-
公开(公告)号:US20250039667A1
公开(公告)日:2025-01-30
申请号:US18599982
申请日:2024-03-08
Applicant: ZTE Corporation
Inventor: Zhen Xing , Shllin YOU , Yuze LIU , Jin PENG , Zhaoji LIN , LI TIAN
IPC: H04W12/06 , H04W12/041
Abstract: This disclosure generally relates to securely pushing messages from an AF to a User Equipment (UE) in communication networks. Performed by a wireless device in a wireless network, the method includes receiving, from a first network element hosting an Application Function (AF), a message comprising one of: an AKMA (Authentication and Key Management for Applications) key identifier (ID) identifying an AKMA anchor key of the wireless device; or a set of parameters indicative of the AKMA key ID; and storing the AKMA key ID and an AF key associated with the first network element in a security context, wherein the first network element outside of a core network of the wireless network.
-
公开(公告)号:US20240080321A1
公开(公告)日:2024-03-07
申请号:US18139906
申请日:2023-04-26
Applicant: ZTE Corporation
Inventor: Jin PENG , Shilin YOU , Yuze LIU , Zhen XING , Zhaoji LIN
CPC classification number: H04L63/123 , H04W8/205 , H04W12/06
Abstract: This patent document describes, among other things, techniques, and apparatuses for providing onboarding and provisioning of networks. In one aspect, a method of wireless communication is disclosed. The method includes receiving, by a first network node from a second network node, an authentication notification including an identifier for a third network node where a key is stored. The method further includes transmitting, by a first network node, a wireless device parameter update message to the third network node identified by the identifier.
-
公开(公告)号:US20240007983A1
公开(公告)日:2024-01-04
申请号:US18465317
申请日:2023-09-12
Applicant: ZTE Corporation
Inventor: Yuze LIU , Shilin YOU , Jinguo ZHU , He HUANG , Shuang LIANG , Xingyue ZHOU , Jin PENG , Zhen XING , Zhaoji LIN
Abstract: This disclosure generally relates performing UE authentication and registration with the core network, and in particular, to supporting secure interactions between the UE and the target AMF when the UE is re-allocated to the target AMF. After the UE initiates a first registration request, the initial AMF may retrieve a candidate AMF list and selects a target AMF to serve the UE. The initial AMF generates a 5G-GUTI for the UE, based on the selected target AMF. The initial AMF requests the UE to initiate a second registration request, by using the generated 5G-GUTI. With the solutions provided in this disclosure, the message interactions between the UE and the target AMF are integrity protected and/or ciphered, without the need to upgrade the UE and without using an indirect connection of the core network.
-
公开(公告)号:US20230422032A1
公开(公告)日:2023-12-28
申请号:US18033374
申请日:2021-09-29
Applicant: ZTE CORPORATION
Inventor: Yuze LIU , Shilin YOU , Jin PENG , Zhaoji LIN
IPC: H04W12/06 , H04W12/0433 , H04W12/72
CPC classification number: H04W12/06 , H04W12/0433 , H04W12/72
Abstract: A session request method, a session request apparatus, a terminal, and a storage medium are provided. The session request method includes: generating an authentication server key when a key agreement authentication is passed; determining, according to the authentication server key, a key identifier of an authentication and key management for applications (AKMA) anchor key; when the key identifier is invalid, updating the key identifier according to a mobile subscriber identification number (MSIN); and sending an updated key identifier to an application function, to request a key-based session.
-
公开(公告)号:US20230379709A1
公开(公告)日:2023-11-23
申请号:US18360251
申请日:2023-07-27
Applicant: ZTE CORPORATION
Inventor: Yuze LIU , Shilin YOU , Jin PENG , Zhen XING , Zhaoji LIN
CPC classification number: H04W12/068 , H04W12/04 , H04W60/04 , H04W12/69
Abstract: Provided are a registration method and apparatus, an authentication method and apparatus, a routing indicator determination method and apparatus, an entity, and a terminal. The registration method includes acquiring authentication information of a unified data management (UDM); determining a routing indicator (RID) according to the authentication information; and sending a registration request to a key anchor function according to the RID.
-
36.
公开(公告)号:US20220394472A1
公开(公告)日:2022-12-08
申请号:US17889758
申请日:2022-08-17
Applicant: ZTE CORPORATION
Inventor: Yuze LIU , Shilin YOU , Jin PENG , Wantao YU , Zhaoji LIN
Abstract: Systems and methods for wireless communications are disclosed herein. In one embodiment, a wireless communication method includes storing, by a first network entity, mapping information and determining, by the first network entity, based on identification information and the mapping information, that a first node is authorized to connect to a network.
-
公开(公告)号:US20220368684A1
公开(公告)日:2022-11-17
申请号:US17858271
申请日:2022-07-06
Applicant: ZTE Corporation
Inventor: Shilin YOU , Jiyan CAI , Jin PENG , Wantao YU , Yuze LIU , Zhaoji LIN , Yuxin MAO , Jigang WANG
Abstract: This disclosure generally relates to encrypted communication between terminal devices and service applications via a communication network. Such encrypted communication may be based on various hierarchical levels of encryption keys that are generated and managed by the communication network. Such encrypted communication and key management may be provided by the communication network to the terminal devices as a service that can be subscribed to. The various levels of encryption keys may be managed to improve flexibility of the communication network and to reduce potential security breaches.
-
公开(公告)号:US20220345888A1
公开(公告)日:2022-10-27
申请号:US17861496
申请日:2022-07-11
Applicant: ZTE Corporation
Inventor: Wantao YU , Shilin YOU , Yuze LIU , Jin PENG , Zhaoji LIN , Yuxin MAO
IPC: H04W12/069
Abstract: The present disclosure describes methods, systems and devices for establishing secure communication between a user equipment and a service application in a wireless communication. One method includes receiving, by the user equipment, an authentication and key management for service applications identifier (AKMAID) from an authentication server function (AUSF) upon successful completion of an authentication process for registering the user equipment with the communication network. The method also includes storing, by the user equipment, the AKMAID; deriving, by the user equipment, an application key based on a base authentication key; sending, by the user equipment, a communication request to the service application, the communication request comprising the AKMAID; and receiving, by the user equipment, an application session establishment response to the communication request from the service application to establish a security communication session between the user equipment and the service application based on the application key.
-
公开(公告)号:US20220124092A1
公开(公告)日:2022-04-21
申请号:US17423890
申请日:2020-01-19
Applicant: ZTE Corporation
Inventor: Jin PENG , Shilin YOU , Zhenhua XIE , Wantao YU , Zhaoji LIN , Yongqing QIU
Abstract: Provided are an authentication processing method and device, a storage medium, and an electronic device. The method includes that: a terminal receives an authentication request message from an authentication function; and in cases where authentication on the authentication request message fails, the terminal feeds back an authentication failure message to the authentication function. In cases where the cause of the authentication failure is a Message Authentication Code (MAC) failure and in cases where a cause of authentication failure is a Synchronization (Sync) failure, the terminal feeds back authentication failure messages of the same type to the authentication function.
-
公开(公告)号:US20210289353A1
公开(公告)日:2021-09-16
申请号:US16332682
申请日:2017-07-25
Applicant: ZTE CORPORATION
Inventor: Shilin YOU , Hongjun LIU , Jiyan CAI , Zaifeng ZONG , Jin PENG , Zhaoji LIN , Yunyin ZHANG
Abstract: Embodiments of the prevent disclosure provide a network access authentication method and device. The method includes: receiving an authentication request message sent by a first serving network, the authentication request message carrying a user equipment alias identifier generated by user equipment; determining whether a local user equipment alias identifier is asynchronous with the user equipment alias identifier generated by the user equipment; and when the determination result is positive, obtaining an encrypted International Mobile Subscriber Identification Number IMSI for performing network access authentication on the user equipment
-
-
-
-
-
-
-
-
-