IP Library Granted Patent US 12,375,909
Granted Patent B2
US 12,375,909 · App. 18/348,834 · Granted Jul 29, 2025

Key identifier generation method and related apparatus

Inventors: He Li (Shanghai, CN); Rong Wu (Shenzhen, CN); Yizhuang Wu (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04W12/041H04W12/0433H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,909
App. No.
18/348,834
Granted
Jul 29, 2025
Kind
B2
Abstract

An authentication management function AUSF receives an authentication request message from an access and mobility management function AMF, where the authentication request message carries a subscription concealed identifier SUCI. The AUSF sends an authentication vector get request message to a unified data management UDM function, where the authentication vector get request message carries the SUCI. The AUSF receives an authentication vector get response message from the UDM, where the authentication vector get response message includes authentication and key management for application AKMA indication information. The AUSF generates, based on the AKMA indication information, an authentication and key management for application-key identifier based on a routing indicator RID in the SUCI.

Claims (68)

1. A key identifier generation method, comprising:

receiving, by an authentication management function, a first authentication request message from an access and mobility management function, wherein the first authentication request message carries a subscription concealed identifier, and the subscription concealed identifier is generated based on a permanent identifier of a terminal device;

sending, by the authentication management function, a first authentication vector get request message to a unified data management function, wherein the first authentication vector get request message carries the subscription concealed identifier;

receiving, by the authentication management function, a first authentication vector get response message from the unified data management function, wherein the first authentication vector get response message comprises indication information of authentication and key management for application, and further comprises a routing indicator that is determined based on the subscription concealed identifier; and

generating, by the authentication management function based on the routing indicator and the indication information of authentication and key management for application, a first authentication and key management for application-key identifier.

2. The method according to claim 1 , further comprising:

receiving, by the authentication management function, a second authentication request message from the access and mobility management function, wherein the second authentication request message comprises the permanent identifier;

sending, by the authentication management function, a second authentication vector get request message to the unified data management function, wherein the second authentication vector get request message carries the permanent identifier;

receiving, by the authentication management function, a second authentication vector get response message the unified data management function, wherein the second authentication vector get response message comprises the routing indicator and the indication information of authentication and key management for application; and

generating, by the authentication management function, a new second authentication and key management for application-key identifier using the routing indicator.

3. The method according to claim 1 , further comprising:

receiving, by the authentication management function, a second authentication request message from the access and mobility management function, wherein the second authentication request message comprises the permanent identifier;

sending, by the authentication management function, a second authentication vector get request message to the unified data management function, wherein the second authentication vector get request message carries the permanent identifier;

obtaining, by the authentication management function, the routing indicator from a core network element based on the indication information of authentication and key management for application; and

generating, by the authentication management function, a new second authentication and key management for application-key identifier using the routing indicator.

4. The method according to claim 3 , wherein obtaining, by the authentication management function, the routing indicator from the core network element based on the indication information of authentication and key management for application comprises:

determining, by the authentication management function based on the indication information of authentication and key management for application, that the second authentication and key management for application-key identifier needs to will be generated; and

when the authentication management function does not have the routing indicator locally when it is determined that the second authentication and key management for application-key identifier will be generated, obtaining, by the authentication management function, the routing indicator from the core network element.

5. The method according to claim 3 , wherein the core network element comprises the unified data management function or the access and mobility management function.

6. The method according to claim 3 , wherein before obtaining, by the authentication management function, the routing indicator from the core network element based on the indication information of authentication and key management for application, the method further comprises:

receiving, by the authentication management function, a second authentication vector get response message from the unified data management function, wherein the second authentication vector get response message comprises the indication information of authentication and key management for application.

7. A method, comprising:

receiving, by a unified data management function, a first authentication vector get request message from an authentication management function, wherein the first authentication vector get request message carries a subscription concealed identifier;

determining, by the unified data management function, a routing indicator based on the subscription concealed identifier; and

sending, by the unified data management function, a first authentication vector get response message to the authentication management function, wherein the first authentication vector get response message comprises the routing indicator and indication information of authentication and key management for application.

8. The method according to claim 7 , further comprising:

receiving, by the unified data management function, a second authentication vector get request message from the authentication management function, wherein the second authentication vector get request message carries a permanent identifier of a terminal device;

determining, by the unified data management function, the routing indicator based on the permanent identifier; and

sending, by the unified data management function, a second authentication vector get response message to the authentication management function, wherein the second authentication vector get response message comprises the routing indicator and the indication information of authentication and key management for application.

9. The method according to claim 7 , wherein after determining, by the unified data management function, the routing indicator based on the subscription concealed identifier, the method further comprises:

storing, by the unified data management function, the routing indicator.

10. The method according to claim 7 , further comprising:

determining, by the unified data management function, a terminal device corresponding to the subscription concealed identifier supports a service of authentication and key management for application.

11. An apparatus, comprising:

at least one processor coupled to at least one memory storing instructions, wherein the at least one processor is configured to execute the instructions to cause the apparatus to:

receive a first authentication request message from an access and mobility management function, wherein the first authentication request message carries a subscription concealed identifier, and the subscription concealed identifier is generated based on a permanent identifier of a terminal device;

send a first authentication vector get request message to a unified data management function, wherein the first authentication vector get request message carries the subscription concealed identifier;

receive a first authentication vector get response message from the unified data management function, wherein the first authentication vector get response message comprises indication information of authentication and key management for application, and further comprises a routing indicator that is determined based on the subscription concealed identifier; and

generate, based on the routing indicator and the indication information of authentication and key management for application, a first authentication and key management for application-key identifier.

12. The apparatus according to claim 11 , wherein the at least one processor is configured to execute the instructions to cause the apparatus further to:

receive a second authentication request message from the access and mobility management function, wherein the second authentication request message comprises the permanent identifier;

send a second authentication vector get request message to the unified data management function, wherein the second authentication vector get request message carries the permanent identifier;

receive a second authentication vector get response message from the unified data management function, wherein the second authentication vector get response message comprises the routing indicator and the indication information of authentication and key management for application; and

generate a new second authentication and key management for application-key identifier by using the routing indicator.

13. The apparatus according to claim 11 , wherein the at least one processor is configured to execute the instructions to cause the apparatus further to:

receive a second authentication request message from the access and mobility management function, wherein the second authentication request message 0 comprises the permanent identifier;

send a second authentication vector get request message to the unified data management function, wherein the second authentication vector get request message carries the permanent identifier;

obtain the routing indicator from a core network element based on the indication information of authentication and key management for application; and

generate a new second authentication and key management for application-key identifier by using the routing indicator.

14. The apparatus according to claim 13 , wherein obtaining the routing indicator from the core network element based on the indication information of authentication and key management for application comprises:

determining, based on the indication information of authentication and key management for application, that the second authentication and key management for application-key identifier will be generated; and

when the apparatus does not have the routing indicator locally when it is determined that the second authentication and key management for application-key identifier will be generated, obtaining the routing indicator from the core network element.

15. The apparatus according to claim 13 , wherein the core network element comprises the unified data management function or the access and mobility management function.

16. The apparatus according to claim 13 , wherein the at least one processor is configured to execute the instructions to cause the apparatus further to:

before obtaining the routing indicator from the core network element based on the indication information of authentication and key management for application, receive a second authentication vector get response message from the unified data management function, wherein the second authentication vector get response message comprises the indication information of authentication and key management for application.

17. An apparatus, comprising:

at least one processor coupled to at least one memory storing instructions, wherein the at least one processor is configured to execute the instructions to cause the apparatus to:

receive a first authentication vector get request message from an authentication management function, wherein the first authentication vector get request message carries a subscription concealed identifier;

determine a routing indicator based on the subscription concealed identifier; and

send a first authentication vector get response message to the authentication management function, wherein the first authentication vector get response message comprises the routing indicator, and indication information of authentication and key management for application.

18. The apparatus according to claim 17 , wherein the at least one processor is configured to execute the instructions to cause the apparatus further to:

receive a second authentication vector get request message from the authentication management function, wherein the second authentication vector get request message carries a permanent identifier of a terminal device;

determine the routing indicator based on the permanent identifier; and

send a second authentication vector get response message to the authentication management function, wherein the second authentication vector get response message comprises the routing indicator, and the indication information of authentication and key management for application.

19. The apparatus according to claim 17 , wherein the at least one processor is configured to execute the instructions to cause the apparatus further to:

after determining the routing indicator based on the subscription concealed identifier, store the routing indicator.

20. The apparatus according to claim 17 , wherein the at least one processor is configured to execute the instructions to cause the apparatus further to:

determine a terminal device corresponding to the subscription concealed identifier supports a service of authentication and key management for application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2025
From: LI, HE; WU, RONG; WU, YIZHUANG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 070977/0094 →
Continuity (2)
Continuation PCTCN2021070980 · Jan 8, 2021
Related Publication 20230362636A1 · Nov 9, 2023
References Cited (22)
US 11172426B2 · Chaponniere · 2021 [cited by examiner]
US 11991518B2 · De Kievit · 2024 [cited by examiner]
US 20190174449A1 · Shan et al. · 2019 [cited by applicant]
US 20210273879A1 · Kumar · 2021 [cited by examiner]
US 20210392495A1 · Tsiatsis · 2021 [cited by examiner]
US 20220046412A1 · Choyi · 2022 [cited by examiner]
US 20220386130A1 · Choyi · 2022 [cited by examiner]
US 20230262463A1 · Kunz · 2023 [cited by examiner]
CN 111147421A · 2020 [cited by applicant]
TW 201946485A · 2019 [cited by applicant]
WO 2020093864A1 · 2020 [cited by applicant]
WO 2020098974A1 · 2020 [cited by applicant]
WO WO2020088026A1 · 2020 [cited by examiner]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17), 3GPP TS 33.501, Dec. 2020, 253 pages, V17.0.0. [cited by applicant]
3GPP TS 23.003 V17.0.0 (Dec. 2020), 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Numbering, addressing and identification; (Release 17), 142 pages. [cited by applicant]
ZTE, “Clarification of RID in the clause 6.1”, 3GPP TSG-SA3 Meeting#101e, S3-202901, e-meeting, Nov. 9-20, 2020, 3 pages. [cited by applicant]
3GPP TS 23.501 V16.7.0 (Dec. 2020),3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16), 450 pages. [cited by applicant]
3GPP TS 23.502 V16.7.0 (Dec. 2020), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16), 603 pages. [cited by applicant]
3GPP TS 29.509 V17.0.0 (Dec. 2020), 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Authentication Server Services; Stage 3 (Release 17), 61 pages. [cited by applicant]
3GPP TS 33.501 V15.11.0 (Dec. 2020), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15), 193 pages. [cited by applicant]
3GPP TS 33.535 V17.0.0 (Dec. 2020), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in t… [cited by applicant]
Dekok, A. et al., “The Network Access Identifier”, Internet Engineering Task Force (IETF), Request for Comments 7542, May 2015, 30 pages. [cited by applicant]