IP Library › Granted Patent US 12,316,757
Granted Patent B2
US 12,316,757 · App. 17/857,389 · Granted May 27, 2025

Method, device, and system for application key generation and management in a communication network for encrypted communication with service applications

Inventors: Shilin You (Guangdong, CN); Jiyan Cai (Guangdong, CN); Wantao Yu (Guangdong, CN); Yuze Liu (Guangdong, CN); Jin Peng (Guangdong, CN); Zhaoji Lin (Guangdong, CN); Yuxin Mao (Guangdong, CN); Xiuli Xu (Guangdong, CN)
Assignee: ZTE Corporation
H04L9/0869H04L63/0428H04L63/06H04W12/03H04W12/041H04L2463/061
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,757
App. No.
17/857,389
Granted
May 27, 2025
Kind
B2
Abstract

This disclosure generally relates to encrypted communication between terminal devices and service applications via a communication network. Such encrypted communication may be based on various hierarchical levels of encryption keys that are generated and managed by the communication network. Such encrypted communication and key management may be provided by the communication network to the terminal devices as a service that can be subscribed to. The various levels of encryption keys may be managed to improve flexibility of the communication network and to reduce potential security breaches.

Claims (35)

1. A method for generating an application key by a terminal device for encrypted data transmission via a communication network between the terminal device and a service application, the method comprising:

generating an initial application key based on an anchor key;

sending an initial communication request to the service application;

receiving a response from the service application wherein the response is encrypted by the service application using the initial application key derived at the service application as an encryption key;

extracting a key seed from the response by decrypting the response using the initial application key as a decryption key;

generating the application key based on the anchor key, and additionally based on the key seed such that the application key is distinct from the initial application key; and

sending a data transmission request to the service application to establish an encrypted data communication session with the service application based on the application key.

2. The method of claim 1 , wherein, prior to generating the initial application key, the method further comprises:

generating a base authentication key upon successful completion of an authentication process for registering the terminal device with the communication network; and

generating the anchor key based on the base authentication key.

3. The method of claim 2 , further comprising:

obtaining a subscription data packet for a subscription of the terminal device to an application anchor key management service provided by the communication network; and

extracting from the subscription data packet a subscription dataset for the service application.

4. The method of claim 3 , wherein the subscription dataset comprises an identifier of an application key management network node in the communication network that is associated with the service application and the application anchor key management service.

5. The method of claim 4 , wherein generating the anchor key comprises generating the anchor key based on the base authentication key and further based on at least one of the identifier of the application key management network node, an identifier of a user network module associated with the terminal device, a type of the user network module, an authentication dataset generated during the authentication process for registering the terminal device with the communication network, and a component of the subscription dataset for the service application.

6. The method of claim 5 , wherein:

the authentication dataset comprises a random number generated in the authentication process for registering the terminal device with the communication network; and

generating the anchor key comprises generating the anchor key based on the base authentication key, and at least one of the identifier of the application key management network node and the random number.

7. The method of claim 6 , wherein the initial communication request to the service application comprises an initial identifier for the anchor key, and wherein the initial identifier for the anchor key comprises at least one of the identifier of the application key management network node and the random number.

8. The method of claim 7 wherein:

the key seed comprises a second random number generated by the application key management network node.

9. The method of claim 7 , wherein:

The key seed comprises a second random number and a second identifier for the anchor key generated by the application key management network node; and

generating the application key comprises generating the application key based on the anchor key and the second random number.

10. The method of claim 9 , wherein:

the second identifier for the anchor key generated by the application key management network node comprises the second random number and the identifier for the application key management network node; and

data transmission request comprises the second identifier for the anchor key.

11. The method of claim 3 , wherein generating the anchor key, the initial application key, or the application key is further based on a secure Hash algorithm.

12. A device comprising one or more processors and one or more memories, wherein the one or more processors are configured to read computer code from the one or more memories to:

generate an initial application key based on an anchor key;

send an initial communication request to a service application;

receive a response from the service application wherein the response is encrypted by the service application using the initial application key derived at the service application as an encryption key;

extract a key seed from the response by decrypting the response using the initial application key as a decryption key;

generate the application key based on the anchor key, and additionally based on the key seed such that the application key is distinct from the initial application key; and

send a data transmission request to the service application to establish an encrypted data communication session with the service application based on the application key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 5, 2022
From: YOU, SHILIN; CAI, JIYAN; YU, WANTAO; LIU, YUZE; PENG, JIN; LIN, ZHAOJI; MAO, YUXIN; XU, XIULI
To: ZTE CORPORATION
Reel/Frame 060573/0714 →
Continuity (2)
Continuation PCTCN2020072446 · Jan 16, 2020
Related Publication 20220337408A1 · Oct 20, 2022
References Cited (103)
US 8205085B2 · Yao · 2012 [cited by examiner]
US 9918225B2 · Lee et al. · 2018 [cited by applicant]
US 9930015B2 · Graubner · 2018 [cited by examiner]
US 10708772B2 · Wager · 2020 [cited by examiner]
US 10841084B2 · Lee · 2020 [cited by examiner]
US 10841302B2 · Hahn · 2020 [cited by examiner]
US 10966083B2 · Wu · 2021 [cited by examiner]
US 11012855B2 · Wu · 2021 [cited by examiner]
US 11431561B2 · Smith · 2022 [cited by examiner]
US 11452001B2 · Liao · 2022 [cited by examiner]
US 11456867B2 · Schmatz · 2022 [cited by examiner]
US 11496292B2 · Fischer · 2022 [cited by examiner]
US 11876895B2 · Fischer · 2024 [cited by examiner]
US 11924629B2 · Wu · 2024 [cited by examiner]
US 20020062451A1 · Scheidt · 2002 [cited by examiner]
US 20070140480A1 · Yao · 2007 [cited by examiner]
US 20100268943A1 · Roy-Chowdhury · 2010 [cited by examiner]
US 20120135701A1 · Zhu et al. · 2012 [cited by applicant]
US 20130054967A1 · Davoust et al. · 2013 [cited by applicant]
US 20160226828A1 · Bone · 2016 [cited by applicant]
US 20170054691A1 · Graubner · 2017 [cited by examiner]
US 20170063827A1 · Ricardo · 2017 [cited by examiner]
US 20170195877A1 · Lehtovirta et al. · 2017 [cited by applicant]
US 20180227302A1 · Lee · 2018 [cited by examiner]
US 20180343249A1 · Hahn · 2018 [cited by examiner]
US 20180365411A1 · Falk · 2018 [cited by examiner]
US 20180367991A1 · Wager · 2018 [cited by examiner]
US 20190037395A1 · Lehtovirta et al. · 2019 [cited by applicant]
US 20190253889A1 · Wu · 2019 [cited by examiner]
US 20190297494A1 · Wu · 2019 [cited by examiner]
US 20190349426A1 · Smith · 2019 [cited by examiner]
US 20190387401A1 · Liao · 2019 [cited by examiner]
US 20200014535A1 · Baskaran et al. · 2020 [cited by applicant]
US 20200280896A1 · Ying · 2020 [cited by applicant]
US 20200344048A1 · Fischer · 2020 [cited by examiner]
US 20200396792A1 · Tiwari et al. · 2020 [cited by applicant]
US 20210126781A1 · Schmatz · 2021 [cited by examiner]
US 20210258780A1 · Wu · 2021 [cited by examiner]
US 20220095104A1 · Ben Henda et al. · 2022 [cited by applicant]
US 20220174063A1 · Wu et al. · 2022 [cited by applicant]
US 20220191008A1 · Nair et al. · 2022 [cited by applicant]
US 20220295271A9 · Wu · 2022 [cited by examiner]
US 20220417010A1 · De Kievit et al. · 2022 [cited by applicant]
US 20230070124A1 · Fischer · 2023 [cited by examiner]
US 20230110131A1 · Smith · 2023 [cited by examiner]
CN 101267309A · 2008 [cited by applicant]
CN 101848425A · 2010 [cited by applicant]
CN 106922216A · 2017 [cited by applicant]
CN 104917618B · 2018 [cited by applicant]
CN 109194473A · 2019 [cited by applicant]
CN 110635905A · 2019 [cited by applicant]
IN 201941024005 · 2019 [cited by applicant]
JP 4654498B2 · 2011 [cited by applicant]
JP 2018116231A · 2018 [cited by applicant]
KR 1020140119497A · 2014 [cited by applicant]
KR 1020180106998A · 2018 [cited by applicant]
KR 1020200003108A · 2020 [cited by applicant]
TW 200423675A · 2004 [cited by applicant]
WO WO2012128478A2 · 2012 [cited by applicant]
WO WO2012129503A1 · 2012 [cited by applicant]
WO WO2015069028A1 · 2015 [cited by applicant]
WO WO2017129288A1 · 2017 [cited by applicant]
WO WO2018124857A1 · 2018 [cited by applicant]
WO WO2018144200A1 · 2018 [cited by applicant]
WO WO2018146180A1 · 2018 [cited by applicant]
WO WO2019020440A1 · 2019 [cited by applicant]
WO WO2020221019A1 · 2019 [cited by examiner]
WO WO2019213946A1 · 2019 [cited by applicant]
WO WO2021115614A1 · 2021 [cited by applicant]
Examination Report dispatched Oct. 11, 2022 for Indian Application No. 202217031638. [cited by applicant]
Huawei et al.; “Solution for Key freshness in AKMA”; 3GPP Draft; S3-190169-Solution for Key Freshness in AKMA, 3 [cited by applicant]
Anonymous; “3 [cited by applicant]
Extended European Search Report dated Dec. 22, 2022 for European Application No. 20887214.3. [cited by applicant]
International Search Report mailed Oct. 13, 2020 for International Application No. PCT/CN2020/072446. [cited by applicant]
Written Opinion mailed Oct. 13, 2020 for International Application No. PCT/CN2020/072446. [cited by applicant]
Office Action issued in Chinese Patent Application No. 201980098562.5 dated Feb. 11, 2025, 13 pages. [cited by applicant]
Office Action issued in Chinese Patent Application No. 202080092552.3 dated Feb. 12, 2025, 6 pages. [cited by applicant]
MediaTek “Enhancements to HARQ for NR-U operation” 3GPP TSG RAN WG1 #97, May 13, 2019, R1-1906545, 11 pages. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and key management for applications; based on 3GPP credential in 5G AKMA (Release 16), 3GPP Standard; Technic… [cited by applicant]
Author Unknown, “Security architecture and procedures for 5G System”, Technical Specification, ETSI TS 133 501 V15.2.0 Published Oct. 2018. (Year: 2018). [cited by applicant]
Canadian Office Action, dated Jun. 3, 2024, pp. 1-6, issued in Canadian Patent Application No. 3,159,134, Canadian Intellectual Property Office, Gatineau, Quebec. [cited by applicant]
China Mobile, Add abbreviations and editorial changes to TR 33.835, Nov. 18-22, 2019, pp. 1-12, 3GPP TSG SA3 Meeting #97 S3-194210, Reno, US. [cited by applicant]
China Mobile, Vodafone, Key derivation function in TR 33.841, Sep. 24-28, 2018, pp. 1-4, 3GPP TSG SA WG3 (Security) Meeting #92Adhoc S3-183013, Harbin, China. [cited by applicant]
European Office Action, Dec. 12, 2024, pp. 1-5, issued in European Application No. 20 887 115.2, European Patent Office, Munich, Germany. [cited by applicant]
European Office Action, Sep. 19, 2024, pp. 1-2, issued in Application No. 19 954 008.9. [cited by applicant]
Extended European Search Report dated Nov. 28, 2022 for European Application No. 20888615.0. [cited by applicant]
First Communication issued by the European Patent Office mailed on Jul. 9, 2024, in European Patent Application No. 20887115.2, European Patent Office, Munich, Germany. [cited by applicant]
First Office Action dated Dec. 19, 2022 for Taiwanese Application No. 110101492. [cited by applicant]
Huawei, Hisilicon, Delete the EN of solution 5, May 6-10, 2019, pp. 1-4, 3GPP TSG SA WG3 (Security) Meeting #95 S3-191286, Reno, US. [cited by applicant]
Indian Examination Report dated Jan. 20, 2023 for Indian Application No. 202217037063. [cited by applicant]
Indian Office Action, Feb. 5, 2025, pp. 1-3, issued in Application No. 202217037063, Intellectual Property, Mumbai, India. [cited by applicant]
International Search Report and Written Opinion mailed Oct. 12, 2020 for International Application No. PCT/CN2020/072444. [cited by applicant]
International Search Report and Written Opinion mailed Oct. 13, 2020 for International Application No. PCT/CN2020/072448. [cited by applicant]
Japanese Office Action with English translation, dated Sep. 8, 2023, pp. 1-7, issued in Japanese Patent Application No. 2022-542392. [cited by applicant]
Korean Office Action with English summary, Nov. 16, 2024, pp. 1-9, issued in Application No. 10-2022-7024684. [cited by applicant]
Korean Office Action with English translation, Aug. 20, 2024, pp. 1-14, issued in Patent Application No. 069730164, Seoul, Korea. [cited by applicant]
Mohsin Khan et al: “Privacy Preserving AKMA in 5G”, Security Standardisation Research Workshop, ACM, 2 Penn Plaza, Suite 701 New York NY 1 0121-0701 USA, Nov. 11, 2019 (Nov. 11, 2019), pp. 45-56, XP058444062, DOI: 10.11… [cited by applicant]
Nokia, Nokia Shanghai Bell, China Mobile, Implicit bootstrapping using NEF as the AKMA Anchor Function, Jun. 24-28, 2019, pp. 1-6, 3GPP TSG-SA WG3 Meeting #95 Bis 83-192220, Sapporo, Japan. [cited by applicant]
Official Decision of Grant issued Jul. 3, 2023 for Russian Patent Application No. 2022122039, includin English translation (20 pages) . [cited by applicant]
Supplementary European Search Report, Sep. 5, 2023, pp. 1-9, issued in European Patent Application No. 20887115.2, European Patent Office, Munich, Germany. [cited by applicant]
U.S. Office Action, Aug. 27, 2024, pp. 1-18, issued in U.S. Appl. No. 17/858,271, USPTO, Alexandria, Virginia. [cited by applicant]
U.S. Office Action, Nov. 4, 2024, pp. 1-37, issued in U.S. Appl. No. 17/858,694, USPTO, Alexandria, Virginia. [cited by applicant]
U.S. Office Action issued in U.S. Appl. No. 17/858,694 dated Mar. 5, 2025 (40 pages). [cited by applicant]
Cited By (1)
US 12,556,912