AKMA KEY DIVERSITY FOR MULTIPLE APPLICATIONS IN UE

    公开(公告)号:US20240357355A1

    公开(公告)日:2024-10-24

    申请号:US18682866

    申请日:2022-08-09

    摘要: Systems and methods for enabling Authentication and Key Management for Applications (AKMA) key diversity for multiple applications are disclosed herein. In one embodiment, an AKMA client of a wireless device determines a root key (KAKMA) and an AKMA key identifier (A-KID) based on primary authentication with a telecommunications network. The AKMA client receives an application identifier (APP-ID) and an application function (AF) identifier (AF-ID) from an application of the wireless device. The AKMA client verifies APP-ID, and verifies that the application is entitled to use AF-ID. If successful, an application key (KAPP) is derived based on KAKMA. AF-ID, and APP-ID. Optionally, the AKMA client encrypts APP-ID and outputs A-KID. KAPP, and the encrypted APP-ID to the application, and the application sends a session establishment request to an AF, the session establishment request comprising A-KID and the encrypted APP-ID.

    APPLICATION-SPECIFIC GPSI RETRIEVAL
    6.
    发明公开

    公开(公告)号:US20240276217A1

    公开(公告)日:2024-08-15

    申请号:US18289591

    申请日:2022-04-08

    摘要: A method for a user equipment (UE) configured to communicate with an application function (AF) via a communication network is provided. The method comprises sending, to the AF, an application service request including: a second identifier (GPSI) specific to one or more applications, including an application associated with the UE and the AF; and information (app-info) associated with the second identifier and descriptive of the one or more applications. The method further comprises authenticating the AF based on an application-specific key (KAF) derived from a security key (KAKMA) associated with the UE; and receiving, from the AF, an application service response indicating whether the second identifier (GPSI) matches a corresponding second identifier (GPSI*) derived from the information associated with the second identifier.

    USER EQUIPMENT (UE) IDENTIFIER REQUEST
    7.
    发明公开

    公开(公告)号:US20240064510A1

    公开(公告)日:2024-02-22

    申请号:US18271799

    申请日:2021-12-15

    摘要: A method performed by an application function (AF) associated with a communication network is provided. The method comprises sending, to a network function (NF) of the communication network, a key request for a security key (KAF) associated with an application session between 5 the AF and a user equipment (UE), wherein the key request includes one of the following: a request for a first identifier of the UE, or a second identifier of the UE. The method further comprises receiving, from the NF, a response that includes the security key (KAF) and one of the following: the first identifier, or a response code associated with the second identifier or the first identifier. The method further comprises authenticating the UE for the application session 0 based on the response.

    REPRESENTATION TOKENS IN INDIRECT COMMUNICATION

    公开(公告)号:US20230412589A1

    公开(公告)日:2023-12-21

    申请号:US17913889

    申请日:2021-03-16

    IPC分类号: H04L9/40

    CPC分类号: H04L63/083 H04L63/102

    摘要: A method comprises receiving an access token request from a first network entity for granting access to a network function, NF, service producer. The method further comprises determining whether an access token can be granted for the first network entity. Responsive to determining that the access token can be granted, the method further comprises generating the access token that includes an identifier of a NF consumer associated with the first network entity and an identifier of each network entity in a communication path between the first network entity and the NF service producer and transmitting the access token towards the first network entity.

    Integrity Verification in a Wireless Communication Network

    公开(公告)号:US20230319571A1

    公开(公告)日:2023-10-05

    申请号:US18022856

    申请日:2021-08-17

    IPC分类号: H04W12/106 H04W12/06

    CPC分类号: H04W12/106 H04W12/068

    摘要: Network equipment implements a network function in a wireless communication network. The network equipment obtains integrity verification information that is a function of only a portion of a message. The message is either a request for a service to be consumed by the network function or a response to a request for a service provided by the network function. The network equipment digitally signs an assertion that includes the integrity verification information, and then sends the message and the digitally signed assertion to a service communication proxy. Other network equipment that receives the message and the digitally signed assertion may check an integrity of the portion of the message, based on integrity verification information that the other network equipment obtains and on the integrity verification information included in the digitally signed assertion.