Application-specific GPSI retrieval
A method for a user equipment (UE) configured to communicate with an application function (AF) via a communication network is provided. The method comprises sending, to the AF, an application service request including: a second identifier (GPSI) specific to one or more applications, including an application associated with the UE and the AF; and information (app-info) associated with the second identifier and descriptive of the one or more applications. The method further comprises authenticating the AF based on an application-specific key (KAF) derived from a security key (KAKMA) associated with the UE; and receiving, from the AF, an application service response indicating whether the second identifier (GPSI) matches a corresponding second identifier (GPSI*) derived from the information associated with the second identifier.
1 . A method for a user equipment (UE) configured to communicate with an application function (AF) via a communication network, the method comprising:
sending, to the AF, an application service request including:
a second identifier (GPSI) of the UE that is specific to one or more applications, including an application associated with the UE and the AF; and
information (app-info) associated with the second identifier and descriptive of the one or more applications;
authenticating the AF based on an application-specific key (K AF ) derived from a security key (K AKMA ) associated with the UE; and
receiving, from the AF, an application service response indicating whether the second identifier (GPSI) matches a corresponding second identifier (GPSI*) of the UE that is derived from the information associated with the second identifier.
2 . The method of claim 1 , wherein the application service request also includes a first identifier (A-KID) of the security key (K AKMA ) associated with the UE.
3 . The method of claim 1 , further comprising:
receiving a security challenge from the AF in response to the application service request; and
sending, to the AF in response to the security challenge, a first identifier (A-KID) of the security key (K AKMA ) associated with the UE.
4 . The method of claim 1 , wherein:
the AF comprises one or more of the following servers in an Edge Data Network (EDN) coupled to the communication network: Edge Enabler Server (EES), Edge Application Server (EAS), Edge Configuration Server (ECS); and
the method is performed by a user client, of the UE, that is configured to communicate with the one or more servers comprising the AF.
5 . A method for an application function (AF) associated with a communication network, the method comprising:
receiving, from a user equipment (UE), an application service request including:
a second identifier (GPSI) of the UE that is specific to one or more applications, including an application associated with the UE and the AF; and
information (app-info) associated with the second identifier and descriptive of the one or more applications;
sending, to a network function (NF) of the communication network, a request for a corresponding second identifier (GPSI*) of the UE that is specific to the application associated with the UE and with the AF, wherein the request includes the received information descriptive of the one or more applications; and
receiving the corresponding second identifier from the NF.
6 . The method of claim 5 , wherein:
the request for the corresponding second identifier comprises an AKMA request message that also includes a first identifier (A-KID) of a security key (K AKMA ) associated with the UE; and
the corresponding second identifier (GPSI*) is received from the NF, in response to the AKMA request message, together with an application-specific key (K AF ) associated with the UE and the AF.
7 . The method of claim 6 , further comprising:
authenticating the UE based on the application-specific key (K AF );
determining whether the second identifier (GPSI) received in the application service request from the UE matches the corresponding second identifier (GPSI*) received from the NF; and
sending, to the UE, an application service response indicating whether the second identifier (GPSI) matches the corresponding second identifier (GPSI*).
8 . The method of claim 5 , wherein the application service request also includes a first identifier (A-KID) of a security key (K AKMA ) associated with the UE.
9 . The method of claim 5 , further comprising:
sending a security challenge to the UE in response to the application service request; and
receiving, from the UE in response to the security challenge, a first identifier (A-KID) of a security key (K AKMA ) associated with the UE.
10 . The method of claim 5 , further comprising communicating with a user client of the UE based on the received corresponding second identifier (GPSI*).
11 . The method of claim 5 , wherein:
the AF comprises one or more of the following servers in an Edge Data Network (EDN) coupled to the communication network: Edge Enabler Server (EES), Edge Application Server (EAS), Edge Configuration Server (ECS); and
the one or more servers comprising the AF are configured to communicate with a user client of the UE.
12 . A method for a network function (NF) of a communication network, the method comprising:
receiving, from an application function (AF) associated with the communication network, a request for a corresponding second identifier (GPSI*) of a user equipment (UE) that is specific to an application associated with the UE and with the AF, wherein the request includes information (app-info) descriptive of one or more applications, including the application associated with the UE and with the AF, and
obtaining the corresponding second identifier (GPSI*) based on the information descriptive of the one or more applications; and
sending the corresponding second identifier (GPSI*) to the AF.
13 . The method of claim 12 , wherein obtaining the corresponding second identifier (GPSI*) comprises the following operations:
obtaining a subscription permanent identifier (SUPI) associated with the UE;
sending the SUPI to a unified data management (UDM) function of the communication network; and
receiving the corresponding second identifier (GPSI*) from the UDM.
14 . The method of claim 13 , wherein the SUPI is sent to the UDM together with the information descriptive of the one or more applications.
15 . The method of claim 13 , wherein:
the corresponding second identifier (GPSI*) is one of a plurality of identifiers received from the UDM together with associated descriptive information; and
the method further comprises selecting the corresponding second identifier (GPSI*) from the plurality of identifiers based on a match between the information descriptive of the one or more applications and an entry in the associated descriptive information.
16 . The method of claim 12 , wherein obtaining the corresponding second identifier (GPSI*) comprises retrieving the corresponding second identifier (GPSI*) from local storage.
17 . The method of claim 12 , wherein:
the request for the corresponding second identifier comprises an AKMA request message that also includes a first identifier (A-KID) of a security key (K AKMA ) associated with the UE; and
the method further comprises:
deriving the application-specific key (K AF ) based on the first identifier, and
determining whether the AF is authorized to obtain the corresponding second identifier (GPSI*) based on the information descriptive of the one or more applications.
18 . The method of claim 17 , wherein the corresponding second identifier (GPSI*) is sent to the AF in an AKMA response message together with an application-specific key (K AF ) associated with the UE and the AF, based on a determination that the AF is authorized.
19 . The method of claim 13 , wherein:
the request for the corresponding second identifier comprises a translation request that also includes a UE Internet Protocol (IP) address for a connection between the UE and the AF; and
the subscription permanent identifier (SUPI) is obtained based on the UE IP address.
20 . The method of claim 12 , wherein:
the NF is a network exposure function (NF) or an anchor function for authentication and key management for applications (AAnF); and
the AF comprises one or more of the following servers in an Edge Data Network (EDN) coupled to the communication network: Edge Enabler Server (EES), Edge Application Server (EAS), and Edge Configuration Server (ECS).
21 . A network function (NF) of a communication network, comprising:
processing circuitry, memory and transceiver circuitry collectively configured to perform operations comprising:
receiving, from an application function (AF) associated with the communication network, a request for a corresponding second identifier (GPSI*) of a user equipment (UE) that is specific to an application associated with the UE and with the AF, wherein the request includes information (app-info) descriptive of one or more applications, including the application associated with the UE and with the AF, and
obtaining the corresponding second identifier (GPSI*) based on the information descriptive of the one or more applications; and
sending the corresponding second identifier (GPSI*) to the AF.
22 . The NF of claim 21 , wherein obtaining the corresponding second identifier (GPSI*) comprises the following operations:
obtaining a subscription permanent identifier (SUPI) associated with the UE;
sending the SUPI to a unified data management (UDM) function of the communication network; and
receiving the corresponding second identifier (GPSI*) from the UDM.
23 . The NF of claim 22 , wherein the SUPI is sent to the UDM together with the information descriptive of the one or more applications.
24 . The NF of claim 22 , wherein:
the corresponding second identifier (GPSI*) is one of a plurality of identifiers received from the UDM together with associated descriptive information; and
the method further comprises selecting the corresponding second identifier (GPSI*) from the plurality of identifiers based on a match between the information descriptive of the one or more applications and an entry in the associated descriptive information.
25 . The NF of claim 21 , wherein obtaining the corresponding second identifier (GPSI*) comprises retrieving the corresponding second identifier (GPSI*) from local storage.
26 . The NF of claim 21 , wherein:
the request for the corresponding second identifier comprises an AKMA request message that also includes a first identifier (A-KID) of a security key (K AKMA ) associated with the UE; and
the operations further comprise:
deriving the application-specific key (K AF ) based on the first identifier, and
determining whether the AF is authorized to obtain the corresponding second identifier (GPSI*) based on the information descriptive of the one or more applications.
27 . The NF of claim 26 , wherein the corresponding second identifier (GPSI*) is sent to the AF in an AKMA response message together with an application-specific key (K AF ) associated with the UE and the AF, based on a determination that the AF is authorized.
28 . The NF of claim 22 , wherein:
the request for the corresponding second identifier comprises a translation request that also includes a UE Internet Protocol (IP) address for a connection between the UE and the AF; and
the subscription permanent identifier (SUPI) is obtained based on the UE IP address.
29 . The NF of claim 21 , wherein:
the NF is a network exposure function (NF) or an anchor function for authentication and key management for applications (AAnF); and
the AF comprises one or more of the following servers in an Edge Data Network (EDN) coupled to the communication network: Edge Enabler Server (EES), Edge Application Server (EAS), and Edge Configuration Server (ECS).