Security Anchor Function in 5G Systems
Abstract
A method for handling change of serving Access and Mobility Managing Function for a user equipment. The method comprises sending (S2) of a context request to a source Access and Mobility Managing Function. This sending is performed from a target Access and Mobility Managing Function. In the target Access and Mobility Managing Function, a context is received (S3) in reply from the source Access and Mobility Managing Function. The context comprises a parameter which identifies a Security Anchor Function Access and Mobility Managing Function. The Security Anchor Function Access and Mobility Managing Function keeps a key, which is shared with the user equipment. A method for handling a change of serving Access and Mobility Managing Function in a user equipment is also disclosed as well as Access and Mobility Managing Function and User Equipments therefore.
Claims
exact text as granted — not AI-modified1 - 40 . (canceled)
41 . A method for supporting handling of a change of serving Access and Mobility Managing Function for a user equipment, wherein said method comprises:
sending, from a target Access and Mobility Managing Function, a context request to a source Access and Mobility Managing Function; and receiving, in said target Access and Mobility Managing Function, a context in reply from the source Access and Mobility Managing Function; wherein said context comprises a parameter that identifies a Security Anchor Function Access and Mobility Managing Function; and wherein said Security Anchor Function Access and Mobility Managing Function is an Access and Mobility Managing Function that keeps a key, which is shared with said user equipment.
42 . The method according to claim 41 , further comprising:
receiving a registration request from said user equipment.
43 . The method according to claim 41 , further comprising:
deciding an authentication strategy based on a situation of at least one of said source Access and Mobility Managing Function and said Security Anchor Function Access and Mobility Managing Function.
44 . The method according to claim 43 , wherein said deciding is based on a security policy depending on a location of said source Access and Mobility Managing Function and said Security Anchor Function Access and Mobility Managing Function.
45 . The method according to claim 43 , wherein said authentication strategy comprises one of:
a transfer of a key between Access and Mobility Managing Functions, an execution of a new authentication procedure, and a request of a key from said Security Anchor Function Access and Mobility Managing Function.
46 . The method according to claim 45 , further comprising running a new authentication process in response to said authentication strategy being an execution of a new authentication procedure, said new authentication procedure comprising:
establishing a new key by interaction with an authentication server function; and creating a new parameter identifying said target Access and Mobility Managing Function as a new Security Anchor Function Access and Mobility Managing Function.
47 . The method according to claim 46 , further comprising notifying said Security Anchor Function Access and Mobility Managing Function that said target Access and Mobility Managing Function is said new Security Anchor Function Access and Mobility Managing Function for said user equipment.
48 . The method according to claim 45 , further comprising transferring a core network key between said source Access and Mobility Managing Function and said target Access and Mobility Managing Function in response to a decision that said authentication strategy is a transfer of a key between Access and Mobility Managing Functions.
49 . The method according to claim 45 , further comprising requesting a key in response to a decision that said authentication strategy is a request of a key from said Security Anchor Function Access and Mobility Managing Function, said request of a key comprising:
sending said request for a key to said Security Anchor Function Access and Mobility Managing Function; and receiving said key from said Security Anchor Function Access and Mobility Managing Function.
50 . The method according to claim 41 , wherein said parameter is a Globally Unique Temporary ID associated with said Security Anchor Function Access and Mobility Managing Function.
51 . The method according to claim 41 , further comprising performing a non-access stratum security establishment procedure between said target Access and Mobility Managing Function and said user equipment, said non-access stratum security establishment procedure informing said user equipment about said authentication strategy decided by said target Access and Mobility Managing Function.
52 . The method according to claim 41 , wherein said key, which is shared with said user equipment, is used for deriving other keys.
53 . A method for supporting handling of a change of serving Access and Mobility Managing Function for a user equipment, wherein said method comprises:
receiving, in a source Access and Mobility Managing Function, a context request from a target Access and Mobility Managing Function; and sending, from said source Access and Mobility Managing Function, a context in reply to said target Access and Mobility Managing Function; wherein said context comprises a parameter that identifies a Security Anchor Function Access and Mobility Managing Function; wherein said Security Anchor Function Access and Mobility Managing Function keeps a key, which is shared with said user equipment.
54 . The method according to claim 53 , further comprising retrieving said parameter that identifies said Security Anchor Function Access and Mobility Managing Function from a memory.
55 . The method according to claim 53 , further comprising transferring a core network key between said source Access and Mobility Managing Function and said target Access and Mobility Managing Function.
56 . The method according to claim 53 , wherein said parameter is a Globally Unique Temporary ID associated with said Security Anchor Function Access and Mobility Managing Function.
57 . The method according to claim 53 , wherein said key, which is shared with said user equipment, is used for deriving other keys.
58 . A method for supporting handling of a change of serving Access and Mobility Managing Function for a user equipment, wherein said method comprises:
sending, from said user equipment, a registration request to a target Access and Mobility Managing Function; performing a non-access stratum security establishment procedure between said target Access and Mobility Managing Function and said user equipment, wherein said non-access stratum security establishment procedure informs said user equipment about an authentication strategy decided by said target Access and Mobility Managing Function; and applying key procedures according to said authentication strategy.
59 . The method according to claim 58 , wherein said authentication strategy comprises one of:
a transfer of a key between Access and Mobility Managing Functions, an execution of a new authentication procedure, and a request of a key from a Security Anchor Function Access and Mobility Managing Function.
60 . The method according to claim 58 , wherein said registration request comprises information identifying a presently used Access and Mobility Managing Function as a source Access and Mobility Managing Function.
61 . A method for supporting handling of a change of serving Access and Mobility Managing Function for a user equipment, wherein said method comprises:
receiving, in a Security Anchor Function Access and Mobility Managing Function, a request from a target Access and Mobility Managing Function for a new key for said user equipment; deriving, in said Security Anchor Function Access and Mobility Managing Function, a new core network key from a key that is shared with said user equipment; and sending said new core network key to said target Access and Mobility Managing Function.
62 . The method according to claim 61 , further comprising:
receiving a notification from a target Access and Mobility Managing Function that said user equipment has a new Security Anchor Function Access and Mobility Managing Function; and disposing said key that is shared with said user equipment.
63 . A network node configured to support handling of a change of serving Access and Mobility Managing Function for a user equipment, said network node comprising:
processing circuitry; and a memory storing instructions that, when executed by the processing circuitry, cause the processing circuitry to:
send, via an Access and Mobility Managing Function, a context request to a source Access and Mobility Managing Function; and
receive, via said Access and Mobility Managing Function, a context in reply from said source Access and Mobility Managing Function, wherein said context comprises a parameter that identifies a Security Anchor Function Access and Mobility Managing Function, and wherein said Security Anchor Function Access and Mobility Managing Function keeps a key, which is shared with said user equipment.
64 . A network node configured to support handling of a change of serving Access and Mobility Managing Function for a user equipment, said network node comprising:
processing circuitry; and a memory storing instructions that, when executed by the processing circuitry, cause the processing circuitry to:
receive, via an Access and Mobility Managing Function, a context request from a target Access and Mobility Managing Function; and
send, via said Access and Mobility Managing Function, a context in reply to said target Access and Mobility Managing Function, wherein said context comprises a parameter that identifies a Security Anchor Function Access and Mobility Managing Function, and wherein said Security Anchor Function Access and Mobility Managing Function keeps a key, which is shared with said user equipment.
65 . A network node configured to support handling of a change of serving Access and Mobility Managing Function for a user equipment, said network node comprising:
processing circuitry; and a memory storing instructions that, when executed by the processing circuitry, cause the processing circuitry to:
receive, via an Access and Mobility Managing Function, a request from a target Access and Mobility Managing Function for a new key for said user equipment;
derive, via said Access and Mobility Managing Function, a new core network key from a key that is shared with said user equipment; and
send, via said Access and Mobility Managing Function, said new core network key to said target Access and Mobility Managing Function.
66 . A user equipment configured for use in a communication network, said user equipment comprising:
processing circuitry; and a memory storing instructions that, when executed by the processing circuitry, cause the processing circuitry to:
send a registration request to a target Access and Mobility Managing Function;
perform a non-access stratum security establishment procedure between said target Access and Mobility Managing Function and said user equipment, wherein said non-access stratum security establishment procedure informs said user equipment about an authentication strategy decided by said target Access and Mobility Managing Function; and
apply key procedures according to said authentication strategy.Join the waitlist — get patent alerts
Track US2020084676A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.