US2021274345A1PendingUtilityA1

Key maerial generation optimization for authentication and key management for applications

Assignee: ERICSSON TELEFON AB L MPriority: Feb 20, 2020Filed: May 14, 2021Published: Sep 2, 2021
Est. expiryFeb 20, 2040(~13.6 yrs left)· nominal 20-yr term from priority
H04W 88/18H04W 88/14H04W 88/02H04W 12/06H04W 12/0433H04W 12/35H04W 12/041G16Y 30/10H04W 4/70H04W 12/069
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method performed by a wireless device includes determining whether a first message received from a network node includes an Authentication and Key Management for Applications (AKMA) key indicator and, based on whether the first message includes the AKMA indicator, determining whether to generate AKMA key material for the authentication procedure with the network.

Claims

exact text as granted — not AI-modified
1 . A method performed by a network node operating as a Unified Data Management, UDM, node, the method comprising:
 receiving a first message associated with an authentication request message of a wireless device;   based on subscription information associated with the wireless device, generating a second message comprising an authentication response message, the second message including an Authentication and Key Management for Applications, AKMA, key indicator to trigger the wireless device to generate AKMA key material; and   transmitting the second message comprising the authentication response message to trigger the wireless device to generate the AKMA key material.   
     
     
         2 . The method of  claim 1 , wherein the first message initiates an authentication procedure of a wireless device with a network. 
     
     
         3 . The method of  claim 2 , wherein the authentication procedure comprises a primary authentication procedure of the wireless device. 
     
     
         4 . The method of  claim 1 , wherein the AKMA key indicator comprises a AKMA key material generation flag to trigger the wireless device to generate the AKMA key material. 
     
     
         5 . The method of  claim 1 , wherein the AKMA key material comprises an Authentication and Key Management for Applications anchor key, K AKMA . 
     
     
         6 . The method of  claim 5 , wherein the AKMA key material comprises a K AKMA  Identifier, K AKMA ID, and wherein the K AKMA  and the K AKMA ID are derived based on a K AUSF . 
     
     
         7 . The method of  claim 1 , wherein:
 the first message is received from a second network node operating as an Authentication Server Function, AUSF, and   the second message is sent to the second network node operating as the AUSF.   
     
     
         8 . The method of  claim 1 , further comprising:
 prior to receiving the first message from the wireless device, receiving a third message from a NF, the third message comprising the subscription information associated with the wireless device.   
     
     
         9 . A method performed by a first network node operating as an Authentication Server Function, AUSF, the method comprising:
 determining whether a first message received from a second network node includes an Authentication and Key Management for Applications, AKMA, key indicator; and   based on whether the first message includes the AKMA indicator, determining whether to generate AKMA key material.   
     
     
         10 . The method of  claim 9 , wherein:
 determining whether the first message comprises the AKMA key indicator comprises determining that the first message comprises the AKMA key indicator; and   the method further comprises generating the AKMA key material based on the AKMA key indicator in the first message.   
     
     
         11 . The method of  claim 9 , wherein:
 determining whether the first message comprises the AKMA key indicator comprises determining that the first message does not include the AKMA key indicator; and   the method further comprises determining not to generate the AKMA key material for the authentication procedure with the network based on the first message not including the AKMA key indicator.   
     
     
         12 . The method of  claim 9 , wherein the second network node comprises a Unified Data Management, UDM, node. 
     
     
         13 . The method of  claim 9 , further comprising transmitting a second message comprising the AKMA key indicator to a wireless device to trigger the wireless device to generate the AKMA key material. 
     
     
         14 . The method of  claim 9 , wherein the AKMA key material comprises an Authentication and Key Management for Applications Anchor Key, K AKMA . 
     
     
         15 . The method of  claim 14 , wherein:
 the AKMA key material comprises a K AKMA  Identifier, K AKMA ID, associated with a wireless device, and   the K AKMA  and the K AKMA ID are derived based on a K AUSF .   
     
     
         16 . The method of  claim 9 , wherein the AKMA key indicator comprises an AKMA key material generation flag. 
     
     
         17 . A method performed by a wireless device, the method comprising:
 in response to determining a need to initiate a communication session with an Application Function, AF, generating an Authentication and Key Management for Applications Anchor Key, K AKMA ; and   transmitting, to the AF, a request to initiate the communication session.   
     
     
         18 . The method of  claim 17 , wherein the need to initiate the communication session with the AF is determined after a performance of a primary authentication procedure with a network. 
     
     
         19 . The method of  claim 18 , further comprising, during the performance of the primary authentication procedure, generating a root key, K AUSF . 
     
     
         20 . The method of  claim 19 , further comprising generating the K AKMA  and a K AKMA  Identifier, K AKMA ID, based on the K AUSF . 
     
     
         21 . The method of  claim 17 , further comprising determining to generate a K AKMA  based on subscription information stored in or at the wireless device. 
     
     
         22 . A network node operating as a Unified Data Management, UDM, node, the network node comprising:
 processing circuitry configured to:
 receive a first message associated with an authentication request message of a wireless device; 
 based on subscription information associated with the wireless device, generate a second message comprising an authentication response message, the second message including an Authentication and Key Management for Applications, AKMA, key indicator to trigger the wireless device to generate AKMA key material; and 
 transmit the second message comprising the authentication response message to trigger the wireless device to generate the AKMA key material. 
   
     
     
         23 . The network node of  claim 22 , wherein the first message initiates an authentication procedure of a wireless device with a network. 
     
     
         24 . The network node of  claim 23 , wherein the authentication procedure comprises a primary authentication procedure of the wireless device. 
     
     
         25 . The network node of  claim 22 , wherein the AKMA key indicator comprises a AKMA key material generation flag to trigger the wireless device to generate the AKMA key material. 
     
     
         26 . The network node of  claim 22 , wherein the AKMA key material comprises an Authentication and Key Management for Applications anchor key, K AKMA . 
     
     
         27 . The network node of  claim 26 , wherein the AKMA key material comprises a K AKMA  Identifier, K AKMA ID, and wherein the K AKMA  and the K AKMA ID are derived based on a K AUSF . 
     
     
         28 . The network node of  claim 22 , wherein:
 the first message is received from a second network node operating as an Authentication Server Function, AUSF, and   the second message is sent to the second network node operating as the AUSF.   
     
     
         29 . The network node of  claim 22 , wherein the processing circuitry is configured to:
 prior to receiving the first message from the wireless device, receiving a third message from a NF, the third message comprising the subscription information associated with the wireless device.   
     
     
         30 . A first network node operating as an Authentication Server Function, AUSF, the first network node comprising:
 processing circuitry configured to:
 determine whether a first message received from a second network node includes an Authentication and Key Management for Applications, AKMA, key indicator; and 
 based on whether the first message includes the AKMA indicator, determine whether to generate AKMA key material. 
   
     
     
         31 . The first network node of  claim 30 , wherein when the processing circuitry determines that the first message includes the AKMA key indicator, the processing circuitry is further configured to generate the AKMA key material. 
     
     
         32 . The first network node of  claim 31 , wherein when the processing circuitry determines that the first message does not include the AKMA key indicator, the processing circuitry is further configured to determine not to generate the AKMA key material for the authentication procedure with the network. 
     
     
         33 . The first network node of  claim 30 , wherein the second network node comprises a Unified Data Management, UDM, node. 
     
     
         34 . The first network node of  claim 30 , wherein the processing circuitry is configured to transmit a second message comprising the AKMA key indicator to a wireless device to trigger the wireless device to generate the AKMA key material. 
     
     
         35 . The first network node of  claim 30 , wherein the AKMA key material comprises an Authentication and Key Management for Applications Anchor Key, K AKMA . 
     
     
         36 . The first network node of  claim 35 , wherein:
 the AKMA key material comprises a K AKMA  Identifier, K AKMA ID, associated with a wireless device, and   the K AKMA  and the K AKMA ID are derived based on the K AUSF .   
     
     
         37 . The first network node of  claim 30 , wherein the AKMA key indicator comprises an AKMA key material generation flag. 
     
     
         38 . A wireless device comprising:
 processing circuitry configured to:
 in response to determining a need to initiate a communication session with an Application Function, AF, generate an Authentication and Key Management for Applications Anchor Key, K AKMA ; and 
 transmit, to the AF, a request to initiate the communication session. 
   
     
     
         39 . The wireless device of  claim 38 , wherein the need to initiate the communication session with the AF is determined after a performance of a primary authentication procedure with a network. 
     
     
         40 . The wireless device of  claim 39 , wherein, during the performance of the primary authentication procedure, the processing circuitry is configured to generate a root key, K AUSF . 
     
     
         41 . The wireless device of  claim 40 , wherein the processing circuitry is configured to generate the K AKMA  and a K AKMA  Identifier, K AKMA ID, based on the K AUSF . 
     
     
         42 . The wireless device of  claim 38 , wherein the processing circuitry is configured to determine to generate a K AKMA  based on subscription information stored in or at the wireless device.

Join the waitlist — get patent alerts

Track US2021274345A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.