted that, the name and values for such new fields are only examples, not limitation.
[0249] FIG. 20 is a diagram showing a procedure for notification to UE for the change of altRid and ridType, according to embodiments of the present disclsoure.
[0250] As shown in FIG. 20, in a step 1, the UDM may detect that altRid and ridType are changed in UDR via Simple Object Access Protocol (SOAP) Trigger.
[0251] In step2, UDM uses UPU procedure to send the notification of the change to UE as per the cause 6.15.2.1 of 3GPP TS 33.501 V18.6.0 (2024-06) .
[0252] In step 3, the UE stores / updates altRid and ridType.
[0253] In step 4, re-authentication procedure is performed, such as re-authentication procedure defined in Release 18 Authentication and Key Management for Applications (AKMA) (such as in TS 33.535) . Namely, the AUSF / UE may generate a new A-KID, based on updated / changed altRid and ridType.
[0254] As shown in above diagram, the change of altRid and ridType in UDR shall be notified to UE via UPU procedure. UE shall store altRid and ridType which will be used when constructing A-KID. UE also shall trigger re-authorization to refresh the A-KID.
[0255] FIG. 21 is a diagram showing a procedure for deriving KAKMA after primary authentication, according to embodiments of the present disclsoure.
[0256] Above diagram shows the procedure to create AKMA context. Step 1 to 5 are almost the same as defined in 3GPP TS 33.535 clause 6.1, such as shown in FIG. 1. Only step3 and the way to generate A-KID will be enhanced.
[0257] In step3, altRid and ridType shall be included if it is present. Then the AUSF / UE may generate A-KID per ridType.
[0258] Further, AuthenticationInfoResult defined in 3GPP TS 29.503 V19.0.0 (2024-09) shall be enhanced as below. It should be noted that the names and values of the proposed parameters are only examples, not limitation.
[0259] For A-KID generation, it is formatted as the following string defined in 3GPP TS 29.522 V19.0.0 (2024-09) . " <username>@<realm>", wherein, <username> shall include Routing Indicator and the A-TID in the format "rid<value>. atid<value>" , where "rid" and "atid" are labels indicating Routing Indicator and A-TID and <realm> shall include Home Network Id.
[0260] There are two options to enhance it to support alternative routing indicator.
[0261] Option1: Extend the usage of rid and introduce a new optional tag ridtype in username part of A-KID. The format shall be "rid<value>. atid<value>. ridtype<value>" .
[0262] If ridType is not present or is present and equals to 00, UE and AUSF shall use RID to construct the username part of A-KID without ridtype or with ridtype00. For example:
[0263] rid012. atid123456 or rid012. atid123456. ridtype00
[0264] If ridType is present and does not equal to 00, UE and AUSF shall use the received altRid and ridType to construct the username part of A-KID. For example: if the received altRid is 1234 and ridType is 01 which indicates GID, the username of A-KID shall be rid1234. atid123456. ridtype01
[0265] Note: the specific values, 00, 01, of ridtype are only examples, not limitation.
[0266] Option2: Simply introduce a new filed gid to support group id based AAnF selection. The format shall be "gid<value>. atid<value>”
[0267] If ridType is not present or is present and equals to 00, UE and AUSF shall use RID to construct the username part of A-KID. For example: rid012. atid123456
[0268] If ridType is present and does not equal to 00, UE and AUSF shall use the received altRid and ridType to determine if GID is used to construct the username part of A-KID. For example: if the received altRid is 1234 and ridType is 01 which indicates GID, the username of A-KID shall be gid1234. atid123456
[0269] Note: the specific name, gid, is only examples, not limitation.
[0270] Further, AF / NEF may be also enhanced as below.
[0271] FIG. 22 is a diagram showing a procedure for KAF generation from KAKMA, according to embodiments of the present disclsoure.
[0272] Above diagram shows the procedure defined in 3GPP TS 33.535, as shown in FIG. 2, is used by the AF to request application function specific AKMA keys from the AAnF, when the AF is located inside the operator's network.
[0273] AAnF selection happens before step2. AF shall be enhanced to determine whether use RID or altRid per ridType to select AAnF. NEF also needs to do similar enhancement.
[0274] Compared to FIG. 2, the difference is that, that A-KID may include different information, such as different Ids for AAnF discovery, as shown in flowing options.
[0275] A-KID generation Option1:
[0276] If ridtype is not present or is present and equals to 00 in A-KID in step1, for example, rid012. atid123456, AF shall use “routing-indicator” as query parameter with the value of rid (012 in this example) to query NRF for AAnF discovery.
[0277] If ridtype is present and does not equal to 00 in A-KID in step1, for example, rid1234. atid123456. ridtype01, AF shall use “group-id-list” as query parameter with the value of rid (1234 in this example) to query NRF for AAnF discovery.
[0278] A-KID generation Option2:
[0279] If the username part of the received A-KID in step1 contains “rid” tag. For example:
[0280] rid012. atid123456, AF shall use “routing-indicator” as query parameter with the value of rid (012 in this example) to query NRF for AAnF discovery.
[0281] If the username part of the received A-KID in step1 contains “gid” tag. For example, gid1234. atid123456, AF shall use “group-id-list” as query parameter with the value of rid (1234 in this example) to query NRF for AAnF discovery.
[0282] Note: the specific names and values are only examples, not limitation.
[0283] Further, AAnF NRF Registration and Discovery may be also enhanced, accordingly.
[0284] For example, AanfInfo defined in 3GPP TS 29.510 V19.0.0 (2024-09) shall be enhanced as below to allow AAnF do NRF Registration with groupId. With this enhancement, AAnF can do NRF registration with groupId which is the same as the one for UDM / UDR / Unstructured Data Storage network function (UDSF) . Then AUSF (obtain the groupId via querying NRF by using SUPI) and AF / NEF (obtain from A-KID) can use it to discovery the correct AAnF.
[0285]
[0286] AanfInfo:
[0287] description: Represents the information relative to an AAnF NF Instance.
[0288] type: object
[0289] properties:
[0290] routingIndicators:
[0291] type: array
[0292] items:
[0293] type: string
[0294] pattern: '^ [0-9] {1, 4} $'
[0295] minItems: 1
[0296] groupId:
[0297] $ref: 'TS29571_CommonData. yaml# / components / schemas / NfGroupId'
[0298] NfGroupId:
[0299] type: string
[0300] description: Identifier of a group of NFs.
[0301] GroupId:
[0302] type: string
[0303] pattern: '^ [A-Fa-f0-9] {8} - [0-9] {3} - [0-9] {2, 3} - ( [A-Fa-f0-9] [A-Fa-f0-9] ) {1, 10} $'
[0304] description: >
[0305] String identifying a group of devices network internal globally unique ID which identifies a set of IMSIs, as specified in clause 19.9 of 3GPP TS 23.003.
[0306]
[0307] According to above exemplary embodiments of the present disclosure, a mechanism for enhancement of Authentication and Key Management for Applications Anchor Function (AAnF) selection may be provided. It will be selectable / configurable to use different identifiers / indicators of different types related to a network node, for identifying and selecting the network node. Therefore, the applicability and compatibility for using the network node in different networks of different operators will be greatly improved.
[0308] For example, the invention provides solutions for negotiating between the UE and the AUSF to use RID or GID to generate the A_KID in AKMA service scenario. If the operator does not support routing ID, a new defined group ID can be used to generate A-KID for AKMA.
[0309] As described in above exemplary embodiments of this disclosure, embodiments herein afford many advantages. According to embodiments of the present disclosure, it will be selectable / configurable to use different identifiers / indicators of different types related to a network node, for identifying and selecting the network node. Therefore, the applicability and compatibility for using the network node in different networks of different operators will be greatly improved.
[0310] It should be understood that the above embodiments are only for illustration but not limitation. The present disclosure may be carried out in other ways than those specifically set forth herein without departing from essential characteristics of the disclosure. All changes to these embodiments not departing from the meaning and equivalency of the appended claims are intended to be comprised herein.
[0311] The following documents may be incorporated in entirety by reference.
[0312] 3rd generation partnership project technical specification (3GPP TS) 33.535 V18.2.0 (2023-12)
[0313] 3GPP TS 29.522 V19.0.0 (2024-09)
[0314] 3GPP TS 29.505 V19.0.0 (2024-09)
[0315] 3GPP TS 33.501 V18.6.0 (2024-06)
[0316] 3GPP TS 29.503 V19.0.0 (2024-09)
[0317] 3GPP TS 29.510 V19.0.0 (2024-09)
[0318] 3GPP TS 29.571 V19.0.0 (2024-09)
[0319] ABBREVIATION EXPLANATION
[0320] AKMA Authentication and Key Management for Applications
[0321] A-KID AKMA Key IDentifier
[0322] AAnF AKMA Anchor Function
[0323] AF Application Function
[0324] AF_ID AF Identifier
[0325] AUSF AUthentication Server Function
[0326] KAF AKMA Application Key
[0327] KAKMA AKMA Anchor Key
[0328] UDM Unified Data Management
[0329] UDR Unified Data Repository
[0330] SUPI SUbscription Permanent Identifier
[0331] UPU UE Parameters Update
[0332] RID Routing Indicator
[0333] GID Group Indicator
[0334] SUCI Subscription Concealed Identifier
[0335] AV Authentication Vector
[0336] Ind Indicator
[0337] GPSI Generic Public Subscription Identifier
[0338] Exp Expiration
[0339] AUSF AUthentication Server Function
[0340] NEF Network Exposure Function
[0341] NF Network Function
[0342] UE User Equipment
[0343] NR New Radio
[0344] 3GPP 3rd Generation Partnership Project
[0345] TR Technical Report
[0346] NW Network
[0347] UE User Equipment
[0348] 3GPP 3rd generation partnership project
[0349] 5GC 5th Generation Core Network
[0350] KI Key Issue
[0351] 5G fifth generation
[0352] NR New Radio
[0353] 6G sixth generation
[0354] RRC Radio Resource Control
[0355] Rel Release
[0356] DL Downlink
[0357] UL Uplink
Claims
1.An apparatus (30) operating as a terminal device, comprising:at least one processor (302) ; andat least one memory (304) including computer program code;the at least one memory (304) and the computer program code configured to, with the at least one processor (302) , cause the apparatus (30) operating as the terminal device at least to perform:receiving (S402) at least one identifier related to an apparatus operating as a first network node;transmitting (S404) an identifier in the at least one identifier to an apparatus operating as a second network node, for the apparatus operating as the second network node to identify the apparatus operating as the first network node;wherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.2.The apparatus (30) operating as the terminal device according to claim 1,wherein the first identifier is a routing identifier; andwherein the second identifier is a group identifier.3.The apparatus (30) operating as the terminal device according to claim 2,wherein the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.4.The apparatus (30) operating as the terminal device according to any of claims 1 to 3,wherein the at least one identifier includes the first identifier or the second identifier.5.The apparatus (30) operating as the terminal device according to any of claims 1 to 3,wherein the at least one identifier includes the first identifier and the second identifier;wherein the at least one memory and the computer program code are further configured to cause the apparatus operating as the terminal device to receive an indication about whether to use the first identifier or the second identifier; andwherein the first identifier and the second identifier are received via different messages during different procedures.6.The apparatus (30) operating as the terminal device according to claim 5,wherein the at least one memory and the computer program code are further configured to cause the apparatus operating as the terminal device to perform:receiving (S406) the at least one identifier and / or the indicator in a Non Access Stratum, NAS, message from an apparatus operating as a third network node; andwherein the NAS message comprises a registration complete message, or the NAS message is for UE Parameters Update, UPU.7.The apparatus (30) operating as the terminal device according to any of claims 1 to 6,wherein when transmitting the identifier, the apparatus operating as the terminal device uses the same name tag for the first identifier and the second identifier, and the apparatus operating as the terminal device further uses a type indication for differentiating the first identifier and the second identifier; orwherein when transmitting the identifier, the apparatus operating as the terminal device uses different name tags for the first identifier and the second identifier.8.The apparatus (30) operating as the terminal device according to any of claims 1 to 7,wherein the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF;wherein the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; andwherein the identifier is included by the apparatus operating as the terminal device in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.9.An apparatus (50) operating as a second network node, comprising:at least one processor (502) ; andat least one memory (504) including computer program code;the at least one memory (504) and the computer program code configured to, with the at least one processor (502) , cause the apparatus operating as the second network node at least to perform:receiving (S602) , from an apparatus operating as a terminal device or an apparatus operating as a fourth network node, an identifier related to an apparatus operating as a first network node; andidentifying (S604) the apparatus operating as the first network node, based at least on the received identifier;wherein the identifier is one identifier in at least one identifier related to the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.10.The apparatus (50) operating as the second network node according to claim 9,wherein the first identifier is a routing identifier; andwherein the second identifier is a group identifier.11.The apparatus (50) operating as the second network node according to claim 10,wherein the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.12.The apparatus (50) operating as the second network node according to any of claims 9 to 11,wherein the same name tag is used by the apparatus operating as the terminal device or the apparatus operating as the fourth network node for the first identifier and the second identifier, and a type indication are further used by the apparatus operating as the termina device or the apparatus operating as the fourth network node for differentiating the first identifier and the second identifier; orwherein different name tags are used by the apparatus operating as the terminal device or the apparatus operating as the fourth network node for the first identifier and the second identifier.13.The apparatus (50) operating as the second network node according to any of claims 9 to 12,wherein the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF;wherein the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF;wherein the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; andwherein the identifier is included, by the apparatus operating as the terminal device or the apparatus operating as the fourth network node, in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.14.An apparatus (70) operating as a third network node, comprising:at least one processor (702) ; andat least one memory (704) including computer program code;the at least one memory (704) and the computer program code configured to, with the at least one processor (702) , cause the third network node at least to perform:transmitting (S802) , to an apparatus operating as a terminal device, at least one identifier related to an apparatus operating as the first network node;wherein the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.15.The apparatus (70) operating as the third network node according to claim 14,wherein the first identifier is a routing identifier; andwherein the second identifier is a group identifier.16.The apparatus (70) operating as the third network node according to claim 15,wherein the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.17.The apparatus (70) operating as the third network node according to any of claims 14 to 16, wherein the at least one memory and the computer program code are further configured to cause the apparatus operating as the third network node to perform:transmitting (S804) , to the apparatus operating as the terminal device, an indication about whether to use the first identifier or the second identifier.18.The apparatus (70) operating as the third network node according to claim 17,wherein the at least one identifier and / or the indication are included in a Non Access Stratum, NAS, message; andwherein the NAS message comprises a registration complete message, or the NAS message is for UE Parameters Update, UPU.19.The apparatus (70) operating as the third network node according to claim 17 or 18, wherein the at least one memory and the computer program code are further configured to cause the apparatus operating as the third network node to perform:receiving (S806) the at least one identifier and / or the indicator from an apparatus operating as a fourth network node during a primary authentication procedure for the apparatus operating as the terminal device; orreceiving (S808) the at least one identifier and / or the indicator from an apparatus operating as a fifth network node, during a registration procedure for the apparatus operating as the terminal device or during a UPU procedure for the apparatus operating as the terminal device.20.The apparatus (70) operating as the third network node according to claim 19,wherein the apparatus operating as the fourth network node has the second identifier of the apparatus operating as the first network node, when the apparatus operating as the fourth network node and the apparatus operating as the first network node are in the same group; orwherein the apparatus operating as the fourth network node obtains the at least one identifier and / or the indicator from the apparatus operating as the fifth network node during the primary authentication procedure for the apparatus operating as the terminal device.21.The apparatus (70) operating as the third network node according to claim 19 or 20,wherein the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; andwherein the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.22.The apparatus (70) operating as the third network node according to any of claims 14 to 21,wherein the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF;wherein the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF; andwherein the apparatus operating as the third network node comprises an Access and Mobility Management Function, AMF.23.An apparatus (90) operating as a fourth network node, comprising:at least one processor (902) ; andat least one memory (904) including computer program code;the at least one memory (904) and the computer program code configured to, with the at least one processor (902) , cause the fourth network node at least to perform:transmitting (S1002) , to an apparatus operating as a third network node, at least one identifier related to an apparatus operating as a first network node;wherein an identifier in the at least one identifier is to be used by an apparatus operating as the second network node to identify the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.24.The apparatus (90) operating as the fourth network node according to claim 23,wherein the first identifier is a routing identifier; andwherein the second identifier is a group identifier.25.The apparatus (90) operating as the fourth network node according to claim 24,wherein the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.26.The apparatus (90) operating as the fourth network node according to any of claims 23 to 25, wherein the at least one memory and the computer program code are further configured to cause the apparatus operating as the fourth network node to perform:transmitting (S1004) , to the apparatus operating as the third network node, an indication about whether to use the first identifier or the second identifier.27.The apparatus (90) operating as the fourth network node according to claim 26,wherein the apparatus operating as the fourth network node has the second identifier of the apparatus operating as the first network node, when the apparatus operating as the fourth network node and the apparatus operating as the first network node are in the same group; orwherein the apparatus operating as the fourth network node receives the at least one identifier and / or the indicator from an apparatus operating as a fifth network node during the primary authentication procedure for the apparatus operating as the terminal device.28.The apparatus (90) operating as the fourth network node according to claim 27,wherein the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.29.The apparatus (90) operating as the fourth network node according to any of claims 26 to 28, wherein the at least one memory and the computer program code are further configured to cause the apparatus operating as the fourth network node to perform:transmitting (S1006) , to the apparatus operating as the second network node, the identifier;wherein when transmitting the identifier, the apparatus operating as the fourth network node uses the same name tag for the first identifier and the second identifier, and the fourth network node further uses a type indication for differentiating the first identifier and the second identifier; orwherein when transmitting the identifier, the apparatus operating as the fourth network node uses different name tags for the first identifier and the second identifier.30.The apparatus (90) operating as the fourth network node according to claim 29,wherein the identifier is included by the apparatus operating as the fourth network node in an Authentication and Key Management for Applications Key Identifier, A-KID, for transmitting.31.The apparatus (90) operating as the fourth network node according to any of claims 23 to 28,wherein the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; andwherein the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF;wherein the apparatus operating as the third network node comprises an Access and Mobility Management Function; andwherein the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF.32.An apparatus (110) operating as a fifth network node, comprising:at least one processor (1102) ; andat least one memory (1104) including computer program code;the at least one memory (1104) and the computer program code configured to, with the at least one processor (1102) , cause the apparatus operating as the fifth network node at least to perform:transmitting (S1202) , to an apparatus operating as a third network node and / or an apparatus operating as a fourth network node, at least one identifier related to an apparatus operating as a first network node;wherein an identifier in the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.33.The apparatus (110) operating as the fifth network node according to claim 32,wherein the first identifier is a routing identifier; andwherein the second identifier is a group identifier.34.The apparatus (110) operating as the fifth network node according to claim 33,wherein the group identifier is for a subscriber data management, SDM, group including the apparatus operating as the first network node.35.The apparatus (110) operating as the fifth network node according to any of claims 32 to 34, wherein the at least one memory and the computer program code are further configured to cause the apparatus operating as the fifth network node to perform:transmitting (S1204) , to the apparatus operating as the third network node and / or the apparatus operating as the fourth network node, an indication about whether to use the first identifier or the second identifier.36.The apparatus (110) operating as the fifth network node according to claim 35,wherein the apparatus operating as the fifth network node transmits the at least one identifier and / or the indication, during at least one of:a primary authentication procedure for the apparatus operating as the terminal device;a registration procedure for the apparatus operating as the terminal device; ora UPU procedure for the apparatus operating as the terminal device.37.The apparatus (110) operating as the fifth network node according to any of claims 33 to 36,wherein the apparatus operating as the first network node comprises an Authentication and Key Management for Applications Anchor Function, AAnF; andwherein the apparatus operating as the second network node comprises an Application Function, AF, or a Network Exposure Function, NEF;wherein the apparatus operating as the third network node comprises an Access and Mobility Management Function;wherein the apparatus operating as the fourth network node comprises an AUthentication Server Function, AUSF; andwherein the apparatus operating as the fifth network node comprises a Unified Data Management, UDM.38.A method (40) performed by an apparatus operating as a terminal device, comprising:receiving (S402) at least one identifier related to an apparatus operating as the first network node;transmitting (S404) an identifier in the at least one identifier to an apparatus operating as a second network node, for the apparatus operating as the second network node to identify the apparatus operating as the first network node;wherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.39.The method (40) according to claim 38, performed by the apparatus according to any of claims 2 to 8.40.A method (60) performed by an apparatus operating as a second network node, comprising:receiving (S602) , from an apparatus operating as a terminal device or an apparatus operating as a fourth network node, an identifier related to an apparatus operating as a first network node; andidentifying (S604) the apparatus operating as the first network node, based at least on the received identifier;wherein the identifier is one identifier in at least one identifier related to the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.41.The method (60) according to claim 40, performed by the apparatus according to any of claims 10 to 13.42.A method (80) performed by an apparatus operating as a third network node, comprising:transmitting (S802) , to an apparatus operating as a terminal device, at least one identifier related to a apparatus operating as a first network node;wherein the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.43.The method (80) according to claim 42, performed by the apparatus according to any of claims 15 to 22.44.A method (100) performed by an apparatus operating as a fourth network node, comprising:transmitting (S1002) , to an apparatus operating as a third network node, at least one identifier related to an apparatus operating as a first network node;wherein an identifier in the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.45.The method (100) according to claim 44, performed by the apparatus according to any of claims 24 to 31.46.A method (120) performed by an apparatus operating as a fifth network node, comprising:transmitting (S1202) , to an apparatus operating as a third network node and / or an apparatus operating as a fourth network node, at least one identifier related to an apparatus operating as a first network node;wherein an identifier in the at least one identifier is to be used by an apparatus operating as a second network node to identify the apparatus operating as the first network node; andwherein the at least one identifier includes at least a first identifier of a first type, and / or a second identifier of a second type.47.The method (120) according to claim 46, performed by the apparatus according to any of claims 33 to 37.48.A computer-readable storage medium (130) storing instructions (131) , which when executed by at least one processor of an apparatus, cause the at least one processor of the apparatus to at least perform the method according to any of claims 38 to 47.