WO2023016451A1 - 更新方法、网络侧设备、终端和计算机可读存储介质 - Google Patents
更新方法、网络侧设备、终端和计算机可读存储介质 Download PDFInfo
- Publication number
- WO2023016451A1 WO2023016451A1 PCT/CN2022/111148 CN2022111148W WO2023016451A1 WO 2023016451 A1 WO2023016451 A1 WO 2023016451A1 CN 2022111148 W CN2022111148 W CN 2022111148W WO 2023016451 A1 WO2023016451 A1 WO 2023016451A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- update
- key
- aanf
- request message
- akma
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
Definitions
- the present disclosure relates to the field of communication technologies, and in particular to an update method, network side equipment, terminal and computer-readable storage medium.
- AKMA Authentication and Key Management for Applications
- the present disclosure provides an update method, network-side equipment, terminal and computer-readable storage medium, capable of actively initiating a KAF update process to avoid the AKMA service between the UE and the network, because there is no new communication between the UE and the network Problems interrupted by initial authentication.
- the present disclosure provides an update method, which is applied to AF, and the update method includes:
- AKMA anchor Function AAnF
- the present disclosure provides an update method applied to AAnF, the update method comprising:
- An updated K AF is sent to the AF.
- the present disclosure provides an update method, which is applied to a unified data management functional entity (Unified Data Management, UDM), and the update method includes:
- the present disclosure provides an update method, which is applied to a UE, and the update method includes:
- an AF including:
- the first sending module is configured to send a key update request message to AAnF;
- the first receiving module is configured to receive the updated K AF sent by the AAnF.
- an AAnF comprising:
- the second receiving module is configured to receive a key update request message sent by the AF;
- the third sending module is configured to send the updated K AF to the AF.
- the present disclosure provides a UDM, including:
- a fourth receiving module configured to receive a parameter update request message sent by AAnF;
- a fifth sending module configured to send update parameters to the UE, where the update parameters are used by the UE to generate K AF in combination with the K AKMA currently stored by the UE.
- the present disclosure provides a UE, including:
- the fifth receiving module is configured to receive a key update instruction message sent by the AF, where the key update instruction message is used to instruct the UE to update K AF .
- the present disclosure provides a network side device, including: a processor and a transceiver;
- the transceiver is configured to send a key update request message to AAnF;
- the transceiver is further configured to receive the updated K A sent by the AAnF;
- the transceiver is configured to receive a key update request message sent by the AF;
- the transceiver is further configured to send an updated K AF to the AF;
- the transceiver is configured to receive a parameter update request message sent by AAnF;
- the transceiver is further configured to send update parameters to the UE, where the update parameters are used by the UE to generate K AF in combination with the K AKMA currently stored by the UE.
- the present disclosure provides a user equipment UE, including: a processor and a transceiver;
- the transceiver is configured to receive a key update indication message sent by the AF, where the key update indication message is used to instruct the UE to update K AF .
- the present disclosure provides a network-side device, including a processor, a memory, and a computer program stored on the memory and operable on the processor, and the computer program is executed by the processor
- a network-side device including a processor, a memory, and a computer program stored on the memory and operable on the processor, and the computer program is executed by the processor
- the present disclosure provides a terminal device, including a processor, a memory, and a computer program stored on the memory and operable on the processor, when the computer program is executed by the processor Implement the steps in the update method as described in the fourth aspect.
- the present disclosure provides a computer-readable storage medium, where a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the update method as described in the first aspect is implemented or implement the steps in the update method as described in the second aspect, or implement the steps in the update method as described in the third aspect, or implement the steps in the update method as described in the fourth aspect.
- a key update process initiated by the AF is provided, which can actively update the K AF to avoid the problem of K AF expiration caused by the lack of new initial authentication between the UE and the network in the related art , so as to ensure the smooth progress of AKMA business.
- FIG. 1 is a schematic diagram of an update process of K AF in the related art
- FIG. 2 is a flow chart of an update method applied to AF provided by an embodiment of the present disclosure
- FIG. 3 is a flow chart of an update method applied to AAnF provided by an embodiment of the present disclosure
- FIG. 4 is a flow chart of an update method applied to UDM provided by an embodiment of the present disclosure
- FIG. 5 is a flow chart of an update method applied to a UE provided by an embodiment of the present disclosure
- FIG. 6 is a schematic diagram of data interaction between a UE and a network-side device in an embodiment of the present disclosure
- FIG. 7 is a schematic structural diagram of an AF provided by an embodiment of the present disclosure.
- Fig. 8 is a schematic structural diagram of an AAnF provided by an embodiment of the present disclosure.
- FIG. 9 is a schematic structural diagram of a UDM provided by an embodiment of the present disclosure.
- FIG. 10 is a schematic structural diagram of a network-side device provided by an embodiment of the present disclosure.
- FIG. 11 is a schematic structural diagram of a UE provided by an embodiment of the present disclosure.
- Fig. 12 is a schematic structural diagram of a terminal device provided by an embodiment of the present disclosure.
- sequence numbers of the following processes do not mean the order of execution, and the execution order of each process should be determined by its functions and internal logic, and should not be implemented in the present disclosure.
- the implementation of the examples constitutes no limitation.
- 3rd Generation Partnership Project 3rd Generation Partnership Project, 3GPP related agreement defines the following architecture and process of application layer authentication and key management:
- the UE before invoking the AKMA service, the UE should have successfully registered to the fifth generation (the 5 th Generation, 5G) core network, so that after passing the 5G access authentication, the authentication server function (AUthentication Server Function, AUSF) key (AUSF Key, K AUSF ) will be stored in AUSF and UE.
- the authentication server function AUthentication Server Function, AUSF
- AUSF Key AUSF Key
- AUSF, AAnF and UE belong to the same public land mobile network (Home Public Land Mobile Network, HPLMN) to which the user belongs.
- HPLMN Home Public Land Mobile Network
- UE which can also be called a terminal
- the terminal accesses the operator's network and performs the 5G personal identity verification specified in the main authentication (which is also called initial authentication)
- the terminal accesses the operator's network and performs the 5G personal identity verification specified in the main authentication (which is also called initial authentication)
- the terminal accesses the operator's network and performs the 5G personal identity verification specified in the main authentication (which is also called initial authentication)
- the terminal accesses the operator's network and performs the 5G personal identity verification specified in the main authentication (which is also called initial authentication)
- the terminal accesses the operator's network and performs the 5G personal identity verification specified in the main authentication (which is also called initial authentication)
- the terminal accesses the operator's network and performs the 5G personal identity verification specified in the main authentication (which is also called initial authentication)
- the terminal accesses the operator's network and performs the 5G personal identity verification specified in the main authentication (which is also called initial authentication)
- the terminal accesse
- the terminal and AUSF will generate the AKMA intermediate key K AKMA and the corresponding key identifier (AKMA Key IDentifier, A-KID) accordingly, and based on this K AKMA and A-KID provide the subsequent session key K AF to the application server, so that the UE and the application server can perform application layer authentication or data encryption based on the K AF .
- K AKMA AKMA Key IDentifier
- the request message will carry the A-KID
- the application server receives the request, it will request the AAnF for the session key with the A-KID.
- the AAnF derives the session key K AF according to the AKMA intermediate key K AKMA acquired from the AUSF, and returns the session key K AF to the application server.
- the terminal after receiving the application layer response message returned by the application server, the terminal also derives the session key K AF according to the K AKMA stored in itself. In this way, the application server and the terminal can use the session key for subsequent application layer authentication or data encryption.
- the current K AKMA and A-KID are valid until the next successful initial authentication (implicit lifetime). After the next successful initial authentication is performed, the K AKMA and A-KID will be updated.
- the AKMA session key K AF has a definite lifetime according to the operator's policy. When the lifetime of K AF expires, a new AKMA application key will need to be established based on the current AKMA intermediate key K AKMA .
- TLS Transport Layer Security
- K AF can be actively updated to avoid the UE and the network due to There is no KAF expiration problem caused by new initial authentication between networks, which can ensure the smooth progress of AKMA business.
- the first update method provided by the embodiment of the present disclosure, the subject of execution may be AF, as shown in Fig. 2, the update method may include the following steps:
- Step 201 Send a key update request message to the AAnF.
- the AF that executes the update method provided by the embodiment of the present disclosure may specifically be an AF that uses the AKMA service, which has the following additional functions:
- the AF should be authenticated and authorized by the operator network before providing the AKMA application key to the AF.
- the AF sends a key update request message to AAnF, so that AAnF generates a new K AF according to the key update request message, and returns the newly generated K AF to the AF.
- Step 202 Receive the updated K AF sent by the AAnF.
- the above new initial authentication between the UE and the network can also be initiated by the terminal by instructing the terminal through the AAnF.
- the terminal needs to be modified, and the basic security mechanism of the terminal is affected.
- the terminal needs to release the Non-Access Stratum (Non-Access Stratum, NAS) link, and the NAS key set identifier (NAS key set identifier) needs to be modified.
- NAS key set identifier NAS key set identifier
- ngKSI triggering the main authentication.
- the embodiment of the present disclosure also provides another optional implementation as follows, so that the update of K AF no longer depends on the update of K AKMA :
- the K AF may be a key generated at least according to update parameters and the K AKMA currently stored in the AAnF.
- the AAnF after the AAnF receives the key update request message sent by the AF, it can directly generate a new K AF based on the key update request message and the update parameters and the K AKMA currently stored in the AAnF.
- K AF KDF(K AKMA , AF_ID)
- KDF represents the key derivation function (Key Derivation Function).
- AF_ID represents the identifier of the AF.
- the freshness parameter refers to the above update parameters.
- the above-mentioned update parameter can be understood as: a key freshness parameter (freshness parameter), which is used to indicate the freshness of the K AF , and the value of the update parameter can be a count value of a counter (COUNTER) or a random number, etc. etc.
- a key freshness parameter freshness parameter
- COUNTER count value of a counter
- updating parameters with different values can be used each time K AF is derived, so that the K AF deduced according to the above derivation formula is different.
- update parameters may also be other UE parameter update (UE Parameter Update, UPU) parameters.
- this embodiment adds an update parameter, so that the update of K AF no longer depends on the update of K AKMA , but can be implemented by updating the update parameters based on the same K AKMA implements updates to K AF .
- this method even if there is no new initial authentication between the UE and the network, it is no longer necessary to initiate a new initial authentication between the UE and the network to update K AKMA , but to use the introduced K AKMA Update the parameters to realize the update of K AF . This method avoids frequent main authentication of the 5G network and changes to the network and terminals.
- K AF can be generated according to the existing derivation formula, or K AF can be generated according to the derivation formula of the new key fresh parameter, which is the disclosure
- the freshness parameter mentioned above is an optional parameter, which is determined according to different processing methods. For example: in the implementation mode in which the update of K AF depends on the update of K AKMA , the freshness parameter may not be used in the derivation formula; and in the implementation mode in which the update of K AF no longer depends on the update of K AKMA , it can be used in The freshness parameter is used in the derivation formula.
- the above key update request message may also carry the A-KID.
- the key update request message is a key acquisition request message
- the key acquisition request message carries a key update indicator
- the key update indicator is used to indicate that the AF needs to update K AF .
- the above-mentioned key acquisition request message is a key acquisition request message in the related art, and the above-mentioned key update indicator is implemented through a reserved field in the key acquisition request message.
- the existing key acquisition request message can be used to implement the KAF update process, and the update instruction can be implemented through the reserved field in the key acquisition request message.
- the key acquisition request message may not carry the key update indicator.
- the AAnF may not update the K AF , but in the key Get the K AF currently stored in the AAnF carried in the response message.
- the AAnF can resend the currently stored K AF to the AF.
- whether the key update indicator is carried in the existing key acquisition request message is used to make the key update process different from the existing key acquisition process, so that updating K AF and obtaining K AF can be performed through different Process to achieve, simplifying the process.
- the above key update request message may also be a newly added message, which is not specifically limited here.
- the AF may also perform the following steps:
- the AF may notify/instruct the UE to update the K AF after acquiring the new K AF from the AAnF, so that the UE and the AF use the same K AF .
- key synchronization between AF and UE can also be achieved in other ways, for example, through the UPU process, or AAnF instructs UE to update K AF , here the key synchronization between AF and UE
- the specific implementation of key synchronization is not specifically limited.
- the K AF is carried in a key update response message.
- step 202 may specifically be: receiving a key update response message sent by the AAnF, and the key update response message carries an updated K AF .
- the AAnF can also send the updated K AF to the AF through any other message or indication information, which is not specifically limited here.
- the key update response message also carries a key life cycle
- the sending of the key update request message to AAnF specifically includes:
- the AF can determine when the K AF expires according to the key life cycle, for example: the above key life cycle can be a point in time at which the K AF expires, or the above key life cycle It may be a preset time length, and the K AF expires after using the preset time length.
- the specific form of the key life cycle is not limited here.
- the above-mentioned sending the key update request message to AAnF according to the key life cycle can be understood as: according to the key life cycle, when it is determined that the current K AF is about to expire , send the key update request message to AAnF.
- the key update request message is sent to the AAnF at a preset time (for example: 1s, 2s, etc.) before the current K AF expires.
- the KAF update process can be initiated in advance before the current KAF expires.
- the above-mentioned sending the key update request message to AAnF according to the key life cycle can be understood as: according to the key life cycle, after determining that the current K AF expires , send the key update request message to AAnF.
- the key update request message is sent to the AAnF at a preset time (for example: 0s, 1s, 2s, etc.) after the expiration of the current K AF is determined.
- a KAF update process can be initiated.
- a key update process initiated by the AF is provided, which can actively update the K AF to avoid the problem of K AF expiration caused by the lack of new initial authentication between the UE and the network in the related art , so as to ensure the smooth progress of AKMA business.
- the execution subject may be AAnF, as shown in Fig. 3, the update method may include the following steps:
- Step 301 Receive a key update request message sent by the AF.
- Step 302. Send the updated K AF to the AF.
- the key update request message and the updated K AF in the embodiment of the present disclosure have the same meaning and function as the key update request message and the updated K AF in the method embodiment shown in FIG. repeat.
- the embodiments of the present disclosure can also actively update K AF under the trigger of AF, so as to avoid the problem of K AF expiration caused by no new initial authentication between the UE and the network in the related art, thereby ensuring the smooth operation of AKMA services conduct.
- the K AF is carried in a key update response message.
- the AAnF can update the K AF according to the K AF update process in the method embodiment shown in Figure 2, and the key The updated K AF is carried in the update response message.
- the K AF when the K AF is about to expire, or the K AF has expired, the K AF can be updated according to the update process of the K AF in the method embodiment shown in Figure 2, and the key update response message carries the updated key.
- the KAF when the K AF is about to expire, or the K AF has expired, the K AF can be updated according to the update process of the K AF in the method embodiment shown in Figure 2, and the key update response message carries the updated key.
- the KAF when the K AF is about to expire, or the K AF has expired, the K AF can be updated according to the update process of the K AF in the method embodiment shown in Figure 2, and the key update response message carries the updated key.
- the KAF when the K AF is about to expire, or the K AF has expired, the K AF can be updated according to the update process of the K AF in the method embodiment shown in Figure 2, and the key update response message carries the updated key.
- the KAF when the K AF is
- A-KID, AF_ID and refresh indicator (refresh indicator) information may be carried in the key update request message.
- the AAnF can distinguish whether it is an initial request to obtain K AF or a request to update K AF according to the updated information.
- the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the AAnF.
- the update of K AF no longer depends on the update of K AKMA , but the update of K AF can be realized by updating the update parameters, so that it is no longer necessary to pass the update between the UE and the network.
- the update of K AKMA can be realized by the new initial authentication of K AF . This method avoids the main authentication of the 5G network and the modification of the terminal.
- the update method provided by this embodiment of the present disclosure further includes:
- the UDM may store AKMA subscription data of AKMA service subscribers.
- the UDM may initiate a UPU procedure based on the received parameter update request message to update UE parameters, where the UE parameters include update parameters.
- the existing UPU process can be used to issue update parameters to the UE, so that the UE can derive the updated K AF according to the update parameters, that is, the updated update parameters can be updated using the existing UE parameter update process. Synchronized to UE.
- the AAnF when the AAnF receives the parameter update response message sent by the UDM, it can derive K AF based on the updated parameters and the current K AKMA . In this way, the derived new K AF can be sent to the AF through step 302 .
- the updated update parameters can be synchronized to the UE by using the existing UE parameter update process, so that the UE and the AAnF can derive the same K AF based on the synchronized update parameters.
- the AAnF executes step 302 after receiving the parameter update response message sent by the UDM, which can avoid the problem of key inconsistency between UE and AF due to unsuccessful UPU.
- the key update request message is a key acquisition request message
- the key acquisition request message carries a key update indicator
- an existing key acquisition request message is used to implement the K AF update process, and an update instruction is implemented through a reserved field in the key acquisition request message.
- the update method for AAnF in the embodiment of the present disclosure corresponds to the update method for AF as shown in FIG. 2 , and can achieve the same beneficial effects as the update method for AF shown in FIG. 2 . repeat.
- the execution subject may be UDM, as shown in FIG. 4, the update method may include the following steps:
- Step 401 Receive a parameter update request message sent by the AAnF.
- Step 402. Send an update parameter to the UE, where the update parameter is used by the UE to generate a session key K AF in combination with K AKMA currently stored in the UE.
- the updating method further includes:
- the embodiment of the present disclosure can achieve the same beneficial effect as the embodiment of the update method shown in FIG.
- the updated parameters are derived to obtain the same K AF .
- the execution subject may be UE, as shown in FIG. 5, the update method may include the following steps:
- Step 501 Receive a key update indication message sent by an application function entity AF, where the key update indication message is used to instruct the UE to update K AF .
- the foregoing key update indication message in the embodiment of the present disclosure has the same meaning as the key update indication message in the method embodiment shown in FIG. 2 .
- the update method provided in the embodiment of the present disclosure further includes:
- the update parameter sent by the UDM is received; the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the UE.
- This step corresponds to step 402 in the method embodiment shown in FIG. 4 , and will not be repeated here.
- the embodiment of the present disclosure can achieve the same beneficial effect as the update method embodiment shown in any one of Fig. 2 to Fig. 4 , and can actively update K AF , so as to avoid the situation in the related art due to the fact that there is no new update between the UE and the network.
- the problem of K AF expiration caused by the initial certification can ensure the smooth progress of AKMA business.
- the update method provided by the embodiment of the present disclosure is illustrated by taking the interaction process between the UE and the network side device as shown in FIG. 6 as an example.
- the process of updating K AF the following interactions can be performed between the UE and the network side device:
- Step 1 When the K AF is about to expire, the AF sends a key update request message (Naanf_AKMA_ApplicationKey_Get_Request) to the AAnF.
- a key update request message Naanf_AKMA_ApplicationKey_Get_Request
- the key update request message carries refresh indicator information to instruct the AAnF to update the KAF .
- the above key update request message may also carry A-KID and AF_ID.
- Step 2 AAnF sends a parameter update request message to UDM.
- the parameter update request message may carry an update parameter, and requests the UDM to deliver the update parameter to the UE.
- step 3 the UDM executes the UPU process.
- the UDM sends the update parameter to the UE if there is an update parameter in the process of executing the UPU process.
- step 4 the execution of the UPU process ends, and the UDM returns a parameter update response message to the AAnF.
- Step 5 AAnF derives K AF based on the updated parameters and K AKMA .
- AAnF after AAnF receives the parameter update response message sent by UDM, it can use the following derivation formula to deduce K AF based on K AKMA :
- K AF KDF(K AKMA , AF_ID, freshness parameter).
- Step 6 AAnF sends a key update response message to the AF.
- the above key update response message may carry the new K AF deduced by the AAnF and its key life cycle.
- Step 7 The AF sends an indication message to the UE.
- the above indication message is used to notify the UE that the key update is successful, and instruct the UE to perform key derivation on the terminal side according to the received update parameters.
- the UE can use the same derivation formula as in step 5 to perform key derivation on the terminal side according to the received update parameters.
- FIG. 7 is a schematic structural diagram of an AF provided by an embodiment of the present disclosure.
- the AF 700 includes:
- the first sending module 701 is configured to send a key update request message to AAnF;
- the first receiving module 702 is configured to receive the updated K AF sent by the AAnF.
- the K AF is carried in the key update response message.
- AF 700 also includes:
- the second sending module is configured to send an indication message to the UE, instructing the UE to update K AF .
- the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the AAnF.
- the key update request message is a key acquisition request message
- the key acquisition request message carries a key update indicator
- the key update response message also carries a key life cycle
- the first sending module 701 is specifically used for:
- the AF 700 provided by the embodiment of the present disclosure may specifically be an AF applying the updating method as shown in FIG. 2 , and the AF 700 can achieve the same beneficial effect as the method embodiment shown in FIG. 2 , which will not be described in detail here.
- FIG. 8 is a schematic structural diagram of the AAnF provided by the embodiment of the present disclosure.
- the AAnF 800 includes:
- the second receiving module 801 is configured to receive a key update request message sent by the AF;
- the third sending module 802 is configured to send the updated K AF to the AF.
- the K AF is carried in the key update response message.
- the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the AAnF.
- AAnF 800 also includes:
- a fourth sending module configured to send a parameter update request message to UDM, indicating that the UDM sends the update parameter to UE;
- the third receiving module is configured to receive the parameter update response message sent by the UDM.
- the key update request message is a key acquisition request message
- the key acquisition request message carries a key update indicator
- the AAnF 800 provided by the embodiment of the present disclosure may specifically be an AAnF applying the updating method as shown in FIG. 3 , and the AAnF 800 can achieve the same beneficial effect as the method embodiment shown in FIG. 3 , which will not be described in detail here.
- FIG. 9 is a schematic structural diagram of a UDM provided by an embodiment of the present disclosure.
- the UDM 900 includes:
- the fourth receiving module 901 is configured to receive a parameter update request message sent by AAnF;
- the fifth sending module 902 is configured to send update parameters to the UE, where the update parameters are used by the UE to generate K AF in combination with the K AKMA currently stored by the UE.
- UDM 900 also includes:
- a sixth sending module configured to send a parameter update response message to the AAnF.
- the UDM 900 provided by the embodiment of the present disclosure may specifically be a UDM applying the updating method as shown in FIG. 4 , and the UDM 900 can achieve the same beneficial effect as the method embodiment shown in FIG. 4 , which will not be described in detail here.
- FIG. 10 is a schematic structural diagram of a network-side device provided by an embodiment of the present disclosure.
- the network-side device includes: a bus 1001, a transceiver 1002, an antenna 1003, a bus interface 1004, and a processor 1005 and memory 1006 .
- the above-mentioned network-side device may be an AF:
- Transceiver 1002 configured to send a key update request message to AAnF;
- the transceiver 1002 is further configured to receive the updated K AF sent by the AAnF.
- the K AF is carried in a key update response message.
- the transceiver 1002 is further configured to send an indication message to the UE, instructing the UE to update K AF .
- the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the AAnF.
- the key update request message is a key acquisition request message
- the key acquisition request message carries a key update indicator
- the key update response message also carries a key life cycle
- the sending of the key update request message to AAnF performed by the transceiver 1002 specifically includes:
- the network side device can implement each process implemented by AF in the method embodiment shown in FIG. 2 , and has the same beneficial effects. To avoid repetition, details are not repeated here.
- the above-mentioned network side device may be AAnF:
- the transceiver 1002 is configured to receive the key update request message sent by the AF;
- the transceiver 1002 is further configured to send the updated K AF to the AF.
- the K AF is carried in a key update response message.
- the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the AAnF.
- the transceiver 1002 is further configured to:
- the key update request message is a key acquisition request message
- the key acquisition request message carries a key update indicator
- the network-side device can implement each process implemented by AAnF in the method embodiment shown in FIG. 3 , and has the same beneficial effects. To avoid repetition, details are not repeated here.
- the above-mentioned network side device may be a UDM:
- Transceiver 1002 configured to receive a parameter update request message sent by AAnF;
- the transceiver 1002 is further configured to send update parameters to the UE, where the update parameters are used by the UE to generate a session key K AF in combination with K AKMA currently stored in the UE.
- the transceiver 1002 is further configured to:
- the network side device can realize each process implemented by UDM in the method embodiment shown in FIG. 4 , and has the same beneficial effect. To avoid repetition, details are not repeated here.
- bus architecture (represented by bus 1001), bus 1001 may include any number of interconnected buses and bridges, bus 1001 will include one or more processors represented by processor 1005 and memory represented by memory 1006 The various circuits are linked together.
- the bus 1001 may also link together various other circuits such as peripherals, voltage regulators, and power management circuits, etc., which are well known in the art and therefore will not be further described herein.
- the bus interface 1004 provides an interface between the bus 1001 and the transceiver 1002 .
- Transceiver 1002 may be a single element, or multiple elements, such as multiple receivers and transmitters, providing a means for communicating with various other devices over a transmission medium.
- the data processed by the processor 1005 is transmitted on the wireless medium through the antenna 1003 , further, the antenna 1003 also receives the data and transmits the data to the processor 1005 .
- the processor 1005 is responsible for managing the bus 1001 and general processing, and may also provide various functions including timing, peripheral interface, voltage regulation, power management, and other control functions. And the memory 1006 may be used to store data used by the processor 1005 when performing operations.
- the processor 1005 can be a central processing unit (Central Processing Unit, CPU), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable logic gate array (Field Programmable Gate Array, FPGA) or a complex programmable Logic device (Complex Programmable logic device, CPLD).
- CPU Central Processing Unit
- ASIC Application Specific Integrated Circuit
- FPGA Field Programmable Gate Array
- CPLD Complex Programmable logic device
- an embodiment of the present disclosure further provides a network side device, including a processor 1005, a memory 1006, a computer program stored in the memory 1006 and operable on the processor 1005, and the computer program is executed by the processor 1005
- a network side device including a processor 1005, a memory 1006, a computer program stored in the memory 1006 and operable on the processor 1005, and the computer program is executed by the processor 1005
- FIG. 11 is a schematic structural diagram of a UE provided by an embodiment of the present disclosure.
- the UE 1100 includes:
- the fifth receiving module 1101 is configured to receive a key update instruction message sent by the AF, where the key update instruction message is used to instruct the UE to update K AF .
- UE 1100 also includes:
- the sixth receiving module is configured to receive the update parameter sent by UDM; the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the UE.
- the UE 1100 provided in the embodiment of the present disclosure may specifically be a UE applying the update method as shown in FIG. 5, and the UE 1100 can obtain the same beneficial effect as the method embodiment shown in FIG. 5, and no specific description is given here.
- FIG. 12 is a structural diagram illustrating a terminal device provided by an embodiment of the present disclosure.
- the first user device includes: a bus 1201, a transceiver 1202, an antenna 1203, a bus interface 1204, and a processor 1205 and memory 1206.
- the transceiver 1202 is configured to receive a key update instruction message sent by the AF, where the key update instruction message is used to instruct the UE to update K AF .
- the transceiver 1202 is also used for:
- the update parameter sent by the UDM is received; the K AF is a key generated at least according to the update parameter and the K AKMA currently stored in the UE.
- the terminal device can implement each process implemented by the UE in the method embodiment shown in FIG. 5 , and has the same beneficial effects. To avoid repetition, details are not repeated here.
- bus architecture (represented by bus 1201), bus 1201 may include any number of interconnected buses and bridges, bus 1201 will include one or more processors represented by processor 1205 and memory represented by memory 1206 The various circuits are linked together.
- the bus 1201 may also link together various other circuits such as peripherals, voltage regulators, and power management circuits, etc., which are well known in the art and thus will not be further described herein.
- the bus interface 1204 provides an interface between the bus 1201 and the transceiver 1202 .
- Transceiver 1202 may be a single element or multiple elements, such as multiple receivers and transmitters, providing a means for communicating with various other devices over a transmission medium.
- the data processed by the processor 1205 is transmitted on the wireless medium through the antenna 1203 , further, the antenna 1203 also receives the data and transmits the data to the processor 1205 .
- the processor 1205 is responsible for managing the bus 1201 and general processing, and may also provide various functions including timing, peripheral interface, voltage regulation, power management, and other control functions. Instead, the memory 606 may be used to store data used by the processor 1205 when performing operations.
- the processor 1205 may be a CPU, ASIC, FPGA or CPLD.
- an embodiment of the present disclosure further provides a terminal device, including a processor 1205, a memory 1206, and a computer program stored in the memory 1206 and operable on the processor 1205.
- a terminal device including a processor 1205, a memory 1206, and a computer program stored in the memory 1206 and operable on the processor 1205.
- the computer program is executed by the processor 1205
- the various processes of the embodiment of the update method shown in FIG. 5 above are implemented, and the same technical effect can be achieved. In order to avoid repetition, details are not repeated here.
- An embodiment of the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the implementation of the update method shown in any one of Figures 2 to 5 above is implemented. Each process can achieve the same technical effect, so in order to avoid repetition, it will not be repeated here.
- the computer-readable storage medium is, for example, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disk, and the like.
- ROM Read-Only Memory
- RAM Random Access Memory
- magnetic disk or an optical disk and the like.
- the computer software product is stored in a storage medium (such as ROM/RAM, magnetic disk, optical disk, etc.) ) includes several instructions to make a terminal (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) execute the methods described in various embodiments of the present disclosure.
- a storage medium such as ROM/RAM, magnetic disk, optical disk, etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本公开提供一种更新方法、网络侧设备、终端和计算机可读存储介质,其中,应用于AF的更新方法,包括:向会话密钥管理锚点功能实体AAnF发送密钥更新请求消息;接收所述AAnF发送的更新的会话密钥K AF。
Description
相关申请的交叉引用
本公开主张在2021年8月9日在中国提交的中国专利申请号No.202110909519.1的优先权,其全部内容通过引用包含于此。
本公开涉及通信技术领域,尤其涉及一种更新方法、网络侧设备、终端和计算机可读存储介质。
相关的应用层认证和会话密钥管理(Authentication and Key Management for Applications,AKMA)流程中,只有在用户设备(User Equipment,UE)和网络之间进行了新的初始认证,以产生了新的AKMA中间密钥(AKMA Anchor Key,K
AKMA)的时候,才会通过UE和应用功能实体(Application Function,AF)之间的Ua*协议更新AKMA会话密钥(AKMA Application Key,K
AF)。这样,就存在K
AF过期后,如果UE和网络之间没有进行新的初始认证,则UE和网络之间的AKMA业务就会由于K
AF失效而中断的缺陷。
发明内容
本公开提供一种更新方法、网络侧设备、终端和计算机可读存储介质,能够主动发起K
AF的更新流程,以避免UE和网络之间的AKMA业务,因UE和网络之间未进行新的初始认证而中断的问题。
为解决上述技术问题,本公开是这样实现的:
第一方面,本公开提供了一种更新方法,应用于AF,所述更新方法包括:
向会话密钥管理锚点功能实体(AKMA anchor Function,AAnF)发送密钥更新请求消息;
接收所述AAnF发送的更新的K
AF。
第二方面,本公开提供了一种更新方法,应用于AAnF,所述更新方法 包括:
接收AF发送的密钥更新请求消息;
向所述AF发送更新的K
AF。
第三方面,本公开提供了一种更新方法,应用于统一数据管理功能实体(Unified Data Management,UDM),所述更新方法包括:
接收AAnF发送的参数更新请求消息;
发送更新参数到UE,所述更新参数用于所述UE结合所述UE当前存储的应用层认证和会话密钥管理AKMA中间密钥K
AKMA生成K
AF。
第四方面,本公开提供了一种更新方法,应用于UE,所述更新方法包括:
接收AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新K
AF。
第五方面,本公开提供了一种AF,包括:
第一发送模块,用于向AAnF发送密钥更新请求消息;
第一接收模块,用于接收所述AAnF发送的更新的K
AF。
第六方面,本公开提供了一种AAnF,包括:
第二接收模块,用于接收AF发送的密钥更新请求消息;
第三发送模块,用于向所述AF发送更新的K
AF。
第七方面,本公开提供了一种UDM,包括:
第四接收模块,用于接收AAnF发送的参数更新请求消息;
第五发送模块,用于发送更新参数到UE,所述更新参数用于所述UE结合所述UE当前存储的K
AKMA生成K
AF。
第八方面,本公开提供了一种UE,包括:
第五接收模块,用于接收AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新K
AF。
第九方面,本公开提供了一种网络侧设备,包括:处理器和收发机;
所述收发机,用于向AAnF发送密钥更新请求消息;
所述收发机,还用于接收所述AAnF发送的更新的K
A;
和/或
所述收发机,用于接收AF发送的密钥更新请求消息;
所述收发机,还用于向所述AF发送更新的K
AF;
和/或
所述收发机,用于接收AAnF发送的参数更新请求消息;
所述收发机,还用于发送更新参数到UE,所述更新参数用于所述UE结合所述UE当前存储的K
AKMA生成K
AF。
第十方面,本公开提供了一种用户设备UE,包括:处理器和收发机;
所述收发机,用于接收AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新K
AF。
第十一方面,本公开提供了一种网络侧设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如第一方面所述的更新方法中的步骤,或者实现如第二方面所述的更新方法中的步骤,或者实现如第三方面所述的更新方法中的步骤。
第十二方面,本公开提供了一种终端设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,所述计算机程序被所述处理器执行时实现如第四方面所述的更新方法中的步骤。
第十三方面,本公开提供了一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时,实现如第一方面所述的更新方法中的步骤,或者实现如第二方面所述的更新方法中的步骤,或者实现如第三方面所述的更新方法中的步骤,或者实现如第四方面所述的更新方法中的步骤。
本公开实施例中,提供了一种AF主动发起的密钥更新流程,能够主动更新K
AF,以避免相关技术中由于UE和网络之间没有进行新的初始认证而导致的K
AF过期的问题,进而能够保证AKMA业务的顺利进行。
图1是相关技术中K
AF的更新流程示意图;
图2是本公开实施例提供的一种应用于AF的更新方法的流程图;
图3是本公开实施例提供的一种应用于AAnF的更新方法的流程图;
图4是本公开实施例提供的一种应用于UDM的更新方法的流程图;
图5是本公开实施例提供的一种应用于UE的更新方法的流程图;
图6是本公开实施例中UE与网络侧设备之间的数据交互示意图;
图7是本公开实施例提供的一种AF的结构示意图;
图8是本公开实施例提供的一种AAnF的结构示意图;
图9是本公开实施例提供的一种UDM的结构示意图;
图10是本公开实施例提供的一种网络侧设备的结构示意图;
图11是本公开实施例提供的一种UE的结构示意图;
图12是本公开实施例提供的一种终端设备的结构示意图。
为使本公开要解决的技术问题、技术方案和优点更加清楚,下面将结合附图及具体实施例进行详细描述。在下面的描述中,提供诸如具体的配置和组件的特定细节仅仅是为了帮助全面理解本公开的实施例。因此,本领域技术人员应该清楚,可以对这里描述的实施例进行各种改变和修改而不脱离本公开的范围和精神。另外,为了清楚和简洁,省略了对已知功能和构造的描述。
应理解,说明书通篇中提到的“一个实施例”或“一实施例”意味着与实施例有关的特定特征、结构或特性包括在本公开的至少一个实施例中。因此,在整个说明书各处出现的“在一个实施例中”或“在一实施例中”未必一定指相同的实施例。此外,这些特定的特征、结构或特性可以任意适合的方式结合在一个或多个实施例中。
在本公开的各种实施例中,应理解,下述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本公开实施例的实施过程构成任何限定。
在相关技术中,第三代合作伙伴计划(3rd Generation Partnership Project,3GPP)相关协议定义了如下应用层认证和密钥管理的架构和流程:
如图1所示,在调用AKMA服务之前,UE应已成功注册到第五代(the 5
th Generation,5G)核心网,这样,在通过5G接入认证后,认证服务器功能 (AUthentication Server Function,AUSF)密钥(AUSF Key,K
AUSF)将存储在AUSF和UE中。
其中,AUSF、AAnF以及UE同属于一个用户归属的公共陆地移动网络(Home Public Land Mobile Network,HPLMN)。
如图1所示,在用户设备(即UE,其也可以称之为终端)接入运营商网络并执行完主认证(其也称之为初始认证)规定的5G个人身份验证成功之后,终端和网络侧的认证服务器功能实体(AUthentication Server Function,AUSF)就生成密钥K
AUSF。如果终端注册并签约了AKMA服务,那么在初始认证完成之后,终端和AUSF就会相应地生成AKMA中间密钥K
AKMA及对应的密钥标识符(AKMA Key IDentifier,A-KID),并基于该K
AKMA及A-KID向应用服务器提供后续的会话密钥K
AF,进而使UE和应用服务器能够基于该K
AF进行对应用层认证或数据加密等。
具体的,终端向应用服务器发起业务请求时,在请求消息中会携带A-KID,当应用服务器收到该请求时,会带着该A-KID向AAnF请求会话密钥。此时,AAnF根据从AUSF处获取的AKMA中间密钥K
AKMA推衍会话密钥K
AF,并将该会话密钥K
AF返回给应用服务器。相应的,终端在收到应用服务器返回给自己的应用层响应消息后,也根据自身存储的K
AKMA推衍出会话密钥K
AF。这样,应用服务器和终端即可使用该会话密钥进行后续的应用层认证或数据加密等。
需要说明的是,在执行下一次成功的初始认证(隐式生存期)之前,当前的K
AKMA和A-KID是有效的。而在执行下一次成功的初始认证之后,K
AKMA和A-KID会被更新。而AKMA的会话密钥K
AF根据运营商的政策具有明确的寿命。当K
AF的生存期到期时,将需要基于当前AKMA中间密钥K
AKMA建立新的AKMA应用程序密钥。而相关技术中,并不是所有的Ua*协议都支持密钥刷新,比如传输层安全(Transport Layer Security,TLS)协议并不支持对应的更新流程。所以当Ua*不支持密钥更新机制时,就存在以下问题:如果此时UE和网络侧之间没有进行新的初始认证,即K
AKMA没有更新,即则无法触发K
AF的更新流程。
换而言之,在初始认证周期内即使K
AF过期,由于此时K
AKMA没有发生 更新,则无法触发K
AF的更新,造成AF可能会断开与UE的应用层连接,进而出现AKMA业务中断。
而本公开实施例中,提供了一种AF主动发起的密钥更新流程,即使在UE和网络之间没有进行新的初始认证时,也能够主动更新K
AF,以避免相关技术中由于UE和网络之间没有进行新的初始认证而导致的K
AF过期的问题,进而能够保证AKMA业务的顺利进行。
为了更清楚的说明本公开提供的更新方法,以下实施例中,结合附图,对本公开实施例提供的更新方法进行说明:
请参阅图2,本公开实施例提供的第一种更新方法,其执行主体可以是AF,如图2所示,该更新方法可以包括以下步骤:
步骤201、向AAnF发送密钥更新请求消息。
在具体实施中,执行本公开实施例提供的更新方法的AF,具体可以是使用AKMA服务的AF,其具有以下附加功能:
支持使用A-KID从AAnF请求K
AF。
在向AF提供AKMA应用密钥之前,AF应由运营商网络进行认证和授权。
本步骤中,AF通过向AAnF发送密钥更新请求消息,以使AAnF根据该密钥更新请求消息生成新的K
AF,并将该新生成的K
AF返回给AF。
步骤202、接收所述AAnF发送的更新的K
AF。
在一种可选的实施方式中,AAnF在接收到所述密钥更新请求消息时,可以触发UE和网络执行的新的初始认证,以生成新的K
AKMA,然后再根据新生成的K
AKMA来实现K
AF的更新,即K
AF=KDF(K
AKMA,AF_ID)。
本实施方式中,即使UE和网络之间不需要进行新的初始认证的情况下,但由于K
AF的更新需求,需要触发新的初始认证。这种方式下,应用层的密钥更新会影响5G网络基础主认证。而K
AF的更新需求相对于初始认证更加频繁,因此上述的方式会导致对5G网络频繁发起主认证,进而造成对5G网络的DDoS攻击隐患,影响5G网络基础业务运行。
当然,上述UE和网络之间的新的初始认证也可以由AAnF指示终端,以由终端发起。而这种方式,需要对终端进行改动,且影响终端的基础安全 机制,例如:需要终端释放非接入层(Non-Access Stratum,NAS)链接,并修改NAS密钥集标识(NAS key set identifier,ngKSI)参数,故而触发主认证。
因此,为了解决上述的问题,本公开实施例还提供如下另一种可选的实施方式,以使K
AF的更新不再依赖于K
AKMA的更新:
所述K
AF可以是至少根据更新参数和所述AAnF当前存储的K
AKMA生成的密钥。
本实施方式中,当AAnF接收到AF发送的密钥更新请求消息之后,可以基于接收到该密钥更新请求消息,而直接根据更新参数和AAnF当前存储的K
AKMA生成新的K
AF。
在相关技术中,K
AF的推衍公式如下:
K
AF=KDF(K
AKMA,AF_ID)
其中,KDF表示密钥推衍函数(Key Derivation Function)。AF_ID表示AF的标识符。
而本实施方式中,可以将K
AF的推衍公式修改为:
K
AF=KDF(K
AKMA,AF_ID,freshness parameter)或K
AF=KDF(K
AKMA,freshness parameter)
其中,freshness parameter即表示上述更新参数。
可选的,上述更新参数,可以理解为:密钥新鲜参数(freshness parameter),用于表示K
AF的新鲜度,且该更新参数的取值可以是计数器(COUNTER)的计数值或随机数等等,这样,每一次推衍K
AF时可以采用不同取值的更新参数,以使根据上述推衍公式推衍出的K
AF不同。
当然,上述更新参数还可以是其他UE参数更新(UE Parameter Update,UPU)参数。
本实施方式相较于上一可选的实施方式来说,新增了更新参数,使得K
AF的更新不再依赖于K
AKMA的更新,而是可以通过对更新参数进行更新来实现基于相同的K
AKMA实现对K
AF的更新。上述的方式中,即使在UE和网络之间没有进行新的初始认证时,也不再需要发起UE和网络之间的新的初始认证来更新K
AKMA,而是通过引入的K
AKMA之外的更新参数来实现K
AF的更新。 这种方式避免了对5G网络的频发的主认证以及对网络和终端的改动。
上述的两种方式中,根据不同的场景或者处理方式,可以根据已有的推衍公式来生成K
AF,也可以根据新增密钥新鲜参数的推衍公式来生成K
AF,也就是本公开具体实施例中,上述的freshness parameter为可选的参数,根据不同的处理方式而确定。例如:在K
AF的更新依赖于K
AKMA的更新的实施方式下,可以在推衍公式中不采用freshness parameter;而在K
AF的更新不再依赖于K
AKMA的更新的实施方式下,可以在推衍公式中采用freshness parameter。
进一步的,上述密钥更新请求消息还可以携带A-KID。
作为一种可选的实施方式,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
在具体实施中,上述密钥更新指示符用于指示AF需要更新K
AF。
在具体实施中,上述密钥获取请求消息为相关技术中的密钥获取请求消息,且上述密钥更新指示符通过密钥获取请求消息中的保留字段来实现。这样,能够利用已有密钥获取请求消息来实现K
AF更新流程,并通过密钥获取请求消息中的保留字段来实现更新指示。
在实际应用中,密钥获取请求消息中也可以不携带密钥更新指示符,此时,AAnF在接收到AF发送的密钥获取请求消息之后,可以不对K
AF进行更新,而是在密钥获取响应消息中携带AAnF当前存储的K
AF。
例如:在K
AF未过期,且AF丢失或未成功接收到K
AF的情况下,AAnF可以重新向AF发送当前存储的K
AF。
相应的,在K
AF未更新的情况下,不需要将K
AF和UE同步,这样,可以避免因密钥更新流程与密钥获取流程未区分而造成,的不论是更新K
AF还是获取K
AF,都需要与UE进行密钥同步,而是仅在密钥更新流程中才与UE进行密钥同步,可以简化密钥获取流程。
本实施方式中,利用现有的密钥获取请求消息中是否携带密钥更新指示符,使密钥更新流程区别于现有的密钥获取流程,使得更新K
AF和获取K
AF可以通过不同的流程来实现,简化了流程。
当然,在实际应用中,上述密钥更新请求消息也可以是新增的消息,在此不作具体限定。
可选地,在步骤202之后,为了实现AF与UE之间的密钥同步,AF还可以执行以下步骤:
向UE发送指示消息,指示所述UE更新K
AF。
本步骤中,AF可以在从AAnF获取到的新的K
AF之后,通知/指示UE更新K
AF,以使UE和AF使用相同的K
AF。
当然,在实际应用中,还可以通过其他方式实现AF与UE之间的密钥同步,例如:通过UPU流程来实现,或者由AAnF指示UE更新K
AF,在此对AF与UE之间的密钥同步的具体实现方式,不作具体限定。
可选地,所述K
AF携带于密钥更新响应消息中。
也就是说,步骤202具体可以是:接收所述AAnF发送的密钥更新响应消息,且所述密钥更新响应消息中携带更新的K
AF。
当然,除了上述密钥更新响应消息之外,AAnF还可以通过其他任意消息或指示信息将更新的K
AF发送至AF,在此不作具体限定。
作为一种可选的实施方式,所述密钥更新响应消息还携带密钥生命周期,所述向AAnF发送密钥更新请求消息,具体包括:
根据所述密钥生命周期,向AAnF发送所述密钥更新请求消息。
在具体实施中,AF能够根据该密钥生命周期确定K
AF在什么时间过期,例如:上述密钥生命周期可以是一个时间点,在达到该时间点时K
AF过期,或者上述密钥生命周期可以是预设时间长度,K
AF在使用预设时间长度后过期。在此对密钥生命周期的具体形式不作限定。
在一种可选的实施方式中,上述根据所述密钥生命周期,向AAnF发送所述密钥更新请求消息,可以理解为:根据所述密钥生命周期,在确定当前的K
AF即将过期时,向AAnF发送所述密钥更新请求消息。例如:在当前的K
AF到期之前的预设时间(例如:1s、2s等),向AAnF发送所述密钥更新请求消息。
本实施方式可以在当前的K
AF到期之前,提前发起K
AF的更新流程。
在另一种可选的实施方式中,上述根据所述密钥生命周期,向AAnF发送所述密钥更新请求消息,可以理解为:根据所述密钥生命周期,在确定当前的K
AF过期时,向AAnF发送所述密钥更新请求消息。例如:在确定当前 的K
AF到期后的预设时间(例如:0s、1s、2s等),向AAnF发送所述密钥更新请求消息。
本实施方式可以在当前的K
AF到期之后,发起K
AF的更新流程。
本公开实施例中,提供了一种AF主动发起的密钥更新流程,能够主动更新K
AF,以避免相关技术中由于UE和网络之间没有进行新的初始认证而导致的K
AF过期的问题,进而能够保证AKMA业务的顺利进行。
请参阅图3,本公开实施例提供的第二种更新方法,其执行主体可以是AAnF,如图3所示,该更新方法可以包括以下步骤:
步骤301、接收AF发送的密钥更新请求消息。
步骤302、向所述AF发送更新的K
AF。
本公开实施例中的上述密钥更新请求消息、更新的K
AF分别与如图2所示方法实施例中的密钥更新请求消息、更新的K
AF具有相同的含义和作用,在此不再赘述。
本公开实施例同样能够在AF的触发下,主动更新K
AF,以避免相关技术中由于UE和网络之间没有进行新的初始认证而导致的K
AF过期的问题,进而能够保证AKMA业务的顺利进行。
可选地,所述K
AF携带于密钥更新响应消息中。
在一种可选的实施方式中,AAnF在接收到AF发送的密钥更新请求消息之后,可以按照如图2所示方法实施例中K
AF的更新流程对K
AF进行更新,并在密钥更新响应消息中携带更新后的K
AF。
例如:在K
AF即将过期,或者K
AF已经过期的情况下,可以按照如图2所示方法实施例中K
AF的更新流程对K
AF进行更新,并在密钥更新响应消息中携带更新后的K
AF。
在实际应用中,可以在密钥更新请求消息中携带A-KID、AF_ID以及更新指示(refresh indicator)信息。
这样,AAnF可以根据更新这些信息区分是初次请求获取K
AF还是用于请求更新K
AF。
可选的,所述K
AF为至少根据更新参数和所述AAnF当前存储的K
AKMA生成的密钥。
本实施方式中,通过新增更新参数,使得K
AF的更新不再依赖于K
AKMA的更新,而是可以通过更新参数的更新来实现K
AF的更新,从而不再需要通过UE和网络之间的新的初始认证来更新K
AKMA,便可以实现K
AF的更新。这种方式避免了对5G网络的主认证以及终端的改动。
可选的,在上述步骤301和步骤302之间,本公开实施例提供的更新方法还包括:
向UDM发送参数更新请求消息,指示所述UDM发送所述更新参数到用户设备UE;
接收所述UDM发送的参数更新响应消息。
在具体实施中,UDM可以存储AKMA服务订阅用户的AKMA订阅数据。在实施中,UDM基于接收到的参数更新请求消息,可以发起UPU流程,以更新UE参数,该UE参数包括更新参数。这样,可以利用现有的UPU流程向UE下发更新参数,以使UE能够根据该更新参数推衍得到更新后的K
AF,即实现了利用现有的UE参数更新流程将更新后的更新参数同步至UE。
另外,AAnF在接收到UDM发送的参数更新响应消息时,可以基于更新参数和当前的K
AKMA推衍K
AF。这样,便可以通过步骤302将推衍得到的新的K
AF发送给AF。
本实施方式中,可以利用现有的UE参数更新流程将更新后的更新参数同步至UE,进而使UE和AAnF可以基于同步的更新参数推衍得到相同的K
AF。
换个方向来说,在实际应用中还可能存在UPU失败的情况,此时,因UPU失败,UE没能够获取到更新参数,此时若AAnF直接执行步骤302,则存在因UPU不成功,而导致UE和AF密钥不一致的问题。
而本实施方式中,AAnF在收到UDM发送的参数更新响应消息之后,才执行步骤302,能够避免因UPU不成功,则导致的UE和AF密钥不一致的问题。
可选的,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
本实施方式中,利用已有密钥获取请求消息来实现K
AF更新流程,并通 过密钥获取请求消息中的保留字段来实现更新指示。
本公开实施例中用于AAnF的更新方法与如图2所示用于AF的更新方法相对应,且能够取得与如图2所示用于AF的更新方法相同的有益效果,在此不再赘述。
请参阅图4,本公开实施例提供的第三种更新方法,其执行主体可以是UDM,如图4所示,该更新方法可以包括以下步骤:
步骤401、接收AAnF发送的参数更新请求消息。
步骤402、发送更新参数到UE,所述更新参数用于所述UE结合所述UE当前存储的K
AKMA生成会话密钥K
AF。
可选的,在上述步骤402之后,所述更新方法还包括:
向所述AAnF发送参数更新响应消息。
本公开实施例中的上述参数更新请求消息、更新参数和参数更新响应消息分别与如图3所示方法实施例中的参数更新请求消息、更新参数和参数更新响应消息具有相同的含义,在此不再赘述。
本公开实施例能够取得与如图3所示更新方法实施例相同的有益效果,且可以利用现有的UE参数更新流程将更新后的更新参数同步至UE,进而使UE和AAnF可以基于同步的更新参数推衍得到相同的K
AF。
请参阅图5,本公开实施例提供的第四种更新方法,其执行主体可以是UE,如图5所示,该更新方法可以包括以下步骤:
步骤501、接收应用功能实体AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新K
AF。
本公开实施例中的上述密钥更新指示消息与如图2所示方法实施例中的密钥更新指示消息具有相同的含义。
可选的,本公开实施例提供的更新方法还包括:
接收UDM发送的更新参数;所述K
AF为至少根据所述更新参数和所述UE当前存储的K
AKMA生成的密钥。
本步骤与如图4所示方法实施例中的步骤402相对应,在此不再赘述。
本公开实施例能够取得与如图2至图4中任一项所示更新方法实施例相同的有益效果,且能够主动更新K
AF,以避免相关技术中由于UE和网络之间 没有进行新的初始认证而导致的K
AF过期的问题,进而能够保证AKMA业务的顺利进行。
为了便于理解本公开实施例通过的更新方法,以如图6所示UE与网络侧设备之间的交互过程为例,对本公开实施例提供的更新方法进行举例说明,在更新K
AF的过程中,UE与网络侧设备之间可以进行以下交互:
步骤1,在K
AF即将过期时,由AF向AAnF发送密钥更新请求消息(Naanf_AKMA_ApplicationKey_Get_Request)。
本步骤中,上述密钥更新请求消息携带更新指示(refresh indicator)信息,以指示AAnF进行K
AF的更新。上述密钥更新请求消息还可以携带A-KID和AF_ID。
步骤2,AAnF向UDM发送参数更新请求消息。
本步骤中,参数更新请求消息可以携带更新参数,要求UDM向UE下发该更新参数。
步骤3,UDM执行UPU流程。
本步骤中,UDM在执行UPU流程的过程中,在有更新参数的情况下,将该更新参数发送给UE。
步骤4,UPU流程执行结束,UDM向AAnF返回参数更新响应消息。
步骤5,AAnF基于更新参数和K
AKMA推衍K
AF。
本步骤中,AAnF在收到UDM发送的参数更新响应消息后,可以采用以下推衍公式,实现基于K
AKMA推衍K
AF:
K
AF=KDF(K
AKMA,AF_ID,freshness parameter)。
步骤6,AAnF向AF发送密钥更新响应消息。
本步骤中,上述密钥更新响应消息可以携带AAnF推演出的新的K
AF及其密钥生命周期。
步骤7.AF向UE发送指示消息。
本步骤中,收到更新后的K
AF后,通过上述指示消息通知UE密钥更新成功,并指示UE根据收到的更新参数在终端侧进行密钥推衍。且UE可以采用与步骤5中相同的推衍公式,来根据收到的更新参数在终端侧进行密钥推衍。
如图6所示实施方式下,在K
AF密钥推衍过程中,新增了更新参数,通过新增更新参数使得K
AF的更新不再依赖于K
AKMA的更新,而是通过更新参数的更新来实现K
AF的更新,且该更新参数的传递可以利用现有的UPU流程。
请参阅图7,是本公开实施例提供的一种AF的结构示意图,如图7所示,该AF 700包括:
第一发送模块701,用于向AAnF发送密钥更新请求消息;
第一接收模块702,用于接收所述AAnF发送的更新的K
AF。
可选的,所述K
AF携带于密钥更新响应消息中。
可选的,AF 700还包括:
第二发送模块,用于向UE发送指示消息,指示所述UE更新K
AF。
可选的,所述K
AF为至少根据更新参数和所述AAnF当前存储的K
AKMA生成的密钥。
可选的,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
可选的,所述密钥更新响应消息还携带密钥生命周期,第一发送模块701,具体用于:
根据所述密钥生命周期,向AAnF发送所述密钥更新请求消息。
本公开实施例提供的AF 700具体可以是应用如图2所示更新方法的AF,且该AF 700能够取得与如图2所示方法实施例相同的有益效果,在此不作具体阐述。
请参阅图8,是本公开实施例提供的AAnF的结构示意图,如图8所示,该AAnF 800包括:
第二接收模块801,用于接收AF发送的密钥更新请求消息;
第三发送模块802,用于向所述AF发送更新的K
AF。
可选的,所述K
AF携带于密钥更新响应消息中。
可选的,所述K
AF为至少根据更新参数和所述AAnF当前存储的K
AKMA生成的密钥。
可选的,AAnF 800还包括:
第四发送模块,用于向UDM发送参数更新请求消息,指示所述UDM发 送所述更新参数到UE;
第三接收模块,用于接收所述UDM发送的参数更新响应消息。
可选的,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
本公开实施例提供的AAnF 800具体可以是应用如图3所示更新方法的AAnF,且该AAnF 800能够取得与如图3所示方法实施例相同的有益效果,在此不作具体阐述。
请参阅图9,是本公开实施例提供的UDM的结构示意图,如图9所示,该UDM 900包括:
第四接收模块901,用于接收AAnF发送的参数更新请求消息;
第五发送模块902,用于发送更新参数到UE,所述更新参数用于所述UE结合所述UE当前存储的K
AKMA生成K
AF。
可选的,UDM 900还包括:
第六发送模块,用于向所述AAnF发送参数更新响应消息。
本公开实施例提供的UDM 900具体可以是应用如图4所示更新方法的UDM,且该UDM 900能够取得与如图4所示方法实施例相同的有益效果,在此不作具体阐述。
请参阅图10,是本公开实施例提供的一种网络侧设备的结构示意图,如图10所示,该网络侧设备包括:总线1001、收发机1002、天线1003、总线接口1004、处理器1005和存储器1006。
在第一种实施方式中,上述网络侧设备可以是AF:
收发机1002,用于向AAnF发送密钥更新请求消息;
收发机1002,还用于接收所述AAnF发送的更新的K
AF。
可选地,所述K
AF携带于密钥更新响应消息中。
可选地,收发机1002,还用于向UE发送指示消息,指示所述UE更新K
AF。
可选地,所述K
AF为至少根据更新参数和所述AAnF当前存储的K
AKMA生成的密钥。
可选地,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请 求消息中携带密钥更新指示符。
可选地,所述密钥更新响应消息还携带密钥生命周期,收发机1002执行的所述向AAnF发送密钥更新请求消息,具体包括:
根据所述密钥生命周期,向AAnF发送所述密钥更新请求消息。
本实施方式中,网络侧设备能够实现图2所示方法实施例中AF实现的各个过程,且具有相同的有益效果,为避免重复,这里不再赘述。
在第二种实施方式中,上述网络侧设备可以是AAnF:
收发机1002,用于接收AF发送的密钥更新请求消息;
收发机1002,还用于向所述AF发送更新的K
AF。
可选地,所述K
AF携带于密钥更新响应消息中。
可选地,所述K
AF为至少根据更新参数和所述AAnF当前存储的K
AKMA生成的密钥。
可选地,收发机1002在执行所述接收AF发送的密钥更新请求消息和向所述AF发送更新的K
AF之间,还用于:
向UDM发送参数更新请求消息,指示所述UDM发送所述更新参数到UE;
接收所述UDM发送的参数更新响应消息。
可选地,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
本实施方式中,网络侧设备能够实现图3所示方法实施例中AAnF实现的各个过程,且具有相同的有益效果,为避免重复,这里不再赘述。
在第三种实施方式中,上述网络侧设备可以是UDM:
收发机1002,用于接收AAnF发送的参数更新请求消息;
收发机1002,还用于发送更新参数到UE,所述更新参数用于所述UE结合所述UE当前存储的K
AKMA生成会话密钥K
AF。
可选地,收发机1002在执行所述发送更新参数到UE之后,还用于:
向所述AAnF发送参数更新响应消息。
本实施方式中,网络侧设备能够实现图4所示方法实施例中UDM实现的各个过程,且具有相同的有益效果,为避免重复,这里不再赘述。
在图10中,总线架构(用总线1001来代表),总线1001可以包括任意数量的互联的总线和桥,总线1001将包括由处理器1005代表的一个或多个处理器和存储器1006代表的存储器的各种电路链接在一起。总线1001还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口1004在总线1001和收发机1002之间提供接口。收发机1002可以是一个元件,也可以是多个元件,比如多个接收器和发送器,提供用于在传输介质上与各种其他装置通信的单元。经处理器1005处理的数据通过天线1003在无线介质上进行传输,进一步,天线1003还接收数据并将数据传送给处理器1005。
处理器1005负责管理总线1001和通常的处理,还可以提供各种功能,包括定时,外围接口,电压调节、电源管理以及其他控制功能。而存储器1006可以被用于存储处理器1005在执行操作时所使用的数据。
可选的,处理器1005可以是中央处理器(Central Processing Unit,CPU)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程逻辑门阵列(Field Programmable Gate Array,FPGA)或复杂可编程逻辑器件(Complex Programmable logic device,CPLD)。
优选的,本公开实施例还提供一种网络侧设备,包括处理器1005,存储器1006,存储在存储器1006上并可在所述处理器1005上运行的计算机程序,该计算机程序被处理器1005执行时实现上述图2至图4中任一项所示更新方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
请参阅图11,是本公开实施例提供的UE的结构示意图,如图11所示,该UE 1100包括:
第五接收模块1101,用于接收AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新K
AF。
可选的,UE 1100还包括:
第六接收模块,用于接收UDM发送的更新参数;所述K
AF为至少根据所述更新参数和所述UE当前存储的K
AKMA生成的密钥。
本公开实施例提供的UE 1100具体可以是应用如图5所示更新方法的UE,且该UE 1100能够取得与如图5所示方法实施例相同的有益效果,在此不作具体阐述。
请参阅图12,是示意本公开实施例提供的一种终端设备的结构图,如图12所示,该第一用户设备包括:总线1201、收发机1202、天线1203、总线接口1204、处理器1205和存储器1206。
收发机1202,用于接收AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新K
AF。
可选地,收发机1202,还用于:
接收UDM发送的更新参数;所述K
AF为至少根据所述更新参数和所述UE当前存储的K
AKMA生成的密钥。
本实施方式中,终端设备能够实现图5所示方法实施例中UE实现的各个过程,且具有相同的有益效果,为避免重复,这里不再赘述。
在图12中,总线架构(用总线1201来代表),总线1201可以包括任意数量的互联的总线和桥,总线1201将包括由处理器1205代表的一个或多个处理器和存储器1206代表的存储器的各种电路链接在一起。总线1201还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口1204在总线1201和收发机1202之间提供接口。收发机1202可以是一个元件,也可以是多个元件,比如多个接收器和发送器,提供用于在传输介质上与各种其他装置通信的单元。经处理器1205处理的数据通过天线1203在无线介质上进行传输,进一步,天线1203还接收数据并将数据传送给处理器1205。
处理器1205负责管理总线1201和通常的处理,还可以提供各种功能,包括定时,外围接口,电压调节、电源管理以及其他控制功能。而存储器606可以被用于存储处理器1205在执行操作时所使用的数据。
可选的,处理器1205可以是CPU、ASIC、FPGA或CPLD。
优选的,本公开实施例还提供一种终端设备,包括处理器1205,存储器1206,存储在存储器1206上并可在所述处理器1205上运行的计算机程序, 该计算机程序被处理器1205执行时实现上述图5所示更新方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
本公开实施例还提供一种计算机可读存储介质,计算机可读存储介质上存储有计算机程序,该计算机程序被处理器执行时实现上述图2至图5中任一项所示更新方法实施的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述的计算机可读存储介质,如只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本公开的技术方案本质上或者说对相关技术做出贡献的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,空调器,或者网络设备等)执行本公开各个实施例所述的方法。
上面结合附图对本公开的实施例进行了描述,但是本公开并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本公开的启示下,在不脱离本公开宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本公开的保护之内。
Claims (31)
- 一种更新方法,应用于应用功能实体AF,所述更新方法包括:向会话密钥管理锚点功能实体AAnF发送密钥更新请求消息;接收所述AAnF发送的更新的会话密钥K AF。
- 根据权利要求1所述的更新方法,其中,所述K AF携带于密钥更新响应消息中。
- 根据权利要求1所述的更新方法,其中,在所述接收所述AAnF发送的更新的K AF之后,还包括:向用户设备UE发送指示消息,指示所述UE更新K AF。
- 根据权利要求1所述的更新方法,其中,所述K AF为至少根据更新参数和所述AAnF当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成的密钥。
- 根据权利要求1所述的更新方法,其中,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
- 根据权利要求2所述的更新方法,其中,所述密钥更新响应消息还携带密钥生命周期,所述向AAnF发送密钥更新请求消息,具体包括:根据所述密钥生命周期,向AAnF发送所述密钥更新请求消息。
- 一种更新方法,应用于会话密钥管理锚点功能实体AAnF,所述更新方法包括:接收应用功能实体AF发送的密钥更新请求消息;向所述AF发送更新的会话密钥K AF。
- 根据权利要求7所述的更新方法,其中,所述K AF携带于密钥更新响应消息中。
- 根据权利要求8所述的更新方法,其中,所述K AF为至少根据更新参数和所述AAnF当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成的密钥。
- 根据权利要求9所述的更新方法,其中,所述接收AF发送的密钥更新请求消息和所述向所述AF发送更新的K AF之间,还包括:向统一数据管理功能实体UDM发送参数更新请求消息,指示所述UDM发送所述更新参数到用户设备UE;接收所述UDM发送的参数更新响应消息。
- 根据权利要求7所述的更新方法,其中,所述密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
- 一种更新方法,应用于统一数据管理功能实体UDM,所述更新方法包括:接收会话密钥管理锚点功能实体AAnF发送的参数更新请求消息;发送更新参数到用户设备UE,所述更新参数用于所述UE结合所述UE当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成会话密钥K AF。
- 根据权利要求12所述的更新方法,其中,所述发送更新参数到UE之后,所述更新方法还包括:向所述AAnF发送参数更新响应消息。
- 一种更新方法,应用于用户设备UE,所述更新方法包括:接收应用功能实体AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新会话密钥K AF。
- 根据权利要求14所述的更新方法,还包括:接收统一数据管理功能实体UDM发送的更新参数;所述K AF为至少根据所述更新参数和所述UE当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成的密钥。
- 一种应用功能实体AF,包括:第一发送模块,用于向会话密钥管理锚点功能实体AAnF发送密钥更新请求消息;第一接收模块,用于接收所述AAnF发送的更新的会话密钥K AF。
- 根据权利要求16所述的AF,还包括:第二发送模块,用于向用户设备UE发送指示消息,指示所述UE更新K AF。
- 根据权利要求17所述的AF,其中,所述K AF为至少根据更新参数 和所述AAnF当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成的密钥。
- 根据权利要求16所述的AF,其中,所述密钥密钥更新请求消息为密钥获取请求消息,所述密钥获取请求消息中携带密钥更新指示符。
- 一种会话密钥管理锚点功能实体AAnF,包括:第二接收模块,用于接收应用功能实体AF发送的密钥更新请求消息;第三发送模块,用于向所述AF发送更新的会话密钥K AF。
- 根据权利要求20所述的AAnF,其中,所述K AF为至少根据更新参数和所述AAnF当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成的密钥。
- 根据权利要求20所述的AAnF,其中,所述密钥更新请求消息为密钥获取请求消息,所述密钥密钥获取请求消息中携带密钥更新指示符。
- 一种统一数据管理功能实体UDM,包括:第四接收模块,用于接收会话密钥管理锚点功能实体AAnF发送的参数更新请求消息;第五发送模块,用于发送更新参数到用户设备UE,所述更新参数用于所述UE结合所述UE当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成会话密钥K AF。
- 根据权利要求23所述的UDM,还包括:第六发送模块,用于向所述AAnF发送参数更新响应消息。
- 一种用户设备UE,包括:第五接收模块,用于接收应用功能实体AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新会话密钥K AF。
- 根据权利要求25所述的UE,还包括:第六接收模块,用于接收统一数据管理功能实体UDM发送的更新参数;所述K AF为至少根据所述更新参数和所述UE当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成的密钥。
- 一种网络侧设备,包括:处理器和收发机;所述收发机,用于向会话密钥管理锚点功能实体AAnF发送密钥更新请 求消息;所述收发机,还用于接收所述AAnF发送的更新的会话密钥K AF;和/或所述收发机,用于接收应用功能实体AF发送的密钥更新请求消息;所述收发机,还用于向所述AF发送更新的会话密钥K AF;和/或所述收发机,用于接收会话密钥管理锚点功能实体AAnF发送的参数更新请求消息;所述收发机,还用于发送更新参数到用户设备UE,所述更新参数用于所述UE结合所述UE当前存储的应用层认证和会话密钥管理AKMA中间密钥K AKMA生成会话密钥K AF。
- 一种用户设备UE,包括:处理器和收发机;所述收发机,用于接收应用功能实体AF发送的密钥更新指示消息,所述密钥更新指示消息用于指示所述UE更新会话密钥K AF。
- 一种网络侧设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,其中,所述计算机程序被所述处理器执行时实现如权利要求1至6中任一项所述的更新方法中的步骤,或者实现如权利要求7至11中任一项所述的更新方法中的步骤,或者实现如权利要求12或13所述的更新方法中的步骤。
- 一种终端设备,包括处理器、存储器及存储在所述存储器上并可在所述处理器上运行的计算机程序,其中,所述计算机程序被所述处理器执行时实现如权利要求14或15所述的更新方法中的步骤。
- 一种计算机可读存储介质,所述计算机可读存储介质上存储有计算机程序,其中,所述计算机程序被处理器执行时,实现如权利要求1至6中任一项所述的更新方法中的步骤,或者实现如权利要求7至11中任一项所述的更新方法中的步骤,或者实现如权利要求12或13所述的更新方法中的步骤,或者实现如权利要求14或15所述的更新方法中的步骤。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202110909519.1A CN115706663A (zh) | 2021-08-09 | 2021-08-09 | 更新方法、网络侧设备、终端和计算机可读存储介质 |
| CN202110909519.1 | 2021-08-09 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2023016451A1 true WO2023016451A1 (zh) | 2023-02-16 |
Family
ID=85179928
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2022/111148 Ceased WO2023016451A1 (zh) | 2021-08-09 | 2022-08-09 | 更新方法、网络侧设备、终端和计算机可读存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN115706663A (zh) |
| WO (1) | WO2023016451A1 (zh) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2024193506A1 (zh) * | 2023-03-20 | 2024-09-26 | 中国移动通信有限公司研究院 | 密钥更新方法、装置、通信设备及可读存储介质 |
| US12445296B2 (en) | 2022-11-10 | 2025-10-14 | Qualcomm Incorporated | Authentication and key management for applications (AKMA) application key (KAF) refresh |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN118678347A (zh) * | 2023-03-20 | 2024-09-20 | 中国移动通信有限公司研究院 | 一种通信方法、装置和存储介质 |
| CN116709315A (zh) * | 2023-07-05 | 2023-09-05 | 中国电信股份有限公司技术创新中心 | 一种密钥更新方法及装置 |
| CN116709311B (zh) * | 2023-07-06 | 2026-02-13 | 中国电信股份有限公司技术创新中心 | 一种密钥更新方法及相关装置 |
| CN117956459A (zh) * | 2023-08-04 | 2024-04-30 | 中兴通讯股份有限公司 | 密钥更新方法、通信装置及存储介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2021093162A1 (en) * | 2020-01-16 | 2021-05-20 | Zte Corporation | Method, device, and system for anchor key generation and management in a communication network for encrypted communication with service applications |
| WO2021098115A1 (en) * | 2020-03-31 | 2021-05-27 | Zte Corporation | Parameters for application communication establishment |
| CN113163402A (zh) * | 2020-01-23 | 2021-07-23 | 华为技术有限公司 | 一种通信方法、装置及系统 |
| CN113225176A (zh) * | 2020-02-04 | 2021-08-06 | 华为技术有限公司 | 密钥获取方法及装置 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN113162758B (zh) * | 2020-01-23 | 2023-09-19 | 中国移动通信有限公司研究院 | 一种密钥生成方法及设备 |
-
2021
- 2021-08-09 CN CN202110909519.1A patent/CN115706663A/zh active Pending
-
2022
- 2022-08-09 WO PCT/CN2022/111148 patent/WO2023016451A1/zh not_active Ceased
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2021093162A1 (en) * | 2020-01-16 | 2021-05-20 | Zte Corporation | Method, device, and system for anchor key generation and management in a communication network for encrypted communication with service applications |
| CN113163402A (zh) * | 2020-01-23 | 2021-07-23 | 华为技术有限公司 | 一种通信方法、装置及系统 |
| CN113225176A (zh) * | 2020-02-04 | 2021-08-06 | 华为技术有限公司 | 密钥获取方法及装置 |
| WO2021098115A1 (en) * | 2020-03-31 | 2021-05-27 | Zte Corporation | Parameters for application communication establishment |
Non-Patent Citations (2)
| Title |
|---|
| ERICSSON: "pCR to TS 33.535: Update of the AKMA procedures", 3GPP DRAFT; S3-200741, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20200414 - 20200417, 3 April 2020 (2020-04-03), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051868649 * |
| ERICSSON: "Several clarifications and editorials", 3GPP DRAFT; S3-202039, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20200817 - 20200828, 7 August 2020 (2020-08-07), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051916561 * |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12445296B2 (en) | 2022-11-10 | 2025-10-14 | Qualcomm Incorporated | Authentication and key management for applications (AKMA) application key (KAF) refresh |
| WO2024193506A1 (zh) * | 2023-03-20 | 2024-09-26 | 中国移动通信有限公司研究院 | 密钥更新方法、装置、通信设备及可读存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN115706663A (zh) | 2023-02-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2023016451A1 (zh) | 更新方法、网络侧设备、终端和计算机可读存储介质 | |
| JP7235160B2 (ja) | 1つ以上のユーザアイデンティティを有するueの課金及びポリシーを有効化するためのシステム及び方法 | |
| US8769283B2 (en) | MTC device authentication method, MTC gateway, and related device | |
| JP5392879B2 (ja) | 通信デバイスを認証するための方法および装置 | |
| CN102396203B (zh) | 根据通信网络中的认证过程的紧急呼叫处理 | |
| CN113039825A (zh) | 接入被拒绝的网络资源 | |
| CN115299168B (zh) | 用于切换的方法和装置 | |
| WO2019019736A1 (zh) | 安全实现方法、相关装置以及系统 | |
| WO2019017837A1 (zh) | 网络安全管理的方法及装置 | |
| WO2019220172A1 (en) | Token-based debugging for a service-based architecture | |
| WO2022237741A1 (zh) | 一种通信方法及装置 | |
| JP2021520660A (ja) | 通信ネットワーク構成要素及びスライス固有の認証及び認可を開始するための方法 | |
| KR20230079179A (ko) | 무선 네트워크에서 보안 키 동기화를 처리하기 위한 방법, 단말, 및 네트워크 개체 | |
| WO2024093923A1 (zh) | 通信方法和通信装置 | |
| WO2023144649A1 (en) | Application programming interface (api) access management in wireless systems | |
| WO2023246753A1 (zh) | 通信方法和装置 | |
| CN107295511B (zh) | Wlan终端、基站及lte网络向wlan网络的切换控制方法 | |
| WO2021132087A1 (ja) | Amfノード及びその方法 | |
| EP4268489A1 (en) | Security methods for protecting discovery procedures in wireless networks | |
| US20250260979A1 (en) | Communication method and communication apparatus | |
| US20240373215A1 (en) | Security configuration update in communication networks | |
| EP4457975B1 (en) | Authentication support for an electronic device to connect to a telecommunications network | |
| CN117014875A (zh) | 由归属网络触发的用户设备(ue)的重新认证 | |
| CN119547473A (zh) | 为漫游用户启用应用服务的认证和密钥管理 | |
| WO2023216274A1 (zh) | 密钥管理方法、装置、设备和存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 22855432 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 32PN | Ep: public notification in the ep bulletin as address of the adressee cannot be established |
Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 12.06.2024) |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 22855432 Country of ref document: EP Kind code of ref document: A1 |