Method of user equipment related to authentication and key agreement procedure, and user equipment
A procedure to establish latest security key in a UE and a network is disclosed. More specifically, the procedure defines various method to establish latest Kausf in the UE and the network and make the UE and network uses the same Kausf in various security procedure.
1 . A method of a User Equipment (UE) which stores a first K AUSF (Authentication Server Function) , the method comprising:
in a 5G Authentication and Key Agreement (AKA) based primary authentication and key agreement procedure, receiving, from an Access and Mobility Management Function (AMF), an authentication request message;
computing response information based on the authentication request message;
deriving second K AUSF based on the authentication request message; and
returning, to the AMF, an authentication response message including the response information;
receiving, from the AMF, a Non-Access-Stratum (NAS) message after the 5G AKA based primary authentication and key agreement procedure is successful; and
in a case where the UE receives the NAS message,
deleting the first K AUSF ,
considering the second K AUSF to be valid K AUSF ; and
resetting a counter to zero.
2 . The method according to claim 1 ,
wherein the counter is a Steering of Roaming (SoR) counter.
3 . The method according to claim 1 ,
wherein the counter is a UE Parameters Update (UPU) counter.
4 . The method according to claim 1 , further comprising:
using the second K AUSF in a steering of roaming security mechanism or a UE parameters update via Unified Data Management (UDM) control plane procedure security mechanism.
5 . The method according to claim 1 ,
wherein the first K AUSF is stored in the UE before the 5G AKA based primary authentication and key agreement procedure is initiated.
6 . A User Equipment (UE) which stores a first K AUSF (Authentication Server Function) , comprising:
at least one memory storing instructions; and
at least one processor configured to execute the instructions to:
receive, in a 5G Authentication and Key Agreement (AKA) based primary authentication and key agreement procedure, from an Access and Mobility Management Function (AMF), an authentication request message;
compute, in the 5G AKA based primary authentication and key agreement procedure, response information based on the authentication request message;
derive, in the 5G AKA based primary authentication and key agreement procedure, second K AUSF based on the authentication request message; and
return, in the 5G AKA based primary authentication and key agreement procedure, to the AMF, an authentication response message including the response information;
receive, from the AMF, a Non-Access-Stratum (NAS) message after the 5G AKA based primary authentication and key agreement procedure is successful; and
in a case where the UE receives the NAS message,
delete the first K AUSF ;
consider the second K AUSF to be valid K AUSF ; and
reset a counter to zero.
7 . The UE according to claim 6 ,
wherein the counter is a Steering of Roaming (SoR) counter.
8 . The UE according to claim 6 ,
wherein the counter is a UE Parameters Update (UPU) counter.
9 . The UE according to claim 6 ,
wherein the at least one processor is further configured to execute the instructions to use the second K AUSF in a steering of roaming security mechanism or a UE parameters update via Unified Data Management (UDM) control plane procedure security mechanism.
10 . The UE according to claim 6 ,
wherein the first K AUSF is stored in the UE before the 5G AKA based primary authentication and key agreement procedure is initiated.