TW202320557A - Securing application communication - Google Patents

Securing application communication Download PDF

Info

Publication number
TW202320557A
TW202320557A TW111134693A TW111134693A TW202320557A TW 202320557 A TW202320557 A TW 202320557A TW 111134693 A TW111134693 A TW 111134693A TW 111134693 A TW111134693 A TW 111134693A TW 202320557 A TW202320557 A TW 202320557A
Authority
TW
Taiwan
Prior art keywords
session key
freshness parameter
processor
naf
application
Prior art date
Application number
TW111134693A
Other languages
Chinese (zh)
Inventor
愛德利恩愛德華 伊史考特
李秀凡
艾納德 帕拉尼古德
金弘壹
Original Assignee
美商高通公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from US17/931,505 external-priority patent/US20230093720A1/en
Application filed by 美商高通公司 filed Critical 美商高通公司
Publication of TW202320557A publication Critical patent/TW202320557A/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0431Key distribution or pre-distribution; Key agreement
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/061Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying further key derivation, e.g. deriving traffic keys from a pair-wise master key

Abstract

In embodiments of systems and methods for synchronous content presentation, a user equipment (UE) may generate a freshness parameter, generate a unique session key based on a first session key and the freshness parameter, and send the freshness parameter to a Network Application Function (NAF) of a network device in a configuration that will enable the NAF to generate the unique session key. The network device may receive the freshness parameter, receive from a Key Server Function (KSF) the first session key, and generate based on the freshness parameter and the first session key the unique session key. The UE and the network device may then conduct secure communications using the unique session key without exchanging the unique session key between the two devices.

Description

保護應用通訊Secure Application Communications

本專利申請案主張於2021年9月17日提出申請的、名稱為「SECURING APPLICATION COMMUNICATION」的美國臨時申請案第 63/245,692號的優先權權益,據此將上述申請的全部內容經由引用的方式併入本文以用於所有目的。This patent application claims the benefit of priority to U.S. Provisional Application No. 63/245,692, filed September 17, 2021, entitled "SECURING APPLICATION COMMUNICATION," which is hereby incorporated by reference in its entirety Incorporated herein for all purposes.

本揭示案係關於保護應用通訊。This disclosure is about protecting application communications.

第五代(5G)新無線電(NR)和其他通訊技術實現與諸如無線裝置之類的使用者設備(UE)的超可靠低時延通訊。針對此種通訊系統的一個應用是向UE提供各種服務。在一些情況下,可使用邊緣計算架構來遞送此種服務。邊緣計算架構賦能從被定位為相對靠近UE的網路裝置或元件(如伺服器)提供服務,此可減少端到端時延並且減少通訊網路上的資源需求和消耗。一些應用和服務可採用或者可能需要通訊安全來提供一或多個功能。Fifth-generation (5G) New Radio (NR) and other communications technologies enable ultra-reliable, low-latency communications with user equipment (UE) such as wireless devices. One application for such a communication system is to provide various services to UEs. In some cases, edge computing architectures can be used to deliver such services. The edge computing architecture enables services to be provided from network devices or components (such as servers) located relatively close to UEs, which reduces end-to-end latency and reduces resource requirements and consumption on the communication network. Some applications and services may employ or may require communication security to provide one or more functions.

各個態樣包括由UE的處理器執行的用於保護通訊的方法。一些態樣可包括:產生新鮮度參數;基於第一通信期金鑰和該新鮮度參數來產生唯一通信期金鑰;在將使得網路應用功能(NAF)能夠產生該唯一通信期金鑰的配置中向該NAF發送該新鮮度參數;及使用該唯一通信期金鑰來與該NAF進行通訊。Various aspects include a method performed by a processor of a UE for securing communications. Some aspects may include: generating a freshness parameter; generating a unique session key based on the first session key and the freshness parameter; at a time that will enable a network application function (NAF) to generate the unique session key sending the freshness parameter to the NAF during configuration; and using the unique communication session key to communicate with the NAF.

在一些態樣中,該新鮮度參數可為由該UE的安全牽引客戶端來產生的,並且該UE的應用客戶端可使用該唯一通信期金鑰來與該NAF進行通訊。在一些態樣中,該UE的該安全牽引客戶端可包括通用牽引架構(GBA)客戶端或用於應用的認證和金鑰管理(AKMA)客戶端中的一者。在一些態樣中,該新鮮度參數可與該UE的特定應用相關聯。在一些態樣中,該唯一通信期金鑰可與該UE的特定應用相關聯,並且該第一通信期金鑰可與該UE相關聯。在此種態樣中,該特定應用可包括該應用的特定實例化。In some aspects, the freshness parameter can be generated by the UE's security pull client, and the UE's application client can use the unique session key to communicate with the NAF. In some aspects, the secure pull client for the UE may include one of a Generic Pull Architecture (GBA) client or an Authentication and Key Management for Applications (AKMA) client. In some aspects, the freshness parameter can be associated with a specific application of the UE. In some aspects, the unique session key can be associated with a specific application of the UE, and the first session key can be associated with the UE. In such aspects, the particular application may include a particular instantiation of the application.

在一些態樣中,該新鮮度參數可包括隨機值。在一些態樣中,該新鮮度參數可包括遞增的亂數值。在一些態樣中,在將使得NAF能夠產生該唯一通信期金鑰的配置中向該NAF發送該新鮮度參數可包括:在網路服務請求訊息中向該NAF發送該新鮮度參數。In some aspects, the freshness parameter can include a random value. In some aspects, the freshness parameter may include an incrementing random value. In some aspects, sending the freshness parameter to the NAF in a configuration that will enable the NAF to generate the unique session key may include sending the freshness parameter to the NAF in a web service request message.

進一步的態樣包括一種UE,其具有被配置為執行上文概述的方法中的任何方法的一或多個操作的處理器。進一步的態樣包括用於在UE中使用的處理裝置,其配置有處理器可執行指令以執行上文概述的方法中的任何方法的操作。進一步的態樣包括一種具有儲存在其上的處理器可執行指令的非暫時性處理器可讀儲存媒體,處理器可執行指令被配置為使得UE的處理器執行上文概述的方法中的任何方法的操作。進一步的態樣包括一種UE,其具有用於執行上文概述的方法中的任何方法的功能的手段。進一步的態樣包括一種用於在UE中使用的片上系統,其包括被配置為執行上文概述的方法中的任何方法的一或多個操作的處理器。Further aspects include a UE having a processor configured to perform one or more operations of any of the methods outlined above. Further aspects include processing means for use in a UE configured with processor-executable instructions to perform the operations of any of the methods outlined above. A further aspect includes a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of the UE to perform any of the methods outlined above The operation of the method. Further aspects include a UE having means for performing the function of any of the methods outlined above. Further aspects include a system-on-a-chip for use in a UE comprising a processor configured to perform one or more operations of any of the methods outlined above.

各個態樣包括由網路裝置的處理器執行的用於保護通訊的方法。一些態樣可包括:由NAF從UE接收新鮮度參數;從金鑰伺服器功能(KSF)接收第一通信期金鑰;基於該新鮮度參數和該第一通信期金鑰來產生唯一通信期金鑰;及使用該唯一通信期金鑰與該UE進行通訊。Various aspects include a method performed by a processor of a network device for securing communications. Some aspects may include: receiving, by the NAF, a freshness parameter from the UE; receiving a first session key from a key server function (KSF); generating a unique session based on the freshness parameter and the first session key a key; and using the unique communication period key to communicate with the UE.

在一些態樣中,該新鮮度參數可與該UE的特定應用相關聯。在一些態樣中,該新鮮度參數可包括隨機值。在一些態樣中,其中該新鮮度參數可包括遞增的亂數值。In some aspects, the freshness parameter can be associated with a specific application of the UE. In some aspects, the freshness parameter can include a random value. In some aspects, the freshness parameter may include an increasing random value.

在一些態樣中,該唯一通信期金鑰可與該UE的特定應用相關聯,並且該第一通信期金鑰可與該UE相關聯。在此種態樣中,該特定應用可包括該應用的特定實例化。一些態樣可包括:向該UE發送用於啟動安全通訊的請求。在一些態樣中,由該NAF從該UE接收該新鮮度參數可包括:在網路服務請求訊息中接收該新鮮度參數。In some aspects, the unique session key can be associated with a specific application of the UE, and the first session key can be associated with the UE. In such aspects, the particular application may include a particular instantiation of the application. Some aspects may include sending a request to the UE to initiate secure communication. In some aspects, receiving the freshness parameter from the UE by the NAF may include receiving the freshness parameter in a network service request message.

進一步的態樣包括一種網路裝置,其具有被配置為執行上文概述的方法中的任何方法的一或多個操作的處理器。進一步的態樣包括用於在網路裝置中使用的處理裝置,其被配置有處理器可執行指令以執行上文概述的方法中的任何方法的操作。進一步的態樣包括一種具有儲存在其上的處理器可執行指令的非暫時性處理器可讀儲存媒體,處理器可執行指令被配置為使得網路裝置的處理器執行上文概述的方法中的任何方法的操作。進一步的態樣包括一種網路裝置,其具有用於執行上文概述的方法中的任何方法的功能的手段。進一步的態樣包括一種用於在網路裝置中使用的片上系統,其包括被配置為執行上文概述的方法中的任何方法的一或多個操作的處理器。Further aspects include a network device having a processor configured to perform one or more operations of any of the methods outlined above. Further aspects include processing means for use in a network device configured with processor-executable instructions to perform the operations of any of the methods outlined above. A further aspect includes a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause a processor of a network device to perform one of the methods outlined above. operation of any method. A further aspect includes a network device having means for performing the function of any of the methods outlined above. Further aspects include a system-on-chip for use in a network device comprising a processor configured to perform one or more operations of any of the methods outlined above.

將參照附圖來詳細描述各個實施例。儘可能對所有附圖使用相同的元件符號來指示相同或類似的部分。對特定示例和實現的提及是出於說明性目的,而不意欲限制專利申請範圍的範疇。Various embodiments will be described in detail with reference to the accompanying drawings. Wherever possible, the same reference numbers will be used throughout the drawings to refer to the same or like parts. References to specific examples and implementations are for illustrative purposes and are not intended to limit the scope of the patent claims.

在各個實施例中,為了保護使用者設備(UE)與網路裝置或元件(如伺服器)之間的通訊,在UE內執行的金鑰產生實體可被配置為產生新鮮度參數,其中UE使用該參數來產生唯一通信期金鑰以供在(如安全牽引操作的)通訊協定中使用。UE將新鮮度參數作為牽引操作的一部分發送給網路裝置,隨後網路使用新鮮度參數來產生同一唯一通信期金鑰以供在該通訊協定中使用。隨後,UE和網路裝置使用所產生的唯一通信期金鑰來保護用於特定應用或服務的通訊。在一些實施方式中,UE和網路裝置可產生用於不同的應用或服務的唯一通信期金鑰。以此種方式,UE(例如,邊緣應用)和網路裝置(例如,邊緣伺服器)可使用用於每個應用的通訊的唯一通信期金鑰來保護(防護、加密)多個應用的通訊。各個實施例可在以下各者中使用或作為以下各者的一部分來使用:通用牽引架構(GBA)、用於應用的認證和金鑰管理(AKMA)及其他合適的安全架構和協定。為了清楚起見,本文中可能參考特定安全架構或協定來描述一些實例,但是此並不意欲作為對所描述的概念中的任何概念的限制。In various embodiments, in order to secure communications between a user equipment (UE) and a network device or element (such as a server), a key generation entity executing within the UE may be configured to generate a freshness parameter, wherein the UE Use this parameter to generate unique communication session keys for use in communication protocols such as SafeTow operation. The UE sends the freshness parameter to the network device as part of the pulling operation, and the network then uses the freshness parameter to generate the same unique session key for use in the protocol. The generated unique communication session key is then used by the UE and the network device to secure the communication for the specific application or service. In some embodiments, the UE and the network device can generate unique communication session keys for different applications or services. In this way, UEs (e.g., edge applications) and network devices (e.g., edge servers) can protect (secure, encrypt) communications for multiple applications using a unique session key for each application's communications . Various embodiments may be used in or as part of Generic Traction Architecture (GBA), Authentication and Key Management for Applications (AKMA), and other suitable security architectures and protocols. For clarity, some examples may be described herein with reference to particular security architectures or protocols, but this is not intended as a limitation on any of the concepts described.

術語「使用者設備」和「UE」在本文中用於指示端點或使用者裝置中的任何一者或全部,包括無線裝置、無線路由器設備、無線電器、蜂巢式電話、智慧型電話、可攜式計算裝置、個人或行動多媒體播放機、膝上型電腦、平板電腦、智慧型電腦、超極本、掌上電腦、無線電子郵件接收器、啟用多媒體網際網路的蜂巢式電話、醫療設備和裝置、生物計量感測器/裝置、可穿戴裝置(包括智慧手錶、智慧服裝、智慧眼鏡、智慧腕帶、智慧珠寶(例如,智慧指環和智慧手鏈))、娛樂裝置(例如,無線遊戲控制器、音樂和視訊播放機、衛星無線電單元等)、啟用無線網路的物聯網路(IoT)裝置(包括智慧型儀器表/感測器、工業製造設備、家用或企業用的大型和小型機械和電器、自主和半自主車輛內的無線通訊元件)、附在或併入各種行動平臺中的UE、全球定位系統裝置、及包括記憶體、無線通訊部件和可程式設計處理器的類似電子裝置。The terms "user equipment" and "UE" are used herein to refer to any or all of an endpoint or user device, including wireless devices, wireless router devices, wireless appliances, cellular phones, smartphones, Portable Computing Devices, Personal or Mobile Media Players, Laptops, Tablets, Smart Computers, Ultrabooks, PDAs, Wireless Email Receivers, Multimedia Internet-Enabled Cellular Phones, Medical Devices and devices, biometric sensors/devices, wearable devices (including smart watches, smart clothing, smart glasses, smart wristbands, smart jewelry (such as smart rings and smart bracelets)), entertainment devices (such as wireless game controllers , music and video players, satellite radio units, etc.), wireless network-enabled Internet of Things (IoT) devices (including smart meters/sensors, industrial manufacturing equipment, large and small machinery and appliances, wireless communication components in autonomous and semi-autonomous vehicles), UEs attached to or incorporated into various mobile platforms, GPS devices, and similar electronic devices including memory, wireless communication components, and programmable processors.

術語「片上系統」(SOC)在本文中用於指示單個積體電路(IC)晶片,其包含被整合在單個基板上的多個資源或處理器。單個SOC可包含用於數位、類比、混合信號和射頻功能的電路。單個SOC亦可包括任何數量的通用或專用處理器(數位信號處理器、數據機處理器、視訊處理器等)、記憶體區塊(如ROM、RAM、快閃記憶體等)和資源(如計時器、電壓調節器、振盪器等)。SOC亦可包括用於控制整合資源和處理器及用於控制周邊裝置的軟體。The term "system on a chip" (SOC) is used herein to refer to a single integrated circuit (IC) die containing multiple resources or processors integrated on a single substrate. A single SOC can contain circuits for digital, analog, mixed-signal and radio functions. A single SOC can also include any number of general-purpose or special-purpose processors (digital signal processors, modem processors, video processors, etc.), memory blocks (such as ROM, RAM, flash memory, etc.), and resources (such as timers, voltage regulators, oscillators, etc.). The SOC may also include software for controlling integrated resources and processors and for controlling peripheral devices.

術語「系統級封裝」(SIP)在本文中可用於指示在兩個或兩個以上IC晶片、基板或SOC上包含多個資源、計算單元、核心或處理器的單個模組或封裝。例如,SIP可包括在其上多個IC晶片或半導體晶粒是以垂直配置而堆疊的單個基板。類似地,SIP可包括在其上多個IC或半導體晶粒被封裝到統一基板中的一或多個多晶片模組(MCM)。SIP亦可包括多個獨立SOC,其經由高速通訊電路耦合在一起並且被緊密地封裝在諸如單個主機板上或單個無線裝置中。SOC的接近度促進高速通訊及記憶體和資源的共用。The term "system-in-package" (SIP) may be used herein to refer to a single module or package containing multiple resources, computing units, cores or processors on two or more IC dies, substrates or SOCs. For example, a SIP may include a single substrate on which multiple IC dies or semiconductor dies are stacked in a vertical configuration. Similarly, a SIP may include one or more multi-chip modules (MCMs) on which multiple ICs or semiconductor die are packaged into a unified substrate. A SIP may also include multiple independent SOCs coupled together via high-speed communication circuits and tightly packaged, such as on a single motherboard or in a single wireless device. The proximity of the SOC facilitates high-speed communication and sharing of memory and resources.

如本文所使用的,術語「網路」、「系統」、「無線網路」、「蜂巢網路」和「無線通訊網路」可互換地指示與無線裝置及/或無線裝置上的訂製相關聯的載波的無線網路的一部分或全部。本文描述的技術可用於各種無線通訊網路,如分碼多工存取(CDMA)、分時多工存取(TDMA)、FDMA、正交FDMA(OFDMA)、單載波FDMA(SC-FDMA)和其他網路。通常,可在給定的地理區域中部署任何數量的無線網路。每個無線網路可支援至少一種無線電存取技術,其可在一或多個頻率或頻率範圍上操作。例如,CDMA網路可實現通用陸地無線電存取(UTRA)(包括寬頻分碼多工存取(WCDMA)標準)、CDMA2000(包括IS-2000、IS-95及/或IS-856標準)等。在另一實例中,TDMA網路可實現用於GSM進化的GSM增強資料速率(EDGE)。在另一實例中,OFDMA網路可實現進化型UTRA(E-UTRA)(包括LTE標準)、電氣與電子工程師協會(IEEE)802.11(Wi-Fi)、IEEE 802.16(WiMAX)、IEEE 802.20、快閃OFDM®等。可參考使用LTE標準的無線網路,並且因此術語「進化型通用陸地無線電存取」、「E-UTRAN」和「eNodeB」亦可在本文中互換地用於指示無線網路。然而,提供此類參考僅作為實例,而並不意欲排除使用其他通訊標準的無線網路。例如,儘管本文論述了各種第三代(3G)系統、第四代(4G)系統和第五代(5G)系統,但是該等系統僅是作為示例來引用的,並且可在各個實例中替換未來各代系統(例如,第六代(6G)或更高的系統)。As used herein, the terms "network," "system," "wireless network," "cellular network," and "wireless communication network" are used interchangeably to refer to Part or all of the wireless network of the connected carrier. The techniques described in this paper can be used in various wireless communication networks such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), FDMA, Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA) and other networks. In general, any number of wireless networks may be deployed in a given geographic area. Each wireless network can support at least one radio access technology, which can operate on one or more frequencies or frequency ranges. For example, a CDMA network may implement Universal Terrestrial Radio Access (UTRA) (including Wideband Code Division Multiple Access (WCDMA) standards), CDMA2000 (including IS-2000, IS-95 and/or IS-856 standards), and the like. In another example, a TDMA network may implement Enhanced Data Rates for GSM (EDGE) for GSM Evolution. In another example, an OFDMA network may implement Evolved UTRA (E-UTRA) (including LTE standards), Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Fast Flash OFDM® etc. Reference may be made to wireless networks using the LTE standard, and thus the terms "Evolved Universal Terrestrial Radio Access", "E-UTRAN" and "eNodeB" may also be used interchangeably herein to refer to wireless networks. However, such references are provided as examples only and are not intended to exclude wireless networks using other communication standards. For example, although various third-generation (3G) systems, fourth-generation (4G) systems, and fifth-generation (5G) systems are discussed herein, such systems are cited as examples only and may be substituted in each instance Future generations of systems (for example, sixth generation (6G) or higher systems).

經由5G NR和其他合適的通訊技術實現的超可靠低時延通訊賦能向UE提供各種服務。在一些情況下,可至少部分地使用邊緣計算架構來提供此種服務,該架構賦能從被定位為相對靠近UE的網路裝置或元件(如伺服器)提供服務。從邊緣裝置提供服務可減少端到端時延,並且減少通訊網路上的資源需求和消耗。Ultra-reliable and low-latency communication enabled by 5G NR and other suitable communication technologies can provide various services to UE. In some cases, such services may be provided at least in part using an edge computing architecture that enables services to be provided from network devices or elements (eg, servers) located relatively close to the UE. Providing services from edge devices reduces end-to-end latency and reduces resource requirements and consumption on the communication network.

一些應用和服務可採用或者可能需要通訊安全來提供一或多個功能。例如,通用牽引架構(GBA)可提供如下的機制:該機制使用諸如3GPP認證和金鑰協商(AKA)的協定來配置在UE與網路裝置之間的共用秘密。作為另一實例,用於應用的認證和金鑰管理(AKMA)可在UE與網路裝置(例如,執行應用功能(AF))之間採用類似的操作。在習知方法中,UE和網路裝置針對由所有服務和應用進行的所有通訊共用單個共用秘密。Some applications and services may employ or may require communication security to provide one or more functions. For example, a Generic Pull Architecture (GBA) may provide a mechanism for configuring a shared secret between a UE and a network device using a protocol such as 3GPP Authentication and Key Agreement (AKA). As another example, Authentication and Key Management for Applications (AKMA) may employ similar operations between UEs and network devices (eg, performing Application Functions (AF)). In known approaches, UEs and network devices share a single common secret for all communications by all services and applications.

各個實施例包括方法和計算裝置,其被配置為執行用於保護在UE與針對應用或服務提供個性化通訊安全的網路裝置之間的通訊的方法。在一些實施例中,UE可產生新鮮度參數(如經由UE的安全牽引客戶端(例如,GBA客戶端))。使用第一通信期金鑰(例如,與網路裝置共用的根金鑰)和新鮮度參數,UE可產生唯一通信期金鑰。在各種實施方式中,新鮮度參數可與在UE上執行或正被提供給UE的特定應用相關聯。例如,UE可具有在UE的處理器上執行的若干不同的邊緣應用,該等邊緣應用正在與相同的邊緣伺服器進行通訊。例如,多個同時的邊緣應用可能包括導航應用、媒體(例如,音樂)串流應用和增強現實應用,每個應用皆應當具有不同的唯一金鑰。在各個實施例中,UE和邊緣伺服器可向該等不同的應用中的每一者指派與第一通信期金鑰相結合的唯一的新鮮度參數,從而為每個應用提供唯一通信期金鑰,而無需改變用於UE與邊緣伺服器之間的通訊的第一通信期金鑰。Various embodiments include methods and computing devices configured to perform a method for securing communications between a UE and a network device providing personalized communication security for an application or service. In some embodiments, the UE may generate the freshness parameter (eg, via the UE's secure pull client (eg, GBA client)). Using the first session key (eg, the root key shared with the network device) and the freshness parameter, the UE can generate a unique session key. In various implementations, the freshness parameter may be associated with a particular application executing on or being provided to the UE. For example, a UE may have several different edge applications executing on the UE's processor that are communicating with the same edge server. For example, multiple simultaneous edge applications may include a navigation application, a media (eg, music) streaming application, and an augmented reality application, each of which should have a different unique key. In various embodiments, the UE and the edge server may assign to each of the different applications a unique freshness parameter combined with the first communication session key, thereby providing each application with a unique communication session key without changing the first communication session key used for communication between the UE and the edge server.

在一些實施方式中,新鮮度參數可包括隨機值。在一些實施方式中,新鮮度參數可包括遞增值,如每次需要新的唯一通信期金鑰(例如,對於新應用或應用的新實例化)時,計數器的值可被遞增。在一些實施例中,遞增值可用作亂數值(例如,遞增的亂數值)。In some implementations, the freshness parameter may include a random value. In some implementations, the freshness parameter may include an incremented value, eg, a counter may be incremented each time a new unique session key is required (eg, for a new application or a new instantiation of an application). In some embodiments, incrementing values may be used as nonce values (eg, incrementing nonce values).

在各個實施例中,UE可在將使得網路應用功能(NAF)能夠產生唯一通信期金鑰的配置中向網路裝置的NAF(例如,GBA中的NAF、AKMA中的應用功能或其他合適的功能)發送新鮮度參數。在一些實施例中,UE可將新鮮度參數作為網路服務請求訊息(例如,應用請求訊息)的一部分進行發送。在各個實施例中,NAF可執行與由UE使用的相同的演算法,以使用從UE接收的新鮮度參數來產生相同的唯一通信期金鑰(亦即,與由UE產生的唯一通信期金鑰相同的唯一通信期金鑰)。在一些實施例中,NAF可從在網路裝置上執行的金鑰伺服器功能(KSF)(如引導伺服器功能(BSF)、AKMA功能或其他合適的功能)接收(或者可請求並且回應於請求而接收)第一通信期金鑰(亦即,與由UE使用的第一通信期金鑰相同的通信期金鑰)。使用新鮮度參數和第一通信期金鑰,NAF可產生唯一通信期金鑰。隨後,UE和NAF可使用唯一通信期金鑰進行通訊,而無需交換唯一通信期金鑰。在各個實施例中,UE和NAF可產生用於UE的每個應用或服務的唯一通信期金鑰(或由網路裝置提供給UE)。In various embodiments, the UE may request a network application function (NAF) to a network device's NAF (e.g., NAF in GBA, application function in AKMA, or other suitable function) to send the freshness parameter. In some embodiments, the UE may send the freshness parameter as part of a network service request message (eg, an application request message). In various embodiments, the NAF may execute the same algorithm as used by the UE to use the freshness parameters received from the UE to generate the same unique communication session key (i.e., identical to the unique communication session key generated by the UE key with the same unique communication session key). In some embodiments, the NAF may receive (or may request and respond to Received upon request) a first session key (ie, the same session key as the first session key used by the UE). Using the freshness parameter and the first session key, the NAF can generate a unique session key. Subsequently, the UE and the NAF can communicate using the unique session key without exchanging the unique session key. In various embodiments, the UE and the NAF may generate (or be provided to the UE by the network device) a unique communication session key for each application or service of the UE.

在一些實施例中,UE可從NAF接收用於啟動安全通訊的請求。在一些實施例中,用於啟動安全通訊的請求可包括NAF的網域名稱(例如,完整網域名稱(FQDN))和安全協定識別符(如NAF與UE之間的介面,如Ua介面)。在一些實施例中,UE可基於NAF的網域名稱和安全協定識別符來推導(產生、計算)第一通信期金鑰。在一些實施例中,UE可回應於從NAF接收的用於啟動安全通訊的請求,來產生新鮮度參數並且將新鮮度參數發送給網路裝置(例如,發送給NAF)。例如,UE(例如,GBA客戶端、AKMA客戶端或其他合適的客戶端)可產生新鮮度參數並且將新鮮度參數傳遞給NAF。UE亦可使用新鮮度參數和第一通信期金鑰來產生唯一通信期金鑰。在一些實施例中,第一通信期金鑰可與UE相關聯。例如,通信期金鑰(如Ks_NAF、Ks_int_NAF或Ks_ext_NAF)可為在GBA中使用的通信期金鑰。在一些實施例中,新鮮度參數可與UE的特定應用(或服務)相關聯。在一些實施例中,新鮮度參數可與UE的應用(或服務)的特定實例化相關聯。此外,NAF可從UE接收新鮮度參數並且從KSF接收第一通信期金鑰的版本,並且NAF可使用新鮮度參數和第一通信期金鑰來產生其自己版本的唯一通信期金鑰。In some embodiments, the UE may receive a request from the NAF to initiate secure communication. In some embodiments, the request for initiating secure communication may include the NAF's domain name (e.g., Full Network Domain Name (FQDN)) and security protocol identifier (e.g., the interface between the NAF and the UE, such as the Ua interface) . In some embodiments, the UE may derive (generate, calculate) the first session key based on the domain name of the NAF and the security protocol identifier. In some embodiments, the UE may generate the freshness parameter and send the freshness parameter to the network device (eg, to the NAF) in response to a request received from the NAF to initiate secure communication. For example, a UE (eg, a GBA client, AKMA client, or other suitable client) may generate a freshness parameter and pass the freshness parameter to the NAF. The UE may also use the freshness parameter and the first session key to generate a unique session key. In some embodiments, a first session key may be associated with the UE. For example, a communication session key (such as Ks_NAF, Ks_int_NAF or Ks_ext_NAF) may be a communication session key used in GBA. In some embodiments, the freshness parameter may be associated with a specific application (or service) of the UE. In some embodiments, a freshness parameter may be associated with a specific instantiation of the UE's application (or service). Furthermore, the NAF may receive the freshness parameter from the UE and the version of the first session key from the KSF, and the NAF may use the freshness parameter and the first session key to generate its own version of the unique session key.

在各個實施例中,UE可在UE與NAF之間交換的訊息的現有欄位中包括新鮮度參數。以此種方式,可在不改變訊息或訊息交換的協定或架構的情況下實現各個實施例。例如,對於採用Digest AKA協定的裝置和網路,新鮮度參數可被包括在「cnonce」欄位中。作為另一實例,對於採用傳輸層安全性(TLS)的裝置和網路,新鮮度參數可被包括在ClientHello訊息或其他合適的訊息的現有欄位中。在各個實施例中,新鮮度參數的長度可被配置為適配在現有欄位及/或訊息內。在各個實施例中,UE可在與其他加密金鑰或通信期金鑰類似的安全級別及/或類似的受保護的記憶體部分中產生新鮮度參數,並且UE和網路裝置可處理新鮮度參數。In various embodiments, the UE may include a freshness parameter in an existing field of messages exchanged between the UE and the NAF. In this way, various embodiments may be implemented without changing the protocol or architecture of messages or message exchanges. For example, for devices and networks employing the Digest AKA protocol, a freshness parameter may be included in the "cnonce" field. As another example, for devices and networks employing Transport Layer Security (TLS), the freshness parameter may be included in an existing field of the ClientHello message or other suitable message. In various embodiments, the length of the freshness parameter can be configured to fit within existing fields and/or messages. In various embodiments, the UE may generate the freshness parameter in a similar security level and/or a similar protected portion of memory as other encryption keys or session keys, and the UE and network device may process the freshness parameter.

各個實施例使得UE和網路裝置能夠產生用於UE的每個應用或服務的唯一金鑰,而無需交換私有或安全資訊(如私密金鑰)。因此,各個實施例經由提高UE和網路裝置之間的通訊的安全性來改進UE、網路裝置和通訊系統的操作。Various embodiments enable UE and network devices to generate unique keys for each application or service of the UE without exchanging private or secure information such as private keys. Accordingly, various embodiments improve the operation of UEs, network devices, and communication systems by increasing the security of communications between the UE and network devices.

圖1A是示出示例通訊系統100的系統方塊圖。通訊系統100可為5G新無線電(NR)網路,或任何其他合適的網路(如長期進化(LTE)網路)。儘管圖1A圖示5G網路,但是後代網路可包括相同或相似的元件。因此,在以下描述中對5G網路和5G網路元件的引用是出於說明性目的而非意欲是限制性的。FIG. 1A is a system block diagram illustrating an example communication system 100 . The communication system 100 can be a 5G New Radio (NR) network, or any other suitable network (such as a Long Term Evolution (LTE) network). Although FIG. 1A illustrates a 5G network, future generations of networks may include the same or similar elements. Accordingly, references to 5G networks and 5G network elements in the following description are for illustrative purposes and are not intended to be limiting.

通訊系統100可包括異質網路架構,該異質網路架構包括核心網路140和各種UE(在圖1中被示為UE 120a-120e)。通訊系統100可包括邊緣網路142,以經由一或多個網路裝置142a提供靠近行動裝置的網路計算資源、應用及/或服務。通訊系統100亦可包括多個基地台(被示為BS 110a、BS 110b、BS 110c和BS 110d)和其他網路實體。基地台是與UE進行通訊的實體,並且亦可被稱為節點B、LTE進化型NodeB(eNodeB或eNB)、存取點(AP)、無線電頭端、發送接收點(TRP)、新無線電基地台(NR BS)、5G NodeB(NB)、下一代節點B(gNodeB或gNB)等。每個基地台可提供針對特定地理區域的通訊覆蓋。在3GPP中,術語「細胞」可指示基地台的覆蓋區域、服務於該覆蓋區域的基地台子系統或其組合,此取決於使用該術語的上下文。核心網路140可為任何類型的核心網路,如LTE核心網路(例如,進化封包核心(EPC)網路)、5G核心網路等。The communication system 100 may include a heterogeneous network architecture including a core network 140 and various UEs (shown as UEs 120a - 120e in FIG. 1 ). The communication system 100 may include an edge network 142 to provide network computing resources, applications and/or services close to the mobile device via one or more network devices 142a. Communication system 100 may also include multiple base stations (shown as BS 110a, BS 110b, BS 110c, and BS 110d) and other network entities. A base station is an entity that communicates with a UE and may also be referred to as Node B, LTE Evolved NodeB (eNodeB or eNB), Access Point (AP), Radio Head, Transceiver Point (TRP), New Radio Base Station (NR BS), 5G NodeB (NB), Next Generation Node B (gNodeB or gNB), etc. Each base station provides communication coverage for a specific geographic area. In 3GPP, the term "cell" can refer to a coverage area of a base station, a base station subsystem serving the coverage area, or a combination thereof, depending on the context in which the term is used. The core network 140 can be any type of core network, such as an LTE core network (eg, an evolved packet core (EPC) network), a 5G core network, and the like.

基地台110a-110d可提供針對巨集細胞、微微細胞、毫微微細胞、另一種類型的細胞,或其組合的通訊覆蓋。巨集細胞可覆蓋相對大的地理區域(例如,半徑為數公里),並且可允許由具有服務訂製的UE進行的不受限制的存取。微微細胞可覆蓋相對小的地理區域,並且可允許由具有服務訂製的UE進行的不受限制的存取。毫微微細胞可覆蓋相對小的地理區域(例如,住宅),並且可允許由與該毫微微細胞具有關聯的UE(例如,封閉使用者群組(CSG)中的UE)進行的受限制的存取。用於巨集細胞的基地台可被稱為巨集BS。用於微微細胞的基地台可被稱為微微BS。用於毫微微細胞的基地台可被稱為毫微微BS或家庭BS。在圖1中示出的實例中,基地台110a可為用於巨集細胞102a的巨集BS,基地台110b可為用於微微細胞102b的微微BS,及基地台110c可為用於毫微微細胞102c的毫微微BS。基地台110a-110d可支援一或多個(例如,三個)細胞。術語「eNB」、「基地台」、「NR BS」、「gNB」、「TRP」、「AP」、「節點B」、「5G NB」和「細胞」在本文中可互換地使用。The base stations 110a-110d may provide communication coverage for macrocells, picocells, femtocells, another type of cell, or a combination thereof. A macrocell may cover a relatively large geographic area (eg, several kilometers in radius) and may allow unrestricted access by UEs with service subscription. A picocell may cover a relatively small geographic area and may allow unrestricted access by UEs with a service subscription. A femtocell may cover a relatively small geographic area (e.g., a residence) and may allow limited storage by UEs associated with the femtocell (e.g., UEs in a Closed Subscriber Group (CSG)). Pick. A base station for a macro cell may be referred to as a macro BS. A base station for a pico cell may be referred to as a pico BS. A base station for a femto cell may be called a femto BS or a home BS. In the example shown in FIG. 1, base station 110a may be a macro BS for macro cell 102a, base station 110b may be a pico BS for pico cell 102b, and base station 110c may be a pico BS for femto cell 102b. Femto BS of cell 102c. The base stations 110a-110d may support one or more (eg, three) cells. The terms "eNB", "base station", "NR BS", "gNB", "TRP", "AP", "Node B", "5G NB" and "cell" are used interchangeably herein.

在一些實例中,細胞可能不是靜止的,並且細胞的地理區域可根據行動基地台的位置進行移動。在一些實例中,基地台110a-110d可使用任何適當的傳輸網路,經由各種類型的回載介面(如直接實體連接、虛擬網路,或其組合)來彼此互連及與通訊系統100中的一或多個其他基地台或網路節點(未圖示)互連。In some instances, a cell may not be stationary, and the geographic area of the cell may move depending on the location of the mobile base station. In some examples, the base stations 110a-110d can be interconnected with each other and with the communication system 100 through various types of backhaul interfaces (such as direct physical connections, virtual networks, or combinations thereof) using any suitable transmission network. One or more other base stations or network nodes (not shown) are interconnected.

基地台110a-110d可在有線或無線通訊鏈路126上與核心網路140進行通訊。UE 120a-120e可在無線通訊鏈路122上與基地台110a-110d進行通訊。Base stations 110 a - 110 d may communicate with core network 140 over wired or wireless communication links 126 . UEs 120a-120e may communicate over wireless communication link 122 with base stations 110a-110d.

有線通訊鏈路126可使用各種有線網路(如乙太網路、電視電纜、電話、光纖和其他形式的實體網路連接),該等有線網路可使用一或多個有線通訊協定(如乙太網路、點對點通訊協定、高階資料連結控制(HDLC)、高級資料通訊控制協定(ADCCP)和傳輸控制協定/網際網路協定(TCP/IP))。Wired communication link 126 can use various wired networks (such as Ethernet, television cable, telephone, fiber optics, and other forms of physical network connections) that can use one or more wired communication protocols (such as Ethernet, Point-to-Point Protocol, High-Level Data Link Control (HDLC), Advanced Data Communication Control Protocol (ADCCP), and Transmission Control Protocol/Internet Protocol (TCP/IP)).

通訊系統100亦可包括中繼站(如中繼BS 110d)。中繼站是可從上游站(例如,基地台或UE)接收資料傳輸並且將資料傳輸發送給下游站(例如,UE或基地台)的實體。中繼站亦可為能夠為其他UE中繼傳輸的無線裝置(例如,UE)。在圖1中示出的實例中,中繼站110d可與巨集基地台110a和UE 120d進行通訊,以便促進基地台110a與UE 120d之間的通訊。中繼站亦可被稱為中繼基地台、中繼基地台、中繼器等。The communication system 100 may also include a relay station (such as the relay BS 110d). A relay station is an entity that may receive data transmissions from upstream stations (eg, base stations or UEs) and send data transmissions to downstream stations (eg, UEs or base stations). A relay station may also be a wireless device (eg, UE) capable of relaying transmissions for other UEs. In the example shown in FIG. 1 , relay station 110d may communicate with macro base station 110a and UE 120d to facilitate communication between base station 110a and UE 120d. A repeater station may also be called a repeater base station, repeater base station, repeater, etc.

通訊系統100可為包括不同類型的基地台(例如,巨集基地台、微微基地台、毫微微基地台、中繼基地台等)的異質網路。該等不同類型的基地台可具有不同的發射功率位準、不同的覆蓋區域及對通訊系統100中的干擾的不同影響。例如,巨集基地台可具有高發射功率位準(例如,5到40瓦特),而微微基地台、毫微微基地台和中繼基地台可具有較低的發射功率位準(例如,0.1到2瓦特)。The communication system 100 may be a heterogeneous network including different types of base stations (eg, macro base stations, pico base stations, femto base stations, relay base stations, etc.). The different types of base stations may have different transmit power levels, different coverage areas, and different effects on interference in the communication system 100 . For example, macro base stations may have high transmit power levels (e.g., 5 to 40 watts), while pico, femto, and relay base stations may have lower transmit power levels (e.g., 0.1 to 40 watts). 2 watts).

網路控制器130可耦合到一組基地台,並且可提供針對該等基地台的協調和控制。網路控制器130可經由回載與基地台進行通訊。基地台亦可例如經由無線或有線回載直接地或間接地與彼此進行通訊。A network controller 130 can be coupled to a group of base stations and can provide coordination and control for the base stations. The network controller 130 can communicate with the base station via the backhaul. Base stations may also communicate with each other directly or indirectly, eg, via wireless or wired backhaul.

UE 120a、120b、120c可散佈於整個通訊系統100中,並且每個UE可為靜止的或行動的。UE亦可被稱為存取終端、終端、行動站、使用者單元、站、無線裝置等。UEs 120a, 120b, 120c may be dispersed throughout communication system 100, and each UE may be stationary or mobile. A UE may also be called an access terminal, terminal, mobile station, user unit, station, wireless device, and the like.

巨集基地台110a可在有線或無線通訊鏈路126上與通訊網路140進行通訊。UE 120a、120b、120c可在無線通訊鏈路122上與基地台110a-110d進行通訊。Macro base station 110 a can communicate with communication network 140 over wired or wireless communication link 126 . UEs 120a, 120b, 120c may communicate over wireless communication link 122 with base stations 110a-110d.

無線通訊鏈路122和124可包括複數個載波信號、頻率或頻帶,其中每一者可包括複數個邏輯通道。無線通訊鏈路122和124可利用一或多個無線存取技術(RAT)。可在無線通訊鏈路中使用的RAT的實例包括3GPP LTE、3G、4G、5G(如NR)、GSM、分碼多工存取(CDMA)、寬頻分碼多工存取(WCDMA)、全球互通微波存取性(WiMAX)、分時多工存取(TDMA)及其他行動電話通訊技術蜂巢RAT。可在通訊系統100內的各種無線通訊鏈路中的一或多個無線通訊鏈路中使用的RAT的另外的實例包括中程協定(如Wi-Fi、LTE-U、LTE直連、LAA、MuLTEfire)和相對短程RAT(如ZigBee、藍芽和藍芽低能(LE))。Wireless communication links 122 and 124 may include a plurality of carrier signals, frequencies or frequency bands, each of which may include a plurality of logical channels. Wireless communication links 122 and 124 may utilize one or more radio access technologies (RATs). Examples of RATs that can be used in wireless communication links include 3GPP LTE, 3G, 4G, 5G (such as NR), GSM, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Global Interoperable microwave access (WiMAX), time-division multiple access (TDMA) and other mobile phone communication technologies cellular RAT. Additional examples of RATs that may be used in one or more of the various wireless communication links within the communication system 100 include medium-range protocols (e.g., Wi-Fi, LTE-U, LTE Direct, LAA, MuLTEfire) and relatively short-range RATs such as ZigBee, Bluetooth, and Bluetooth Low Energy (LE).

某些無線網路(例如,LTE)在下行鏈路上利用正交分頻多工(OFDM)及在上行鏈路上利用單載波分頻多工(SC-FDM)。OFDM和SC-FDM將系統頻寬劃分成多個(K個)正交次載波,該多個正交次載波通常亦被稱為音調、頻段等。可利用資料來調變每個次載波。通常,在頻域中利用OFDM及在時域中利用SC-FDM來發送調變符號。相鄰次載波之間的間隔可為固定的,並且次載波的總數(K)可取決於系統頻寬。例如,次載波的間隔可為15 kHz並且最小資源配置(被稱為「資源區塊」)可為12個次載波(或180 kHz)。因此,針對1.25、2.5、5、10或20兆赫茲(MHz)的系統頻寬,標稱的快速檔案傳輸(FFT)大小可分別等於128、256、512、1024或2048。亦可將系統頻寬劃分成次頻帶。例如,次頻帶可覆蓋1.08 MHz(亦即,6個資源區塊),並且針對1.25、2.5、5、10或20 MHz的系統頻寬,可分別存在1、2、4、8或16個次頻帶。Certain wireless networks (eg, LTE) utilize Orthogonal Frequency Division Multiplexing (OFDM) on the downlink and Single Carrier Frequency Division Multiplexing (SC-FDM) on the uplink. OFDM and SC-FDM divide the system bandwidth into multiple (K) orthogonal sub-carriers, which are also commonly referred to as tones, frequency bands, and the like. Data can be used to modulate each subcarrier. In general, modulation symbols are sent in the frequency domain with OFDM and in the time domain with SC-FDM. The spacing between adjacent subcarriers may be fixed, and the total number of subcarriers (K) may depend on the system bandwidth. For example, the spacing of subcarriers may be 15 kHz and the minimum resource allocation (referred to as a "resource block") may be 12 subcarriers (or 180 kHz). Thus, the nominal fast file transfer (FFT) size may be equal to 128, 256, 512, 1024 or 2048 for a system bandwidth of 1.25, 2.5, 5, 10 or 20 megahertz (MHz), respectively. The system bandwidth may also be divided into sub-bands. For example, a sub-band may cover 1.08 MHz (i.e., 6 resource blocks), and there may be 1, 2, 4, 8 or 16 sub-bands for a system bandwidth of 1.25, 2.5, 5, 10 or 20 MHz, respectively. frequency band.

儘管對一些實現的描述可能使用了與LTE技術相關聯的術語和實例,但是一些實現可適用於其他無線通訊系統,如新無線電(NR)或5G網路。NR可在上行鏈路(UL)和下行鏈路(DL)上利用具有循環字首(CP)的OFDM,並且可包括針對使用分時雙工(TDD)的半雙工操作的支援。可支援100 MHz的單分量載波頻寬。NR資源區塊可在0.1毫秒(ms)持續時間內跨越具有75 kHz的次載波頻寬的12個次載波。每個無線電訊框可由50個子訊框組成,具有10 ms的長度。因此,每個子訊框可具有0.2 ms的長度。每個子訊框可指示用於資料傳輸的鏈路方向(亦即,DL或UL),並且可動態地切換用於每個子訊框的鏈路方向。每個子訊框可包括DL/UL資料及DL/UL控制資料。可支援波束成形並且可動態地配置波束方向。亦可支援具有預編碼的多輸入多輸出(MIMO)傳輸。DL中的MIMO配置可支援多至八個發射天線,其中多層DL傳輸多至八個串流並且每個UE多至兩個串流。可支援具有每個UE多至2個串流的多層傳輸。Although some implementations may be described using terms and examples associated with LTE technology, some implementations are applicable to other wireless communication systems, such as New Radio (NR) or 5G networks. NR may utilize OFDM with a cyclic prefix (CP) on the uplink (UL) and downlink (DL), and may include support for half-duplex operation using time division duplex (TDD). It can support a single component carrier bandwidth of 100 MHz. An NR resource block may span 12 subcarriers with a subcarrier bandwidth of 75 kHz for a 0.1 millisecond (ms) duration. Each radio frame may consist of 50 subframes with a length of 10 ms. Therefore, each subframe may have a length of 0.2 ms. Each subframe can indicate the link direction (ie, DL or UL) used for data transmission, and the link direction for each subframe can be dynamically switched. Each subframe can include DL/UL data and DL/UL control data. Beamforming can be supported and the beam direction can be dynamically configured. Multiple-input multiple-output (MIMO) transmission with precoding may also be supported. MIMO configurations in DL can support up to eight transmit antennas, with multi-layer DL transmission up to eight streams and up to two streams per UE. Multi-layer transmission with up to 2 streams per UE can be supported.

可支援具有多至八個服務細胞的多個細胞的聚合。替代地,NR可支援除了基於OFDM的空中介面之外的不同的空中介面。Aggregation of multiple cells with up to eight serving cells can be supported. Alternatively, NR may support different air interfaces other than OFDM-based air interfaces.

一些UE可被認為是機器類型通訊(MTC)或者進化型或增強型機器類型通訊(eMTC)UE。MTC和eMTC UE包括例如機器人、無人機、遠端裝置、感測器、儀錶、監視器、位置標籤等,其可與基地台、另一裝置(例如,遠端裝置)或某個其他實體進行通訊。無線計算平臺可例如經由有線或無線通訊鏈路來提供針對網路(例如,諸如網際網路或蜂巢網路之類的廣域網)的連接或到網路的連接。一些UE可被認為是物聯網路(IoT)裝置或者可被實現成NB-IoT(窄頻物聯網)裝置。UE 120a-120e可被包括在容納UE 120a-120e的部件(如處理器部件、記憶體部件、類似部件,或其組合)的殼體內部。Some UEs may be considered as machine type communication (MTC) or evolved or enhanced machine type communication (eMTC) UEs. MTC and eMTC UEs include, for example, robots, drones, remote devices, sensors, meters, monitors, location tags, etc., which may interact with a base station, another device (e.g., a remote device), or some other entity communication. A wireless computing platform may provide connectivity to or to a network (eg, a wide area network such as the Internet or a cellular network), eg, via wired or wireless communication links. Some UEs may be considered Internet of Things (IoT) devices or may be implemented as NB-IoT (Narrow Band Internet of Things) devices. The UEs 120a-120e may be included inside housings housing components of the UEs 120a-120e, such as processor components, memory components, the like, or combinations thereof.

通常,可在給定的地理區域中部署任何數量的通訊系統和任何數量的無線網路。每個通訊系統和無線網路可支援特定的無線存取技術(RAT)並且可在一或多個頻率上操作。RAT亦可被稱為無線電技術、空中介面等。頻率亦可被稱為載波、頻率通道等。每個頻率可在給定的地理區域中支援單一RAT,以便避免不同RAT的通訊系統之間的干擾。在一些情況下,可部署4G/LTE及/或5G/NR RAT網路。例如,5G非獨立(NSA)網路可在5G NSA網路的4G/LTE RAN側利用4G/LTE RAT,並且在5G NSA網路的5G/NR RAN側利用5G/NR RAT。4G/LTE RAN和5G/NR RAN兩者可彼此連接並且可連接到5G NSA網路中的4G/LTE核心網路(例如,進化封包核心(EPC)網路)。其他示例網路配置可包括5G獨立(SA)網路,其中5G/NR RAN連接到5G核心網路。In general, any number of communication systems and any number of wireless networks may be deployed in a given geographic area. Each communication system and wireless network may support a specific radio access technology (RAT) and may operate on one or more frequencies. A RAT may also be referred to as a radio technology, an air interface, and the like. A frequency may also be referred to as a carrier, frequency channel, or the like. Each frequency can support a single RAT in a given geographic area in order to avoid interference between communication systems of different RATs. In some cases, 4G/LTE and/or 5G/NR RAT networks may be deployed. For example, a 5G non-standalone (NSA) network could utilize 4G/LTE RAT on the 4G/LTE RAN side of the 5G NSA network and utilize 5G/NR RAT on the 5G/NR RAN side of the 5G NSA network. Both the 4G/LTE RAN and the 5G/NR RAN are connectable to each other and to the 4G/LTE core network (eg, Evolved Packet Core (EPC) network) in the 5G NSA network. Other example network configurations may include 5G Standalone (SA) networks where the 5G/NR RAN is connected to the 5G core network.

在一些實施方式中,兩個或兩個以上UE 120a-120e(例如,被示為UE 120a和UE 120e)可使用一或多個側行鏈路通道直接進行通訊(例如,在不使用基地台110a-110d作為彼此進行通訊的仲介的情況下)。例如,UE 120a-120e可使用對等(P2P)通訊、裝置到裝置(D2D)通訊、運載工具到萬物(V2X)協定(其可包括運載工具到運載工具(V2V)協定、運載工具到基礎設施(V2I)協定或類似協定)、網狀網路,或類似網路,或其組合進行通訊。在此種情況下,UE 120a-120e可執行排程操作、資源選擇操作及在本文其他地方被描述為由基地台110a-110d執行的其他操作。In some embodiments, two or more UEs 120a-120e (eg, shown as UE 120a and UE 120e) may communicate directly using one or more sidelink channels (eg, without using a base station 110a-110d act as intermediaries for communicating with each other). For example, UEs 120a-120e may use peer-to-peer (P2P) communications, device-to-device (D2D) communications, vehicle-to-everything (V2X) protocols (which may include vehicle-to-vehicle (V2V) protocols, vehicle-to-infrastructure (V2I) protocol or similar), mesh network, or similar network, or a combination thereof. In such cases, UEs 120a-120e may perform scheduling operations, resource selection operations, and other operations described elsewhere herein as being performed by base stations 110a-110d.

圖1B是示出適於與各個實施例一起使用的示例邊緣計算系統150的系統方塊圖。在一些實施例中,邊緣計算系統150可包括邊緣網路142和UE 170(例如,UE 120a-120e),其被配置為經由3GPP核心網路160進行通訊。邊緣資料網路152可包括與邊緣配置伺服器158相通訊的邊緣應用伺服器154和一或多個邊緣賦能伺服器156。邊緣應用伺服器154、邊緣賦能伺服器156和邊緣配置伺服器158的實例包括網路裝置142a。UE 170可包括與一或多個邊緣賦能器客戶端174相通訊的應用客戶端172。邊緣計算系統150的元件中的每一者皆可經由邊緣介面(例如,EDGE-1、EDGE-2、……、EDGE-9)進行通訊。FIG. 1B is a system block diagram illustrating an example edge computing system 150 suitable for use with various embodiments. In some embodiments, edge computing system 150 may include edge network 142 and UEs 170 (eg, UEs 120a - 120e ) configured to communicate via 3GPP core network 160 . The edge data network 152 may include an edge application server 154 and one or more edge enabling servers 156 in communication with an edge provisioning server 158 . Examples of edge application server 154, edge enabling server 156, and edge configuration server 158 include network device 142a. UE 170 may include an application client 172 in communication with one or more edge enabler clients 174 . Each of the elements of the edge computing system 150 can communicate via an edge interface (eg, EDGE-1, EDGE-2, . . . , EDGE-9).

邊緣應用伺服器154和應用客戶端172可各自被配置為處理計算任務,並且可經由3GPP核心網路160傳送應用資料訊務(亦即,與計算任務、應用、服務等相關的資料)。邊緣賦能伺服器156可被配置為(例如,向諸如UE 170之類的裝置)維護和通告由邊緣應用伺服器154提供的應用。邊緣配置伺服器158可被配置為管理一或多個邊緣資料網路152內和之間的通訊。Edge application server 154 and application client 172 may each be configured to process computing tasks, and may transmit application data traffic (ie, data related to computing tasks, applications, services, etc.) via 3GPP core network 160 . Edge-enabled server 156 may be configured to maintain and advertise (eg, to devices such as UE 170 ) applications provided by edge application server 154 . Edge configuration server 158 may be configured to manage communications within and between one or more edge data networks 152 .

邊緣應用伺服器154可經由EDGE-3介面來向邊緣賦能伺服器156提供有關其應用及其功能的資訊。邊緣賦能伺服器156可經由EDGE-6介面來向邊緣配置伺服器158提供有關邊緣資料網路152的資訊。邊緣應用伺服器154和邊緣賦能伺服器156可分別經由EDGE-7介面和EDGE-2介面與3GPP核心網路160進行通訊。The edge application server 154 can provide information about its applications and their functions to the edge enabling server 156 via the EDGE-3 interface. The edge enabling server 156 can provide information about the edge data network 152 to the edge provisioning server 158 via the EDGE-6 interface. The edge application server 154 and the edge enablement server 156 can communicate with the 3GPP core network 160 through the EDGE-7 interface and the EDGE-2 interface respectively.

在一些實施例中,邊緣賦能器客戶端174可經由EDGE-1介面從邊緣賦能伺服器156獲得(及/或經由EDGE-4介面從邊緣配置伺服器158獲得)有關可用的邊緣資料網路152的資訊。在一些實施例中,邊緣賦能器客戶端174可經由EDGE-4介面獲得有關邊緣應用伺服器154的資訊,如可用的應用及其功能。在一些實施例中,邊緣賦能器客戶端174、邊緣賦能伺服器156和邊緣配置伺服器158可經由其相應的邊緣介面來採用發現和供應程序。In some embodiments, the edge enabler client 174 may obtain information about available edge data networks from the edge enablement server 156 via the EDGE-1 interface (and/or from the edge configuration server 158 via the EDGE-4 interface). Information on Lu 152. In some embodiments, the edge enabler client 174 can obtain information about the edge application server 154 via the EDGE-4 interface, such as available applications and their functions. In some embodiments, edge enabler client 174, edge enablement server 156, and edge configuration server 158 may employ discovery and provisioning procedures via their respective edge interfaces.

應用客戶端172可經由EDGE-5介面來與邊緣賦能器客戶端174進行通訊。在一些實施例中,邊緣賦能器客戶端174可經由Edge-4介面來從邊緣配置伺服器158獲得關於可用的邊緣資料網路152的資訊,並且可經由EDGE-1介面來與邊緣賦能伺服器156協調對邊緣應用伺服器154的使用。邊緣賦能伺服器156可經由EDGE-9介面彼此協調。The application client 172 can communicate with the edge enabler client 174 via the EDGE-5 interface. In some embodiments, the edge enabler client 174 can obtain information about available edge data networks 152 from the edge configuration server 158 via the Edge-4 interface, and can communicate with the edge enabler via the EDGE-1 interface. Server 156 coordinates use of edge application server 154 . Edge-enabled servers 156 may coordinate with each other via the EDGE-9 interface.

圖2是示出適於實現各個實施例中的任何實施例的示例計算和無線數據機系統200的部件方塊圖。各個實施例可在包括片上系統(SOC)或系統級封裝(SIP)的多個單一處理器和多處理器電腦系統上實現。FIG. 2 is a block diagram illustrating components of an example computing and wireless modem system 200 suitable for implementing any of the various embodiments. Various embodiments may be implemented on a number of single-processor and multi-processor computer systems including systems on a chip (SOC) or system-in-package (SIP).

參考圖1A-2,所示出的示例計算系統200(在一些實施例中,其可為SIP)包括:兩個SOC 202、204,其耦合到時鐘206;電壓調節器208;及無線收發機266,其被配置為經由天線(未圖示)向UE(如基地台110a)發送無線通訊/經由天線從其接收無線通訊。在一些實施方式中,第一SOC 202可作為UE的中央處理單元(CPU)進行操作,其經由執行由軟體應用程式的指令指定的算術、邏輯、控制和輸入/輸出(I/O)操作來執行該等指令。在一些實施方式中,第二SOC 204可作為專用處理單元進行操作。例如,第二SOC 204可作為專用5G處理單元進行操作,其負責管理大容量、高速度(如5 Gbps等)或極高頻率短波長(如28 GHz毫米波頻譜等)的通訊。Referring to Figures 1A-2, an example computing system 200 is shown (which may be a SIP in some embodiments) including: two SOCs 202, 204 coupled to a clock 206; a voltage regulator 208; and a wireless transceiver 266, which is configured to send/receive wireless communication to/from the UE (eg, base station 110a) via an antenna (not shown). In some implementations, the first SOC 202 can operate as the central processing unit (CPU) of the UE by executing arithmetic, logic, control, and input/output (I/O) operations specified by instructions of a software application. carry out such instructions. In some implementations, the second SOC 204 can operate as a dedicated processing unit. For example, the second SOC 204 can operate as a dedicated 5G processing unit responsible for managing high-capacity, high-speed (eg, 5 Gbps, etc.) or very high-frequency short-wavelength (eg, 28 GHz mmWave spectrum, etc.) communications.

第一SOC 202可包括數位信號處理器(DSP)210、數據機處理器212、圖形處理器214、應用處理器216、連接到該等處理器中的一者或多者的一或多個輔助處理器218(如向量輔助處理器)、記憶體220、定製電路222、系統部件和資源224、互連/匯流排模組226、一或多個溫度感測器230、熱管理單元232和熱功率包絡(TPE)部件234。第二SOC 204可包括5G數據機處理器252、功率管理單元254、互連/匯流排模組264、多個毫米波收發機256、記憶體258和各種額外的處理器260(如應用處理器、封包處理器等)。The first SOC 202 may include a digital signal processor (DSP) 210, a modem processor 212, a graphics processor 214, an application processor 216, one or more auxiliary processor 218 (e.g., vector coprocessor), memory 220, custom circuitry 222, system components and resources 224, interconnect/bus module 226, one or more temperature sensors 230, thermal management unit 232, and thermal power envelope (TPE) component 234 . The second SOC 204 may include a 5G modem processor 252, a power management unit 254, an interconnect/bus module 264, multiple mmWave transceivers 256, memory 258, and various additional processors 260 (such as application processors , packet processor, etc.).

每個處理器210、212、214、216、218、252、260可包括一或多個核,並且每個處理器/核可獨立於其他處理器/核來執行操作。例如,第一SOC 202可包括執行第一類型的作業系統(如FreeBSD、LINUX、OS X等)的處理器和執行第二類型的作業系統(如MICROSOFT WINDOWS 10)的處理器。另外,處理器210、212、214、216、218、252、260中的任何一者或全部可被包括為處理器集群架構(例如,同步處理器集群架構、非同步或異構處理器集群架構等)的一部分。Each processor 210, 212, 214, 216, 218, 252, 260 may include one or more cores, and each processor/core may perform operations independently of the other processors/cores. For example, the first SOC 202 may include a processor executing a first type of operating system (such as FreeBSD, LINUX, OS X, etc.) and a processor executing a second type of operating system (such as MICROSOFT WINDOWS 10). Additionally, any or all of the processors 210, 212, 214, 216, 218, 252, 260 may be included in a processor cluster architecture (e.g., a synchronous processor cluster architecture, an asynchronous or heterogeneous processor cluster architecture etc.) part.

第一SOC 202和第二SOC 204可包括各種系統部件、資源和定製電路,其用於管理感測器資料、類比數位轉換、無線資料傳輸及用於執行其他專用操作,如解碼資料封包和處理經編碼的音訊和視訊信號以在web瀏覽器中呈現。例如,第一SOC 202的系統部件和資源224可包括功率放大器、電壓調節器、振盪器、鎖相迴路、周邊橋、資料控制器、記憶體控制器、系統控制器、存取埠、計時器和用於支援在UE上執行的處理器和軟體客戶端的其他類似部件。系統部件和資源224或定製電路222亦可包括與周邊設備(如相機、電子顯示器、無線通訊設備、外部記憶體晶片等)對接的電路。The first SOC 202 and the second SOC 204 may include various system components, resources, and custom circuits for managing sensor data, analog-to-digital conversion, wireless data transfer, and for performing other specialized operations, such as decoding data packets and Process encoded audio and video signals for presentation in a web browser. For example, system components and resources 224 of the first SOC 202 may include power amplifiers, voltage regulators, oscillators, phase locked loops, peripheral bridges, data controllers, memory controllers, system controllers, access ports, timers and other similar components for supporting processors and software clients executing on UEs. System components and resources 224 or custom circuits 222 may also include circuits that interface with peripheral devices (eg, cameras, electronic displays, wireless communication devices, external memory chips, etc.).

第一SOC 202和第二SOC 204可經由互連/匯流排模組250進行通訊。各種處理器210、212、214、216、218可經由互連/匯流排模組226互連到一或多個記憶體元件220、系統部件和資源224、及定製電路222、及熱管理單元232。類似地,處理器252可經由互連/匯流排模組264互連到功率管理單元254、毫米波收發機256、記憶體258和各種額外的處理器260。互連/匯流排模組226、250、264可包括可重配置的邏輯閘的陣列或實現匯流排架構(如CoreConnect、AMBA等)。可經由高級互連(如高效能片上網路(NoC))提供通訊。The first SOC 202 and the second SOC 204 can communicate via the interconnect/bus module 250 . The various processors 210, 212, 214, 216, 218 may be interconnected via an interconnect/bus module 226 to one or more memory elements 220, system components and resources 224, and custom circuitry 222, and a thermal management unit 232. Similarly, processor 252 may be interconnected to power management unit 254 , mmWave transceiver 256 , memory 258 and various additional processors 260 via interconnect/bus module 264 . The interconnect/bus modules 226, 250, 264 may include arrays of reconfigurable logic gates or implement a bus architecture (eg, CoreConnect, AMBA, etc.). Communications can be provided via advanced interconnects such as high performance on-chip networks (NoCs).

第一SOC 202或第二SOC 204亦可包括用於與在SOC外部的資源(如時鐘206和電壓調節器208)進行通訊的輸入/輸出模組(未圖示)。在SOC外部的資源(如時鐘206、電壓調節器208)可由內部SOC處理器/核中的兩者或更多者共用。The first SOC 202 or the second SOC 204 may also include an input/output module (not shown) for communicating with resources external to the SOC, such as the clock 206 and the voltage regulator 208 . Resources external to the SOC (eg clock 206, voltage regulator 208) may be shared by two or more of the internal SOC processors/cores.

除了以上論述的示例SIP 200之外,一些實現可在多種多樣的計算系統中實現,其可包括單個處理器、多個處理器、多核處理器,或其任何組合。In addition to the example SIP 200 discussed above, some implementations may be implemented in a wide variety of computing systems, which may include a single processor, multiple processors, multi-core processors, or any combination thereof.

圖3是示出適於實現各個實施例中的任何實施例的軟體架構300的部件方塊圖,軟體架構300包括用於無線通訊中的使用者和控制平面的無線電協定堆疊。參考圖1A-3,UE 320可實現軟體架構300以促進UE 320(例如,UE 120a-120e、200)與通訊系統(例如,100)中的網路裝置350(例如,邊緣網路142中的網路裝置142a)之間的通訊。在各個實施例中,軟體架構300中的層可形成與網路裝置350的軟體中的對應層的邏輯連接。軟體架構300可分佈在一或多個處理器(例如,處理器212、214、216、218、252、260)之間。儘管關於一個無線電協定堆疊進行了說明,但是在多SIM(使用者身份模組)UE中,軟體架構300可包括多個協定堆疊,其中每個協定堆疊可與不同的SIM相關聯(例如,分別與雙SIM無線通訊設備中的兩個SIM相關聯的兩個協定堆疊)。儘管下文參照LTE通訊層進行了描述,但是軟體架構300可支援用於無線通訊的各種標準和協定中的任何一種,及/或可包括支援用於無線通訊的各種標準和協定中的任何一種的額外協定堆疊。3 is a block diagram illustrating components of a software architecture 300 suitable for implementing any of the various embodiments, the software architecture 300 including a radio protocol stack for user and control planes in wireless communications. 1A-3, UE 320 can implement software architecture 300 to facilitate communication between UE 320 (eg, UE 120a-120e, 200) and network device 350 (eg, in edge network 142) in communication system (eg, 100). communication between network devices 142a). In various embodiments, layers in the software architecture 300 may form logical connections with corresponding layers in the software of the network device 350 . Software architecture 300 may be distributed among one or more processors (eg, processors 212, 214, 216, 218, 252, 260). Although described with respect to one radio protocol stack, in a multi-SIM (Subscriber Identity Module) UE, the software architecture 300 may include multiple protocol stacks, where each protocol stack may be associated with a different SIM (e.g., respectively Two protocol stacks associated with two SIMs in a dual SIM wireless communication device). Although described below with reference to the LTE communication layer, the software architecture 300 may support and/or may include support for any of the various standards and protocols for wireless communications Additional protocol stacks.

軟體架構300可包括非存取層(NAS)302和存取層(AS)304。NAS 302可包括用於支援UE的SIM(如SIM 204)與其核心網路140之間的封包過濾、安全管理、行動性控制、通信期管理及訊務和信號傳遞的功能和協定。AS 304可包括支援SIM(如SIM 204)與所支援的存取網路的實體(如基地台)之間的通訊的功能和協定。具體地,AS 304可包括至少三個層(層1、層2和層3),其中每個層可包含各種子層。The software architecture 300 may include a non-access layer (NAS) 302 and an access layer (AS) 304 . NAS 302 may include functions and protocols to support packet filtering, security management, mobility control, session management, and traffic and signaling between a UE's SIM (eg, SIM 204 ) and its core network 140 . AS 304 may include functions and protocols to support communication between SIMs, such as SIM 204, and supported entities accessing the network, such as base stations. Specifically, AS 304 may include at least three layers (Layer 1, Layer 2, and Layer 3), where each layer may contain various sub-layers.

在使用者和控制平面中,AS 304的層1(L1)可為實體層(PHY)306,其可監督經由無線收發機(例如,266)在空中介面上實現發送或接收的功能。此種實體層306功能的示例可包括循環冗餘檢查(CRC)附加、編碼塊、加擾和解擾、調變和解調、信號量測、MIMO等。實體層可包括各種邏輯通道,包括實體下行鏈路控制通道(PDCCH)和實體下行鏈路共享通道(PDSCH)。In the user and control plane, layer 1 (L1) of AS 304 may be a physical layer (PHY) 306, which may oversee the function of transmitting or receiving over the air interface via a wireless transceiver (eg, 266). Examples of such physical layer 306 functions may include cyclic redundancy check (CRC) appending, coding blocks, scrambling and descrambling, modulation and demodulation, signal measurements, MIMO, and the like. The physical layer may include various logical channels, including a physical downlink control channel (PDCCH) and a physical downlink shared channel (PDSCH).

在使用者和控制平面中,AS 304的層2(L2)可負責在UE 320與網路裝置350之間在實體層306之上的鏈路。在一些實施方式中,層2可包括媒體存取控制(MAC)子層308、無線電鏈路控制(RLC)子層310、封包資料彙聚協定(PDCP)312子層及服務資料適配協定(SDAP)317子層,其中每一者形成在網路裝置350處端接的邏輯連接。Layer 2 (L2) of AS 304 may be responsible for the link between UE 320 and network device 350 above physical layer 306 in the user and control planes. In some embodiments, Layer 2 may include a Media Access Control (MAC) sublayer 308, a Radio Link Control (RLC) sublayer 310, a Packet Data Convergence Protocol (PDCP) 312 sublayer, and a Service Data Adaptation Protocol (SDAP) sublayer. ) 317 sublayers, each of which forms a logical connection terminated at network device 350 .

在控制平面中,AS 304的層3(L3)可包括無線電資源控制(RRC)子層3。儘管未圖示,但是軟體架構300可包括額外的層3子層及在層3之上的各種上層。在一些實施方式中,RRC子層313可提供包括以下各項的功能:廣播系統資訊、傳呼、及在UE 320與網路裝置350之間建立和釋放RRC信號傳遞連接。In the control plane, Layer 3 (L3) of AS 304 may include a Radio Resource Control (RRC) sublayer 3 . Although not shown, software architecture 300 may include additional Layer 3 sub-layers and various upper layers above Layer 3 . In some embodiments, the RRC sublayer 313 may provide functions including broadcasting system information, paging, and establishing and releasing an RRC signaling connection between the UE 320 and the network device 350 .

在各個實施例中,SDAP子層317可提供服務品質(QoS)流與資料無線電承載(DRB)之間的映射。在一些實施方式中,PDCP子層312可提供上行鏈路功能,包括不同的無線電承載與邏輯通道之間的多工、序號添加、交遞資料處理、完整性保護、加密和標頭壓縮。在下行鏈路中,PDCP子層312可提供包括以下各項的功能:資料封包的按順序遞送、重複資料封包偵測、完整性驗證、解密和標頭解壓縮。In various embodiments, the SDAP sublayer 317 may provide mapping between quality of service (QoS) flows and data radio bearers (DRBs). In some embodiments, the PDCP sublayer 312 may provide uplink functions including multiplexing between different radio bearers and logical channels, sequence number addition, handover data handling, integrity protection, encryption and header compression. In the downlink, the PDCP sublayer 312 may provide functions including in-sequence delivery of data packets, duplicate data packet detection, integrity verification, decryption, and header decompression.

在上行鏈路中,RLC子層310可提供上層資料封包的分段和串接、丟失資料封包的重傳及自動重傳請求(ARQ)。而在下行鏈路中,RLC子層310功能可包括資料封包的重排序以補償無序接收、上層資料封包的重新組裝及ARQ。In the uplink, the RLC sublayer 310 may provide segmentation and concatenation of upper layer data packets, retransmission of lost data packets, and automatic repeat request (ARQ). While in the downlink, RLC sublayer 310 functions may include data packet reordering to compensate for out-of-order reception, upper layer data packet reassembly, and ARQ.

在上行鏈路中,MAC子層308可提供包括以下各項的功能:邏輯通道與傳輸通道之間的多工、隨機存取程序、邏輯通道優先順序和混合ARQ(HARQ)操作。在下行鏈路中,MAC層功能可包括細胞內的通道映射、解多工、不連續接收(DRX)和HARQ操作。In the uplink, the MAC sublayer 308 may provide functions including multiplexing between logical lanes and transport lanes, random access procedures, logical lane prioritization, and hybrid ARQ (HARQ) operation. In the downlink, MAC layer functions may include intracellular channel mapping, demultiplexing, discontinuous reception (DRX) and HARQ operations.

儘管軟體架構300可提供用於經由實體媒體來發送資料的功能,但是軟體架構300亦可包括至少一個主機層314,以向UE 320中的各種應用提供資料傳輸服務。在一些實施方式中,由至少一個主機層314提供的特定於應用的功能可提供軟體架構與通用處理器206之間的介面。Although the software architecture 300 may provide functions for transmitting data via physical media, the software architecture 300 may also include at least one host layer 314 to provide data transmission services to various applications in the UE 320 . In some implementations, application-specific functionality provided by at least one host layer 314 may provide an interface between the software architecture and the general-purpose processor 206 .

在其他實施方式中,軟體架構300可包括提供主機層功能的一或多個較高邏輯層(如傳輸、通信期、呈現、應用等)。例如,在一些實施方式中,軟體架構300可包括其中邏輯連接在封包資料網路(PDN)閘道(PGW)處端接的網路層(如網際網路協定(IP)層)。在一些實施方式中,軟體架構300可包括其中邏輯連接在另一設備(如最終使用者設備、伺服器等)處端接的應用層。在一些實施方式中,軟體架構300亦可在AS 304中包括實體層306與通訊硬體(如一或多個射頻(RF)收發機)之間的硬體介面316。In other embodiments, the software architecture 300 may include one or more higher logic layers (eg, transport, communication, presentation, application, etc.) that provide host layer functionality. For example, in some implementations, the software architecture 300 may include a network layer (eg, an Internet Protocol (IP) layer) where logical connections are terminated at a packet data network (PDN) gateway (PGW). In some implementations, the software architecture 300 may include an application layer where a logical connection terminates at another device (eg, an end user device, server, etc.). In some embodiments, the software architecture 300 may also include a hardware interface 316 in the AS 304 between the physical layer 306 and communication hardware, such as one or more radio frequency (RF) transceivers.

圖4A和4B是示出根據各個實施例的被配置用於增強用於初始存取的覆蓋的系統400的部件方塊圖。參考圖1A-4B,系統400可包括UE 402(例如,120a-120e、170、320)和網路裝置404(例如,142a、154、156、158、350)。在一些實施例中,UE 402和網路裝置404可交換無線通訊以便建立無線通訊鏈路(例如,122)。4A and 4B are block diagrams illustrating components of a system 400 configured to enhance coverage for initial access, according to various embodiments. Referring to Figures 1A-4B, a system 400 may include a UE 402 (eg, 120a-120e, 170, 320) and a network device 404 (eg, 142a, 154, 156, 158, 350). In some embodiments, UE 402 and network device 404 may exchange wireless communications to establish a wireless communication link (eg, 122 ).

UE 402和網路裝置404可包括耦合到電子儲存裝置426、430和無線收發機(例如,266)的一或多個處理器428、432。在UE 402和網路裝置404中,無線收發機266可被配置為接收在傳輸中發送的訊息,並且將此種訊息傳遞給處理器428、432以進行處理。類似地,處理器428、432可被配置為將用於傳輸的訊息發送給無線收發機266以進行傳輸。The UE 402 and network device 404 may include one or more processors 428, 432 coupled to electronic storage devices 426, 430 and wireless transceivers (eg, 266). In UE 402 and network device 404, wireless transceiver 266 may be configured to receive messages sent in transmission and pass such messages to processors 428, 432 for processing. Similarly, the processors 428, 432 may be configured to send a message for transmission to the wireless transceiver 266 for transmission.

參考UE 402,處理器432可由機器可讀取指令434來配置。機器可讀取指令406可包括一或多個指令模組。指令模組可包括電腦程式模組。指令模組可包括新鮮度參數模組436、唯一通信期金鑰模組438、TX/RX模組440及/或其他指令模組中的一者或多者。Referring to UE 402 , processor 432 may be configured by machine-readable instructions 434 . Machine-readable instructions 406 may include one or more instruction modules. The command module may include a computer program module. The command module may include one or more of the freshness parameter module 436 , the unique communication period key module 438 , the TX/RX module 440 and/or other command modules.

新鮮度參數模組436可被配置為產生新鮮度參數。在一些實施例中,新鮮度參數模組436可在UE 402的安全牽引客戶端(如GBA客戶端)內執行。在一些實施例中,新鮮度參數模組436使用亂數產生器來產生亂數以用作新鮮度參數。在一些實施例中,新鮮度參數模組436使用計數器來產生亂數值以用作新鮮度參數。The freshness parameter module 436 may be configured to generate a freshness parameter. In some embodiments, the freshness parameter module 436 may execute within a secure pull client (eg, a GBA client) of the UE 402 . In some embodiments, the freshness parameter module 436 uses a random number generator to generate a nonce for use as the freshness parameter. In some embodiments, the freshness parameter module 436 uses a counter to generate random values for use as the freshness parameter.

唯一通信期金鑰模組438可被配置為基於第一通信期金鑰和新鮮度參數來產生唯一通信期金鑰。在一些實施例中,新鮮度參數可與UE 402的特定應用相關聯。在一些實施例中,第一通信期金鑰可與UE 402相關聯。在一些實施例中,唯一通信期金鑰可與UE 402的特定應用相關聯。The unique session key module 438 may be configured to generate a unique session key based on the first session key and the freshness parameter. In some embodiments, a freshness parameter may be associated with a particular application of UE 402 . In some embodiments, a first session key may be associated with UE 402 . In some embodiments, a unique session key may be associated with a particular application of UE 402 .

TX/RX模組440可被配置為實現與網路裝置404的通訊,例如經由無線收發機266。The TX/RX module 440 can be configured to communicate with the network device 404 , such as via the wireless transceiver 266 .

TX/RX模組440可被配置為在將使得NAF能夠產生唯一通信期金鑰的配置中向網路裝置404的NAF發送新鮮度參數(例如,經由無線收發機266)。TX/RX模組440可被配置為使用唯一通信期金鑰與網路裝置404進行通訊。TX/RX模組440可被配置為從NAF接收用於啟動安全通訊的請求,該請求包括NAF的網域名稱和安全協定識別符。TX/RX module 440 may be configured to send the freshness parameter to the NAF of network device 404 (eg, via wireless transceiver 266 ) in a configuration that will enable the NAF to generate a unique session key. The TX/RX module 440 can be configured to communicate with the network device 404 using a unique session key. The TX/RX module 440 may be configured to receive a request from the NAF for initiating secure communication, the request including the NAF's domain name and security protocol identifier.

參考網路裝置404,處理器428可由機器可讀取指令406來配置。機器可讀取指令406可包括一或多個指令模組。指令模組可包括電腦程式模組。指令模組可包括新鮮度參數模組408、唯一通信期金鑰模組410、發送/接收(TX/RX)模組412及/或其他指令模組中的一者或多者。Referring to network device 404 , processor 428 may be configured by machine readable instructions 406 . Machine-readable instructions 406 may include one or more instruction modules. The command module may include a computer program module. The command module may include one or more of the freshness parameter module 408 , the unique session key module 410 , the transmit/receive (TX/RX) module 412 and/or other command modules.

新鮮度參數模組408可被配置為從UE 402接收新鮮度參數。Freshness parameter module 408 may be configured to receive a freshness parameter from UE 402 .

唯一通信期金鑰模組410可被配置為從網路裝置404的KSF接收第一通信期金鑰。唯一通信期金鑰模組410可被配置為基於新鮮度參數和第一通信期金鑰來產生唯一通信期金鑰。The unique session key module 410 may be configured to receive a first session key from the KSF of the network device 404 . The unique session key module 410 may be configured to generate a unique session key based on the freshness parameter and the first session key.

TX/RX模組412可被配置為使用唯一通信期金鑰(例如,經由無線收發機266)與UE 402進行通訊。TX/RX模組412可被配置為向UE 402發送用於啟動安全通訊的請求,該請求包括NAF的網域名稱和安全協定識別符。TX/RX module 412 may be configured to communicate with UE 402 using a unique communication session key (eg, via wireless transceiver 266). The TX/RX module 412 may be configured to send a request to the UE 402 for initiating secure communication, the request including the domain name of the NAF and the security protocol identifier.

在一些實施例中,UE 402和網路裝置404可經由一或多個無線通訊鏈路(例如,無線通訊鏈路122)操作性地連結。將理解,此並非意欲進行限制,本案內容的範圍包括其中UE 402和網路裝置404可經由某種其他通訊媒體操作性地連結的實施例。In some embodiments, UE 402 and network device 404 may be operatively coupled via one or more wireless communication links (eg, wireless communication link 122 ). It will be understood that this is not intended to be limiting and that the scope of the present disclosure includes embodiments in which UE 402 and network device 404 may be operatively linked via some other communication medium.

電子儲存裝置426、430可包括電子地儲存資訊的非暫時性儲存媒體。電子儲存裝置426、430的電子儲存媒體可包括以下各者中的一者或兩者:與UE 402和網路裝置404整體地提供(即基本上不可移除)的系統儲存裝置;及/或可移除儲存裝置,可移除儲存裝置經由例如埠(例如,通用序列匯流排(USB)埠、火線埠等)或驅動器(例如,磁碟機等)可移除地連接到UE 402和網路404。電子儲存裝置426、430可包括以下各者中的一者或多者:光學可讀儲存媒體(例如,光碟等)、磁性可讀儲存媒體(例如,磁帶、磁性硬碟、軟碟機等)、基於電荷的儲存媒體(例如,EEPROM、RAM等)、固態儲存媒體(例如,快閃記憶體驅動器等)及/或其他電子可讀儲存媒體。電子儲存裝置426、430可包括一或多個虛擬儲存資源(例如,雲儲存、虛擬私有網路及/或其他虛擬儲存資源)。電子儲存裝置426、430可儲存軟體演算法、由處理器428、432決定的資訊、從UE 402和網路裝置404接收的資訊,或者使得UE 403和網路裝置40能夠如本文描述地執行的其他資訊。Electronic storage devices 426, 430 may include non-transitory storage media that store information electronically. The electronic storage media of electronic storage devices 426, 430 may include one or both of: system storage provided integrally (ie, substantially non-removable) with UE 402 and network device 404; and/or A removable storage device that is removably connected to the UE 402 and the network via, for example, a port (e.g., a Universal Serial Bus (USB) port, a FireWire port, etc.) or a drive (e.g., a disk drive, etc.) Road 404. Electronic storage devices 426, 430 may include one or more of the following: optically readable storage media (e.g., optical discs, etc.), magnetically readable storage media (e.g., magnetic tape, magnetic hard disks, floppy drives, etc.) , charge-based storage media (eg, EEPROM, RAM, etc.), solid-state storage media (eg, flash memory drives, etc.), and/or other electronically readable storage media. Electronic storage devices 426, 430 may include one or more virtual storage resources (eg, cloud storage, virtual private network, and/or other virtual storage resources). Electronic storage devices 426, 430 may store software algorithms, information determined by processors 428, 432, information received from UE 402 and network device 404, or to enable UE 403 and network device 40 to execute as described herein other information.

處理器428、432可被配置為在UE 402和網路裝置404中提供資訊處理能力。因此,處理器428、432可包括以下各者中的一或更多者:數位處理器、類比處理器、被設計為處理資訊的數位電路、被設計為處理資訊的類比電路、狀態機,及/或用於電子地處理資訊的其他機制。儘管處理器428、432被示為單個實體,但是此僅用於說明性目的。在一些實施例中,處理器428、432可包括複數個處理單元及/或處理器核心。處理單元可實體地位於相同的裝置內,或者處理器428、432可表示協同地操作的複數個裝置的處理功能。處理器428、432可被配置為經由以下各項來執行模組408-412、模組436-440及/或其他模組:軟體;硬體;韌體;軟體、硬體及/或韌體的某種組合;及/或用於配置處理器428、432上的處理能力的其他機制。如本文所使用的,術語「模組」可指示執行歸屬於該模組的功能的任何部件或部件集。此可包括在執行處理器可讀取指令期間的一或多個實體處理器、處理器可讀取指令、電路、硬體、儲存媒體或任何其他部件。Processors 428 , 432 may be configured to provide information processing capabilities in UE 402 and network device 404 . Accordingly, the processors 428, 432 may include one or more of the following: digital processors, analog processors, digital circuits designed to process information, analog circuits designed to process information, state machines, and and/or other mechanisms for electronically processing information. Although processors 428, 432 are shown as a single entity, this is for illustrative purposes only. In some embodiments, the processors 428, 432 may include a plurality of processing units and/or processor cores. The processing units may be physically located within the same device, or the processors 428, 432 may represent the processing functionality of a plurality of devices operating in concert. Processors 428, 432 may be configured to execute modules 408-412, modules 436-440, and/or other modules via: software; hardware; firmware; software, hardware, and/or firmware and/or other mechanisms for configuring processing capabilities on the processors 428, 432. As used herein, the term "module" may refer to any component or collection of components that performs the functionality attributed to the module. This may include one or more physical processors, processor-readable instructions, circuits, hardware, storage media, or any other component during execution of processor-readable instructions.

對由下文描述的不同模組408-412和模組436-440提供的功能的描述是出於說明性目的,而並不意欲進行限制,因為模組408-412和模型436-440中的任何一者皆可提供比所描述的更多或更少的功能。例如,模組408-412和模組436-440中的一者或多者可被消除,其功能中的一些或所有功能可由其他模組408-412和模型436-440來提供。作為另一實例,處理器428、432可被配置為執行一或多個額外模組,該等模組可執行下文歸屬於模組408-412和模組436-440之一的功能的一些或所有功能。The description of the functionality provided by the various modules 408-412 and modules 436-440 described below is for illustrative purposes and is not intended to be limiting, as any of the modules 408-412 and models 436-440 Either may provide more or less functionality than described. For example, one or more of modules 408-412 and modules 436-440 may be eliminated and some or all of their functionality may be provided by other modules 408-412 and models 436-440. As another example, processors 428, 432 may be configured to execute one or more additional modules that may perform some or all of the functions ascribed below to one of modules 408-412 and modules 436-440. All functions.

圖5A是示出適於與各個實施例一起使用的用於牽引應用安全的示例系統500a的方塊圖。參考圖1A-5A,系統500a可包括UE 502、NAF 504、金鑰伺服器功能(KSF)506、家庭使用者伺服器(HSS)508和使用者定位器功能(SLF)510。FIG. 5A is a block diagram illustrating an example system 500a for towing application safety suitable for use with various embodiments. Referring to FIGS. 1A-5A , system 500a may include UE 502 , NAF 504 , Key Server Function (KSF) 506 , Home Subscriber Server (HSS) 508 and Subscriber Locator Function (SLF) 510 .

在各個實施例中,UE 502和KSF 506可執行認證操作以對UE 202進行認證。在一些實施例中,KSF 506和UE 502之間的協商可經由Ub介面來執行認證操作,並且可採用諸如AKA之類的協定。UE 502可經由Ua介面與NAF 504進行通訊。在各個實施例中,UE 502和NAF 504可能沒有先前的安全關聯。UE 502可產生第一通信期金鑰,例如Ks_NAF。NAF 504可經由Zn介面來從KSF 506接收第一通信期金鑰(例如,Ks_NAF)。In various embodiments, UE 502 and KSF 506 may perform authentication operations to authenticate UE 202 . In some embodiments, the negotiation between KSF 506 and UE 502 may perform authentication operations via the Ub interface, and may employ a protocol such as AKA. UE 502 can communicate with NAF 504 via Ua interface. In various embodiments, UE 502 and NAF 504 may have no previous security association. UE 502 may generate a first session key, such as Ks_NAF. NAF 504 may receive a first session key (eg, Ks_NAF) from KSF 506 via the Zn interface.

HSS 508可充當資料庫或其他合適的資料儲存裝置,其可儲存用於UE 502的使用者認證憑證,如使用者安全設定(USS)(例如,GBA使用者安全設定(GUSS))。在一些實施例中,HSS 508可將使用者認證憑證映射到私有標識,如IP多媒體私有標識(IMPI)。HSS 508可經由Zh介面來將該資訊和其他資訊傳送給KSF 506。SLF 510可儲存並且提供用於標識儲存關於UE 502(即關於特定UE)的資訊的HSS 508的資訊。KSF 506和SLF 510可經由Dz介面進行通訊。HSS 508 may act as a database or other suitable data store that may store user authentication credentials, such as user security settings (USS) (eg, GBA user security settings (GUSS)) for UE 502 . In some embodiments, HSS 508 may map user authentication credentials to a private identity, such as an IP Multimedia Private Identity (IMPI). HSS 508 may communicate this and other information to KSF 506 via the Zh interface. SLF 510 may store and provide information identifying HSS 508 that stores information about UE 502 (ie, about a particular UE). KSF 506 and SLF 510 can communicate via Dz interface.

圖5B是示出根據各個實施例的可在用於保護通訊的方法500b期間在UE和網路裝置之間交換的通訊的訊息流程圖。參考圖1A-5B,在一些實施例中,UE 520(例如,120a-120e、170、320、404、502)和網路裝置526(例如,142a、154、156、158、350、402)可經由無線通訊網路進行通訊,上文參考圖1A和1B描述了無線通訊網路的各態樣。UE 520可包括GBA客戶端522和應用客戶端420。網路裝置526可包括NAF 528和KSF 530。Figure 5B is a message flow diagram illustrating communications that may be exchanged between a UE and a network device during a method 500b for securing communications, according to various embodiments. 1A-5B, in some embodiments, UE 520 (eg, 120a-120e, 170, 320, 404, 502) and network device 526 (eg, 142a, 154, 156, 158, 350, 402) may Communication is performed via a wireless communication network, various aspects of which are described above with reference to FIGS. 1A and 1B . UE 520 may include GBA client 522 and application client 420 . Network device 526 may include NAF 528 and KSF 530 .

NAF 528可可選地向GBA客戶端522發送請求訊息532。訊息532可包括用於啟動安全通訊的請求,該請求包括NAF的網域名稱(例如,FQDN)和安全協定識別符(例如,Ua安全協定識別符)。在一些實施例中,安全協定識別符可實現針對不同的協定產生不同的金鑰。在一些實施例中,每個金鑰可限於一次使用。在一些實施例中,NAF的網域名稱可使得金鑰對於NAF 528是唯一的。NAF 528 may optionally send request message 532 to GBA client 522 . Message 532 may include a request to initiate secure communication, the request including the NAF's domain name (eg, FQDN) and security protocol identifier (eg, Ua security protocol identifier). In some embodiments, the security protocol identifier enables different keys to be generated for different protocols. In some embodiments, each key may be limited to one use. In some embodiments, the domain name of the NAF may make the key unique to the NAF 528 .

在操作534中,GBA客戶端522可產生新鮮度參數。在一些實施例中,新鮮度參數可為或包括亂數或偽數位,諸如使用亂數產生演算法而產生的。在一些實施例中,新鮮度參數可為或包括遞增值,如每次需要新的唯一通信期金鑰(例如,用於新應用或應用的新實例化)時而遞增的計數器的值。在一些實施例中,遞增值可用作亂數值(例如,遞增的亂數值)。In operation 534, the GBA client 522 may generate a freshness parameter. In some embodiments, the freshness parameter may be or include nonces or pseudo-digits, such as generated using a nonce generation algorithm. In some embodiments, the freshness parameter may be or include an incremental value, such as the value of a counter that is incremented each time a new unique session key is required (eg, for a new application or new instantiation of an application). In some embodiments, incrementing values may be used as nonce values (eg, incrementing nonce values).

在操作536中,GBA客戶端522可基於第一通信期金鑰(例如,Ks_NAF)和新鮮度參數來產生唯一通信期金鑰(其可被稱為Ks_NAF_unique)。GBA客戶端522可在訊息538中向應用客戶端524發送新鮮度參數。In operation 536, the GBA client 522 may generate a unique session key (which may be referred to as Ks_NAF_unique) based on the first session key (eg, Ks_NAF) and the freshness parameter. GBA client 522 may send the freshness parameter to application client 524 in message 538 .

應用客戶端524可在訊息540中向NAF 528發送新鮮度參數。在一些實施例中,訊息540可包括網路服務請求訊息(例如,應用請求訊息)。在一些實施例中,網路服務請求訊息可包括牽引交易識別符(B-TID)。在一些實施例中,B-TID可用作第一通信期金鑰(例如,Ks_NAF)的識別符。Application client 524 may send the freshness parameter to NAF 528 in message 540 . In some embodiments, the message 540 may include a web service request message (eg, an application request message). In some embodiments, the web service request message may include a pull transaction identifier (B-TID). In some embodiments, the B-TID may be used as an identifier for the first session key (eg, Ks_NAF).

NAF 528可在訊息542中向KSF 530發送B-TID。在一些實施例中,訊息542亦可包括NAF識別符。在一些實施例中,訊息542可包括認證請求訊息。NAF 528 may send the B-TID to KSF 530 in message 542 . In some embodiments, message 542 may also include a NAF identifier. In some embodiments, message 542 may include an authentication request message.

KSF 530可在訊息544中向NAF 528發送第一通信期金鑰(例如,Ks_NAF)的版本。在一些實施例中,訊息544亦可包括與UE相關聯的應用特定識別符(例如,來自與UE相關聯的使用者簡檔)。在一些實施例中,訊息544可包括認證應答訊息。KSF 530 may send a version of the first term key (eg, Ks_NAF) to NAF 528 in message 544 . In some embodiments, the message 544 may also include an application specific identifier associated with the UE (eg, from a user profile associated with the UE). In some embodiments, the message 544 may include an authentication response message.

如前述,在各個實施例中,UE 520(例如,GBA客戶端522)和網路裝置526(例如,NAF 520)可在UE 520和網路裝置526之間的訊息的現有欄位中包括新鮮度參數,以賦能在不改變訊息或訊息交換的協定或架構的情況下實現各個實施例。例如,對於採用Digest AKA協定的裝置,新鮮度參數可被包括在「cnonce」欄位中。作為另一實例,對於採用傳輸層安全性(TLS)的裝置,新鮮度參數可被包括在ClientHello訊息或其他合適的訊息的現有欄位中。在一些實施例中,新鮮度參數的長度可被配置為適配在此種現有欄位及/或訊息內。在各個實施例中,GBA客戶端522可在與其他加密金鑰或通信期金鑰類似的安全級別及/或類似的受保護的記憶體部分中產生新鮮度參數。在各個實施例中,GBA客戶端522和NAF 528可在相應設備的安全記憶體中處置、使用、處理及/或儲存新鮮度參數及/或唯一通信期金鑰。As previously mentioned, in various embodiments, UE 520 (e.g., GBA client 522) and network device 526 (e.g., NAF 520) may include fresh degree parameters to enable implementation of various embodiments without changing the protocol or architecture of messages or message exchanges. For example, for devices employing the Digest AKA protocol, a freshness parameter may be included in the "cnonce" field. As another example, for devices employing Transport Layer Security (TLS), the freshness parameter may be included in an existing field of the ClientHello message or other suitable message. In some embodiments, the length of the freshness parameter may be configured to fit within such existing fields and/or messages. In various embodiments, the GBA client 522 may generate the freshness parameter at a similar security level and/or in a similarly protected portion of memory as other encryption keys or session keys. In various embodiments, the GBA client 522 and the NAF 528 may handle, use, process and/or store the freshness parameter and/or the unique session key in the secure memory of the respective devices.

在操作546中,NAF 528可基於從KSF 530接收的第一通信期金鑰和從UE 520接收的新鮮度參數來產生唯一通信期金鑰。因此,在操作546中,NAF能夠決定並且使用與由UE產生的相同的唯一通信期金鑰,而無需交換可能用於破壞由唯一通信期金鑰提供的加密安全性的任何私密金鑰或資訊,因為新鮮度參數僅一次用於產生在每個通訊通信期中改變的唯一通信期金鑰。In operation 546 , the NAF 528 may generate a unique session key based on the first session key received from the KSF 530 and the freshness parameter received from the UE 520 . Thus, in operation 546, the NAF is able to determine and use the same unique session key as generated by the UE without exchanging any private keys or information that could be used to break the cryptographic security provided by the unique session key , since the freshness parameter is only used once to generate a unique session key that changes in each session.

在操作548中,NAF 528可將所產生的唯一通信期金鑰儲存在NAF 528(或網路裝置526)的記憶體中,以供在通訊通訊期使用。In operation 548, the NAF 528 may store the generated unique session key in the memory of the NAF 528 (or the network device 526) for use during the communication session.

NAF 528可向應用客戶端524發送回應訊息550(例如,回應於訊息540,例如,應用請求訊息)。在一些實施例中,訊息550可包括應用應答訊息。NAF 528 may send response message 550 to application client 524 (eg, in response to message 540, eg, an application request message). In some embodiments, the message 550 may include an application response message.

UE 520(例如,應用客戶端524)和網路裝置526(例如,NAF 528)可使用唯一通信期金鑰來執行安全通訊552。如前述,唯一通信期金鑰對於UE 520的一個應用或服務可為唯一的。UE 520 (eg, application client 524 ) and network device 526 (eg, NAF 528 ) may perform secure communication 552 using a unique session key. As mentioned above, the unique session key may be unique to one application or service of the UE 520 .

圖6是示出根據各個實施例的可由UE的處理器執行的用於保護與網路元件的通訊的方法600的程序流程圖。參考圖1A-6,方法600的操作可由UE(例如,120a-120e、170、320、404、502、520)的處理器(如處理器210、212、214、216、218、252、260、432)來執行。FIG. 6 is a program flow diagram illustrating a method 600 executable by a processor of a UE for securing communications with network elements according to various embodiments. 1A-6, the operation of method 600 may be performed by a processor (such as processor 210, 212, 214, 216, 218, 252, 260, 432) to execute.

在可選方塊602中,處理器可從網路裝置的網路應用功能(NAF)接收用於啟動安全通訊的請求。在一些實施例中,該請求可包括NAF的網域名稱和安全協定識別符。用於執行可選方塊602的操作的手段可包括處理器210、212、214、216、218、252、260、432、無線收發機266、TX/RX模組440和GBA客戶端522。In optional block 602, the processor may receive a request from a network application function (NAF) of a network device to initiate a secure communication. In some embodiments, the request may include the NAF's domain name and security protocol identifier. Means for performing the operations of optional block 602 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , wireless transceiver 266 , TX/RX module 440 and GBA client 522 .

在方塊604中,處理器可產生新鮮度參數。在一些實施例中,新鮮度參數可為由在該處理器中或在UE的另一處理器(例如,在安全處理域中)中執行的安全牽引客戶端來產生的。在一些實施例中,新鮮度參數可與在UE中執行的特定應用或應用的特定實例化(例如,第一實例化、第二實例化等)相關聯。在一些實施例中,新鮮度參數可為或包括隨機值。在一些實施例中,新鮮度參數可包括或是遞增的亂數值。用於執行方塊604的操作的手段可包括處理器210、212、214、216、218、252、260、432、新鮮度參數模組436及/或GBA客戶端522。In block 604, the processor may generate a freshness parameter. In some embodiments, the freshness parameter may be generated by a secure pull client executing in the processor or in another processor of the UE (eg in a secure processing domain). In some embodiments, the freshness parameter may be associated with a specific application or a specific instantiation of an application (eg, a first instantiation, a second instantiation, etc.) executing in the UE. In some embodiments, the freshness parameter may be or include a random value. In some embodiments, the freshness parameter may comprise or increment a random value. Means for performing the operations of block 604 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , freshness parameter module 436 , and/or GBA client 522 .

在方塊606中,處理器可基於第一通信期金鑰和新鮮度參數來產生唯一通信期金鑰。例如,處理器可將第一通信期金鑰(例如,Ks_NAF)和新鮮度參數應用於金鑰產生演算法,以產生唯一通信期金鑰(例如,Ks_NAF_unique)。在一些實施例中,唯一通信期金鑰可與UE的特定應用相關聯,並且第一通信期金鑰可和UE相關聯。在一些實施例中,特定應用可為或可包括應用的特定實例化(例如,第一實例化、第二實例化等)。用於執行方塊606的操作的手段可包括處理器210、212、214、216、218、252、260、432、唯一通信期金鑰模組438和GBA客戶端522。In block 606, the processor may generate a unique session key based on the first session key and the freshness parameter. For example, the processor may apply the first session key (eg, Ks_NAF) and the freshness parameter to a key generation algorithm to generate a unique session key (eg, Ks_NAF_unique). In some embodiments, a unique session key may be associated with a particular application of the UE, and a first session key may be associated with the UE. In some embodiments, a particular application can be or include a particular instantiation of an application (eg, a first instantiation, a second instantiation, etc.). Means for performing the operations of block 606 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , unique session key module 438 , and GBA client 522 .

在方塊608中,處理器可在將使得NAF能夠產生唯一通信期金鑰的配置中向NAF(例如,504、528)發送新鮮度參數。在一些實施例中,處理器可在網路服務請求訊息(例如,應用請求訊息)中向NAF發送新鮮度參數。用於執行方塊608的操作的手段可包括處理器210、212、214、216、218、252、260、432、無線收發機266、TX/RX模組440和應用客戶端524。In block 608, the processor may send the freshness parameter to the NAF (eg, 504, 528) in a configuration that will enable the NAF to generate a unique session key. In some embodiments, the processor may send the freshness parameter to the NAF in a web service request message (eg, an application request message). Means for performing the operations of block 608 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , wireless transceiver 266 , TX/RX module 440 , and application client 524 .

在方塊610中,處理器可使用唯一通信期金鑰來與NAF進行通訊(例如,以加密被發送給NAF的訊息並且解密從NAF接收的訊息)。在一些實施例中,在處理器中執行的應用客戶端可執行與NAF的通訊。用於執行方塊610的操作的手段可包括處理器210、212、214、216、218、252、260、432、無線收發機266、TX/RX模組440和應用客戶端524。In block 610, the processor may use the unique session key to communicate with the NAF (eg, to encrypt messages sent to the NAF and to decrypt messages received from the NAF). In some embodiments, an application client executing in a processor may perform communication with the NAF. Means for performing the operations of block 610 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , wireless transceiver 266 , TX/RX module 440 and application client 524 .

圖7是示出根據各個實施例的可由網路裝置的處理器執行的用於保護與UE的通訊的方法700的程序流程圖。參考圖1A-7,方法700的操作可由網路裝置(例如,142a、154、156、158、350、404、526)的處理器(如處理器210、212、214、216、218、252、260、432)來執行。FIG. 7 is a process flow diagram illustrating a method 700 executable by a processor of a network device for securing communications with a UE according to various embodiments. 1A-7, the operations of method 700 may be performed by processors (eg, processors 210, 212, 214, 216, 218, 252, 260, 432) to execute.

在可選方塊702中,處理器可向UE發送用於啟動安全通訊的請求。在一些實施例中,該請求可包括NAF的網域名稱和安全協定識別符。用於執行可選方塊702的操作的手段可包括處理器210、212、214、216、218、252、260、432、無線收發機266、TX/RX模組440和NAF 528。In optional block 702, the processor may send a request to the UE to initiate secure communication. In some embodiments, the request may include the NAF's domain name and security protocol identifier. Means for performing the operations of optional block 702 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , wireless transceiver 266 , TX/RX module 440 and NAF 528 .

在方塊704中,NAF可從UE接收新鮮度參數。在一些實施例中,新鮮度參數可與UE的特定應用相關聯。在一些實施例中,特定應用可為或可包括應用的特定實例化(例如,第一實例化、第二實例化等)。在一些實施例中,新鮮度參數可為或包括隨機值。在一些實施例中,新鮮度參數可為或包括遞增的亂數值。用於執行方塊704的操作的手段可包括處理器210、212、214、216、218、252、260、432、無線收發機266、新鮮度參數模組408和NAF 528。In block 704, the NAF may receive a freshness parameter from the UE. In some embodiments, the freshness parameter may be associated with a particular application of the UE. In some embodiments, a particular application can be or include a particular instantiation of an application (eg, a first instantiation, a second instantiation, etc.). In some embodiments, the freshness parameter may be or include a random value. In some embodiments, the freshness parameter may be or include an incrementing random value. Means for performing the operations of block 704 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , wireless transceiver 266 , freshness parameter module 408 , and NAF 528 .

在方塊706中,處理器可從金鑰伺服器功能(KSF)接收第一通信期金鑰。在一些實施例中,第一通信期金鑰可與UE相關聯,例如,Ks_NAF通信期金鑰。用於執行方塊706的操作的手段可包括處理器210、212、214、216、218、252、260、432、唯一通信期金鑰模組410、NAF 528和KSF 506、530。In block 706, the processor may receive a first session key from a key server function (KSF). In some embodiments, a first session key may be associated with the UE, eg, a Ks_NAF session key. Means for performing the operations of block 706 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , unique session key module 410 , NAF 528 and KSF 506 , 530 .

在方塊708中,處理器可基於新鮮度參數和第一通信期金鑰來產生唯一通信期金鑰。例如,處理器可將新鮮度參數和第一通信期金鑰(例如,Ks_NAF)應用於與在方法600的方塊606中由UE使用的相同的金鑰產生演算法,以產生唯一通信期金鑰(如,Ks_NAF_unique),並且因此產生與由UE產生的相同的唯一通信期金鑰。在一些實施例中,唯一通信期金鑰可與UE的特定應用相關聯,並且第一通信期金鑰與UE相關聯。在一些實施例中,特定應用可為應用的特定實例化(例如,第一實例化、第二實例化等)。用於執行方塊706的操作的手段可包括處理器210、212、214、216、218、252、260、432、唯一通信期金鑰模組410、NAF 528。In block 708, the processor may generate a unique session key based on the freshness parameter and the first session key. For example, the processor may apply the freshness parameter and the first session key (e.g., Ks_NAF) to the same key generation algorithm as used by the UE in block 606 of method 600 to generate a unique session key (eg, Ks_NAF_unique), and thus generate the same unique session key as generated by the UE. In some embodiments, a unique session key may be associated with a particular application of the UE, and a first session key is associated with the UE. In some embodiments, a particular application may be a particular instantiation of an application (eg, a first instantiation, a second instantiation, etc.). Means for performing the operations of block 706 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , unique session key module 410 , NAF 528 .

在方塊710中,處理器可使用唯一通信期金鑰來與UE進行通訊,以加密被發送給UE的訊息並且解密從UE接收的訊息。用於執行方塊710的操作的手段可包括處理器210、212、214、216、218、252、260、432、無線收發機266、TX/RX模組440和NAF 528。In block 710, the processor may communicate with the UE using the unique session key to encrypt messages sent to the UE and decrypt messages received from the UE. Means for performing the operations of block 710 may include processors 210 , 212 , 214 , 216 , 218 , 252 , 260 , 432 , wireless transceiver 266 , TX/RX module 440 and NAF 528 .

圖8是適於與各個實施例一起使用的網路裝置800的部件方塊圖。此種網路裝置(例如,網路裝置142a、154、156、158、350、404、526)可至少包括在圖8中示出的部件。參考圖1A-8,網路裝置800通常可包括耦合到揮發性記憶體802和大容量非揮發性記憶體(如磁碟機808)的處理器801。網路裝置800亦可包括周邊記憶體存取裝置806,如耦合到處理器801的軟碟機、壓縮光碟(CD)或數位視訊光碟(DVD)驅動器。網路裝置800亦可包括耦合到處理器801的網路存取埠804(或介面),其用於與網路(如網際網路或耦合到其他系統電腦和伺服器的區域網路)建立資料連接。網路裝置800可包括可連接到無線通訊鏈路的用於發送和接收電磁輻射的一或多個天線807。網路裝置800可包括用於耦合到周邊設備、外部記憶體或其他設備的額外的存取埠,如USB、Firewire、Thunderbolt等。FIG. 8 is a block diagram of components of a network device 800 suitable for use with various embodiments. Such network devices (eg, network devices 142a, 154, 156, 158, 350, 404, 526) may include at least the components shown in FIG. 8 . Referring to FIGS. 1A-8 , a network device 800 may generally include a processor 801 coupled to a volatile memory 802 and a large capacity non-volatile memory (eg, a disk drive 808 ). The network device 800 may also include a peripheral memory access device 806 such as a floppy disk drive, compact disk (CD) or digital video disk (DVD) drive coupled to the processor 801 . The network device 800 may also include a network access port 804 (or interface) coupled to the processor 801 for establishing a network connection such as the Internet or a local area network coupled to other system computers and servers. data connection. Network device 800 may include one or more antennas 807 connectable to a wireless communication link for transmitting and receiving electromagnetic radiation. The network device 800 may include additional access ports such as USB, Firewire, Thunderbolt, etc. for coupling to peripheral devices, external memory or other devices.

圖9是適於與各個實施例一起使用的UE 900的部件方塊圖。參考圖1A-9,可在各種UE 900(例如,UE 120a-120e、170、320、402、502、520)上實現各個實施例,在圖9中以智慧型電話的形式圖示其實例。UE 900可包括第一SOC 202(例如,SOC-CPU),其耦合到第二SOC 204(例如,具有5G能力的SOC)。第一SOC 202和第二SOC 204可耦合到內部記憶體916、顯示器912及揚聲器914。另外,UE 900可包括用於發送和接收電磁輻射的天線904,其可連接到無線收發機266,無線收發機266耦合到第一SOC 202及/或第二SOC 204中的一或多個處理器。UE 900可包括用於接收使用者輸入的功能表選擇按鈕或翹板開關920。Figure 9 is a block diagram of components of a UE 900 suitable for use with various embodiments. Referring to Figures 1A-9, various embodiments may be implemented on various UEs 900 (eg, UEs 120a-120e, 170, 320, 402, 502, 520), an example of which is illustrated in Figure 9 in the form of a smartphone. The UE 900 may include a first SOC 202 (eg, SOC-CPU) coupled to a second SOC 204 (eg, a 5G capable SOC). First SOC 202 and second SOC 204 may be coupled to internal memory 916 , display 912 and speaker 914 . Additionally, the UE 900 may include an antenna 904 for transmitting and receiving electromagnetic radiation, which may be connected to a wireless transceiver 266 coupled to one or more processing devices in the first SOC 202 and/or the second SOC 204 device. UE 900 may include a menu selection button or rocker switch 920 for receiving user input.

UE 900可包括聲音編碼/解碼(CODEC)電路910,其將從麥克風接收的聲音數位化為適於無線傳輸的資料封包,並且對接收到的聲音封包進行解碼以產生類比信號,類比信號被提供給揚聲器以產生聲音。第一SOC 202和第二SOC 204中的處理器中的一或多個處理器、無線收發機266和CODEC 910可包括數位信號處理器(DSP)電路(未單獨示出)。The UE 900 may include a sound encoding/decoding (CODEC) circuit 910 that digitizes sound received from a microphone into data packets suitable for wireless transmission, and decodes the received sound packets to generate an analog signal, which is provided Give the speakers to produce sound. One or more of the processors in first SOC 202 and second SOC 204 , wireless transceiver 266 and CODEC 910 may include digital signal processor (DSP) circuitry (not separately shown).

網路裝置800和UE 900的處理器可為任何可程式設計微處理器、微型電腦,或一或多個多處理器晶片,其可由軟體指令(應用)配置為執行各種功能,包括下文描述的一些實現的功能。在一些UE中,可提供多個處理器,諸如專用於無線通訊功能的SOC 204內的一個處理器、及專用於執行其他應用的SOC 202內的一個處理器。在存取軟體應用並且將其載入到處理器之前,可將其其儲存在記憶體802、916中。處理器可包括足以儲存應用軟體指令的內部記憶體。The processors of network device 800 and UE 900 can be any programmable microprocessor, microcomputer, or one or more multiprocessor chips that can be configured by software instructions (applications) to perform various functions, including the Some implemented functions. In some UEs, multiple processors may be provided, such as one processor within SOC 204 dedicated to wireless communication functions and one processor within SOC 202 dedicated to executing other applications. The software application may be stored in memory 802, 916 before it is accessed and loaded into the processor. The processor may include internal memory sufficient to store application software instructions.

如本案中所使用的,術語「部件」、「模組」、「系統」等意欲包括電腦相關實體,諸如但不限於硬體、韌體、硬體和軟體的組合、軟體或者執行中的軟體,其被配置為執行特定操作或功能。例如,部件可為但不限於是:在處理器上執行的程序、處理器、物件、可執行檔、執行的執行緒、程式或電腦。經由說明的方式,在UE上執行的應用和UE兩者可被稱為部件。一或多個部件可位於程序或執行的執行緒中,並且部件可定位於一個處理器或核上或分佈在兩個或兩個以上處理器或核之間。另外,該等部件可從具有儲存在其上的各種指令或資料結構的各種非暫時性電腦可讀取媒體來執行。部件可經由本端或遠端程序、函數或程式撥叫、電子信號、資料封包、記憶體讀/寫及其他已知的與網路、電腦、處理器或程序相關的通訊方法的方式進行通訊。As used in this case, the terms "component", "module", "system" and the like are intended to include computer-related entities such as, but not limited to, hardware, firmware, a combination of hardware and software, software, or software in execution , which is configured to perform a specific operation or function. For example, a component may be, but is not limited to being, a program executing on a processor, a processor, an object, an executable, a thread of execution, a program, or a computer. By way of illustration, both an application executing on a UE and the UE may be referred to as a component. One or more components may reside within a program or thread of execution, and a component may be localized on one processor or core or distributed between two or more processors or cores. In addition, these components can execute from various non-transitory computer-readable media having various instructions or data structures stored thereon. Components can communicate via local or remote programs, function or program calls, electrical signals, data packets, memory read/write, and other known communication methods associated with networks, computers, processors, or programs .

將來可獲得或預期多種不同的蜂巢和行動通訊服務和標準,所有該等皆可實現並且受益於各個實施例。此種服務和標準包括例如第三代合作夥伴計畫(3GPP)、長期進化(LTE)系統、第三代無線行動通訊技術(3G)、第四代無線行動通訊技術(4G)、第五代無線行動通訊技術(5G)及後代3GPP技術、行動通訊全球系統(GSM)、通用行動電信系統(UMTS)、3GSM、通用封包無線電服務(GPRS)、分碼多工存取(CDMA)系統(例如,cdmaOne、CDMA1020TM)、增強型GSM進化資料速率(EDGE)、高級行動電話系統(AMPS)、數位AMPS(IS-136/TDMA)、進化資料最佳化(EV-DO)、數位增強型無電源線電信(DECT)、全球互通微波存取性(WiMAX)、無線區域網路(WLAN)、Wi-Fi保護存取I和II(WPA、WPA2)和整合數位增強型網路(iDEN)。該等技術中的每種技術皆涉及例如語音、資料、信號傳遞及/或內容訊息的發送和接收。應當理解的是,除非在請求項的語言中具體地記載,否則對與單獨的電信標準及/或技術有關的術語或技術細節的任何引用僅出於說明性目的,並且不意欲將請求項的範圍限制於特定的通訊系統或技術。Many different cellular and mobile communication services and standards are available or expected in the future, all of which can be implemented and benefit from various embodiments. Such services and standards include, for example, the 3rd Generation Partnership Project (3GPP), Long Term Evolution (LTE) systems, third generation wireless mobile communication technology (3G), fourth generation wireless mobile communication technology (4G), fifth generation Wireless mobile communication technology (5G) and its offspring 3GPP technology, Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), 3GSM, Universal Packet Radio Service (GPRS), Code Division Multiple Access (CDMA) systems (such as , cdmaOne, CDMA1020TM), Enhanced GSM Evolution Data Rate (EDGE), Advanced Mobile Phone System (AMPS), Digital AMPS (IS-136/TDMA), Evolution Data Optimization (EV-DO), Digital Enhanced No Power Wired Telecommunications (DECT), Worldwide Interoperability for Microwave Access (WiMAX), Wireless Local Area Networks (WLAN), Wi-Fi Protected Access I and II (WPA, WPA2) and Integrated Digital Enhanced Networking (iDEN). Each of these technologies involves, for example, the transmission and reception of voice, data, signaling and/or content information. It should be understood that unless specifically recited in the language of the claimed item, any reference to terms or technical details related to individual telecommunications standards and/or technologies is for illustrative purposes only and is not intended to The scope is limited to a specific communication system or technology.

所示出和描述的各個實施例僅作為示例來提供,以說明請求項的各種特徵。然而,關於任何給定實施例示出和描述的特徵不一定限於相關聯的實施例,並且可與所示出和描述的其他實施例一起使用或組合。此外,請求項並不意欲被任何一個示例實施例所限制。例如,本文描述的方法和操作的一項或多項可被該方法和操作中的一或多個操作替換或與其進行組合。The various embodiments shown and described are provided by way of example only to illustrate various features of the claimed item. However, features shown and described with respect to any given embodiment are not necessarily limited to the associated embodiment, and may be used or combined with other embodiments shown and described. Furthermore, the claims are not intended to be limited by any one example embodiment. For example, one or more of the methods and operations described herein may be substituted for or combined with one or more of the methods and operations.

在以下段落中描述了實現實例。儘管依據示例方法描述了以下實現示例中的一些實現實例,但是進一步的示例實現可包括:在以下段落中論述的由UE或網路裝置實現的示例方法,UE或網路裝置包括被配置有處理器可執行指令以執行以下實現實例的方法的操作的處理器;在以下段落中論述的由UE或網路裝置實現的示例方法,UE或網路裝置包括用於執行以下實現示例的方法的功能的手段;並且在以下段落中論述的示例方法可被實現為具有儲存在其上的處理器可執行指令的非暫時性處理器可讀儲存媒體,該處理器可執行指令被配置為使得UE或網路裝置的處理器執行以下實現示例的方法的操作。Implementation examples are described in the following paragraphs. Although some implementation examples in the following implementation examples are described in terms of example methods, further example implementations may include: the example methods discussed in the following paragraphs implemented by a UE or a network device comprising a device configured to process Processor executable instructions to perform the following operations implementing the method of the example; the example method implemented by the UE or network device discussed in the following paragraphs, the UE or the network device includes functionality for performing the following method implementing the example and the example methods discussed in the following paragraphs may be implemented as a non-transitory processor-readable storage medium having stored thereon processor-executable instructions configured to cause the UE or A processor of the network device performs the following operations to implement the exemplary method.

示例1、一種由使用者設備(UE)的處理器執行的保護通訊的方法,包括:產生新鮮度參數;基於第一通信期金鑰和該新鮮度參數來產生唯一通信期金鑰;在將使得網路應用功能(NAF)能夠產生該唯一通信期金鑰的配置中向該NAF發送該新鮮度參數;及使用該唯一通信期金鑰來與該NAF進行通訊。Example 1. A method of securing a communication performed by a processor of a user equipment (UE), comprising: generating a freshness parameter; generating a unique communication session key based on a first communication session key and the freshness parameter; sending the freshness parameter to the NAF in a configuration enabling a network application function (NAF) to generate the unique session key; and communicating with the NAF using the unique session key.

示例2、根據示例1之方法,其中該新鮮度參數是由在該處理器中執行的安全牽引客戶端來產生的;並且其中在該處理器中執行的應用客戶端使用該唯一通信期金鑰來與該NAF進行通訊,包括使用該唯一通信期金鑰來與該NAF進行通訊。Example 2. The method of example 1, wherein the freshness parameter is generated by a secure pull client executing in the processor; and wherein an application client executing in the processor uses the unique session key to communicate with the NAF, including using the unique communication session key to communicate with the NAF.

示例3、根據示例2之方法,其中該UE的該安全牽引客戶端包括通用牽引架構(GBA)客戶端或用於應用的認證和金鑰管理(AKMA)客戶端中的一者。Example 3. The method of example 2, wherein the secure pull client of the UE comprises one of a Generic Pull Architecture (GBA) client or an Authentication and Key Management for Applications (AKMA) client.

示例4、根據示例1-3中任一項所述的方法,其中該新鮮度參數與該UE的特定應用相關聯。Example 4. The method of any of examples 1-3, wherein the freshness parameter is associated with a specific application of the UE.

示例5、根據示例1-4中任一項所述的方法,其中該唯一通信期金鑰與該UE的特定應用相關聯,並且該第一通信期金鑰與該UE相關聯。Example 5. The method of any of examples 1-4, wherein the unique session key is associated with a specific application of the UE, and the first session key is associated with the UE.

示例6、根據示例5之方法,其中該特定應用包括該應用的特定實例化。Example 6. The method of example 5, wherein the specific application comprises a specific instantiation of the application.

示例7、根據示例1-6中任一項所述的方法,亦包括:從該NAF接收用於啟動安全通訊的請求。Example 7. The method of any one of examples 1-6, further comprising receiving a request from the NAF to initiate secure communication.

示例8、根據示例1-7中任一項所述的方法,其中該新鮮度參數包括隨機值。Example 8. The method of any of examples 1-7, wherein the freshness parameter comprises a random value.

示例9、根據示例1-8中任一項所述的方法,其中該新鮮度參數包括遞增的亂數值。Example 9. The method of any of examples 1-8, wherein the freshness parameter comprises an incrementing random value.

示例10、根據示例1-9中任一項所述的方法,其中在將使得該NAF能夠產生該唯一通信期金鑰的配置中向該NAF發送該新鮮度參數包括:在網路服務請求訊息中向該NAF發送該新鮮度參數。Example 10. The method of any of examples 1-9, wherein sending the freshness parameter to the NAF in a configuration that will enable the NAF to generate the unique session key comprises: in a web service request message Send the freshness parameter to the NAF.

示例11、一種由設備的處理器執行的保護通訊的方法,包括:由網路應用功能(NAF)從使用者設備(UE)接收新鮮度參數;從金鑰伺服器功能(KSF)接收第一通信期金鑰;基於該新鮮度參數和該第一通信期金鑰來產生唯一通信期金鑰;及使用該唯一通信期金鑰與該UE進行通訊。Example 11. A method, performed by a processor of a device, of securing a communication comprising: receiving, by a network application function (NAF), a freshness parameter from a user equipment (UE); receiving a first a session key; generating a unique session key based on the freshness parameter and the first session key; and communicating with the UE using the unique session key.

示例12、根據示例11之方法,其中該新鮮度參數是由在該UE的安全牽引客戶端來產生的;並且該UE的應用客戶端使用該唯一通信期金鑰來與該NAF進行通訊。Example 12. The method of example 11, wherein the freshness parameter is generated by a security pull client at the UE; and an application client of the UE communicates with the NAF using the unique session key.

示例13、根據示例12之方法,其中該UE的該安全牽引客戶端包括通用牽引架構(GBA)客戶端或用於應用的認證和金鑰管理(AKMA)客戶端中的一者。Example 13. The method of example 12, wherein the secure pull client of the UE comprises one of a Generic Pull Architecture (GBA) client or an Authentication and Key Management for Applications (AKMA) client.

示例14、根據示例11-13中任一項所述的方法,其中該新鮮度參數與該UE的特定應用相關聯。Example 14. The method of any of examples 11-13, wherein the freshness parameter is associated with a specific application of the UE.

示例15、根據示例11-14中任一項所述的方法,其中該唯一通信期金鑰與該UE的特定應用相關聯,並且該第一通信期金鑰與該UE相關聯。Example 15. The method of any of examples 11-14, wherein the unique session key is associated with a specific application of the UE, and the first session key is associated with the UE.

示例16、根據示例11-15中任一項所述的方法,其中該特定應用包括該應用的特定實例化。Example 16. The method of any of examples 11-15, wherein the specific application comprises a specific instantiation of the application.

示例17、根據示例11-16中任一項所述的方法,其中該新鮮度參數包括隨機值。Example 17. The method of any of examples 11-16, wherein the freshness parameter comprises a random value.

示例18、根據示例11-17中任一項所述的方法,其中該新鮮度參數包括遞增的亂數值。Example 18. The method of any of examples 11-17, wherein the freshness parameter comprises an incrementing random value.

示例19、根據示例11-18中任一項所述的方法,亦包括:向該UE發送用於啟動安全通訊的請求。Example 19. The method of any one of Examples 11-18, further comprising: sending a request to the UE to initiate secure communication.

示例20、根據示例11-19中任一項所述的方法,其中經由該NAF從該UE接收該新鮮度參數包括:在網路服務請求訊息中接收該新鮮度參數。Example 20. The method of any of examples 11-19, wherein receiving the freshness parameter from the UE via the NAF comprises receiving the freshness parameter in a web service request message.

前述的方法描述和程序流程圖僅是作為說明性示例來提供的,而不意欲要求或暗示各個實施例的操作必須按照所提供的順序來執行。如本領域技藝人士將明白的,前述實施例中的操作的順序可按照任何順序來執行。諸如「此後」、「隨後」、「接著」等詞並不意欲限制操作的順序;該等詞用於引導讀者通讀對方法的描述。此外,以單數形式(例如,使用冠詞「一(a)」、「一(an)」或「該(the)」)對請求項要素的任何引用不應被解釋為將該元素限製成單數。The foregoing method descriptions and program flow charts are provided as illustrative examples only, and are not intended to require or imply that the operations of the various embodiments must be performed in the order provided. As will be apparent to those skilled in the art, the sequence of operations in the foregoing embodiments may be performed in any order. Words such as "thereafter," "then," "next," etc. are not intended to limit the order of operations; such words are used to guide the reader through the description of the methods. Furthermore, any reference to a claim element in the singular (for example, using the articles "a", "an", or "the") shall not be construed as limiting that element to the singular .

結合本文揭示的實施例所描述的各種說明性的邏輯區塊、模組、部件、電路和演算法操作可實現成電子硬體、電腦軟體,或者兩者的組合。為了清楚地示出硬體和軟體的此種可互換性,上文已經對各種說明性的部件、方塊、模組、電路及操作圍繞其功能進行了整體描述。至於此種功能是實現成硬體亦是實現成軟體,取決於具體應用和施加在整體系統上的設計約束。技藝人士可針對每個特定應用,以變化的方式實現所描述的功能,但是,此種實施例決策不應當被解釋為導致脫離請求項的範圍。The various illustrative logical blocks, modules, components, circuits, and algorithmic operations described in connection with the embodiments disclosed herein may be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and operations have been described above generally in terms of their functionality. Whether such functions are implemented as hardware or as software depends on the specific application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the claims.

可利用被設計為執行本文所描述的功能的通用處理器、數位信號處理器(DSP)、特殊應用積體電路(ASIC)、場可程式設計閘陣列(FPGA)或其他可程式設計邏輯裝置、個別閘門或電晶體邏輯、個別硬體部件,或者其任何組合來實現或執行用於實現結合本文揭示的實施例所描述的各種說明性的邏輯、邏輯區塊、模組及電路的硬體。通用處理器可為微處理器,但是在替代的方式中,處理器可為任何一般的處理器、控制器、微控制器或狀態機。處理器亦可實現為接收器智慧物件的組合,例如,DSP和微處理器的組合、多個微處理器、一或多個微處理器結合DSP核,或者任何其他此種配置。替代地,一些操作或方法可由特定於給定功能的電路來執行。A general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device designed to perform the functions described herein may be utilized, Individual gate or transistor logic, individual hardware components, or any combination thereof implement or execute the hardware for implementing the various illustrative logic, logic blocks, modules, and circuits described in connection with the embodiments disclosed herein. A general-purpose processor may be a microprocessor, but in the alternative, the processor may be any general processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of receiver smart objects, eg, a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration. Alternatively, some operations or methods may be performed by circuitry specific to a given function.

在一或多個實施例中,該功能可用硬體、軟體、韌體或其任何組合來實現。若用軟體來實現,則可將該功能作為一或多個指令或代碼儲存在非暫時性電腦可讀取儲存媒體或者非暫時性處理器可讀儲存媒體上。本文所揭示的方法或演算法的操作可體現在處理器可執行軟體模組或處理器可執行指令中,處理器可執行軟體模組或處理器可執行指令可常駐在非暫時性電腦可讀或處理器可讀儲存媒體上。非暫時性電腦可讀或處理器可讀儲存媒體可為可由電腦或處理器存取的任何儲存媒體。經由舉例而非限制性的方式,此種非暫時性電腦可讀或處理器可讀儲存媒體可包括RAM、ROM、EEPROM、快閃記憶體、CD-ROM或其他光碟儲存、磁碟儲存或其他磁儲存智慧物件,或者可用於以指令或資料結構的形式儲存期望的程式碼並且可由電腦存取的任何其他媒體。如本文所使用的,磁碟和光碟包括壓縮光碟(CD)、雷射光碟、光碟、數位多功能光碟(DVD)、軟碟和藍光光碟,其中磁碟通常磁性地複製資料,而光碟用雷射來光學地複製資料。上述的組合亦被包括在非暫時性電腦可讀和處理器可讀取媒體的範圍之內。此外,方法或演算法的操作可作為代碼及/或指令中的一個或任何組合,或代碼及/或指令集常駐在非暫時性處理器可讀儲存媒體及/或電腦可讀取儲存媒體上,該非暫時性處理器可讀儲存媒體及/或電腦可讀取儲存媒體可被併入電腦程式產品。In one or more embodiments, the functionality may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored as one or more instructions or code on a non-transitory computer-readable storage medium or a non-transitory processor-readable storage medium. The operations of the methods or algorithms disclosed herein may be embodied in processor-executable software modules or processor-executable instructions, which may reside in non-transitory computer-readable or on a processor-readable storage medium. A non-transitory computer-readable or processor-readable storage medium can be any storage medium that can be accessed by a computer or a processor. By way of example and not limitation, such non-transitory computer-readable or processor-readable storage media may include RAM, ROM, EEPROM, flash memory, CD-ROM or other optical disk storage, magnetic disk storage or other A magnetic storage smart object, or any other medium that can be used to store desired code in the form of instructions or data structures and that can be accessed by a computer. Disk and disc, as used herein, includes compact disc (CD), laser disc, compact disc, digital versatile disc (DVD), floppy disc, and Blu-ray disc, where disks usually reproduce data magnetically and discs use Injection optically reproduces data. Combinations of the above are also included within the scope of non-transitory computer-readable and processor-readable media. In addition, the operation of the method or algorithm may be implemented as one or any combination of codes and/or instructions, or codes and/or instructions set resident on a non-transitory processor-readable storage medium and/or computer-readable storage medium , the non-transitory processor-readable storage medium and/or computer-readable storage medium can be incorporated into a computer program product.

提供所揭示的實施例的以上描述使本領域任何技藝人士能夠實施或使用請求項。對於本領域技藝人士來說,對該等實施例的各種修改將是顯而易見的,並且在不脫離專利申請範圍的範疇的情況下,可將本文定義的整體原理應用於其他實施例。因此,本案內容並不意欲限於本文示出的實施例,而是要被賦予與所附請求項和本文所揭示的原理和新穎特徵的相一致的最寬範圍。The above description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the claimed terms. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the patent claims. Thus, the present disclosure is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the appended claims and the principles and novel features disclosed herein.

100:通訊系統 102a:巨集細胞 102b:微微細胞 102c:毫微微細胞 110a:BS 110b:BS 110c:BS 110d:BS 120a:UE 120b:UE 120c:UE 120d:UE 120e:UE 122:無線通訊鏈路 124:無線通訊鏈路 126:有線通訊鏈路 130:網路控制器 140:核心網路 142:邊緣網路 142a:網路裝置 150:邊緣計算系統 154:邊緣應用伺服器 156:邊緣賦能伺服器 158:邊緣配置伺服器 160:3GPP核心網路 170:UE 172:應用客戶端 174:邊緣賦能器客戶端 200:計算和無線數據機系統 202:SOC 204:SOC 206:時鐘 208:電壓調節器 210:數位信號處理器 212:數據機處理器 214:圖形處理器 216:應用處理器 218:輔助處理器 220:記憶體 222:定製電路 224:系統部件和資源 226:互連/匯流排模組 230:溫度感測器 232:熱管理單元 234:熱功率包絡(TPE)部件 250:互連/匯流排模組 252:5G數據機處理器 254:功率管理單元 256:毫米波收發機 258:記憶體 260:處理器 264:互連/匯流排模組 266:無線收發機 300:軟體架構 302:NAS 304:AS 306:PHY 308:媒體存取控制(MAC)子層 310:無線電鏈路控制(RLC)子層 312:封包資料彙聚協定(PDCP)子層 313:RRC子層 314:主機層 316:硬體介面 317:服務資料適配協定(SDAP)子層 320:UE 350:網路裝置 400:系統 402:UE 404:網路裝置 406:機器可讀取指令 408:新鮮度參數模組 410:唯一通信期金鑰模組 412:發送/接收(TX/RX)模組 426:電子儲存裝置 428:處理器 430:電子儲存裝置 432:處理器 434:機器可讀取指令 436:新鮮度參數模組 438:唯一通信期金鑰模組 440:TX/RX模組 500a:系統 500b:方法 502:UE 504:NAF 506:KSF 508:家庭使用者伺服器(HSS) 510:使用者定位器功能(SLF) 520:UE 522:GBA客戶端 524:應用客戶端 526:網路裝置 528:NAF 530:KSF 532:請求訊息 534:操作 536:操作 538:訊息 540:訊息 542:訊息 544:訊息 546:操作 548:操作 550:訊息 552:安全通訊 600:方法 602:操作 604:操作 606:操作 608:操作 610:操作 700:方法 702:操作 704:操作 706:操作 708:操作 710:操作 800:網路裝置 801:處理器 802:揮發性記憶體 804:網路存取埠 806:周邊記憶體存取装置 807:天線 808:磁碟機 900:UE 904:天線 910:聲音編碼/解碼(CODEC)電路 912:顯示器 914:揚聲器 916:內部記憶體 920:功能表選擇按鈕|翹板開關 Dz:介面Dz EDGE-1:邊緣介面EDGE-1 EDGE-2:邊緣介面EDGE-1 EDGE-3:邊緣介面EDGE-1 EDGE-4:邊緣介面EDGE-1 EDGE-5:邊緣介面EDGE-1 EDGE-6:邊緣介面EDGE-1 EDGE-7:邊緣介面EDGE-1 EDGE-9:邊緣介面EDGE-1 L1:層1 L2:層2 L3:層3 MAC:媒體存取控制 PDCP:封包資料彙聚協定 PHY:實體層 RLC:無線電鏈路控制 RRC:無線電資源控制 SDAP:服務資料適配協定 Ua:介面Ua Ub:介面Ub Zh:介面Zh Zn:介面Zn 100: Communication system 102a: Macrocytosis 102b: pico cells 102c: Femtocells 110a:BS 110b:BS 110c:BS 110d:BS 120a:UE 120b:UE 120c:UE 120d:UE 120e:UE 122: Wireless communication link 124: Wireless communication link 126: Wired communication link 130: Network controller 140: core network 142:Edge network 142a: Network device 150:Edge Computing System 154:Edge application server 156:Edge-enabled server 158:Edge configuration server 160: 3GPP core network 170:UE 172: Application client 174:Edge enabler client 200: Computing and wireless modem systems 202: SOC 204: SOC 206: clock 208:Voltage regulator 210: Digital Signal Processor 212: modem processor 214: graphics processor 216: application processor 218: auxiliary processor 220: memory 222: Custom circuit 224: System Components and Resources 226:Interconnection/bus module 230: temperature sensor 232: thermal management unit 234: Thermal Power Envelope (TPE) Components 250: Interconnect/bus module 252: 5G modem processor 254: Power management unit 256: millimeter wave transceiver 258: memory 260: Processor 264: Interconnect/bus module 266: wireless transceiver 300: Software Architecture 302:NAS 304: AS 306:PHY 308: Media Access Control (MAC) sublayer 310: Radio Link Control (RLC) sublayer 312: Packet Data Convergence Protocol (PDCP) sublayer 313: RRC sublayer 314: host layer 316: hardware interface 317: Service Data Adaptation Protocol (SDAP) sublayer 320:UE 350: network device 400: system 402:UE 404: Network device 406: Machine Readable Instructions 408: Freshness parameter module 410: Unique communication period key module 412: Send/receive (TX/RX) module 426: Electronic storage device 428: Processor 430: Electronic storage device 432: Processor 434: Machine Readable Instructions 436:Freshness parameter module 438: Unique communication period key module 440:TX/RX module 500a: System 500b: method 502:UE 504:NAF 506:KSF 508: Home User Server (HSS) 510: User Locator Function (SLF) 520:UE 522: GBA client 524: application client 526: network device 528:NAF 530:KSF 532: request message 534: Operation 536: Operation 538: message 540: message 542: message 544: message 546: Operation 548:Operation 550: message 552: Secure communication 600: method 602: Operation 604: Operation 606: Operation 608: Operation 610: Operation 700: method 702: Operation 704: Operation 706: Operation 708: Operation 710: Operation 800: network device 801: Processor 802: Volatile memory 804: Network access port 806:Peripheral memory access device 807:antenna 808:Disk drive 900:UE 904: Antenna 910: Sound encoding/decoding (CODEC) circuit 912: display 914:Speaker 916: internal memory 920: menu selection button | rocker switch Dz: interface Dz EDGE-1: Edge interface EDGE-1 EDGE-2: Edge interface EDGE-1 EDGE-3: Edge interface EDGE-1 EDGE-4: Edge interface EDGE-1 EDGE-5: Edge interface EDGE-1 EDGE-6: Edge interface EDGE-1 EDGE-7: Edge Interface EDGE-1 EDGE-9: Edge interface EDGE-1 L1: Layer 1 L2: Layer 2 L3: Layer 3 MAC: Media Access Control PDCP: Packet Data Convergence Protocol PHY: physical layer RLC: Radio Link Control RRC: Radio Resource Control SDAP: Service Data Adaptation Protocol Ua: Interface Ua Ub: Interface Ub Zh: Interface Zh Zn: Interface Zn

被併入本文並且構成本說明書的一部分的附圖圖示示例性實施例,並且連同上文提供的整體描述和下文提供的詳細描述一起用於解釋各個實施例的特徵。The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate exemplary embodiments and, together with the general description provided above and the detailed description provided below, serve to explain features of various embodiments.

圖1A是示出適於實現各個實施例中的任何實施例的示例通訊系統的系統方塊圖。Figure 1A is a system block diagram illustrating an example communication system suitable for implementing any of the various embodiments.

圖1B是示出適於與各個實施例一起使用的示例邊緣計算系統的系統方塊圖。Figure IB is a system block diagram illustrating an example edge computing system suitable for use with various embodiments.

圖2是示出適於實現各個實施例中的任何實施例的示例計算和無線數據機系統的部件方塊圖。Figure 2 is a block diagram illustrating components of an example computing and wireless modem system suitable for implementing any of the various embodiments.

圖3是示出適於實現各個實施例中的任何實施例的軟體架構的部件方塊圖,該軟體架構包括用於無線通訊中的使用者和控制平面的無線電協定堆疊。3 is a component block diagram illustrating a software architecture suitable for implementing any of the various embodiments, the software architecture including a radio protocol stack for user and control planes in wireless communications.

圖4A和4B是示出根據各個實施例的被配置用於增強用於初始存取的覆蓋的系統的部件方塊圖。4A and 4B are block diagrams illustrating components of a system configured to enhance overlays for initial access, according to various embodiments.

圖5A是示出適於與各個實施例一起使用的用於牽引應用安全性的示例系統的方塊圖。5A is a block diagram illustrating an example system for towing application security suitable for use with various embodiments.

圖5B是示出根據各個實施例的在用於保護通訊的方法500b期間在網路裝置之間交換的通訊的訊息流程圖。5B is a message flow diagram illustrating communications exchanged between network devices during a method 500b for securing communications, according to various embodiments.

圖6是示出根據各個實施例的由UE的處理器執行的用於保護通訊的方法的程序流程圖。FIG. 6 is a program flow diagram illustrating a method for securing communications performed by a processor of a UE according to various embodiments.

圖7是示出根據各個實施例的由網路裝置的處理器執行的用於保護通訊的方法的程序流程圖。FIG. 7 is a program flow diagram illustrating a method for securing communications executed by a processor of a network device according to various embodiments.

圖8是適於與各個實施例一起使用的網路裝置的部件方塊圖。Figure 8 is a block diagram of components of a network device suitable for use with various embodiments.

圖9是適於與各個實施例一起使用的UE的部件方塊圖。Figure 9 is a block diagram of components of a UE suitable for use with various embodiments.

國內寄存資訊(請依寄存機構、日期、號碼順序註記) 無 國外寄存資訊(請依寄存國家、機構、日期、號碼順序註記) 無 Domestic deposit information (please note in order of depositor, date, and number) none Overseas storage information (please note in order of storage country, institution, date, and number) none

600:方法 600: method

602:操作 602: Operation

604:操作 604: Operation

606:操作 606: Operation

608:操作 608: Operation

610:操作 610: Operation

Claims (34)

一種使用者設備(UE),包括: 一處理器,其被配置有處理器可執行指令以進行以下操作: 產生一新鮮度參數; 基於一第一通信期金鑰和該新鮮度參數來產生一唯一通信期金鑰; 在將賦能一網路應用功能(NAF)產生該唯一通信期金鑰的一配置中向該NAF發送該新鮮度參數;及 使用該唯一通信期金鑰來與該NAF進行通訊。 A user equipment (UE), comprising: A processor configured with processor-executable instructions to: generate a freshness parameter; generating a unique session key based on a first session key and the freshness parameter; sending the freshness parameter to a network application function (NAF) in a configuration that will enable the NAF to generate the unique session key; and Use the unique session key to communicate with the NAF. 如請求項1之UE,其中: 該新鮮度參數是由在該處理器中執行的一安全牽引客戶端來產生的;並且 在該處理器中執行的一應用客戶端使用該唯一通信期金鑰來與該NAF進行通訊。 Such as the UE of claim item 1, wherein: the freshness parameter is generated by a secure pull client executing in the processor; and An application client executing in the processor communicates with the NAF using the unique session key. 如請求項2之UE,其中該UE的該安全牽引客戶端包括一通用牽引架構(GBA)客戶端或用於一應用的認證和金鑰管理(AKMA)客戶端中的一者。The UE of claim 2, wherein the secure pull client of the UE includes one of a Generic Pull Architecture (GBA) client or an Authentication and Key Management for an Application (AKMA) client. 如請求項1之UE,其中該新鮮度參數與該UE的一特定應用相關聯。The UE of claim 1, wherein the freshness parameter is associated with a specific application of the UE. 如請求項1之UE,其中該處理器亦被配置有處理器可執行指令,使得該唯一通信期金鑰與該UE的特定應用相關聯,並且該第一通信期金鑰與該UE相關聯。The UE of claim 1, wherein the processor is also configured with processor-executable instructions such that the unique session key is associated with a specific application of the UE, and the first session key is associated with the UE . 如請求項5之UE,其中該處理器亦被配置有處理器可執行指令,使得該特定應用包括該應用的一特定實例化。The UE of claim 5, wherein the processor is also configured with processor-executable instructions such that the specific application includes a specific instantiation of the application. 如請求項1之UE,其中該處理器亦被配置有處理器可執行指令,使得該新鮮度參數包括一隨機值。The UE of claim 1, wherein the processor is also configured with processor-executable instructions such that the freshness parameter includes a random value. 如請求項1之UE,其中該處理器亦被配置有處理器可執行指令,使得該新鮮度參數包括一遞增的亂數值。The UE of claim 1, wherein the processor is also configured with processor-executable instructions such that the freshness parameter includes an increasing random value. 如請求項1之UE,其中該處理器亦被配置有處理器可執行指令,以在一網路服務請求訊息中向該NAF發送該新鮮度參數。The UE of claim 1, wherein the processor is also configured with processor-executable instructions to send the freshness parameter to the NAF in a network service request message. 一種由一使用者設備(UE)的一處理器執行的保護通訊的方法,包括: 產生一新鮮度參數; 基於一第一通信期金鑰和該新鮮度參數來產生一唯一通信期金鑰; 在將賦能一網路應用功能(NAF)產生該唯一通信期金鑰的一配置中向該NAF發送該新鮮度參數;及 使用該唯一通信期金鑰來與該NAF進行通訊。 A method of securing communications performed by a processor of a user equipment (UE), comprising: generate a freshness parameter; generating a unique session key based on a first session key and the freshness parameter; sending the freshness parameter to a network application function (NAF) in a configuration that will enable the NAF to generate the unique session key; and Use the unique session key to communicate with the NAF. 如請求項10之方法,其中: 該新鮮度參數是由該UE的一安全牽引客戶端來產生的;並且 該UE的一應用客戶端使用該唯一通信期金鑰來與該NAF進行通訊。 The method of claim 10, wherein: The freshness parameter is generated by a security pull client of the UE; and An application client of the UE uses the unique session key to communicate with the NAF. 如請求項11之方法,其中該UE的該安全牽引客戶端包括一通用牽引架構(GBA)客戶端或一應用的認證和金鑰管理(AKMA)客戶端中的一者。The method of claim 11, wherein the secure pull client of the UE comprises one of a Generic Pull Architecture (GBA) client or an Applied Authentication and Key Management (AKMA) client. 如請求項10之方法,其中該新鮮度參數與該UE的一特定應用相關聯。The method of claim 10, wherein the freshness parameter is associated with a specific application of the UE. 如請求項10之方法,其中該唯一通信期金鑰與該UE的一特定應用相關聯,並且該第一通信期金鑰與該UE相關聯。The method of claim 10, wherein the unique session key is associated with a specific application of the UE, and the first session key is associated with the UE. 如請求項14之方法,其中該特定應用包括該應用的一特定實例化。The method of claim 14, wherein the specific application includes a specific instantiation of the application. 如請求項11之方法,其中該新鮮度參數包括一隨機值。The method of claim 11, wherein the freshness parameter includes a random value. 如請求項11之方法,其中該新鮮度參數包括一遞增的亂數值。The method of claim 11, wherein the freshness parameter includes an increasing random value. 如請求項11之方法,其中在將賦能該NAF產生該唯一通信期金鑰的一配置中向該NAF發送該新鮮度參數包括:在一網路服務請求訊息中向該NAF發送該新鮮度參數。The method of claim 11, wherein sending the freshness parameter to the NAF in a configuration that will enable the NAF to generate the unique session key comprises: sending the freshness parameter to the NAF in a web service request message parameter. 一種網路裝置,包括: 一處理器,其被配置有處理器可執行指令以進行以下操作: 在一網路應用功能(NAF)處從一使用者設備(UE)接收一新鮮度參數; 從一金鑰伺服器功能接收一第一通信期金鑰; 基於該新鮮度參數和該第一通信期金鑰來產生一唯一通信期金鑰;及 使用該唯一通信期金鑰與該UE進行通訊。 A network device, comprising: A processor configured with processor-executable instructions to: receiving a freshness parameter from a user equipment (UE) at a network application function (NAF); receiving a first session key from a key server function; generating a unique session key based on the freshness parameter and the first session key; and communicate with the UE using the unique communication session key. 如請求項19之網路裝置,其中該新鮮度參數與該UE的一特定應用相關聯。The network device according to claim 19, wherein the freshness parameter is associated with a specific application of the UE. 如請求項19之網路裝置,其中該新鮮度參數包括一隨機值。The network device according to claim 19, wherein the freshness parameter includes a random value. 如請求項19之網路裝置,其中該新鮮度參數包括一遞增的亂數值。The network device according to claim 19, wherein the freshness parameter includes an increasing random value. 如請求項19之網路裝置,其中該唯一通信期金鑰與該UE的一特定應用相關聯,並且該第一通信期金鑰與該UE相關聯。The network device according to claim 19, wherein the unique session key is associated with a specific application of the UE, and the first session key is associated with the UE. 如請求項23之網路裝置,其中該特定應用包括該應用的一特定實例化。The network device of claim 23, wherein the specific application includes a specific instantiation of the application. 如請求項19之網路裝置,其中該處理器亦被配置有處理器可執行指令,以向該UE發送一用於啟動安全通訊的請求。The network device according to claim 19, wherein the processor is also configured with processor-executable instructions to send a request for initiating secure communication to the UE. 如請求項19之網路裝置,其中該處理器亦被配置有處理器可執行指令,以在一網路服務請求訊息中接收該新鮮度參數。The network device according to claim 19, wherein the processor is also configured with processor-executable instructions to receive the freshness parameter in a network service request message. 一種由一裝置的一處理器執行的保護通訊的方法,包括: 由一網路應用功能(NAF)從一使用者設備(UE)接收一新鮮度參數; 從一金鑰伺服器功能接收一第一通信期金鑰; 基於該新鮮度參數和該第一通信期金鑰來產生一唯一通信期金鑰;及 使用該唯一通信期金鑰與該UE進行通訊。 A method of securing communications performed by a processor of a device, comprising: receiving a freshness parameter from a user equipment (UE) by a network application function (NAF); receiving a first session key from a key server function; generating a unique session key based on the freshness parameter and the first session key; and communicate with the UE using the unique communication session key. 如請求項27之方法,其中該新鮮度參數與該UE的一特定應用相關聯。The method of claim 27, wherein the freshness parameter is associated with a specific application of the UE. 如請求項27之方法,其中該新鮮度參數包括一隨機值。The method of claim 27, wherein the freshness parameter includes a random value. 如請求項27之方法,其中該新鮮度參數包括一遞增的亂數值。The method of claim 27, wherein the freshness parameter includes an increasing random value. 如請求項27之方法,其中該唯一通信期金鑰與該UE的一特定應用相關聯,並且該第一通信期金鑰與該UE相關聯。The method of claim 27, wherein the unique session key is associated with a specific application of the UE, and the first session key is associated with the UE. 如請求項31之方法,其中該特定應用包括該應用的一特定實例化。The method of claim 31, wherein the specific application comprises a specific instantiation of the application. 如請求項27之方法,亦包括:向該UE發送一用於啟動安全通訊的請求。The method according to claim 27, further comprising: sending a request for starting secure communication to the UE. 如請求項27之方法,其中在該NAF處從該UE接收該新鮮度參數包括:在一網路服務請求訊息中接收該新鮮度參數。The method of claim 27, wherein receiving the freshness parameter from the UE at the NAF comprises: receiving the freshness parameter in a web service request message.
TW111134693A 2021-09-17 2022-09-14 Securing application communication TW202320557A (en)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US202163245692P 2021-09-17 2021-09-17
US63/245,692 2021-09-17
US17/931,505 2022-09-12
US17/931,505 US20230093720A1 (en) 2021-09-17 2022-09-12 Securing Application Communication

Publications (1)

Publication Number Publication Date
TW202320557A true TW202320557A (en) 2023-05-16

Family

ID=83598417

Family Applications (1)

Application Number Title Priority Date Filing Date
TW111134693A TW202320557A (en) 2021-09-17 2022-09-14 Securing application communication

Country Status (3)

Country Link
KR (1) KR20240056515A (en)
TW (1) TW202320557A (en)
WO (1) WO2023043724A1 (en)

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7558957B2 (en) * 2005-04-18 2009-07-07 Alcatel-Lucent Usa Inc. Providing fresh session keys
US7835528B2 (en) * 2005-09-26 2010-11-16 Nokia Corporation Method and apparatus for refreshing keys within a bootstrapping architecture
CN112399369B (en) * 2019-07-31 2022-05-10 华为技术有限公司 Secret key updating method and communication device

Also Published As

Publication number Publication date
WO2023043724A1 (en) 2023-03-23
KR20240056515A (en) 2024-04-30

Similar Documents

Publication Publication Date Title
TW202119849A (en) Uplink and downlink streaming bit rate assistance in 4g and 5g networks
JP2023514705A (en) Method for communicating TX waveform distortion to receiver
KR20220146448A (en) Management of information transmission for wireless communication
TW202315431A (en) 5g non-seamless wireless local area network offload
US11716716B2 (en) Barrage signal for protecting wireless communications
US11751195B2 (en) Control signaling for multicast communications
CN114245974B (en) Providing secure communications between computing devices
TW202207733A (en) Attention (at) interface for radio access network bitrate recommendations
TW202320557A (en) Securing application communication
US20230093720A1 (en) Securing Application Communication
WO2021091722A1 (en) Allocating resources to a plurality of mobile devices
CN117917107A (en) Ensuring application communication security
TW202324964A (en) Generic bootstrapping architecture (gba) signaling to indicate need for key renegotiation
US20220167159A1 (en) Systems and methods for authenticating a wireless device
US20210105612A1 (en) User plane integrity protection (up ip) capability signaling in 5g/4g systems
WO2021174435A1 (en) Managing a downlink bit rate
US20230137968A1 (en) 5G QoS Provisioning For An End-to-End Connection Including Non-5G Networks
WO2022165826A1 (en) Frames-per-second thermal management
US20220346137A1 (en) Managing Uplink Spatial Filter Configuration
TW202322599A (en) Managing end-to-end quality of service (qos) in a multi-network communication path
TW202335521A (en) Securing media stream communications
JP2023527300A (en) Processing data using remote network computing resources
WO2021194703A1 (en) Managing transmit power control
CN116325757A (en) Synchronized content presentation