IP Library Granted Patent US 12,627,639
Granted Patent B2
US 12,627,639 · App. 17/990,963 · Granted May 12, 2026

Communication protection method and apparatus

Inventors: Longhua Guo (Shanghai, CN); He Li (Shanghai, CN); Rong Wu (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L63/0428H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,639
App. No.
17/990,963
Granted
May 12, 2026
Kind
B2
Abstract

Embodiments of this disclosure provide a communication protection method that includes: a terminal device sends an application session establishment request message to a first application function network element (AF), where the application session establishment request message includes an authentication and key management for application (AKMA) key identifier; and the terminal device receives an application session establishment response message from the first AF, where the application session establishment response message includes a security activation indication. The security activation indication indicates whether to activate security protection on communication between the terminal device and a second AF. The security protection includes confidentiality protection and/or integrity protection performed based on a security key, and the security key is generated based on an AKMA key corresponding to the AKMA key identifier.

Claims (69)

1 . A communication protection method performed by a terminal device or a chip in the terminal device, comprising:

sending an application session establishment request message to a first application function network element, wherein the application session establishment request message comprises an authentication and key management for application (AKMA) key identifier; and

receiving an application session establishment response message from the first application function network element, wherein the application session establishment response message comprises a security activation indication, wherein

the security activation indication indicates whether to activate security protection on communication between the terminal device and a second application function network element, the security protection comprises at least one of confidentiality protection or integrity protection performed based on a security key, and wherein the first application function network element and the second application function network element are different application function network elements and the method further comprises:

generating a first application function network element key based on an AKMA key corresponding to the AKMA key identifier;

generating a second application function network element key based on the first application function network element key and a key generation parameter that is shared by the terminal device and the first application function network element; and

generating the security key based on the second application function network element key, wherein the security key comprises at least one of a confidentiality protection key for the confidentiality protection or an integrity protection key for the integrity protection.

2 . The method according to claim 1 , wherein the application session establishment request message further comprises information about a security algorithm supported by the terminal device, wherein the security algorithm supported by the terminal device comprises at least one of a confidentiality protection algorithm supported by the terminal device or an integrity protection algorithm supported by the terminal device; and

the application session establishment response message further comprises information about a security algorithm selected based on the security algorithm supported by the terminal device, wherein the selected security algorithm comprises at least one of a selected confidentiality protection algorithm or a selected integrity protection algorithm.

3 . The method according to claim 2 , wherein the method further comprises:

when the security activation indication indicates to activate the security protection, activating, based on the selected security algorithm and the security key, the security protection on the communication between the terminal and the second application function network element.

4 . The method according to claim 2 , wherein the generating the security key based on the second application function network element key comprises:

generating the security key based on the second application function network element key and the selected security algorithm.

5 . The method according to claim 1 , wherein the application session establishment request message comprises the key generation parameter; and

the key generation parameter comprises at least one selected from the following:

identity information used by the terminal device in the first application function network element or the second application function network element;

a service type requested by the terminal device from the first application function network element or the second application function network element;

identification information of the second application function network element; or

a key freshness parameter.

6 . The method according to claim 1 , wherein the application session establishment response message comprises the key generation parameter, and the key generation parameter comprises a key freshness parameter.

7 . The method according to claim 1 , wherein the application session establishment response message further comprises a key identifier, the key identifier is for identifying a security context between the terminal device and the second application function network element, and the security context comprises the security key.

8 . The method according to claim 1 , wherein the application session establishment response message comprises a first integrity verification parameter, and the method further comprises:

determining, based on the security key and the first integrity verification parameter, whether the application session establishment response message is tampered with.

9 . The method according to claim 8 , wherein the method further comprises:

sending an application session establishment complete message to the second application function network element when the application session establishment response message is not tampered with, wherein the application session establishment complete message comprises a second integrity verification parameter calculated based on the security key.

10 . The method according to claim 1 , wherein the first application function network element and the second application function network element have a same application function network element identifier.

11 . A communication protection method, comprising:

receiving, by a first application function network element, an application session establishment request message from a terminal device, wherein the application session establishment request message comprises an authentication and key management for application (AKMA) key identifier; and

sending, by the first application function network element, an application session establishment response message to the terminal device, wherein the application session establishment response message comprises a security activation indication, wherein

the security activation indication indicates whether to activate security protection on communication between the terminal device and a second application function network element, the security protection comprises at least one of confidentiality protection or integrity protection performed based on a security key; wherein the first application function network element and the second application function network element are different application function network elements and the method further comprises:

generating, by the first application function network element, a first application function network element key based on an AKMA key corresponding to the AKMA key identifier;

generating, by the first application function network element, a second application function network element key based on the first application function network element key and a key generation parameter that is shared by the terminal device and the first application function network element;

generating, by the first application function network element, the security key based on the second application function network element key, wherein the security key comprises at least one of a confidentiality protection key for the confidentiality protection or an integrity protection key for the integrity protection; and

sending, by the first application function network element, a key notification message to the second application function network element, wherein the key notification message comprises the security key.

12 . The method according to claim 11 , wherein the application session establishment request message further comprises information about a security algorithm supported by the terminal device, wherein the security algorithm supported by the terminal device comprises at least one of a confidentiality protection algorithm supported by the terminal device or an integrity protection algorithm supported by the terminal device; and

the application session establishment response message further comprises information about a security algorithm selected based on the security algorithm supported by the terminal device, wherein the selected security algorithm comprises at least one of a selected confidentiality protection algorithm or a selected integrity protection algorithm.

13 . The method according to claim 12 , wherein the method further comprises:

when the security activation indication indicates to activate the security protection, triggering, by the first application function network element, the second application function network element to activate, based on the selected security algorithm and the security key, the security protection on the communication between the second application function network element and the terminal device.

14 . The method according to claim 11 , wherein the generating, by the first application function network element, the security key based on the second application function network element key, comprises:

generating, by the first application function network element, the security key and a key identifier based on the second application function network element key and the selected security algorithm, wherein

the key identifier is for identifying a security context between the terminal device and the second application function network element, the security context comprises the security key, and the application session establishment response message further comprises the key identifier.

15 . The method according to claim 12 , wherein the security activation indication is indicated by the selected security algorithm, wherein

when the selected confidentiality protection algorithm is null, it indicates that the confidentiality protection on the communication between the terminal device and the second application function network element is not activated;

when the selected confidentiality protection algorithm is non-null, it indicates that the confidentiality protection on the communication between the terminal device and the second application function network element is activated;

when the selected integrity protection algorithm is null, it indicates that the integrity protection on the communication between the terminal device and the second application function network element is not activated; and

when the selected integrity protection algorithm is non-null, it indicates that the integrity protection on the communication between the terminal device and the second application function network element is activated.

16 . The method according to claim 12 , wherein the method further comprises:

determining, by the first application function network element, whether to activate the security protection on the communication between the terminal device and the second application function network element; and

generating, by the first application function network element, the security activation indication based on a determining result.

17 . The method according to claim 16 , wherein the determining whether to activate the security protection on the communication between the terminal device and the second application function network element comprises at least one of:

determining, depending on whether the confidentiality protection algorithm supported by the terminal device comprises a confidentiality protection algorithm supported by the second application function network element, whether to activate the confidentiality protection on the communication between the terminal device and the second application function network element; or

determining, depending on whether the integrity protection algorithm supported by the terminal device comprises an integrity protection algorithm supported by the second application function network element, whether to activate the integrity protection on the communication between the terminal device and the second application function network element.

18 . The method according to claim 11 , wherein the method further comprises:

receiving, by the first application function network element, an application session establishment complete message from the terminal device, wherein the application session establishment complete message comprises a second integrity verification parameter; and

determining, by the first application function network element based on the security key and the second integrity verification parameter, whether the application session establishment complete message is tampered with.

19 . An apparatus comprising a processor configured to execute instructions stored in a memory to cause the apparatus to:

send an application session establishment request message to a first application function network element, wherein the application session establishment request message comprises an authentication and key management for application (AKMA) key identifier; and

receive an application session establishment response message from the first application function network element, wherein the application session establishment response message comprises a security activation indication, wherein

the security activation indication indicates whether to activate security protection on communication between the apparatus and a second application function network element, the security protection comprises at least one of confidentiality protection or integrity protection performed based on a security key, and wherein the first application function network element and the second application function network element are different application function network elements and the apparatus is further caused to:

generate a first application function network element key based on an AKMA key corresponding to the AKMA key identifier;

generate a second application function network element key based on the first application function network element key and a key generation parameter that is shared by the apparatus and the first application function network element; and

generate the security key based on the second application function network element key, wherein the security key comprises at least one of a confidentiality protection key for the confidentiality protection or an integrity protection key for the integrity protection.

20 . An apparatus comprising a processor configured to execute instructions stored in a memory to cause the apparatus to:

receive an application session establishment request message from a terminal device, wherein the application session establishment request message comprises an authentication and key management for application (AKMA) key identifier; and

send an application session establishment response message to the terminal device, wherein the application session establishment response message comprises a security activation indication, the security activation indication indicates whether to activate security protection on communication between the terminal device and a second application function network element, the security protection comprises at least one of confidentiality protection or integrity protection performed based on a security key; wherein the apparatus and the second application function network element are different and the apparatus is further caused to:

generate a first application function network element key based on an AKMA key corresponding to the AKMA key identifier;

generate a second application function network element key based on the first application function network element key and a key generation parameter that is shared by the terminal device and the apparatus;

generate the security key based on the second application function network element key, wherein the security key comprises at least one of a confidentiality protection key for the confidentiality protection or an integrity protection key for the integrity protection; and

send a key notification message to the second application function network element, wherein the key notification message comprises the security key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2023
From: GUO, LONGHUA; LI, HE; WU, RONG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 062755/0868 →
Priority Claims (1)
CN 202010441150.1 · May 22, 2020 · national
Continuity (2)
Continuation PCTCN2021093704 · May 13, 2021
Related Publication 20230077391A1 · Mar 16, 2023
References Cited (63)
US 7386736B2 · Bade · 2008 [cited by examiner]
US 9154527B2 · Lee · 2015 [cited by examiner]
US 9455972B1 · Dotan · 2016 [cited by examiner]
US 9584518B1 · Robertson · 2017 [cited by examiner]
US 9705736B2 · Wang · 2017 [cited by examiner]
US 10880743B1 · Berzin · 2020 [cited by examiner]
US 11086897B2 · Ching · 2021 [cited by examiner]
US 11463466B2 · Higgins · 2022 [cited by examiner]
US 11659382B2 · Torvinen · 2023 [cited by examiner]
US 20030236985A1 · Ruuth · 2003 [cited by examiner]
US 20040078568A1 · Pham · 2004 [cited by examiner]
US 20040218605A1 · Gustafsson · 2004 [cited by examiner]
US 20050154875A1 · Chao · 2005 [cited by examiner]
US 20060136748A1 · Bade · 2006 [cited by examiner]
US 20070150934A1 · Fiszman · 2007 [cited by examiner]
US 20070277032A1 · Relyea · 2007 [cited by examiner]
US 20080263672A1 · Chen · 2008 [cited by examiner]
US 20090291637A1 · Alrabady · 2009 [cited by examiner]
US 20130055384A1 · Shulman · 2013 [cited by examiner]
US 20130091578A1 · Bisht · 2013 [cited by examiner]
US 20140198718A1 · Billau · 2014 [cited by examiner]
US 20150033306A1 · Dickenson · 2015 [cited by examiner]
US 20150156601A1 · Donnellan · 2015 [cited by examiner]
US 20160036854A1 · Himawan · 2016 [cited by examiner]
US 20160330246A1 · Narayanaswamy · 2016 [cited by examiner]
US 20160337484A1 · Tola · 2016 [cited by examiner]
US 20160374104A1 · Watfa · 2016 [cited by examiner]
US 20170071029A1 · Cui · 2017 [cited by examiner]
US 20170289197A1 · Mandyam · 2017 [cited by examiner]
US 20170364875A1 · Efroni · 2017 [cited by examiner]
US 20180025332A1 · Huang · 2018 [cited by examiner]
US 20180091528A1 · Shahbaz · 2018 [cited by examiner]
US 20180343238A1 · Tola · 2018 [cited by examiner]
US 20180359642A1 · Torvinen · 2018 [cited by examiner]
US 20190012447A1 · Lesso · 2019 [cited by examiner]
US 20200037165A1 · Kunz · 2020 [cited by examiner]
US 20200128020A1 · Abduljaber · 2020 [cited by examiner]
US 20200287973A1 · Zhang · 2020 [cited by examiner]
US 20200322795A1 · Eskelinen · 2020 [cited by examiner]
US 20210067956A1 · Vigneswaran · 2021 [cited by examiner]
US 20210135885A1 · Hathorn · 2021 [cited by examiner]
US 20210160289A1 · Wifvesson · 2021 [cited by examiner]
US 20210273923A1 · Zhang · 2021 [cited by examiner]
US 20210406381A1 · Heisrath · 2021 [cited by examiner]
US 20220132315A1 · Kolekar · 2022 [cited by examiner]
US 20220183049A1 · Lee · 2022 [cited by examiner]
US 20220225100A1 · Muhanna · 2022 [cited by examiner]
US 20220248230A1 · Wifvesson · 2022 [cited by examiner]
US 20230171600A1 · Baskaran · 2023 [cited by examiner]
US 20230188992A1 · Schliwa-Bertling · 2023 [cited by examiner]
US 20230224700A1 · Torvinen · 2023 [cited by examiner]
CN 104683304B · 2019 [cited by applicant]
CN 111147231A · 2020 [cited by applicant]
WO WO2018000867A1 · 2018 [cited by examiner]
WO WO2019193147A1 · 2019 [cited by examiner]
3GPP TSG-SA WG3 Meeting #95bis, S3-191892, Editorial corrections of AKMA TR 33.835 v0.4.0, NEC, Sapporo (Japan), Jun. 24-28, 2019; 1 page. [cited by applicant]
3GPP TSG-SA3 Meeting #98e, S3-200296, pCR to TS 33.535: Update of the AKMA procedures, Ericsson, e-meeting, Mar. 2-6, 2020; 4 total pages. [cited by applicant]
3GPP TS 22.125 V17.1.0, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Unmanned Aerial System (UAS) support in 3GPP; Stage 1; (Release 17), Dec. 2019; 16 total pages. [cited by applicant]
3GPP TR 33.835 V1.2.0,“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on authentication and key management for applications based on 3GPP credential in 5G (Release 1… [cited by applicant]
3GPP TS 33.501 V16.2.0, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16), Mar. 2020; 227 total pages. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and key management for applications; based on 3GPP credential in 5G ( AKMA ) (Release 16); 3GPP TS 33.535 V0.… [cited by applicant]
3GPP TS 33.535, V0.4.0, S3-200831, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and key management for applications; based on 3GPP credential in 5G (AKMA… [cited by applicant]
CATT: “The details of the AKMA service subscription information confirmation”, 3GPP TSG-SA3, Meeting ad-hoc, e- meeting, Apr. 14-17, 2020; S3-200712; 2 total pages. [cited by applicant]