Abstract: A procedure to establish latest security key in a UE and a network is disclosed. More specifically, the procedure defines various method to establish latest Kausf in the UE and the network and make the UE and network uses the same Kausf in various security procedure.
Technical Field
[0001] The present disclosure relates generally to wireless telecommunications, and, in
[0002]
particular embodiments, relates to handling of security keys during authentication
procedure.
Background Art
The purpose of the primary authentication and key agreement procedure is to
enable mutual authentication between the UE and the network and to provide keying
material that can be used between the UE and network in subsequent security
procedures, as specified in NPL 5. The keys KAusp, KsEAF and KAMF are generated after
successful authentication procedure.
[0003] Two methods of primary authentication and key agreement procedure are defined:
a) EAP based primary authentication and key agreement procedure.
b) 5G AKA based primary authentication and key agreement procedure.
[0004] The UE and the AMP shall support both the EAP based primary authentication
[0005]
and key agreement procedure and the 5G AKA based primary authentication and key
agreement procedure. When the authentication procedure fails in the network, then the
AMP returns Authentication Reject message to the UE.
Fig. 1 illustrates the initiation of authentication procedure and selection of authentication
method initiation of authentication procedure and selection of authentication
method. The authentication method that to be applied to the UE is selected by the
UDM.
[0006] The Fig. 2 illustrates the 5G AKA based primary authentication and key
agreement procedure.
[0007] The KAusF (Kausf) created in the UE and AUSF is used for a security mechanism
in the Steering of roaming (SoR) procedure and UE parameters update via UDM
control plane procedure security mechanism as specified in NPL 5.
[0008] Fig. 3 illustrates the procedure for steering of UE in VPLMN (Visited Public land
mobile network) during registration.
In the Steering of roaming procedure, Kausf is used to derive SoR-MAC-Iausf in
the UE and AUSF. When the UE receives a SOR-MAC-Iausf from the network, the
UE calculates a SoR-MAC-Iasuf and compares with the SOR-MAC-Iausf that is
received from the network. If the SOR-MAC-Iausfs are matched in the UE, then the
UE determines that the security check of SoR transmission is passed and the UE stores
the steering list, I.E. list of preferred PLMN/access technology combinations in the
UE.
[0009] Fig. 4 illustrates the procedure for providing list of preferred PLMN/access
technology combinations after registration.
[0010] In the UE parameters update via UDM control plane procedure, when the UE
[0011]
[0012]
[0013]
receives a UPU-MAC-Iausf from the network, the UE calculates a UPU-MAC-Iausf
and compares with the UPU-MAC-Iausf that is received from the network. If the UPUMAC-
Iausfs are matched in the UE, then the UE determines that the UE parameter
transmission by the UE parameters update via UDM control plane procedure is secured
and stores the UE parameters that is sent by the UDM in the UE.
In addition, the Kasuf is also used to generate AKMA (Authentication and Key
Agreement for Applications) key. In case when the UE is registered to two different
PLMNs (for example, one via 3GPP access and another one via a non-3GPP access),
the UE and the AUSF will store only the latest Kausf. This latest Kausf is used in
various security procedures in the UE and the network.
Citation List
Non Patent Literature
NPL 1: 3GPP TR 21.905: "Vocabulary for 3GPP Specifications". V16.0.0 (2019-06)
NPL 2: 3GPP TS 23.501: "System architecture for the 5G System (5GS)". V16.6.0
(2020-09)
NPL 3: 3GPP TS 23.502: "Procedures for the 5G System (5G"S)". V16.6.0
(2020-09)
NPL 4: 3GPP TS 24.501: "Non-Access-Stratum (NAS) protocol for 5G System
(5GS); Stage 3". V16.6.0 (2020-09)
NPL 5: 3GPP TS 33.501: "Security architecture and procedures for 5G system"
V16.4.0 (2020-09)
NPL 6: 3GPP TS 33.102: "3G Security; Security architecture" V16.0.0 (2020-07).
Summary of Invention
Technical Problem
The authentication and key agreement procedures defined in NPL 5 remains
ambiguous. As stated in the background, synchronizing Kausf information between the
UE and the network is very important for the 5GS as the Kausf information is used by
various security procedures. If Kausf were miss-synchronized between the UE and the
network, the 5GS should not provide any services over the 5GS as the security is very
[0014]
important and thus no compromised.
Solution to Problem
In a first aspect of the present disclosure, a method of a communication terminal
comprises receiving, from a first core network apparatus, an authentication request
message, calculating a first security key and a first authentication response, returning,
to the first core network apparatus, the first authentication response in an authentication
response message; and receiving, from the first core network apparatus, a NAS
message.
[0015] In a second aspect of the present disclosure, a method of a first core network
apparatus comprising: sending, to a second core network apparatus, a first authentication
request message to initiate an authentication with a communication terminal,
sending, to the communication terminal, a second authentication request message,
receiving, from the communication terminal, a first authentication response in a first
authentication response message, receiving, from the second core network apparatus, a
second authentication response message corresponding to the first authentication
request message; and sending, to the communication terminal, a NAS message to
replace a second security key with a first security key calculated by the communication
terminal.
[00 16] In a third aspect of the present disclosure, a method of a first core network apparatus
comprises: sending, to a second core network apparatus, a first authentication request
message to initiate an authentication with a communication terminal, sending, to the
communication terminal, a second authentication request message, receiving, from the
communication terminal, a first authentication response in a second first authentication
response message, receiving, from the second core network apparatus, a second authentication
response message corresponding to the first authentication request
message; and sending, to the communication terminal, a NAS message, wherein the
first security key is not stored in the communication terminal in a case where the NAS
message selects information indicating null encryption and null ciphering algorithm,
wherein the communication terminal sets a session relate to emergency session.
[0017] In a forth aspect of the present disclosure, a communication terminal comprising:
means for receiving, from a first core network apparatus, an authentication request
message, means for calculating a first security key and a first authentication response,
means for returning, to the first core network apparatus, the first authentication
response in an authentication response message; and means for receiving, from the first
core network apparatus, a NAS message.
[0018] In a fifth aspect of the present disclosure, a first core network apparatus comprising:
means for sending, to a second core network apparatus, a first authentication request
message to initiate an authentication with a communication terminal, means for
sending, to the communication terminal, a second authentication request message,
means for receiving, from the communication terminal, a first authentication response
in second authentication response message, means for receiving, from the second core
network apparatus, an authentication response message corresponding to the first authentication
request message; and means for sending, to the communication terminal, a
NAS message to replace a second security key with a first security key calculated by
the communication terminal.
[0019] In a sixth aspect of the present disclosure, a first core network apparatus comprising:
means for sending, to a second core network apparatus, a first authentication request
message to initiate an authentication with a communication terminal, means for
sending, to the communication terminal, a second authentication request message,
means for receiving, from the communication terminal, a first authentication response
in a second first authentication response message, means for receiving, from the
second core network apparatus, a second authentication response message corresponding
to the first authentication request message; and means for sending, to the
communication terminal, a NAS message, wherein the first security key is not stored in
the communication terminal in a case where the NAS message selects information Indicating
null encryption and null ciphering algorithm, wherein the communication
terminal sets a session relate to emergency session.
[Claim 1]
[Claim 2]
[Claim 3]
[Claim 4]
[Claim 5]
[Claim 6]
[Claim 7]
[Claim 8]
[Claim 9]
Claims
A method of a communication terminal comprising:
receiving, from a first core network apparatus, an authentication
request message,
calculating a first security key and a first authentication response,
returning, to the first core network apparatus, the first authentication
response in an authentication response message; and
receiving, from the first core network apparatus, a NAS message.
The method according to Claim 1 comprising:
replacing a second security key with the first security key upon
receiving the NAS message.
The method according to Claim 1 comprising:
setting a session related to emergency session, wherein the first
security key is not stored in the communication terminal in a case
where the NAS message selects information indicating null encryption
and null ciphering algorithm.
The method according to Claim 1 comprising:
establishing a Protocol Data Unit (PDU) session related to
emergency session, wherein the first security key is not stored in the
communication terminal in a case where the NAS message selects Information
indicating null encryption and null ciphering algorithm.
The method according to any one of Claims 1 to 4, wherein the communication
terminal considers an authentication as successful upon
receiving the NAS message.
The method according to any one of Claims 1 to 5, wherein the first
security key is new Kausf.
The method according to any one of Claims 1 to 6, wherein the
second security key is old Kausf.
The method according to any one of Claims 1 to 7, wherein the first
core network apparatus is Access and Mobility Management function
(AMP).
A method of a first core network apparatus comprising:
sending, to a second core network apparatus, a first authentication
request message to initiate an authentication with a communication
terminal,
sending, to the communication terminal, a second authentication
request message,
[Claim 10]
[Claim 11]
[Claim 12]
[Claim 13]
[Claim 14]
receiving, from the communication terminal, a first authentication
response in a first authentication response message,
receiving, from the second core network apparatus, a second authentication
response message corresponding to the first authentication
request message; and
sending, to the communication terminal, a NAS message to replace a
second security key with a first security key calculated by the communication
terminal.
A method of a first core network apparatus comprising:
sending, to a second core network apparatus, a first authentication
request message to initiate an authentication with a communication
terminal,
sending, to the communication terminal, a second authentication
request message,
receiving, from the communication terminal, a first authentication
response in a second first authentication response message,
receiving, from the second core network apparatus, a second authentication
response message corresponding to the first authentication
request message; and
sending, to the communication terminal, a NAS message, wherein
the first security key is not stored in the communication terminal in a
case where the NAS message selects information indicating null encryption
and null ciphering algorithm, wherein the communication
terminal sets a session related to emergency session.
The method according to Claim 9 or 10, wherein the first security
key is new Kausf.
The method according to any one of Claims 9 to 11, wherein the
second security key is old Kausf.
The method according to any one of Claims 9 to 12, wherein the first
core network apparatus is Access and Mobility Management function
(AMP).
A communication terminal comprising:
means for receiving, from a first core network apparatus, an authentication
request message,
means for calculating a first security key and a first authentication
response,
means for returning, to the first core network apparatus, the first authentication
response in an authentication response message; and
[Claim 15]
[Claim 16]
[Claim 17]
[Claim 18]
[Claim 19]
[Claim 20]
[Claim 21]
[Claim 22]
means for receiving, from the first core network apparatus, a NAS
message.
The communication terminal according to Claim 14 comprising:
means for replacing a second security key with the first security key
upon receiving the NAS message.
The communication terminal according to Claim 14 comprising:
means for setting a session related to emergency session, wherein the
first security key is not stored in the communication terminal in a case
where the NAS message selects information indicating null encryption
and null ciphering algorithm.
The communication terminal according to Claim 14 comprising:
establishing a Protocol Data Unit (PDU) session related to
emergency session, wherein the first security key is not stored in the
communication terminal in a case where the NAS message selects Information
indicating null encryption and null ciphering algorithm.
The communication terminal according to any one of Claims 14 to
17, wherein the communication terminal considers an authentication as
successful upon receiving the NAS message.
The communication terminal according to any one of Claims 14 to
18, wherein the first security key is new Kausf.
The communication terminal according to any one of Claims 14 to
19, wherein the second security key is old Kausf.
The communication terminal according to any one of Claims 14 to
20, wherein the first core network apparatus is Access and Mobility
Management function (AMP).
| # | Name | Date |
|---|---|---|
| 1 | 202317012737.pdf | 2023-02-24 |
| 2 | 202317012737-STATEMENT OF UNDERTAKING (FORM 3) [24-02-2023(online)].pdf | 2023-02-24 |
| 3 | 202317012737-REQUEST FOR EXAMINATION (FORM-18) [24-02-2023(online)].pdf | 2023-02-24 |
| 4 | 202317012737-PRIORITY DOCUMENTS [24-02-2023(online)].pdf | 2023-02-24 |
| 5 | 202317012737-POWER OF AUTHORITY [24-02-2023(online)].pdf | 2023-02-24 |
| 6 | 202317012737-NOTIFICATION OF INT. APPLN. NO. & FILING DATE (PCT-RO-105-PCT Pamphlet) [24-02-2023(online)].pdf | 2023-02-24 |
| 7 | 202317012737-FORM 18 [24-02-2023(online)].pdf | 2023-02-24 |
| 8 | 202317012737-FORM 1 [24-02-2023(online)].pdf | 2023-02-24 |
| 9 | 202317012737-DRAWINGS [24-02-2023(online)].pdf | 2023-02-24 |
| 10 | 202317012737-DECLARATION OF INVENTORSHIP (FORM 5) [24-02-2023(online)].pdf | 2023-02-24 |
| 11 | 202317012737-COMPLETE SPECIFICATION [24-02-2023(online)].pdf | 2023-02-24 |
| 12 | 202317012737-MARKED COPIES OF AMENDEMENTS [01-03-2023(online)].pdf | 2023-03-01 |
| 13 | 202317012737-FORM 13 [01-03-2023(online)].pdf | 2023-03-01 |
| 14 | 202317012737-AMMENDED DOCUMENTS [01-03-2023(online)].pdf | 2023-03-01 |
| 15 | 202317012737-Proof of Right [20-04-2023(online)].pdf | 2023-04-20 |
| 16 | 202317012737-FORM 3 [17-08-2023(online)].pdf | 2023-08-17 |
| 17 | 202317012737-Others-010923.pdf | 2023-10-11 |
| 18 | 202317012737-Correspondence-010923.pdf | 2023-10-11 |
| 19 | 202317012737-FER.pdf | 2024-02-09 |
| 20 | 202317012737-FORM 4 [08-08-2024(online)].pdf | 2024-08-08 |
| 21 | 202317012737-OTHERS [06-11-2024(online)].pdf | 2024-11-06 |
| 22 | 202317012737-FORM-26 [06-11-2024(online)].pdf | 2024-11-06 |
| 23 | 202317012737-FER_SER_REPLY [06-11-2024(online)].pdf | 2024-11-06 |
| 24 | 202317012737-CLAIMS [06-11-2024(online)].pdf | 2024-11-06 |
| 25 | 202317012737-ABSTRACT [06-11-2024(online)].pdf | 2024-11-06 |
| 26 | 202317012737-GPA-081124.pdf | 2024-11-13 |
| 27 | 202317012737-Correspondence-081124.pdf | 2024-11-13 |
| 28 | 202317012737-Response to office action [14-05-2025(online)].pdf | 2025-05-14 |
| 1 | SearchHistoryE_02-02-2024.pdf |