IP Library › Granted Patent US 12,445,837
Granted Patent B2
US 12,445,837 · App. 18/309,567 · Granted Oct 14, 2025

Key obtaining method and communication apparatus

Inventor: Yizhuang Wu (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/0431H04W12/041H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,837
App. No.
18/309,567
Granted
Oct 14, 2025
Kind
B2
Abstract

This application discloses a key obtaining method and a communication apparatus. A remote terminal device sends a first identifier and a relay service code to a relay terminal device. The first identifier is an identifier that is of the remote terminal device and that is corresponding to the relay service code, or the first identifier is an anonymous identifier of the remote terminal device. The remote terminal device generates, based on a first shared key, the relay service code, and at least one first freshness parameter, a root key for communication between the remote terminal device and the relay terminal device. A remote authentication service function network element is an authentication service function network element that serves the remote terminal device, and the first shared key is a key shared between the remote terminal device and the remote authentication service function network element.

Claims (81)

1. A key obtaining method, comprising:

sending, by a communication apparatus, a first identifier and a relay service code to a relay terminal device, wherein the first identifier is an anonymous identifier of a remote terminal device; and

generating, by the communication apparatus, a root key for communication between the remote terminal device and the relay terminal device based on a first shared key, the relay service code, and at least one first freshness parameter, wherein the first shared key is a key shared between the remote terminal device and a remote authentication service function network element, wherein the remote authentication service function network element is an authentication service function network element that serves the remote terminal device;

wherein the generating the root key for communication between the remote terminal device and the relay terminal device comprises:

generating, by the communication apparatus, a second shared key based on the first shared key and the relay service code; and

generating, by the communication apparatus, the root key based on the second shared key and the at least one first freshness parameter, wherein the second shared key is a key shared between the remote terminal device and a proximity-based services key management function network element, wherein the proximity-based services key management function network element is a network element configured to manage security information of proximity-based services.

2. The method according to claim 1 , wherein the first identifier is a subscription concealed identifier (SUCI) of the remote terminal device.

3. The method according to claim 1 , wherein the at least one first freshness parameter comprises a first random number, and the method further comprises:

sending, by the communication apparatus, the first random number to the relay terminal device.

4. The method according to claim 1 , wherein the at least one first freshness parameter comprises a second random number, and the method further comprises:

receiving, by the communication apparatus, the second random number from the relay terminal device.

5. The method according to claim 1 , wherein the first shared key is a key negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses a network.

6. The method according to claim 1 , wherein the communication apparatus is the remote terminal device, or an apparatus including the remote terminal device, or a chip in the remote terminal device, or a functional component in the remote terminal device.

7. A key obtaining method, comprising:

obtaining, by a communication apparatus, a relay service code and a second identifier of a remote terminal device, wherein the second identifier is a permanent identifier of the remote terminal device;

obtaining, by the communication apparatus, a first shared key corresponding to the second identifier, wherein the first shared key is a key shared between the remote terminal device and a remote authentication service function network element, wherein the remote authentication service function network element is an authentication service function network element that serves the remote terminal device;

generating, by the communication apparatus, a root key for communication between the remote terminal device and a relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter; and

sending, by the communication apparatus, the root key;

wherein the generating the root key for communication between the remote terminal device and the relay terminal device comprises:

generating, by the communication apparatus, a second shared key based on the first shared key and the relay service code; and

generating, by the communication apparatus, the root key based on the second shared key and the at least one first freshness parameter, wherein the second shared key is a key shared between the remote terminal device and a proximity-based services key management function network element, wherein the proximity-based services key management function network element is a network element configured to manage security information of proximity-based services.

8. The method according to claim 7 , further comprising:

sending, by the communication apparatus, the second shared key to the proximity-based services key management function network element.

9. The method according to claim 8 , further comprising:

receiving, by the proximity-based services key management function network element, the second shared key from the communication apparatus.

10. The method according to claim 8 , further comprising:

receiving, by the proximity-based services key management function network element, the second shared key.

11. The method according to claim 7 , wherein the sending, by the communication apparatus, the root key comprises:

sending, by the communication apparatus, the root key to the relay terminal device.

12. The method according to claim 7 , wherein the at least one first freshness parameter comprises a first random number, and the method further comprises:

receiving, by the communication apparatus, the first random number.

13. The method according to claim 7 , wherein the at least one first freshness parameter comprises a second random number, and the method further comprises:

sending, by the communication apparatus, the second random number.

14. The method according to claim 7 , wherein the first shared key is a key negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses a network.

15. The method according to claim 7 , wherein the communication apparatus is the remote authentication service function network element, or an apparatus including the remote authentication service function network element, or a chip in the remote authentication service function network element, or a functional component in the remote authentication service function network element.

16. A communication apparatus, comprising:

a processor, wherein the processor is coupled to a memory storing a computer program, and the processor is configured to execute the computer program to enable the communication apparatus to perform operations comprising:

sending a first identifier and a relay service code to a relay terminal device, wherein the first identifier is an anonymous identifier of a remote terminal device; and

generating a root key for communication between the remote terminal device and the relay terminal device based on a first shared key, the relay service code, and at least one first freshness parameter, wherein the first shared key is a key shared between the remote terminal device and a remote authentication service function network element, wherein remote authentication service function network element is an authentication service function network element that serves the remote terminal device;

wherein the generating the root key for communication between the remote terminal device and the relay terminal device comprises:

generating a second shared key based on the first shared key and the relay service code; and

generating the root key based on the second shared key and the at least one first freshness parameter, wherein the second shared key is a key shared between the remote terminal device and a proximity-based services key management function network element, wherein the proximity-based services key management function network element is a network element configured to manage security information of proximity-based services.

17. The communication apparatus according to claim 16 , wherein the first identifier is a subscription concealed identifier (SUCI) of the remote terminal device.

18. The communication apparatus according to claim 16 , wherein the at least one first freshness parameter comprises a first random number, and the operations further comprise:

sending the first random number to the relay terminal device.

19. The communication apparatus according to claim 16 , wherein the at least one first freshness parameter comprises a second random number, and the operations further comprise:

receiving the second random number from the relay terminal device.

20. The communication apparatus according to claim 16 , wherein the first shared key is a key negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses a network.

21. The communication apparatus according to claim 16 , wherein the communication apparatus is the remote terminal device, or an apparatus including the remote terminal device, or a chip in the remote terminal device, or a functional component in the remote terminal device.

22. A communication apparatus, comprising:

a processor, wherein the processor is coupled to a memory storing a computer program, and the processor is configured to execute the computer program to enable the communication apparatus to perform operations comprising:

obtaining a relay service code and a second identifier of a remote terminal device, wherein the second identifier is a permanent identifier of the remote terminal device;

obtaining a first shared key corresponding to the second identifier, wherein the first shared key is a key shared between the remote terminal device and a remote authentication service function network element, wherein the remote authentication service function network element is an authentication service function network element that serves the remote terminal device;

generating a root key for communication between the remote terminal device and a relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter; and

sending the root key;

wherein the generating the root key for communication between the remote terminal device and the relay terminal device comprises:

generating a second shared key based on the first shared key and the relay service code; and

generating the root key based on the second shared key and the at least one first freshness parameter, wherein the second shared key is a key shared between the remote terminal device and a proximity-based services key management function network element, wherein the proximity-based services key management function network element is a network element configured to manage security information of proximity-based services.

23. The communication apparatus according to claim 22 , wherein the operations further comprise:

sending the second shared key to the proximity-based services key management function network element.

24. The communication apparatus according to claim 22 , wherein the sending the root key comprises:

sending the root key to the relay terminal device.

25. The communication apparatus according to claim 22 , wherein the at least one first freshness parameter comprises a first random number, and the operations further comprise:

receiving the first random number.

26. The communication apparatus according to claim 22 , wherein the at least one first freshness parameter comprises a second random number, and the operations further comprise:

sending the second random number.

27. The communication apparatus according to claim 22 , wherein the first shared key is a key negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses a network.

28. The communication apparatus according to claim 22 , wherein the communication apparatus is the remote authentication service function network element, or an apparatus including the remote authentication service function network element, or a chip in the remote authentication service function network element, or a functional component in the remote authentication service function network element.

29. A system, comprising:

a remote authentication service function network element, wherein the remote authentication service function network element is an authentication service function network element that serves a remote terminal device; and

a proximity-based services key management function network element, wherein the proximity-based services key management function network element is a network element configured to manage security information of proximity-based services;

wherein the remote authentication service function network element includes a processor configured to:

obtain a relay service code and a second identifier of the remote terminal device, wherein the second identifier is a permanent identifier of the remote terminal device;

obtain a first shared key corresponding to the second identifier, wherein the first shared key is a key shared between the remote terminal device and a remote authentication service function network element;

generate a root key for communication between the remote terminal device and a relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter, wherein the generating the root key for communication between the remote terminal device and the relay terminal device comprises:

generating a second shared key based on the first shared key and the relay service code; and

generating the root key based on the second shared key and the at least one first freshness parameter, wherein the second shared key is a key shared between the remote terminal device and the proximity-based services key management function network element;

send the root key; and

send the second shared key to the proximity-based services key management function network element; and

wherein the proximity-based services key management function network element includes a processor configured to:

receive the second shared key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: WU, YIZHUANG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 071697/0609 →
Continuity (2)
Continuation PCTCN2020125224 · Oct 30, 2020
Related Publication 20230319556A1 · Oct 5, 2023
References Cited (13)
US 11743722B2 · Ben Henda · 2023 [cited by examiner]
US 20190223063A1 · Palanigounder et al. · 2019 [cited by applicant]
US 20190335332A1 · Ying et al. · 2019 [cited by applicant]
US 20220109996A1 · Lee · 2022 [cited by examiner]
CN 109842880A · 2019 [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security Aspects of enhancement for proximity based services in the 5G System (5GS)(Release 17), 3GPP TR 33.847 V0.… [cited by examiner]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on system enhancement for Proximity based Services (ProSe) in the 5G System (5GS)(Release 17),” 3GPP TR 23.752 V0.5.1… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 3GPP System Architecture Evolution (SAE); Security architecture (Release 16),” 3GPP TS 33.401 V16.3.0, Total 170 pages, 3rd… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15),” 3GPP TS 33.501 V15.10.0, Total 192 pages, 3rd Generation … [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security aspects of 3GPP support for advanced Vehicle-to-Everything (V2X) services (Release 16),” 3GPP TS 33.536 V16.1.0, T… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enhancement for proximity based services in the 5G System (5GS)(Release 17),” 3GPP TR 33.847 V… [cited by applicant]
A.Dekok et al., “The Network Access Identifier,” Request for Comments: 7542, Total 30 pages, Internet Engineering Task Force, Reston, Virginia (May 2015). [cited by applicant]
Samsung, “Solution for key management in 5G ProSerelay communication,” 3GPP TSG-SA3 Meeting #100e, e-meeting, S3-201961, Total 4 pages, 3rd Generation Partnership Project, Valbonne, France (Aug. 17-28, 2020). [cited by applicant]