IP Library › Granted Patent US 12,256,005
Granted Patent B2
US 12,256,005 · App. 17/954,167 · Granted Mar 18, 2025

Communication system, method, and apparatus

Inventors: He Li (Shanghai, CN); Rong Wu (Shenzhen, CN); Yizhuang Wu (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04L9/321H04L9/0819H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,256,005
App. No.
17/954,167
Granted
Mar 18, 2025
Kind
B2
Abstract

This application provides a communication system, method, and apparatus. The system is applied to implement authentication and key management for applications (AKMA) service-based data transmission between a terminal device and an application function network element. The system includes an AKMA anchor function network element and a network exposure function network element. The network exposure function network element obtains first identification information from a unified data management network element, where the first identification information is used to determine an authentication server function network element corresponding to the terminal device, and sends the first identification information to the AKMA anchor function network element. The AKMA anchor function network element obtains, from the unified data management network element based on the first identification information, identification information of the authentication server function network element corresponding to the terminal device.

Claims (54)

1. A communication system, wherein the communication system is configured to implement authentication and key management for applications (AKMA) service-based data transmission between a terminal device and an application function network element, and the communication system comprises:

an AKMA anchor function network element; and

a network exposure function network element, wherein:

the network exposure function network element is configured to:

receive second identification information from the application function network element;

in response to determining that the application function network element authorizes the network exposure function network element to request a key, send a first request message to a unified data management network element, wherein the first request message, comprising the second identification information, requests the unified data management network element to determine first identification information based on the second identification information; and

receive a first response message from the unified data management network element, wherein the first response message comprises the first identification information; wherein the first identification information is used to determine an authentication server function network element corresponding to the terminal device, and

send the first identification information to the AKMA anchor function network element; and

the AKMA anchor function network element is configured to:

obtain, from the unified data management network element based on the first identification information, identification information of the authentication server function network element corresponding to the terminal device.

2. The communication system according to claim 1 , wherein the second identification information comprises identification information of a key of the AKMA service, and the first identification information comprises a subscriber permanent identifier (SUPI) of the terminal device.

3. The communication system according to claim 1 , wherein the second identification information comprises identification information of a key of the AKMA service and temporary identity information of the terminal device, and the first identification information comprises an SUPI of the terminal device.

4. The communication system according to claim 2 , wherein when being configured to obtain, from the unified data management network element based on the first identification information, the identification information of the authentication server function network element corresponding to the terminal device, the AKMA anchor function network element is specifically configured to:

send a second request message to the unified data management network element, wherein the second request message comprises the SUPI of the terminal device, and the second request message requests the unified data management network element to determine, based on the SUPI of the terminal device, the identification information of the authentication server function network element corresponding to the terminal device; and

receive a second response message from the unified data management network element, wherein the second response message comprises the identification information of the authentication server function network element corresponding to the terminal device.

5. The communication system according to claim 1 , wherein the authentication server function network element corresponding to the terminal device is an authentication server function network element corresponding to an intermediate key of the terminal device, and the authentication server function network element stores the intermediate key generated by the authentication server function network element in a primary authentication process.

6. A communication method, wherein the method is used to implement authentication and key management for applications (AKMA) service-based data transmission between a terminal device and an application function network element, and the communication method comprises:

receiving, by an AKMA anchor function network element, first identification information from a network exposure function network element, wherein the first identification information comprises a subscriber permanent identifier (SUPI) of the terminal device; and

sending, by the AKMA anchor function network element, a second request message to a unified data management network element, wherein the second request message comprises the SUPI of the terminal device; and

receiving, by the AKMA anchor function network element, a second response message from the unified data management network element, wherein the second response message comprises identification information of an authentication server function network element corresponding to the terminal device.

7. The communication method according to claim 6 , wherein the second response message further comprises subscription data of an AKMA service of the terminal device.

8. The communication method according to claim 6 , wherein the method further comprises:

receiving, by the AKMA anchor function network element, an identifier of the application function network element from the network exposure function network element;

obtaining, by the AKMA anchor function network element from the authentication server function network element corresponding to the terminal device, a key that is of the AKMA service and that is identified by identification information of the key of the AKMA service;

generating, by the AKMA anchor function network element, a communication key between the application function network element and the terminal device based on the identifier of the application function network element and the key of the AKMA service; and

sending, by the AKMA anchor function network element, the communication key to the application function network element by using the network exposure function network element.

9. The communication method according to claim 8 , wherein the method further comprises:

performing, by the AKMA anchor function network element, authorization detection on the terminal device or the application function network element, and

when completing the authorization detection, determining the authentication server function network element identified by the identification information of the authentication server function network element corresponding to the terminal device.

10. The communication method according to claim 6 , wherein the authentication server function network element corresponding to the terminal device is an authentication server function network element corresponding to an intermediate key of the terminal device, and the authentication server function network element stores the intermediate key generated by the authentication server function network element in a primary authentication process.

11. A communication method, wherein the method is used to implement authentication and key management for applications (AKMA) service-based data transmission between a terminal device and an application function network element, and the communication method comprises:

receiving, by a network exposure function network element, second identification information from the application function network element;

when determining that the application function network element authorizes the network exposure function network element to request a key, sending, by the network exposure function network element, a first request message to a unified data management network element, wherein the first request message, comprising the second identification information, requests the unified data management network element to determine first identification information based on the second identification information;

receiving, by the network exposure function network element, a first response message from the unified data management network element, wherein the first response message comprises the first identification information; wherein the first identification information is used to determine an authentication server function network element corresponding to the terminal device; and

sending, by the network exposure function network element, the first identification information to an AKMA anchor function network element.

12. The communication method according to claim 11 , wherein the second identification information comprises identification information of a key of the AKMA service, and the first identification information comprises a subscriber permanent identifier (SUPI) of the terminal device.

13. The communication method according to claim 11 , wherein the second identification information comprises identification information of a key of the AKMA service and temporary identity information of the terminal device, and the first identification information comprises an SUPI of the terminal device.

14. The communication method according to claim 11 , wherein the communication method further comprises:

receiving, by the network exposure function network element, an identifier of the application function network element; and

sending the identifier of the application function network element to the AKMA anchor function network element.

15. The communication method according to claim 11 , wherein the authentication server function network element corresponding to the terminal device is an authentication server function network element corresponding to an intermediate key of the terminal device, and the authentication server function network element stores the intermediate key generated by the authentication server function network element in a primary authentication process.

16. The communication method according to claim 11 , wherein the method further comprises:

receiving, by the AKMA anchor function network element, the first identification information from the network exposure function network element;

sending, by the AKMA anchor function network element, a second request message to the unified data management network element, wherein the second request message comprises an SUPI of the terminal device; and

receiving, by the AKMA anchor function network element, a second response message from the unified data management network element, wherein the second response message comprises identification information of the authentication server function network element corresponding to the terminal device.

17. The communication method according to claim 16 , wherein the second response message further comprises subscription data of an AKMA service of the terminal device.

18. The communication method according to claim 16 , wherein the method further comprises:

receiving, by the AKMA anchor function network element, an identifier of the application function network element from the network exposure function network element;

obtaining, by the AKMA anchor function network element from the authentication server function network element corresponding to the terminal device, a key that is of the AKMA service and that is identified by identification information of the key of the AKMA service;

generating, by the AKMA anchor function network element, a communication key between the application function network element and the terminal device based on the identifier of the application function network element and the key of the AKMA service; and

sending, by the AKMA anchor function network element, the communication key to the application function network element by using the network exposure function network element.

19. The communication method according to claim 18 , wherein the communication method further comprises:

performing, by the AKMA anchor function network element, authorization detection on the terminal device or the application function network element, and when completing the authorization detection, determining the authentication server function network element identified by the identification information of the authentication server function network element corresponding to the terminal device.

20. The communication method according to claim 16 , wherein the authentication server function network element corresponding to the terminal device is an authentication server function network element corresponding to an intermediate key of the terminal device, and the authentication server function network element stores the intermediate key generated by the authentication server function network element in a primary authentication process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2024
From: LI, HE; WU, RONG; WU, YIZHUANG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 069559/0344 →
Priority Claims (1)
CN 202010239015.9 · Mar 30, 2020 · national
Continuity (2)
Continuation PCTCN2021084120 · Mar 30, 2021
Related Publication 20230019089A1 · Jan 19, 2023
References Cited (18)
US 20190223063A1 · Palanigounder et al. · 2019 [cited by applicant]
US 20190261453A1 · Jain et al. · 2019 [cited by applicant]
US 20200053828A1 · Bharatia et al. · 2020 [cited by applicant]
US 20210168599A1 · Ben Henda et al. · 2021 [cited by applicant]
US 20230068196A1 · Sasi · 2023 [cited by examiner]
CN 110167013A · 2019 [cited by applicant]
CN 110881020A · 2020 [cited by applicant]
CN 110881185A · 2020 [cited by applicant]
Office Action in Indian Appln. No. 202217058603, mailed on Dec. 12, 2023, 7 pages (with English translation). [cited by applicant]
Ericsson, “pCR to TS 33.535: Update of the AKMA procedures,” 3GPP SG-SA3 Meeting #98e,S3-200296, Mar. 2-6, 2020, 4 pages. [cited by applicant]
Samsung, “AKMA and Application Key Derivation,” 3GPP TSG-SA3 Meeting #98e, S3-200171, E-meeting, Mar. 2-6, 2020, 5 pages. [cited by applicant]
3GPP TS 33.535 v0.3.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and key management for applications; based on 3GPP credential in 5G (AKMA) (Release 1… [cited by applicant]
3GPP TR 33.835, V0.6.0 22, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on authentication and key management for applications; based on 3GPP credential in 5G (Rel… [cited by applicant]
Extended European Search Report in European Appln No. 21781915.0, dated Jun. 26, 2023, 9 pages. [cited by applicant]
Ericsson, “PCR to TS 33.535: UE Authentication Result Notification,” 3GPP TSG-SA3 Meeting #98e, S3-200297, e-meeting, Mar. 2-6, 2020, 2 pages. [cited by applicant]
Samsung, “AKMA and Application Key Derivation,” 3GPP TSG-SA3 Meeting #98e, S3-200171, e-meeting, Mar. 2-6, 2020, 6 pages. [cited by applicant]
Office Action in Chinese Appln. No. 202010239015.9, dated Jun. 21, 2022, 16 pages (with English translation). [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/CN2021/084120, mailed on Jun. 25, 2021, 15 pages (with English translation). [cited by applicant]
Cited By (1)
US 12,368,599