IP Library › Granted Patent US 12,598,067
Granted Patent B2
US 12,598,067 · App. 17/858,694 · Granted Apr 7, 2026

Method, device, and system for updating anchor key in a communication network for encrypted communication with service applications

Inventors: Shilin You (Shenzhen, CN); Jiyan Cai (Shenzhen, CN); Yuze Liu (Shenzhen, CN); Jin Peng (Shenzhen, CN); Wantao Yu (Shenzhen, CN); Zhaoji Lin (Shenzhen, CN); Yuxin Mao (Shenzhen, CN); Jianhua Liu (Shenzhen, CN)
Assignee: ZTE Corporation
H04L9/0891H04L9/083H04L63/08H04W12/041H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,067
App. No.
17/858,694
Granted
Apr 7, 2026
Kind
B2
Abstract

This disclosure generally relates to encrypted communication between terminal devices and service applications via a communication network. Such encrypted communication may be based on various hierarchical levels of encryption keys that are generated and managed by the communication network. Such encrypted communication and key management may be provided by the communication network to the terminal devices as a service that can be subscribed to. The various levels of encryption keys may be managed to improve flexibility of the communication network and to reduce potential security breaches.

Claims (56)

1 . A method for key regeneration in a terminal device for encrypted communication between the terminal device and a service application in a communication network, comprising:

in response to determining that the terminal device is subscribed to the encrypted communication with the service application as a subscribable security service:

detecting that a first key for enabling encrypted communication with the service application previously generated from a first authentication of the terminal device with the communication network has become invalid;

transmitting a request for a second authentication to the communication network;

generating a second key for enabling encrypted communication with the service application when the second authentication is successful;

replacing the first key with the second key; and

exchanging data with the service application based on the second key;

and in response to determining that the terminal device is not subscribed to the subscribable security service with respect to another service application, exchanging data with the another service application without encryption,

wherein the first key and the second key comprise, respectively, a first anchor key and a second anchor key, generated during the first authentication and the second authentication of the terminal device with the communication network, respectively; and

wherein encrypted communications with service applications are subscribable by the terminal device on a service application by service application basis as managed by the communication network and the service applications supporting the encrypted communications are registered with the communication network.

2 . The method of claim 1 , wherein:

each of the first anchor key and second anchor key is configured to be managed by an application key service; and

each of the first anchor key and second anchor key is configured to function as a basis for a generation of an application key for encrypted communication between the terminal device and the service application.

3 . The method of claim 2 , wherein each of the first anchor key and the second anchor key is associated with a key expiration time period and a key identifier.

4 . The method of claim 1 , wherein the first key and the second key comprise a first application key and a second application key for encrypted communication between the terminal device and the service application.

5 . The method of claim 4 , wherein:

each of the first application key and the second application key are respectively generated from the first anchor key and the second anchor key when the first authentication and the second authentication are successful; and

wherein the first application key, the second application key, the first anchor key and the second anchor key are managed by an application key service offered by the communication network to the terminal device for subscription.

6 . The method of claim 5 , wherein at least one of the first anchor key, the second anchor key, the first application key, and the second application key is associated with a key expiration time period and a key identifier.

7 . The method of claim 1 , wherein detecting that the first key has become invalid comprises determining that the first key has expired according to a predetermined expiration time period.

8 . The method of claim 1 , wherein detecting that the first key has become invalid comprises determining that the first key cannot be identified.

9 . The method of claim 1 , wherein detecting that the first key has become invalid comprises:

transmitting a communication request to the service application comprising an identifier corresponding to the first key; and

receiving a response from the service application indicating the first key has become invalid; and

determining that the first key has become invalid based on the response from the service application.

10 . The method of claim 1 , wherein the request for the second authentication comprises a subscription concealed identifier (SUCI) for identifying the terminal device or a global unique temporary identifier (GUTI) with key set identifier indicating that a security context for the terminal device is invalid.

11 . The method of claim 1 , wherein transmitting the request for the second authentication is initiated when the terminal device is idle.

12 . The method of claim 1 , wherein the terminal device is in an active communication session and wherein transmitting the request for the second authentication is initiated by switching the terminal device into an idle state prior to completion of the active communication session or initiated after the terminal device completes the active communication session and switches to an idle state.

13 . The method of claim 1 , wherein the terminal device is in an active communication session and wherein transmitting the request for the second authentication is initiated after the terminal device completes the active communication session and switches to an idle state when the active communication session is emergency and high-priority, and is initiated without completion of the active communication session if the active communication session is not emergency and low-priority.

14 . The method of claim 1 , wherein the terminal device is in an active communication session and wherein transmitting the request for the second authentication is initiated after the terminal device completes the active communication session and switches to an idle state.

15 . A method for key regeneration for encrypted communication between a terminal device and a service application in a communication network, the method performed by an application key management network node and comprising:

in response to determining that the terminal device is subscribed to the encrypted communication with the service application as a subscribable security service:

receiving a first request for an anchor key from the service application after the service application receives a communication request from the terminal device;

determining that the anchor key being requested is invalid; and

transmitting to the service application a response to the first request for the anchor key indicating that the anchor key being requested is invalid, causing the service application to transmit a second response to the terminal device indicating that the anchor key being requested is invalid and causing the terminal

device to initiate a request for an authentication procedure with the communication network to obtain a replacement to the anchor key; and

in response to determining that the terminal device is not subscribed to the subscribable security service with respect to another service application, enabling data exchange between the terminal device and the another service application without encryption; and

wherein encrypted communications with the service applications are subscribable by the terminal device on a service application by service application basis as managed by the communication network and the service applications supporting the encrypted communications are registered with the communication network.

16 . The method of claim 15 , wherein the first request for the anchor key comprises a first identifier for the anchor key.

17 . The method of claim 16 , wherein determining that the anchor key being requested is invalid comprises:

determining that the anchor key corresponding to the first identifier is non-existent in the application key management network node;

transmitting a second request for the anchor key to an authentication network node wherein the second request comprises the first identifier;

receiving from the authentication network node a response indicating to the second request that the anchor key corresponding to the first identifier is invalid; and

determining that the anchor key being requested is invalid based on the response from the authentication network node.

18 . The method of claim 15 , wherein the anchor key being requested is associated with an expiration time period and the requested anchor key has become invalid due to an end of the expiration time period.

19 . The method of claim 15 , wherein the request for the authentication procedure comprises a subscription concealed identifier (SUCI) for identifying the terminal device or a global unique temporary identifier (GUTI) with key set identifier indicating that a security context for the terminal device is invalid.

20 . A terminal device comprising one or more processors and one or more memories, wherein the one or more processors are configured to read computer code from the one or more memories to:

in response to determining that the terminal device is subscribed to an encrypted communication as a subscribable security service with a service application:

detect that a first key for enabling encrypted communication with the service application previously generated from a first authentication of the terminal device with a communication network has become invalid;

transmit a request for a second authentication to the communication network;

generate a second key for enabling encrypted communication with the service application when the second authentication is successful;

replace the first key with the second key; and

exchange data with the service application based on the second key; and

in response to determining that the terminal device is not subscribed to the subscribable security service with respect to another service application, exchanging data with the another service application without encryption,

wherein the first key and the second key comprise, respectively, a first anchor key and a second anchor key, generated during the first authentication and the second authentication of the terminal device with the communication network, respectively; and

wherein encrypted communications with the service applications are subscribable by the terminal device on a service application by service application basis as managed by the communication network and the service applications supporting the encrypted communications are registered with the communication network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2022
From: YOU, SHILIN; CAI, JIYAN; LIU, YUZE; PENG, JIN; YU, WANTAO; LIN, ZHAOJI; MAO, YUXIN; LIU, JIANHUA
To: ZTE CORPORATION
Reel/Frame 060592/0527 →
Continuity (2)
Continuation PCTCN2020072448 · Jan 16, 2020
Related Publication 20220345307A1 · Oct 27, 2022
References Cited (112)
US 9918225B2 · Lee et al. · 2018 [cited by applicant]
US 10708772B2 · Wager et al. · 2020 [cited by applicant]
US 10841084B2 · Lee et al. · 2020 [cited by applicant]
US 10841302B2 · Hahn et al. · 2020 [cited by applicant]
US 11431561B2 · Smith et al. · 2022 [cited by applicant]
US 11452001B2 · Lia et al. · 2022 [cited by applicant]
US 11456867B2 · Schmatz · 2022 [cited by applicant]
US 11496292B2 · Fischer et al. · 2022 [cited by applicant]
US 11876895B2 · Fischer et al. · 2024 [cited by applicant]
US 20020062451A1 · Scheidt et al. · 2002 [cited by applicant]
US 20070140480A1 · Yao · 2007 [cited by applicant]
US 20100268943A1 · Roy-Chowdhury et al. · 2010 [cited by applicant]
US 20120135701A1 · Zhu · 2012 [cited by examiner]
US 20130054967A1 · Davoust et al. · 2013 [cited by applicant]
US 20150199213A1 · Desai · 2015 [cited by examiner]
US 20160094521A1 · Rao · 2016 [cited by examiner]
US 20160119311A1 · Maria · 2016 [cited by examiner]
US 20160226828A1 · Bone · 2016 [cited by examiner]
US 20170054691A1 · Graubner et al. · 2017 [cited by applicant]
US 20170063827A1 · Ricardo · 2017 [cited by applicant]
US 20170195877A1 · Lehtovirta · 2017 [cited by examiner]
US 20180227302A1 · Lee et al. · 2018 [cited by applicant]
US 20180343249A1 · Hahn et al. · 2018 [cited by applicant]
US 20180365411A1 · Falk et al. · 2018 [cited by applicant]
US 20180367991A1 · Wager et al. · 2018 [cited by applicant]
US 20190037395A1 · Lehtovirta et al. · 2019 [cited by applicant]
US 20190098502A1 · Torvinen et al. · 2019 [cited by applicant]
US 20190253889A1 · Wu et al. · 2019 [cited by applicant]
US 20190261178A1 · Rajadurai et al. · 2019 [cited by applicant]
US 20190349426A1 · Smith et al. · 2019 [cited by applicant]
US 20190387401A1 · Lia et al. · 2019 [cited by applicant]
US 20200014535A1 · Baskaran et al. · 2020 [cited by applicant]
US 20200280896A1 · Ying · 2020 [cited by examiner]
US 20200344048A1 · Fischer et al. · 2020 [cited by applicant]
US 20200344604A1 · He · 2020 [cited by examiner]
US 20200396792A1 · Tiwari · 2020 [cited by examiner]
US 20210126781A1 · Schmatz · 2021 [cited by applicant]
US 20220060896A1 · Wu · 2022 [cited by examiner]
US 20220095104A1 · Ben Henda · 2022 [cited by examiner]
US 20220174063A1 · Wu · 2022 [cited by examiner]
US 20220191008A1 · Nair · 2022 [cited by examiner]
US 20220295271A9 · Wu · 2022 [cited by applicant]
US 20220417010A1 · De Kievit · 2022 [cited by examiner]
US 20230070124A1 · Fischer et al. · 2023 [cited by applicant]
US 20230110131A1 · Smith et al. · 2023 [cited by applicant]
CN 101267309A · 2008 [cited by applicant]
CN 101848425A · 2010 [cited by applicant]
CN 104917618A · 2015 [cited by applicant]
CN 106922216A · 2017 [cited by applicant]
CN 108809635A · 2018 [cited by applicant]
CN 108810890A · 2018 [cited by applicant]
CN 109194473A · 2019 [cited by applicant]
CN 110635905A · 2019 [cited by applicant]
CN 112087753A · 2020 [cited by examiner]
IN 201941024005 · 2019 [cited by examiner]
JP 4654498B2 · 2011 [cited by applicant]
JP WO2018116231A · 2018 [cited by applicant]
KR 1020140119497A · 2014 [cited by applicant]
KR 20180106998A · 2018 [cited by applicant]
KR 1020200003108A · 2020 [cited by applicant]
TW 200423675A · 2004 [cited by applicant]
WO WO2012128478A2 · 2012 [cited by applicant]
WO WO2012129503A1 · 2012 [cited by applicant]
WO WO2015069028A1 · 2015 [cited by applicant]
WO WO2017129288A1 · 2017 [cited by applicant]
WO WO2018124857A1 · 2018 [cited by applicant]
WO WO2018144200A1 · 2018 [cited by applicant]
WO WO2018146180A1 · 2018 [cited by applicant]
WO WO2019020193A1 · 2019 [cited by applicant]
WO WO2019020440A1 · 2019 [cited by applicant]
WO WO2019213946A1 · 2019 [cited by applicant]
WO WO2020221019A1 · 2020 [cited by applicant]
WO WO2021115614A1 · 2021 [cited by applicant]
International Search Report mailed Oct. 13, 2020 for International Application No. PCT/CN2020/072448. [cited by applicant]
Written Opinion mailed Oct. 13, 2020 for International Application No. PCT/CN2020/072448. [cited by applicant]
Official Decision of Grant issued Jul. 3, 2023 for Russian Patent Application No. 2022122039, including English translation (20 pages). [cited by applicant]
Extended European Search Report dated Nov. 28, 2022 for European Application No. 20888615.0. [cited by applicant]
First Office Action dated Dec. 19, 2022 for Taiwanese Application No. 110101492. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and Systems Aspects; Study on authentication and key management for applications based on 3GPP credential in 5G (Release 16), 3GPP Standard; Tec… [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and key management for applications; based on 3GPP credential in 5G AKMA (Release 16), 3GPP Standard; Technic… [cited by applicant]
Author Unknown, “Security architecture and procedures for 5G System”, Technical Specification, ETSI TS 133 501 V15.2.0 Published Oct. 2018. (Year: 2018). [cited by applicant]
Canadian Office Action, dated Jun. 3, 2024, pp. 1-6, issued in Canadian Patent Application No. 3,159,134, Canadian Intellectual Property Office, Gatineau, Quebec. [cited by applicant]
China Mobile, Add abbreviations and editorial changes to TR 33.835, Nov. 18-22, 2019, pp. 1-12, 3GPP TSG SA3 Meeting #97 S3-194210, Reno, US. [cited by applicant]
China Mobile, Vodafone, Key derivation function in TR 33.841, Sep. 24-28, 2018, pp. 1-4, 3GPP TSG SA WG3 (Security) Meeting #92Adhoc S3-183013, Harbin, China. [cited by applicant]
European Office Action, Dec. 12, 2024, pp. 1-5, issued European Application No. 20 887 115.2, European Patent Office, Munich, Germany. [cited by applicant]
European Office Action, Sep. 19, 2024, pp. 1-2, issued in Application No. 19 954 008.9. [cited by applicant]
Examination Report dispatched Oct. 11, 2022 for Indian Application No. 202217031638. [cited by applicant]
Extended European Search Report dated Dec. 22, 2022 for European Application No. 20887214.3. [cited by applicant]
First Communication issued by the European Patent Office mailed on Jul. 9, 2024, in European Patent Application No. 20887115.2, European Patent Office, Munich, Germany. [cited by applicant]
Huawei et al.; “Solution for Key freshness in AKMA”; 3GPP Draft; S3-190169—Solution for Key Freshness in AKMA, 3rd Generation Partnership Project (3GPP), Mobile Competence Centre; Sophia-Antipolis, France; vol. SA WG3, … [cited by applicant]
Huawei, Hisilicon, Delete the EN of solution 5, May 6-10, 2019, pp. 1-4, 3GPP TSG SA WG3 (Security) Meeting #95 S3-191286, Reno, US. [cited by applicant]
Indian Examination Report dated Jan. 20, 2023 for Indian Application No. 202217037063. [cited by applicant]
Indian Office Action, Feb. 5, 2025, pp. 1-3, issued in Application No. 202217037063, Intellectual Property, Mumbai, India. [cited by applicant]
International Search Report and Written Opinion mailed Oct. 12, 2020 for International Application No. PCT/CN2020/072444. [cited by applicant]
International Search Report and Written Opinion mailed Oct. 13, 2020 for International Application No. PCT/CN2020/072446. [cited by applicant]
Japanese Office Action with English translation, dated Sep. 8, 2023, pp. 1-7, issued in Japanese Patent Application No. 2022-542392. [cited by applicant]
Korean Office Action with English summary, Nov. 16, 2024, pp. 1-9, issued in Application No. 10-2022-7024684. [cited by applicant]
Korean Office Action with English translation, Aug. 20, 2024, pp. 1-14, issued in Patent Application No. 069730164, Seoul, Korea. [cited by applicant]
Mohsin Khan et al: “Privacy Preserving AKMA in 5G”, Security Standardisation Research Workshop, ACM, 2 Penn Plaza, Suite 701 New York NY 1 0121-0701 USA, Nov. 11, 2019 (Nov. 11, 2019), pp. 45-56, XP058444062, DOI: 10.11… [cited by applicant]
Nokia, Nokia Shanghai Bell, China Mobile, Implicit bootstrapping using NEF as the AKMA Anchor Function, Jun. 24-28, 2019, pp. 1-6, 3GPP TSG-SA WG3 Meeting #95 Bis S3-192220, Sapporo, Japan. [cited by applicant]
Supplementary European Search Report, Sep. 5, 2023, pp. 1-9, issued in European Patent Application No. 20887115.2, European Patent Office, Munich, Germany. [cited by applicant]
US Office Action, Aug. 27, 2024, pp. 1-18, issued in U.S. Appl. No. 17/858,271, USPTO, Alexandria, Virginia. [cited by applicant]
US Office Action, Mar. 12, 2024, pp. 1-19, issued in U.S. Appl. No. 17/857,389, USPTO, Alexandria, Virginia. [cited by applicant]
US Office Action, Oct. 15, 2024, pp. 1-20, issued in U.S. Appl. No. 17/857,389, USPTO, Alexandria, Virginia. [cited by applicant]
Office Action issued in Chinese Patent Application No. 201980098562.5 dated Feb. 11, 2025, 13 pages. [cited by applicant]
Office Action issued in Chinese Patent Application No. 202080092552.3 dated Feb. 12, 2025, 6 pages. [cited by applicant]
MediaTek “Enhancements to HARQ for NR-U operation” 3GPP TSG RAN WG1 #97, May 13, 2019, R1-1906545, 11 pages. [cited by applicant]
Huawei et al. “HARQ enhancements in NR unlicensed” 3GPP TSG RAN WG1 Meeting #97, R1-1906046, 14 pages. [cited by applicant]
First Office Action dated Feb. 13, 2025 for Chinese Patent Application No. 202080085232.5, with English translation. [cited by applicant]
“3GPP TR 33.835, V 16.0.0”; 3GPP Organizational Partners, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on authentication and key management for applications based … [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16); 3GPP TS 33.501, V16.1.0; Dec. 2019; 202 pages. [cited by applicant]
Extended European Search Report completed Oct. 15, 2025 and Search Opinion for European Patent Application No. EP 25 18 8493.8; 8 pages. [cited by applicant]