IP Library › Granted Patent US 12,273,445
Granted Patent B2
US 12,273,445 · App. 18/050,977 · Granted Apr 8, 2025

Key management method, device, and system

Inventors: Longhua Guo (Shanghai, CN); He Li (Shanghai, CN); Rong Wu (Shenzhen, CN); Yizhuang Wu (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L9/0866H04L9/0825H04L9/14H04L67/141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,445
App. No.
18/050,977
Granted
Apr 8, 2025
Kind
B2
Abstract

This application provides a key management method, a device, and a system. The method includes: A terminal device sends a first application session establishment request message to a first application function network element, where the establishment request message carries identification information of a first key, and the first key is an authentication and key management for applications AKMA key. The terminal device receives a first authentication request message in a procedure of the re-authentication. The terminal device sends a response message for the first authentication request message in the procedure of the re-authentication. The terminal device receives a response message for the establishment request message. The terminal device derives a communication key between the terminal device and the first application function network element by using the first key.

Claims (77)

1. A key management method performed an apparatus which is a terminal device or a component of the terminal device, comprising:

generating a first authentication and key management for applications (AKMA) key and a first identifier identifying the first AKMA key;

sending a first application session establishment request message to an application function network element, wherein the first application session establishment request message comprises the first identifier identifying the first AKMA key;

performing a re-authentication procedure to obtain a second AKMA key and a second identifier identifying the second AKMA key;

receiving a first application session establishment response message for the first application session establishment request message from the application function network element, wherein the first application session establishment response message indicates a failure of an application session establishment requested by the first application session establishment request; and

sending based on the first application session establishment response message, a second application session establishment request message to the application function network element, wherein the second application session establishment request message comprises the second identifier identifying the second AKMA key.

2. The method according to claim 1 , wherein the re-authentication procedure comprises:

receiving a non-access stratum (NAS) message authentication request that comprises a first authentication parameter;

checking the first authentication parameter;

calculating a second authentication parameter; and

sending a NAS message authentication response with the second authentication parameter.

3. The method according to claim 1 , wherein the re-authentication procedure is performed after sending the first application session establishment request message.

4. The method according to claim 1 , further comprising:

generating a communication key based on the second AKMA key and an identifier of the application function network element, wherein the communication key is used between the application function network element and the apparatus.

5. The method according to claim 1 , wherein the re-authentication procedure is performed due to a non-access stratum (NAS) COUNT is about to wrap around.

6. The method according to claim 1 , after the performing the re-authentication procedure, the method further comprising:

deleting the first AKMA key and the first identifier that are stored locally; and

storing the second AKMA key and the second identifier identifying the second AKMA key.

7. A key management method, comprising:

receiving, by an application function network element, a first application session establishment request message from a terminal device, wherein the first application session establishment request message comprises a first identifier identifying a first authentication and key management for applications (AKMA) key;

sending, by the application function network element in response to the first application session establishment request message, a first request message to an AKMA anchor function network element to request a communication key between the terminal device and the application function network element, wherein the first request message comprises the first identifier identifying the first AKMA key and an identifier of the application function network element;

receiving, by the application function network element after sending the first request message, a first response message with a second failure indication from the AKMA anchor function network element;

sending, by the application function network element, an application session establishment response message for the first application session establishment request message to the terminal device based on the second failure indication, wherein the application session establishment response message indicates a failure of an application session establishment requested by the first application session establishment request;

receiving, by the application function network element, a second application session establishment request message from the terminal device, wherein the second application session establishment request message comprises a second identifier identifying a second AKMA key;

sending, by the application function network element in response to the second application session establishment request message, a second request message to the AKMA anchor function network element to request the communication key, wherein the second request message comprises the second identifier identifying the second AKMA key and the identifier of the application function network element; and

receiving, by the application function network element after sending the second request message, a second response message with the communication key from the AKMA anchor function network element, wherein the communication key is related to the second identifier identifying the second AKMA key.

8. The method according to claim 7 , further comprising:

receiving, by the AKMA anchor function network element from an authentication server function, the second AKMA key and the second identifier identifying the second AKMA key;

deleting, by the AKMA anchor function network element, the first AKMA key and the first identifier that are stored locally; and

storing, by the AKMA anchor function network element, the second AKMA key and the second identifier identifying the second AKMA key.

9. The method according to claim 8 , further comprising:

in response to determining that there is no key corresponding to the first identifier, sending, by the AKMA anchor function network element, the first response message with the second failure indication to the application function network element, wherein the second failure indication indicates a failure for requesting the communication key.

10. An apparatus, comprising a processor coupled with a non-transitory memory storing instructions which, when executed by the processor, cause the apparatus to:

generate a first authentication and key management for applications (AKMA) key and a first identifier identifying the first AKMA key;

send a first application session establishment request message to an application function network element, wherein the first application session establishment request message comprises the first identifier identifying the first AKMA key;

perform a re-authentication procedure to obtain a second AKMA key and a second identifier identifying the second AKMA key;

receive an application session establishment response message for the first application session establishment request message from the application function network element, wherein the application session establishment response message indicates a failure of an application session establishment requested by the first application session establishment request; and

send a second application session establishment request message to the application function network element, wherein the second application session establishment request message comprises the second identifier identifying the second AKMA key.

11. The apparatus according to claim 10 , wherein the re-authentication procedure comprises:

receiving a non-access stratum (NAS) message authentication request that comprises a first authentication parameter;

checking the first authentication parameter;

calculating a second authentication parameter; and

sending a NAS message authentication response with the second authentication parameter.

12. The apparatus according to claim 10 , wherein the re-authentication procedure is performed after sending the first application session establishment request message.

13. The apparatus according to claim 10 , wherein the instructions, when executed by the processor, further cause the apparatus to:

generate a communication key based on the second AKMA key and an identifier of the application function network element, wherein the communication key is used between the application function network element and the apparatus.

14. The apparatus according to claim 10 , wherein the re-authentication procedure is performed due to a non-access stratum (NAS) COUNT is about to wrap around.

15. The apparatus according to claim 10 , wherein the instructions, when executed by the processor, further cause the apparatus to:

delete the first AKMA key and the first identifier that are stored locally; and

store the second AKMA key and the second identifier identifying the second AKMA key.

16. An apparatus, comprising a processor coupled with a non-transitory memory storing instructions that, when executed by the processor, cause the apparatus to:

receive a first application session establishment request message from a terminal device, wherein the first application session establishment request message comprises a first identifier identifying a first authentication and key management for applications (AKMA) key;

send, in response to the first application session establishment request message, a first request message to an AKMA anchor function network element to request a communication key between the terminal device and the application function network element, wherein the first request message comprises the first identifier identifying the first AKMA key and an identifier of the application function network element;

receive, after sending the first request message, a first response message with a second failure indication from the AKMA anchor function network element;

send an application session establishment response message for the first application session establishment request message to the terminal device based on the second failure indication, wherein the application session establishment response message indicates a failure of an application session establishment requested by the first application session establishment request;

receive a second application session establishment request message from the terminal device, wherein the second application session establishment request message comprises a second identifier identifying a second AKMA key;

send, in response to the second application session establishment request message, a second request message to the AKMA anchor function network element to request the communication key, wherein the second request message comprises the second identifier identifying the first AKMA key and the identifier of the application function network element; and

receive, after sending the second request message, a second response message with the communication key from the AKMA anchor function network element, wherein the communication key is related to the second identifier identifying the second AKMA key.

17. A system, comprising an application function network element and an authentication and key management for applications (AKMA) anchor function network element,

wherein the application function network element comprises a processor and is configured to:

receive a first application session establishment request message from a terminal device, wherein the first application session establishment request message comprises a first identifier identifying a first AKMA key;

send, in response to the first application session establishment request message, a first request message to the AKMA anchor function network element to request a communication key between the terminal device and the application function network element, wherein the first request message comprises the first identifier identifying the first AKMA key and an identifier of the application function network element;

receive, after sending the first request message, a first response message with a second failure indication from the AKMA anchor function network element;

send an application session establishment response message for the first application session establishment request message to the terminal device based on the second failure indication, wherein the application session establishment response message indicates a failure of an application session establishment requested by the first application session establishment request;

receive a second application session establishment request message from the terminal device, wherein the second application session establishment request message comprises a second identifier identifying a second AKMA key; and

send, in response to the second application session establishment request message, a second request message to the AKMA anchor function network element to request the communication key, wherein the second request message comprises the second identifier identifying the second AKMA key and the identifier of the application function network element; and

wherein the AKMA anchor function network element comprises a processor and is configured to:

receive the first request message from the application function network element; and

in response to determining that there is no key corresponding to the first identifier, send the first response message to the application function network element.

18. The system according to claim 17 , wherein the AKMA anchor function network element is further configured to:

determine the communication key using the second AKMA key and the identifier of the application function network element; and

send a second response message with the communication key to the application function network element.

19. The system according to claim 17 , wherein the AKMA anchor function network element is further configured to:

receive, from an authentication server function, the second AKMA key and the second identifier identifying the second AKMA key;

delete the first AKMA key and the first identifier that are stored locally; and

store the second AKMA key and the second identifier identifying the second AKMA key.

20. The system according to claim 19 , wherein the first AKMA key and the first identifier stored locally are received from the authentication server function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2023
From: GUO, LONGHUA; LI, HE; WU, RONG; WU, YIZHUANG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 062739/0227 →
Priority Claims (1)
CN 202010368028.6 · Apr 30, 2020 · national
Continuity (2)
Continuation PCTCN2021090348 · Apr 27, 2021
Related Publication 20230086032A1 · Mar 23, 2023
References Cited (18)
US 20130014231A1 · Chu et al. · 2013 [cited by applicant]
CN 101079705A · 2007 [cited by applicant]
CN 102014381B · 2012 [cited by applicant]
CN 107005842A · 2017 [cited by applicant]
CN 110022206A · 2019 [cited by applicant]
EP 2207301A1 · 2010 [cited by applicant]
EP 3531732B1 · 2023 [cited by examiner]
WO WO2018201398A1 · 2018 [cited by examiner]
ETSI, “Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS) (3GPP TS 33.535 version 16.2.0 Release 16)”, Jan. 2021, pp. 1-21 (Year: 2021). [cited by examiner]
3GPP TSG-SA WG3 Meeting #95Bis,S3-192000,Solution 2 evaluation,Ericsson,Sapporo(Japan), Jun. 24-28, 2019, total 4 pages. [cited by applicant]
Huawei Hisilicon, “Add details on deleting Kakma”, 3GPP TSG-SA3 Meeting #98e S3-200258,Feb. 21, 2020,total 3 pages. [cited by applicant]
3GPP TS 33.535 V0.4.0 :“3rd Generation Partnership Project;Technical Specification Group Services and System Aspects;Authentication and key management for applications; based on 3GPP credential in 5G AKMA (Release 16)”,… [cited by applicant]
Nokia Nokia Shanghai Bell China Mobile, “Implicit bootstrapping using NEF as the AKMA Anchor Function”, 3GPP TSG-SA WG3 Meeting #95 Bis S3-192220, Jun. 17, 2019,total 4 pages. [cited by applicant]
3GPP TS 33.501 V16.2.0 (Mar. 2020), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system(Release 16), 227 pages. [cited by applicant]
Ericsson, “Solution Key lifetimes”, 3GPP TSG-SA WG3 Meeting #96 Ad-hoc S3-193595, Oct. 7, 2019,total 3 pages. [cited by applicant]
NEC Intel, “Solution to support Fast Re-authentication in 5GS”, 3GPP TSG-SA WG3 Meeting #94Ad-Hoc S3-190634, Mar. 4, 2019,total 3 pages. [cited by applicant]
3GPP TR 33.835 V16.0.0 (Dec. 2019), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on authentication and key management for applications based on 3GPP credential in … [cited by applicant]
ZTE Corporation, Processing of KAKMA failure from AUSF to AAnF. 3GPP TSG-SA3 Meeting #98bis-e, e-meeting, Apr. 14-17, 2020, S3-200676, 1 page. [cited by applicant]