IP Library › Granted Patent US 12,659,739
Granted Patent B2
US 12,659,739 · App. 18/681,943 · Granted Jun 16, 2026

Secure channel establishing method and apparatus, and related device and storage medium

Inventor: Xiaoting Huang (Beijing, CN)
Assignees: CHINA MOBILE COMMUNICATION CO., LTD RESEARCH INSTITUTE; CHINA MOBILE COMMUNICATIONS GROUP CO., LTD.
H04W12/06H04W12/041H04W12/0431H04W12/0433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,739
App. No.
18/681,943
Granted
Jun 16, 2026
Kind
B2
Abstract

Disclosed in the present application are a secure channel establishing method and apparatus, and an MSGin5G UE, an MSGin5G server and a storage medium. The method comprises: an MSGin5G UE generating a first key on the basis of an authentication and key management for application (AKMA) service; and on the basis of the first key, establishing a secure channel between the MSGin5G UE and an MSGin5G server.

Claims (42)

1 . A method for secure channel establishment, applied to a fifth generation message (MSGin5G) user equipment (UE), the method comprising:

generating a first key based on an authentication and key management for application (AKMA) service; and

establishing a secure channel between the MSGin5G UE and an MSGin5G server based on the first key;

wherein establishing the secure channel between the MSGin5G UE and the MSGin5G server based on the first key comprises:

generating a third key based on the first key, and sending a client key exchange message comprising a first identity (ID) to the MSGin5G server, wherein the third key is a premaster key; and

establishing a transport layer security (TLS) secure channel between the MSGin5G UE and the MSGin5G server using the third key.

2 . The method of claim 1 , further comprising: before generating the first key based on the AKMA service,

performing primary authentication between the MSGin5G UE and a core network.

3 . The method of claim 1 , wherein generating the first key based on the AKMA service comprises:

sending a session establishment request to the MSGin5G server, the session establishment request comprising at least the first ID; and

generating the first key using a second key identified by the first ID, the second key and the first ID being generated based on the AKMA service.

4 . The method of claim 3 , wherein generation of the first key using the second key identified by the first ID is performed before or after sending the session establishment request to the MSGin5G server.

5 . The method of claim 3 , further comprising:

receiving a session establishment response sent by the MSGin5G server,

wherein generation of the first key is performed before or after receiving the session establishment response.

6 . A method for secure channel establishment, applied to a fifth generation message (MSGin5G) server, the method comprising:

acquiring a first key based on an authentication and key management for application (AKMA) service; and

establishing a secure channel between the MSGin5G server and an MSGin5G user equipment (UE) based on the first key;

wherein establishing the secure channel between the MSGin5G server and the MSGin5G UE based on the first key comprises:

receiving a client key exchange message sent by the MSGin5G UE, the client key exchange message comprising a first identity (ID); and

acquiring the first key according to the first ID, generating a third key using the first key, and establishing a transport layer security (TLS) secure channel between the MSGin5G server and the MSGin5G UE using the third key, wherein the third key is a premaster key.

7 . The method of claim 6 , wherein acquiring the first key based on the AKMA service comprises:

receiving a session establishment request sent by the MSGin5G UE, the session establishment request comprising at least the first ID;

sending a key request to a core network, the key request comprising at least the first ID; and

receiving first information sent by the core network, the first information comprising at least the first key, the first key being generated based on a second key identified by the first ID, the second key and the first ID being generated based on the AKMA service.

8 . The method of claim 7 , wherein first information further comprises a cycle of the first key.

9 . A fifth generation message (MSGin5G) user equipment (UE), comprising a first communication interface and a first processor,

wherein the first processor is configured to:

generate a first key based on an authentication and key management for application (AKMA) service; and

establish a secure channel between the MSGin5G UE and an MSGin5G server based on the first key;

wherein the first processor is further configured to:

generate a third key based on the first key, and send a client key exchange message comprising a first identity (ID) to the MSGin5G server through the first communication interface, wherein the third key is a premaster key; and

establish a transport layer security (TLS) secure channel between the MSGin5G UE and the MSGin5G server using the third key.

10 . The MSGin5G UE of claim 9 , wherein the first processor is configured to: before generating the first key based on the AKMA service,

perform primary authentication between the MSGin5G UE and a core network.

11 . The MSGin5G UE of claim 9 , wherein the first processor is configured to:

send a session establishment request to the MSGin5G server through the first communication interface, the session establishment request comprising at least the first ID; and

generate the first key using a second key identified by the first ID, the second key and the first ID being generated based on the AKMA service.

12 . The MSGin5G UE of claim 11 , wherein generation of the first key using the second key identified by the first ID is performed before or after sending the session establishment request to the MSGin5G server.

13 . The MSGin5G UE of claim 11 , wherein the first processor is configured to:

receive a session establishment response sent by the MSGin5G server through the first communication interface,

wherein generation of the first key is performed before or after receiving the session establishment response.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2024
From: HUANG, XIAOTING
To: CHINA MOBILE COMMUNICATION CO., LTD RESEARCH INSTITUTE; CHINA MOBILE COMMUNICATIONS GROUP CO., LTD.
Reel/Frame 067054/0701 →
Priority Claims (1)
CN 202110910311.1 · Aug 9, 2021 · national
Continuity (1)
Related Publication 20240349049A1 · Oct 17, 2024
References Cited (26)
US 20030018886A1 · Kuehr-McLaren · 2003 [cited by applicant]
US 20140289826A1 · Croome · 2014 [cited by applicant]
US 20190223009A1 · Salmela · 2019 [cited by examiner]
US 20210058780A1 · Yu · 2021 [cited by applicant]
US 20210165885A1 · Zhang · 2021 [cited by examiner]
US 20220264292A1 · Yu · 2022 [cited by applicant]
US 20230070253A1 · Rajadurai · 2023 [cited by examiner]
US 20240314561A1 · Rohini · 2024 [cited by examiner]
CN 112512043A · 2021 [cited by applicant]
CN 113163399A · 2021 [cited by applicant]
JP 2008099245A · 2008 [cited by applicant]
WO 2021093162A1 · 2021 [cited by applicant]
3GPP TR 33.862 V0.5.0 May 2021 (Year: 2021). [cited by examiner]
Supplementary European Search Report in the European application No. 22855401.0, mailed on Oct. 14, 2024. 10 pages. [cited by applicant]
3GPP TR 33.862 vo.5.0 (May 2021), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of the Message Service for MIoT over the 5G System (MSGin5G)”, … [cited by applicant]
SA3: “Security aspects of the 5GMSG Service”, 3GPP Draft; SP-210835, 3rd Generation Partnership Project (3GPP), Mobile Competence Centre;650, Route Des Lucioles ; F-06921 Sophia-Antipolis Cedex; France vol. TSG SA, No. … [cited by applicant]
“5G; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS) (3GPP TS 33.535 version 16.2.0 Release 16)”, ETSI Technical Specification, European Telecommunications Stan… [cited by applicant]
One2many et al: “Pseudo-CR on Message Aggregation”, 3GPP Draft; S6-210386, 3rd Generation Partnership Project (3GPP), Mobile Competence Centre; 650, Route Des Lucioles; F-06921 Sophia-Antipolis Cedex; France vol. Sa WG6… [cited by applicant]
China Mobile, “Solution to provisioning of PNI-NPN credentials”, 3GPP TSG-SA3 Meeting #102-e S3-210318, e-meeting, Jan. 18-29, 2021, section 6.X.2. 3 pages. [cited by applicant]
International Search Report in the international application No. PCT/CN2022/110922, mailed on Sep. 27, 2022. 2 pages. [cited by applicant]
English translation of the Written Opinion of the International Search Authority in the international application No. PCT/CN2022/110922, mailed on Sep. 27, 2022. 5 pages. [cited by applicant]
3GPP TS 33.535 V17.2.1 (Jun. 2021), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in t… [cited by applicant]
3GPP TS 33.501 V17.5.0 (Jun. 2021), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17), section Annex Y, pp. 28… [cited by applicant]
3GPP TS 23.554 V19.5.0 (Mar. 2025), 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Application architecture for MSGin5G Service; Stage 2 (Release 19), section 8.7. [cited by applicant]
3GPP TS 22.262 V18.0.1 (Mar. 2024), 3rd Generation Partnership; Technical Specification Group Services and System Aspects; Message Service within the 5G System; Stage 1 (Release 18), pp. 1-11. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and key management for applications; based on 3GPP credential in 5G (AKMA) (Release 16)”, 3GPP TS 33.535 V0.… [cited by applicant]