System and method for controlling AKMA application keys for roaming mobile devices
A device may include a processor. The processor may be configured to: receive, from an Application Function (AF), a request for an Authentication and Key Management for Applications (AKMA) Application key; and determine whether a User Equipment device (UE) that sent a session request to the AF is attached to a visiting network or a home network. When the UE is determined to be attached to the visiting network, the processor may be configured to: determine whether to include the AKMA application key in a first reply to the AF; and send the first reply to the AF. When the UE is determined to be attached to the home network, the processor may be configured to: obtain the AKMA application key; and send a second reply that includes the AKMA application key to the AF.
1 . A device comprising:
a Network Exposure Function (NEF); and
a processor to:
receive, at the NEF and from an Application Function (AF), a request for an Authentication and Key Management for Applications (AKMA) Application key;
determine, at the NEF, whether a User Equipment device (UE) that sent a session request to the AF is attached to a visiting network or a home network;
when the UE is determined to be attached to the visiting network:
determine, at the NEF, whether to include the AKMA application key in a first reply to the AF; and
send, from the NEF, the first reply to the AF; and
when the UE is determined to be attached to the home network:
obtain, at the NEF, the AKMA application key; and
send, from the NEF, a second reply that includes the AKMA application key to the AF.
2 . The device of claim 1 , wherein when the processor determines whether the UE is attached to the visiting network or the home network, the processor is further configured to:
obtain a roaming status of the UE from a Unified Data Management (UDM).
3 . The device of claim 1 , wherein when the UE is determined to be attached to the visiting network, the processor is further configured to:
determine to include the AKMA application key in the first reply to the AF;
obtain the AKMA application key from an AKMA Anchor Function (AAnF); and
include the AKMA application key in the first reply.
4 . The device of claim 3 , wherein the when processor obtains the AKMA application key from the AAnF, the processor is configured to:
send a request to the AAnF, wherein the AKMA application key request includes an identifier for an anchor key that is registered at the AAnF.
5 . The device of claim 4 , wherein the AAnF is configured to:
look up the anchor key in response to the AKMA application key request;
generate the AKMA application key from the anchor key; and
send the AKMA application key to the device.
6 . The device of claim 3 , wherein the AAnF is configured to:
store a roaming status of the UE in a Unified Data Management (UDM).
7 . The device of claim 1 , wherein when the processor determines whether to include the AKMA application key in the first reply to the AF, the processor is further configured to:
look up in a database that stores data indicating whether the visited network allows the AKMA application key to be provided to the AF;
include the AKMA application key in the first reply when the indication the data indicates the visited network allows the AKMA application key to be provided to the AF; and
send the first reply to the AF.
8 . The device of claim 7 , wherein the processor is configured to modify the database based on input from one or more of:
an Operations Support System (OSS); or
an Interexchange Carrier (IXC).
9 . The device of claim 1 , wherein the AF is configured to:
receive the session request from the UE, wherein the session request includes an identifier for an anchor key, and
wherein the request from the AF includes the identifier for the anchor key.
10 . A method comprising:
receiving, by a Network Exposure Function (NEF) and from an Application Function (AF), a request for an Authentication and Key Management for Applications (AKMA) Application key;
determining, by the NEF, whether a User Equipment device (UE) that sent a session request to the AF is attached to a visiting network or a home network;
when the UE is determined to be attached to the visiting network:
determining, by the NEF, whether to include the AKMA application key in a first reply to the AF; and
sending, by the NEF, the first reply to the AF; and
when the UE is determined to be attached to the home network:
obtaining, by the NEF, the AKMA application key; and
sending, by the NEF, a second reply that includes the AKMA application key to the AF.
11 . The method of claim 10 , wherein determining whether the UE is attached to the visiting network or the home network comprises:
obtaining a roaming status of the UE from a Unified Data Management (UDM).
12 . The method of claim 10 , wherein when the UE is determined to be attached to the visiting network, the method further comprises:
determining to include the AKMA application key in the first reply to the AF;
obtaining the AKMA application key from an AKMA Anchor Function (AAnF); and
including the AKMA application key in the first reply.
13 . The method of claim 12 , wherein obtaining the AKMA application key from the AAnF comprises:
sending an AKMA application key request to the AAnF, wherein the AKMA application key request includes an identifier for an anchor key that is registered at the AAnF.
14 . The method of claim 13 , further comprising:
looking up, by the AAnF, the anchor key in response to the AKMA application key request;
generating, by the AAnF, the AKMA application key from the anchor key; and
sending, by the AAnF, the AKMA application key to the device.
15 . The method of claim 12 , further comprising:
storing, by the AAnF, a roaming status of the UE in a Unified Data Management (UDM).
16 . The method of claim 10 , wherein determining whether to include the AKMA application key in the first reply to the AF comprises:
looking up in a database that stores data indicating whether the visited network allows the AKMA application key to be provided to the AF;
including the AKMA application key in the first reply when the indication the data indicates the visited network allows the AKMA application key to be provided to the AF; and
sending the first reply to the AF.
17 . The method of claim 16 , further comprising:
modifying the database based on input from one or more of:
an Operations Support System (OSS); or
an Interexchange Carrier (IXC).
18 . A non-transitory computer-readable medium comprising processor-executable instructions, which when executed by a processor cause the processor to:
receive, at a Network Exposure Function (NEF) and from an Application Function (AF), a request for an Authentication and Key Management for Applications (AKMA) Application key;
determine, at the NEF, whether a User Equipment device (UE) that sent a session request to the AF is attached to a visiting network or a home network;
when the UE is determined to be attached to the visiting network:
determine, at the NEF, whether to include the AKMA application key in a first reply to the AF; and
send, at the NEF, the first reply to the AF; and
when the UE is determined to be attached to the home network:
obtain, at the NEF, the AKMA application key; and
send, from the NEF, a second reply that includes the AKMA application key to the AF.
19 . The non-transitory computer-readable medium of claim 18 , wherein when the processor determines whether the UE is attached to the visiting network or the home network, the processor is further configured to:
obtain a roaming status of the UE from a Unified Data Management (UDM).
20 . The non-transitory computer-readable medium of claim 18 , wherein when the UE is determined to be attached to the visiting network, the processor is further configured to:
determine to include the AKMA application key in the first reply to the AF;
obtain the AKMA application key from an AKMA Anchor Function (AAnF); and
include the AKMA application key in the first reply.