Communication method, terminal, network element, system and medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2024-09-27
- Publication Date
- 2026-05-29
AI Technical Summary
In 5G systems, the security and integrity of communication between UE and AMF are difficult to guarantee and are vulnerable to message replay attacks.
By using the SMC procedure, a secure mode command between the terminal and the network element, a NAS security context is created or activated, and encryption and integrity protection keys are used to ensure message security and prevent replay attacks.
It ensures the security of NAS connection between the terminal and network element, guarantees message integrity and confidentiality, and prevents message replay attacks.
Smart Images

Figure CN122122954A_ABST
Abstract
Description
Communication method, terminal, network element, system and medium TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and particularly relates to a communication method, a terminal, a network element, a system and a medium. BACKGROUND
[0002] At present, in a 5th Generation Mobile Communication Technology (5G) system, Non-Access Stratum (NAS) signaling (transparent transmission through a Radio access network (RAN) node) supports communication between a User Equipment (UE) and an Access and Mobility Management Function (AMF) in a core network. Communication between the UE and other NFs can be implemented through AMF relaying.
[0003] SUMMARY
[0004] The present disclosure provides a communication method, a terminal, a network element, a system and a medium.
[0005] According to a first aspect of the present disclosure, a communication method is provided, executed by a terminal, the method comprising: sending a first message, the first message being used for requesting to establish a Non-Access Stratum (NAS) connection with a first network element; creating or activating a first NAS security context for the first network element in a case that a Security Mode Command (SMC) procedure is successfully executed, wherein the SMC procedure is triggered by the first message received by the first network element, the first NAS security context corresponds to a second NAS security context, and the second NAS security context is created or activated for the terminal by the first network element in the case that the SMC procedure is successfully executed.
[0006] According to a second aspect of the present disclosure, a communication method is provided, executed by a first network element, the method comprising: receiving a first message, the first message being used for a terminal to request to establish a Non-Access Stratum (NAS) connection with the first network element; triggering to execute a Security Mode Command (SMC) procedure, and creating or activating a second NAS security context for the terminal in a case that the SMC procedure is successfully executed, wherein the second NAS security context corresponds to a first NAS security context, and the first NAS security context is created or activated for the first network element by the terminal in the case that the SMC procedure is successfully executed.
[0007] According to a third aspect of the embodiments of the present disclosure, a terminal is provided, which comprises: a transceiver configured to send a first message, the first message being used to request a non-access stratum (NAS) connection with a first network element; and a processor configured to create or activate a first NAS security context for the first network element in a case where a security mode command (SMC) procedure is successfully performed, wherein the SMC procedure is triggered by the first message received by the first network element, and the first NAS security context corresponds to a second NAS security context, which is created or activated for the terminal by the first network element in the case where the SMC procedure is successfully performed.
[0008] According to a fourth aspect of the embodiments of the present disclosure, a first network element is provided, which comprises: a transceiver configured to receive a first message, the first message being used to request a non-access stratum (NAS) connection with the first network element by a terminal; and a processor configured to trigger an execution of a security mode command (SMC) procedure, and create or activate a second NAS security context for the terminal in a case where the SMC procedure is successfully performed, wherein the second NAS security context corresponds to a first NAS security context, which is created or activated for the first network element by the terminal in the case where the SMC procedure is successfully performed.
[0009] According to a fifth aspect of the embodiments of the present disclosure, a terminal is provided, which comprises: one or more processors; and a memory coupled to the processors and storing executable instructions, which when executed by the processors, cause the communication method of the first aspect to be performed.
[0010] According to a sixth aspect of the embodiments of the present disclosure, a first network element is provided, which comprises: one or more processors; and a memory coupled to the processors and storing executable instructions, which when executed by the processors, cause the communication method of the second aspect to be performed.
[0011] According to a seventh aspect of the embodiments of the present disclosure, a communication system is provided, which comprises a terminal, a first network element and a second network element, wherein the terminal is configured to implement the communication method of the first aspect, and the first network element is configured to implement the communication method of the second aspect.
[0012] According to an eighth aspect of the embodiments of the present disclosure, a storage medium is provided, which stores instructions, which when executed on a communication device, cause the communication device to perform the communication method of the first aspect or the second aspect.
[0013] According to a ninth aspect of the embodiments of the present disclosure, a computer program product is provided, including a computer program and / or instructions, which, when executed by a communication device, implement the communication method of the first aspect or the second aspect.
[0014] With the above technical solution, the NAS connection between the terminal and the first network element can be established, and the integrity and confidentiality of the NAS message between the terminal and the first network element can be ensured, and the message replay attack can be prevented. BRIEF DESCRIPTION OF DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.
[0016] FIG. 1A is an exemplary schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure.
[0017] FIG. 1B is a schematic diagram of a network element connection according to an embodiment of the present disclosure.
[0018] FIG. 1C is a schematic diagram of a distributed NAS connection terminal according to an embodiment of the present disclosure.
[0019] FIG. 1D is a schematic diagram of a distributed NAS according to an embodiment of the present disclosure.
[0020] FIG. 1E is a schematic diagram of an encryption algorithm according to an embodiment of the present disclosure.
[0021] FIG. 1F is a schematic diagram of an integrity algorithm according to an embodiment of the present disclosure.
[0022] FIG. 2A is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0023] FIG. 2B is a schematic diagram of a NAS security context structure stored in a terminal according to an embodiment of the present disclosure.
[0024] FIG. 2C is a schematic diagram of a NAS security context structure stored in a terminal according to an embodiment of the present disclosure.
[0025] FIG. 2D is a schematic diagram of a NAS security context structure stored in a first network element according to an embodiment of the present disclosure.
[0026] FIG. 2E is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure.
[0027] FIG. 2F is a schematic diagram of a NAS security context structure stored in a terminal according to an embodiment of the present disclosure.
[0028] FIG. 2G is a schematic diagram of a NAS security context structure stored in a terminal according to an embodiment of the present disclosure.
[0029] FIG. 2H is a schematic diagram of a NAS security context structure stored in a first network element according to an embodiment of the present disclosure.
[0030] FIG. 3A is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0031] FIG. 3B is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0032] FIG. 3C is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0033] FIG. 3D is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0034] FIG. 4A is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0035] FIG. 4B is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0036] FIG. 4C is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0037] FIG. 4D is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0038] FIG. 5A is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0039] FIG. 5B is a schematic diagram of a communication method according to an embodiment of the present disclosure.
[0040] FIG. 6A is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.
[0041] FIG. 6B is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.
[0042] FIG. 6C is a schematic diagram of interactions of a communication method according to an embodiment of the present disclosure.
[0043] FIG. 7A is a schematic diagram of a structure of a terminal according to an embodiment of the present disclosure.
[0044] FIG. 7B is a schematic diagram of a structure of a first network element according to an embodiment of the present disclosure.
[0045] FIG. 8A is a schematic diagram of a structure of a communication device according to an embodiment of the present disclosure.
[0046] FIG. 8B is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0047] Embodiments of the present disclosure provide a communication method, a terminal, a network element, a system and a medium.
[0048] In a first aspect, embodiments of the present disclosure provide a communication method performed by a terminal, the method comprising: sending a first message, the first message being used to request establishment of a non-access stratum (NAS) connection with a first network element; and creating or activating a first NAS security context for the first network element in a case where a security mode command (SMC) procedure successfully completes, wherein the SMC procedure is triggered by the first message received by the first network element, the first NAS security context corresponds to a second NAS security context, and the second NAS security context is created or activated for the terminal by the first network element in the case where the SMC procedure successfully completes.
[0049] In the above embodiments, the establishment of the NAS connection between the terminal and the first network element can be implemented, and the integrity and confidentiality of the NAS messages between the terminal and the first network element can be guaranteed, and the message replay attack can be prevented.
[0050] In some embodiments, in combination with some embodiments of the first aspect, in some embodiments, the sending of the first message comprises: sending the first message to a second network element, so as to send the first message or a second message to the first network element through the second network element, the second message being generated based on the first message; or sending the first message to the first network element.
[0051] In the above embodiments, it is specified that the terminal can directly send the first message to the first network element or send the first message to the first network element through the AMF.
[0052] In some embodiments, in combination with some embodiments of the first aspect, in some embodiments, the first message is protected according to a fifth NAS security context, the fifth security context being a NAS security context corresponding to the second network element and stored on the terminal; or the first message is protected according to a third NAS security context corresponding to the first network element and stored on the terminal, a state of the third NAS security context being a non-current state; or the first message is unprotected.
[0053] In the above embodiments, it is specified that the first message can be protected or unprotected.
[0054] In some embodiments, in combination with some embodiments of the first aspect, in some embodiments,
[0055] The first NAS security context comprises at least one of the following:
[0056] NAS connection identifier;
[0057] Security algorithm;
[0058] The first key of the first network element;
[0059] The first NAS count, comprising an uplink NAS count and / or a downlink NAS count;
[0060] The first identifier, a general identifier of the first NAS security context and the fifth NAS security context;
[0061] The second identifier, an identifier of the first NAS security context;
[0062] Encryption protection key;
[0063] Integrity protection key;
[0064] The state item, a value of the state item being a first value, the first value indicating a current state.
[0065] In the above embodiment, the first NAS security context can guarantee the security and integrity of the NAS message sent by the terminal to the first network element and can avoid replay attacks.
[0066] In combination with some embodiments of the first aspect, in some embodiments, the method further comprises: after the SMC procedure is successfully executed, the value of the first NAS count is set to 0.
[0067] In the above embodiment, the value of the first NAS count in the first NAS security context is set to 0 after each SMC procedure is successfully executed, so as to ensure the security of subsequent communication.
[0068] In combination with some embodiments of the first aspect, in some embodiments, the first key of the first network element is generated according to a vertical derivation manner or a horizontal derivation manner.
[0069] In the above embodiment, the terminal can generate the first key of the first network element through vertical derivation or horizontal derivation, thereby enhancing the NAS connection.
[0070] In combination with some embodiments of the first aspect, in some embodiments, the input parameter of the vertical derivation manner comprises at least one of the following:
[0071] The identifier of the terminal;
[0072] Inter-architecture Anti-Downgrade (ABBA) parameter;
[0073] The identifier of the first network element;
[0074] a second key of the second network element;
[0075] a second NAS count, the second NAS count being stored in a NAS security context corresponding to the second network element in the terminal;
[0076] a first random number provided by the terminal;
[0077] a second random number provided by the first network element.
[0078] In the above embodiment, the first key of the first network element can be derived vertically according to the above parameters, so as to guarantee the NAS security.
[0079] With reference to some embodiments of the first aspect, in some embodiments, the second key of the second network element is obtained by: determining a security context corresponding to the second network element according to the first identifier or the second identifier obtained in the SMC process; and determining the second key of the second network element from the security context corresponding to the second network element.
[0080] In the above embodiment, the terminal can determine the key corresponding to the second network element used in the SMC process, and then generate the first key of the first network element to guarantee the NAS security.
[0081] With reference to some embodiments of the first aspect, in some embodiments, the input parameters of the horizontal derivation manner include at least one of: a transmission direction, the transmission direction including an uplink transmission direction and / or a downlink transmission direction; a third NAS count, the third NAS count being determined from a third NAS security context; and a second key of the first network element, the second key of the first network element being determined from the third NAS security context.
[0082] In the above embodiment, the first key of the first network element can be derived horizontally according to the above parameters, so as to guarantee the NAS security.
[0083] With reference to some embodiments of the first aspect, in some embodiments, the method further includes: receiving a third message sent by the first network element, the third message being protected by the first network element according to an encryption protection key and / or an integrity protection key in the second NAS security context, the third message being a response to the first message; and verifying the third message according to the first NAS security context to determine whether the NAS connection with the first network element is successfully established.
[0084] In the above embodiment, the terminal verifies the third message sent by the first network element and used to respond to the first message according to the created or activated first NAS security context, and can determine whether the NAS connection with the first network element is successfully established.
[0085] In some embodiments of the first aspect, after the NAS connection is successfully established, the method further comprises:
[0086] In a case where the fourth message is sent to the first network element, a value of an uplink NAS count in the first NAS security context is increased by 1, wherein the fourth message comprises a first sequence number (SQN), and the first SQN is used by the first network element to update an uplink NAS count in the second NAS security context.
[0087] In the above embodiments, the updating manner of the uplink NAS count is specified.
[0088] In some embodiments of the first aspect, after the NAS connection is successfully established, the method further comprises:
[0089] In a case where the fifth message sent by the first network element is received, a value of a downlink NAS count in the first NAS security context is updated according to a second SQN in the fifth message.
[0090] In the above embodiments, the updating manner of the downlink NAS count is specified.
[0091] In some embodiments of the first aspect, the method further comprises: in a case where the NAS connection is released, updating a value of a state item in the first NAS security context to a second value to obtain a third NAS security context, wherein the second value indicates a non-current state.
[0092] In the above embodiments, after the NAS connection is released, the state of the first NAS security context is changed to the non-current state.
[0093] In some embodiments of the first aspect, the method further comprises: in a case where the NAS connection is released, removing the first NAS security context.
[0094] In the above embodiments, after the NAS connection is released, the first NAS security context is deleted.
[0095] In a second aspect, the embodiments of the present disclosure provide a communication method, performed by a first network element, the method comprising: receiving a first message, the first message being used for a terminal to request to establish a non-access stratum (NAS) connection with the first network element; triggering to perform a security mode command (SMC) procedure, and creating or activating a second NAS security context for the terminal in a case that the SMC procedure is successfully performed, wherein the second NAS security context corresponds to a first NAS security context, and the first NAS security context is created or activated for the first network element by the terminal in the case that the SMC procedure is successfully performed.
[0096] With reference to some embodiments of the second aspect, in some embodiments, the receiving the first message comprises: receiving the first message sent by the terminal; or receiving the first message or a second message sent by a second network element, the second message being generated by the second network element based on the received first message.
[0097] With reference to some embodiments of the second aspect, in some embodiments, the first message is protected according to a fifth NAS security context, the fifth security context being a NAS security context corresponding to the second network element and stored on the terminal; or the first message is protected according to a third NAS security context corresponding to the first network element and stored on the terminal, a state of the third NAS security context being a non-current state; or the first message is unprotected.
[0098] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises: in a case that the first message is protected according to the third NAS security context, verifying, by the first network element, the first message according to a fourth NAS security context, wherein the fourth NAS security context corresponds to the third security context; in response to failing to verify the first message, rejecting, by the first network element, to establish the NAS connection with the terminal.
[0099] With reference to some embodiments of the second aspect, in some embodiments, the second NAS security context comprises at least one of:
[0100] an identifier of the terminal;
[0101] an identifier of the NAS connection;
[0102] a security algorithm;
[0103] a first key of the first network element;
[0104] a first NAS count, comprising an uplink NAS count and / or a downlink NAS count;
[0105] a first identifier, a generic identifier for the second NAS security context and the fifth NAS security context;
[0106] a second identifier, an identifier for the second NAS security context;
[0107] an encryption protection key;
[0108] an integrity protection key;
[0109] a status item, a value of the status item being a first value, the first value indicating a current state.
[0110] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises: setting the value of the first NAS count to 0 after the SMC procedure is successfully performed.
[0111] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises: obtaining at least one of the following from a second message sent by the second network element:
[0112] the first identifier;
[0113] the second identifier;
[0114] a first key of the first network element.
[0115] With reference to some embodiments of the second aspect, in some embodiments, the method further comprises: requesting the second network element to send a first key of the first network element; and receiving at least one of the first key of the first network element, the first identifier, and the second identifier returned by the second network element.
[0116] With reference to some embodiments of the second aspect, in some embodiments, the first key of the first network element is generated by the second network element through a vertical derivation manner, wherein an input parameter of the vertical derivation manner comprises at least one of:
[0117] an identifier of the terminal;
[0118] an inter-architecture anti-bidding down, ABBA, parameter;
[0119] an identifier of the first network element;
[0120] a key of the second network element;
[0121] a fourth NAS count, the fourth NAS count being stored in a NAS security context corresponding to the terminal on the second network element;
[0122] a first random number provided by the terminal;
[0123] The first network element provides a second random number.
[0124] In some embodiments of the second aspect, the method further comprises generating the first key according to a horizontal derivation manner, wherein an input parameter of the horizontal derivation manner comprises at least one of the following:
[0125] a transmission direction, the transmission direction comprising an uplink transmission direction or / and a downlink transmission direction;
[0126] a fifth NAS COUNT, the fifth NAS COUNT being determined from the fourth NAS security context;
[0127] a second key of the first network element, the second key of the first network element being determined from the fourth NAS security context.
[0128] In some embodiments of the second aspect, the method further comprises sending, to the terminal, a third message, the third message being protected by the first network element according to a ciphering protection key and / or an integrity protection key in the second NAS security context, the third message being used for responding to the first message.
[0129] In some embodiments of the second aspect, after the NAS connection establishment is successful, the method comprises: in a case where a fourth message sent by the terminal is received, updating a value of an uplink NAS COUNT in the second NAS security context according to a first sequence number (SQN) in the fourth message.
[0130] In some embodiments of the second aspect, after the NAS connection establishment is successful, the method comprises:
[0131] in a case where a fifth message is sent to the terminal, increasing a value of a downlink NAS COUNT in the second NAS security context by 1, wherein the fifth message comprises a second SQN, the second SQN being used for the terminal to update a downlink NAS COUNT in the first NAS security context.
[0132] In some embodiments of the second aspect, the method further comprises: in a case where the NAS connection is released, updating a value of a state item in the second NAS security context to a second value, the second value indicating a non-current state, to obtain a fourth NAS security context.
[0133] In some embodiments of the second aspect, the method further comprises: in a case where the NAS connection is released, removing the second NAS security context.
[0134] In a third aspect, the embodiments of the present disclosure provide a terminal, which comprises at least one of a transceiver module and a processing module; wherein the terminal is configured to perform the optional implementation manners of the first aspect.
[0135] In a fourth aspect, the embodiments of the present disclosure provide a first network element, which comprises at least one of a transceiver module and a processing module; wherein the first network element is configured to perform the optional implementation manners of the second aspect.
[0136] In a fifth aspect, the embodiments of the present disclosure provide a terminal, which comprises one or more processors; wherein the terminal is configured to perform the optional implementation manners of the first aspect.
[0137] In a sixth aspect, the embodiments of the present disclosure provide a first network element, which comprises one or more processors; wherein the first network element is configured to perform the optional implementation manners of the second aspect.
[0138] In a seventh aspect, the embodiments of the present disclosure provide a communication system, which comprises a terminal, a first network element and a second network element; wherein the terminal is configured to perform the method described in the optional implementation manners of the first aspect, and the first network element is configured to perform the method described in the optional implementation manners of the second aspect.
[0139] In an eighth aspect, the embodiments of the present disclosure provide a storage medium, which stores instructions, when the instructions are run on a communication device, causing the communication device to perform the method described in the optional implementation manners of the first aspect and / or the second aspect.
[0140] In a ninth aspect, the embodiments of the present disclosure provide a program product, which, when executed by a communication device, causes the communication device to perform the method described in the optional implementation manners of the first aspect and / or the second aspect.
[0141] In a tenth aspect, the embodiments of the present disclosure provide a computer program, which, when run on a computer, causes the computer to perform the method described in the optional implementation manners of the first aspect and / or the second aspect.
[0142] In an eleventh aspect, the embodiments of the present disclosure provide a chip or chip system. The chip or chip system comprises processing circuitry configured to perform the method described in the optional implementation manners of the first aspect and / or the second aspect.
[0143] It can be understood that the terminal, the first network element, the second network element, the communication device, the communication system, the storage medium, the program product, the computer program, the chip or the chip system are all configured to perform the method provided by the embodiments of the present disclosure. Therefore, the beneficial effects they can achieve can refer to the beneficial effects in the corresponding method, which will not be described here.
[0144] The embodiments of the present disclosure provide a communication method, a terminal, a network element, a system and a medium. In some embodiments, the communication method and the information processing method, the SMC-based NAS connection method, and the like can be replaced with each other, the communication device and the information processing device, the SMC-based NAS connection device, and the like can be replaced with each other, and the communication system and the information processing system, the SMC-based NAS connection system, and the like can be replaced with each other.
[0145] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, some or all steps of different embodiments can be combined arbitrarily, and an embodiment can be combined with optional implementation manners of other embodiments.
[0146] In the embodiments of the present disclosure, the terms and / or descriptions between the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0147] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.
[0148] In the embodiments of the present disclosure, unless otherwise specified and logically conflicted, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this", and the like, can represent "one and only one", or "one or more", "at least one", and the like. For example, in the case of using articles such as "a", "an", "the" in English, the noun after the article can be understood as singular expression, or as plural expression.
[0149] In the embodiments of the present disclosure, "a plurality of" means two or more.
[0150] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.
[0151] In some embodiments, "at least one of A, B", "A and / or B", "in one case A, in another case B", "in response to case A, in response to case B", and the like, can include the following technical solutions according to the case: in some embodiments, A (A is executed regardless of B); in some embodiments, B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selected from A and B); in some embodiments, A and B (A and B are executed). When there are more branches such as A, B, C, and the like, the above is similar.
[0152] In some embodiments, "A or B" and the like, according to the case, can include the following technical solutions: in some embodiments, A (A is executed regardless of B); in some embodiments, B (B is executed regardless of A); in some embodiments, A and B are selectively executed (A and B are selected from A and B). When there are more branches such as A, B, C, and the like, the above is similar.
[0153] The prefix words "first", "second" and the like in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute a limitation on the position, order, priority, quantity or content of the description objects. The description of the description objects should refer to the description in the context of the claims or embodiments, and should not constitute an additional limitation because of the use of the prefix word. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal word, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different; for another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and the content thereof can be the same or different.
[0154] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0155] In some embodiments, the terms “in response to,” “in response to determining,” “in the event that,” “when,” “if,” “upon,” and the like can be replaced with each other.
[0156] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” “above,” and the like can be replaced with each other, and the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” “below,” and the like can be replaced with each other.
[0157] In some embodiments, an apparatus and the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments, and the terms “apparatus,” “equipment,” “device,” “circuit,” “network element,” “node,” “function,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” “subject,” and the like can be replaced with each other.
[0158] In some embodiments, “network” can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.
[0159] In some embodiments, the terms “access network device (AN device),” “radio access network device (RAN device),” “base station (BS),” “radio base station,” “fixed station,” “node,” “access point,” “transmission point (TP),” “reception point (RP),” “transmission / reception point (TRP),” “panel,” “antenna panel,” “antenna array,” “cell,” “macro cell,” “small cell,” “femto cell,” “pico cell,” “sector,” “cell group,” “serving cell,” “carrier,” “component carrier,” “bandwidth part (BWP),” and the like can be used interchangeably.
[0160] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.
[0161] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.
[0162] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.
[0163] In some embodiments, obtaining data, information, and the like can comply with laws and regulations of the country where the location is situated.
[0164] In some embodiments, data, information, and the like can be obtained after obtaining consent of the user.
[0165] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0166] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1A, the communication system 100 can include a terminal 101 and a network device 102. The network device 102 includes a first network element 1021 and / or a second network element 1022.
[0167] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet computer (Pad), a wireless transceiver-enabled computer, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, a wireless terminal device in a smart home, and the like, but is not limited thereto.
[0168] In some embodiments, the network device 102 can include at least one of an access network device and a core network device.
[0169] Optionally, the network device 102 is an access network device. Optionally, the access network device is at least one of a node or device that accesses a terminal to a wireless network, and can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an Open RAN, a Cloud RAN, a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0170] In some embodiments, the network device 102 is a base station. Optionally, the base station is at least one of a macro base station, a micro base station (also known as a small station), a relay station, an access point, a 5G base station or a future base station, a satellite, a Transmitting and Receiving Point (TRP), a Transmitting Point (TP), a mobile switching center, or other devices that perform the function of a base station in a communication system, etc., and the embodiments of the present disclosure do not make specific limitations thereto. For the convenience of description, in all embodiments of the present disclosure, the apparatus that provides a wireless communication function for a terminal device is collectively referred to as a network device or a base station.
[0171] In some embodiments, the network device 102 is a core network device. Optionally, the core network device can be one device, including all or part of a first network element, a second network element, etc., or can be a plurality of devices or device groups, respectively including all or part of the first network element, the second network element, etc. The network element can be virtual or physical. The core network includes at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), a 6G Core Network (6GCN), a Next Generation Core (NGC), etc.
[0172] In some embodiments, the first network element 1021 can be any NF of the core network except the second network element.
[0173] In some embodiments, the second network element 1022 is a network element responsible for guaranteeing the safe access of users to the network. For example, the second network element is a network element with access and mobility management functions, such as an Access and Mobility Management Function (AMF), or a network element with authentication and authorization functions, such as an Authentication Server Function (AUSF), or a network element with functions of managing security contexts and deriving keys, such as a Security Anchor Function (SEAF), the name is not limited to this, and it can also be other network elements that implement similar functions.
[0174] In some embodiments, the technical solutions of the present disclosure can be applied to the Open RAN architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.
[0175] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), where the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the functions of the protocol layers are controlled by the CU, and the remaining or all of the functions of the protocol layers are distributed in the DU and controlled by the CU. However, this is not limited.
[0176] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed in the embodiments of the present disclosure. It can be known by those skilled in the art that, as the system architecture evolves and new business scenarios appear, the technical solutions proposed in the embodiments of the present disclosure are also applicable to similar technical problems.
[0177] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subjects, but are not limited thereto. The subjects shown in FIG. 1A are illustrative, and the communication system can include all or part of the subjects in FIG. 1A, or other subjects other than those in FIG. 1A. The number and form of each subject is arbitrary, each subject can be physical or virtual, the connection relationship between each subject is illustrative, each subject can not be connected or can be connected, and the connection can be in any manner, can be direct connection or indirect connection, can be wired connection or wireless connection.
[0178] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based on them, or the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, or the like).
[0179] In the related art, the new 6G architecture should support streamlined network functions (NFs) to make them more efficient in terms of capacity, coverage, signaling overhead, scalability, and energy consumption. The dependency between NFs can cause unnecessary complexity and even delay. The dependency and the number of handling points can be reduced by redesigning the network functions. One way to improve the 6G architecture is to increase the possibility of direct signaling between NFs to eliminate potential bottlenecks. Currently, many services require information to be transferred from one new generation radio access network (NG-RAN) node to another through the 5GC. In the 5GC, the information is transferred through limited AMF relays or even without the involvement of the AMF. To simplify such transfers, the introduction of service-based interfaces (SBI) will allow these information to be exchanged directly between NG-RAN NFs without going through the AMF. See the example of FIG. IB. In FIG. IB, the location management function (LMF), network repository function (NRF), policy control function (PCF), unified data management (UDM), UE radio capability management function (UCMF), session management function (SMF), network data analytics function (NWDAF), network exposure function (NEF), user plane function (UPF), and data network (DN) are network elements in the core network (CN) for implementing different functions. Nlmf, Nnrf, Namf, Npcf, Nsmf, Nudm, Nnwdaf, Nucmf, Nnef, Nran, Nl, N2, N3, N4, and N6 are interface sequence numbers.
[0180] In some embodiments, if the RAN evolves to be service-based, it means that the RAN node can be a consumer or producer of other network functions besides the AMF. In the current 5G system, NAS signaling (transmitted transparently through the RAN node) only supports communication between the UE and the AMF in the core network. If the RAN can evolve to communicate directly with other core network functions (NFs) without going through the AMF, it means that NAS signaling needs to be supported between the UE and other core NFs besides the AMF. Therefore, a 6G architecture with multiple NAS instances, as shown in FIG. 1C and FIG. 1D, can be enabled so that the RAN node can communicate directly with any core NF through a service-based interface, and the UE can communicate directly with any core NF using NAS signaling. RRC in FIG. 1D refers to Radio Resource Control. However, the existing NAS COUNT mechanism can not be able to support the multi-NAS architecture. It should be explained that the NAS COUNT is one of the inputs of the encryption algorithm and the integrity algorithm for each NAS signaling, as shown in FIG. 1E and FIG. 1F. In FIG. 1F, MAC-I / NAS-MAC represents the message authentication code calculated by the sender using the integrity algorithm NIA. XMAC-I / XNAS-MAC represents the expected message authentication code calculated by the receiver on the received message.
[0181] In some embodiments, one or both of the following two parts of values can be included in the NAS COUNT:
[0182] 1. 8-bit NAS SQN (Sequence Number) included in the NAS message in clear text. This corresponds to the least significant 8 bits of the NAS COUNT.
[0183] 2. 16-bit NAS OVERFLOW maintained and synchronized as much as possible between the UE and the AMF. This corresponds to the most significant 16 bits of the NAS COUNT.
[0184] In some embodiments, the processing of the NAS OVERFLOW and the NAS COUNT of the incoming message by the receiving entity is as follows:
[0185] If the entity receives a message whose received NAS SQN is higher than its stored NAS SQN value, the NAS COUNT used by the sender should be estimated as (STORED NAS OVERFLOW) || (RECEIVE NAS SQN), and the integrity-protected message should be verified under this assumption. If the integrity verification is successful, the receiving entity should accept the message and update its STORED NAS SQN to be equal to the RECEIVE NAS SQN; otherwise, it will reject the message.
[0186] If the message received by the entity is a message with a receive NAS SQN less than or equal to its stored NAS SQN value, the NAS COUNT used by the sender should be estimated as (STORED NAS OVERFLOW + 1) || (RECEIVE NAS SQN), and the integrity-protected message should be verified under this assumption. If the integrity verification is successful, the receiving entity should accept the message, update its STORED NAS SQN to equal the RECEIVE NAS SQN, and increase its STORED NAS OVERFLOW; otherwise, it will reject the message.
[0187] The NAS COUNT in the related art is maintained in the AMF and the UE, and other NFs do not store the corresponding NAS COUNT for sending / receiving NAS signaling. If there is no correct NAS COUNT, the NAS signaling will be rejected by the receiver. This will affect the traffic of the NAS connection between the UE and other NFs. Therefore, it can be considered to enhance the NAS COUNT mechanism to support the multi-NAS architecture in the 6G or future communication system or other similar system.
[0188] In view of this, the embodiments of the present disclosure propose a communication method, a terminal, a network element, a system and a medium. At least the NAS COUNT can be maintained respectively by all NFs to protect and verify the NAS signaling.
[0189] Before the embodiments of the present disclosure are described in detail, it should be explained that the following embodiments of the present disclosure are exemplarily described taking the second network element 1022 including at least one of the AMF, the SEAF and the AUSF, and the first network element 1021 being any NF in the core network except the second network element as an example.
[0190] Figure 2A is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure. In the embodiment of Figure 2A, the NAS security context includes a state item. The relationship between similar terms in the embodiment of Figure 2A is explained as follows: the NAS security context between the terminal and the first network element in the current state stored at the terminal side is referred to as the first NAS security context. The NAS security context between the terminal and the first network element in the current state stored at the first network element side is referred to as the second NAS security context. The first NAS security context and the second NAS security context correspond to each other, and the state of the first NAS security context and the second NAS security context is the current state. The first NAS security context and the second NAS security context correspond to each other means that, for the NAS connection between the terminal and the first network element, the terminal side uses the first NAS security context to protect the NAS connection, and correspondingly, the first network element side uses the second NAS security context to protect the NAS connection. The first NAS security context and the second NAS security context can have one or more same items. For example, the first NAS security context and the second NAS security context have the same NAS connection identifier (the connection identifier includes 3GPP access and non-3GPP access). For example, the first NAS security context and the second NAS security context have the same security algorithm. For example, the first NAS security context and the second NAS security context have the same encryption protection key or integrity protection key, etc. It is worth noting that the NAS count in the first NAS security context and the second NAS security context can be asynchronous in a short time due to poor network state, etc.
[0191] In some embodiments, if the state of the first NAS security context is changed to a non-current state, the third NAS security context is obtained. Similarly, if the state of the second NAS security context is changed to a non-current state, the fourth NAS security context is obtained. That is, the NAS security context between the terminal and the first network element in the non-current state stored at the terminal side is referred to as the third NAS security context. The NAS security context between the terminal and the first network element in the non-current state stored at the first network element side is referred to as the fourth NAS security context. The third NAS security context and the fourth NAS security context correspond to each other, and the state of the third NAS security context and the fourth NAS security context is the non-current state.
[0192] In the embodiment of Figure 2A, the NAS security context stored at the terminal side can refer to Figure 2B and Figure 2C, and the NAS security context stored at the first network element side can refer to Figure 2D.
[0193] As shown in FIG. 2B, the NAS security context stored at the terminal side can include at least one of the NAS security context corresponding to the second network element (AMF / AUSF / SEAF), the first NAS security context, and the NAS security context corresponding to the second network element (fifth NAS security context) and the common identifier KSI of the first NAS security context. Among them, the NAS security context corresponding to the second network element includes at least one of the NAS connection identifier, the security algorithm, the state item, the key of the first network element, the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key. The first NAS security context includes at least one of the NAS connection identifier, the security algorithm, the state item, the key of the first network element, the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key.
[0194] As shown in FIG. 2C, the NAS security context stored at the terminal side can include at least one of the NAS security context corresponding to the second network element (AMF / AUSF / SEAF) and the first NAS security context. Among them, the NAS security context corresponding to the second network element includes at least one of the NAS connection identifier, the security algorithm, the state item, the key of the first network element, the context identifier (KSI AMF / SEAF / AUSF ), the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key. The first NAS security context includes at least one of the NAS connection identifier, the security algorithm, the state item, the key of the first network element, the context identifier (KSI NF ), the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key.
[0195] As shown in FIG. 2D, the NAS security context stored at the first network element side can include the second NAS security context. The second NAS security context includes at least one of the UE identifier, the NAS connection identifier, the security algorithm, the state item, the key of the first network element, the context identifier (KSI / KSI NF ), the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key.
[0196] As shown in FIG. 2A, the embodiments of the present disclosure relate to a communication method, which is performed by the communication system 100, and the communication method of FIG. 2A includes the following steps:
[0197] In step S2101, the terminal 101 sends a first message to the second network element 1022.
[0198] In some embodiments, the second network element receives the first message. For example, the second network element receives the first message sent by the terminal.
[0199] In some embodiments, the first message is used by the terminal to request the establishment of a NAS connection with the first network element. The first message can be transmitted to the first network element through the second network element.
[0200] In some embodiments, the name of the first message is not limited, which is, for example, initial NAS signaling, NAS connection request, etc.
[0201] In some embodiments, the first message can be protected according to the fifth NAS security context stored on the terminal, i.e., the NAS security context corresponding to the second network element; or the first message is not protected.
[0202] It should be explained that before the NAS security context between the terminal and the first network element is created or activated, i.e., before the communication method of the present disclosure is performed, the NAS security context between the terminal and the second network element has been created or activated by default. For example, the terminal can obtain the NAS security context corresponding to the second network element in the process of accessing the network. The NAS security context corresponding to the second network element stored on the terminal refers to the NAS security context between the terminal and the second network element that is currently available on the terminal. The NAS security context between the terminal and the second network element is used to protect the NAS connection communication between the terminal and the second network element.
[0203] For example, assuming that the first message is protected according to the NAS security context corresponding to the second network element stored on the terminal, the second network element can verify the first message according to the NAS security context between the terminal and the second network element stored by the second network element (i.e., the sixth NAS security context corresponding to the terminal stored by the second network element) in the case of receiving the first message. Optionally, the first message can include an identifier for the second network element to determine the corresponding NAS security context, such as the identifier of the terminal, the first identifier, the second identifier, etc. If the second network element verifies the first message successfully, step S2102 is performed. If the second network element fails to verify the first message, step S2102 is not performed.
[0204] In step S2102, the second network element 1022 sends the first message or the second message to the first network element 1021.
[0205] In some embodiments, the first network element receives the first message or the second message sent by the second network element.
[0206] In some embodiments, the second message includes the original first message or includes the first message after processing. For example, the second message includes one or more fields in the first message. For example, the second message includes the content extracted from the first message.
[0207] In some embodiments, the first message can comprise an identifier of the first network element (e.g. an instance ID or type of the first network element). In this way, it is facilitated for the second network element to send the first message or the second message to the first network element.
[0208] In some embodiments, the second message comprises at least part of the content in the first message and at least one of the first identifier, the second identifier, and the first key of the first network element. Optionally, the first identifier, the second identifier, and the first key of the first network element can all be generated by the second network element. Optionally, the first identifier and the second identifier can also be provided by the terminal in the first message. In this way, it is facilitated for the first network element to obtain at least one of the following from the second message sent by the second network element:
[0209] the first identifier;
[0210] the second identifier;
[0211] the first key of the first network element.
[0212] For example, the first key of the first network element is comprised in the second message.
[0213] For example, the first identifier and the first key of the first network element are comprised in the second message.
[0214] For example, the second identifier and the first key of the first network element are comprised in the second message.
[0215] At least one of the first identifier, the second identifier, and the first key of the first network element can be used by the first network element to generate a NAS security context between the terminal and the first network element (i.e. the second NAS security context on the first network element side).
[0216] It should be explained that the first identifier (KSI) is used to identify the NAS security context between the terminal and the first network element (i.e. the first NAS security context on the terminal side / the second NAS security context on the first network element side) and the NAS security context corresponding to the second network element (i.e. the NAS security context corresponding to the second network element stored by the terminal / the NAS security context corresponding to the terminal stored by the second network element). The second identifier (KSI NF ) is used to identify the NAS security context between the terminal and the first network element (i.e. the first NAS security context on the terminal side / the second NAS security context on the first network element side).
[0217] It should be noted that KSI can be a common identifier of the NAS security context between the terminal and the second network element and the NAS security context between the terminal and the first network element. In some embodiments, the value of KSI AMF / SEAF / AUSF and KSI NF may be the same or different, for example, KSI NFmay be derived from KSI AMF / SEAF / AUSF may be mapped to KSI AMF / SEAF / AUSF may be derived from KSI NF , i.e. KSI NF = NF instance ID / NF type: KSI AMF / SEAF / AUSF .
[0218] In some embodiments, the second network element is a relay node between the terminal and the first network element, and the second network element only has a forwarding function, and the second network element sends the first message to the first network element in the case that the first message sent by the terminal is received.
[0219] In some embodiments, the first message sent by the terminal is not security protected.
[0220] In some embodiments, the first message sent by the terminal is protected using a third NAS security context corresponding to the first network element and stored on the terminal.
[0221] In some embodiments, steps S2101 and S2102 can be omitted or not executed. The terminal 101 can directly send the first message to the first network element 1021, and the first network element receives the first message sent by the terminal.
[0222] In some embodiments, the first message sent by the terminal directly to the first network element can be protected according to a third NAS security context corresponding to the first network element and stored on the terminal, and the state of the third NAS security context is a non-current state; or the first message is not protected. Optionally, the first message can include an identifier (such as including a first identifier, a second identifier) used by the first network element to determine a fourth NAS security context corresponding to the third NAS security context.
[0223] The third NAS security context is a NAS security context between the terminal and the first network element in a non-current state stored on the terminal, which is obtained after the terminal changes the value of the state item in the first security context from a first value to a second value in the case that the terminal releases the NAS connection between the terminal and the first network element last time. The second value indicates a non-current state. That is, the third NAS security context is a NAS security context between the terminal and the first network element in a non-current state stored on the terminal. The non-current state can be understood as a state that is not currently active, or other state indicating that the current NAS security context is not used. Correspondingly, the fourth NAS security context is a NAS security context between the terminal and the first network element in a non-current state stored on the first network element, which is obtained after the first network element changes the value of the state item in the second security context from a first value to a second value in the case that the first network element releases the NAS connection between the terminal and the first network element last time. That is, the fourth NAS security context is a NAS security context between the terminal and the first network element in a non-current state stored on the first network element.
[0224] It should be noted that the first value and the second value are different values. For example, the first value is 1 and the second value is 0. For example, the first value is 0 and the second value is 1.
[0225] The state of the NAS security context includes a current state and a non-current state. Among them, only the current state of the NAS security context is used to protect the NAS message transmitted after the NAS connection is successful.
[0226] In some embodiments, if the first message is unprotected, the first message can include a NAS context identifier with a value of 111. The NAS context identifier with a value of 111 indicates that there is no available NAS security context.
[0227] Step S2103, the first network element 1021 determines the first key of the first network element.
[0228] Among them, the first key of the first network element determined by the first network element is one of the second NAS security contexts activated or generated by the first network element.
[0229] In some embodiments, the first network element requests the first key of the first network element from the second network element. For example, if the first network element does not store the NAS security context identified by the first identifier / second identifier in the received first / two messages, or the NAS context identifier with a value of 111 in the first / two messages is received, the first network element can request the first key K NF of the first network element from the second network element. The first network element receives at least one of the first key of the first network element, the first identifier, and the second identifier returned by the second network element.
[0230] In some embodiments, the first network element obtains at least one of the first key of the first network element, the first identifier, and the second identifier from the second message sent by the second network element.
[0231] In some embodiments, the first key of the first network element is generated by the second network element through vertical derivation. Optionally, the input parameters of the vertical derivation method include at least one of the following:
[0232] The identifier of the terminal (such as IMSI or NAI or GCI or GLI or GPSI or SUPI or SUCI);
[0233] ABBA parameter;
[0234] The identifier of the first network element (such as the instance ID of the first network element or the type of the first network element);
[0235] The key of the second network element (such as K AUSF / K SEAF / K AMF );
[0236] a fourth NAS COUNT, the fourth NAS COUNT being stored in the NAS security context corresponding to the terminal on the second network element;
[0237] a first random number provided by the terminal;
[0238] a second random number provided by the first network element.
[0239] Exemplarily, the input parameters of the vertical derivation manner are the identifier of the terminal, the ABBA parameter, the identifier of the first network element, and the key of the second network element.
[0240] That is, the second network element can actively (i.e. by sending the second message) or passively (i.e. according to the request of the first network element) send at least one of the first key of the first network element, the first identifier, and the second identifier of the first network element to the first network element.
[0241] In some embodiments, in addition to obtaining the first key of the first network element from the second network element, the first network element can also generate the first key of the first network element according to the horizontal derivation manner. For example, if the first message is protected according to the third NAS security context by the terminal, and the first network element stores the fourth NAS security context identified by the received first identifier / second identifier, the first network element can use the fourth NAS security context retrieved based on the received first identifier / second identifier to verify the first message. If the integrity verification fails, the first network element will reject the first message, i.e. the first network element rejects to establish a NAS connection with the terminal. If the integrity verification succeeds, the first network element can initiate horizontal derivation to obtain the updated first key K NF of the first network element. Optionally, the input parameters of the horizontal derivation manner include at least one of the following:
[0242] a transmission direction, the transmission direction being an uplink transmission direction or a downlink transmission direction;
[0243] a fifth NAS COUNT, the fifth NAS COUNT being determined from the fourth NAS security context;
[0244] a second key K NF’ of the first network element, the second key of the first network element being determined from the fourth NAS security context.
[0245] It should be explained that if the value of the transmission direction is 0x01, the fifth NAS COUNT is the value of the NAS COUNT corresponding to the downlink. If the value of the transmission direction is 0x00, the fifth NAS COUNT is the value of the NAS COUNT corresponding to the uplink.
[0246] wherein the fifth NAS COUNT comprises a fifth uplink NAS COUNT and a fifth downlink NAS COUNT.
[0247] For example, the input parameters of the horizontal derivation manner are the uplink transmission direction, the fifth uplink NAS count, and the second key K of the first network element NF’ .
[0248] For example, the input parameters of the horizontal derivation manner are the downlink transmission direction, the fifth downlink NAS count, and the second key K of the first network element NF’ .
[0249] In some embodiments, step S2104 is performed in the case where the first network element obtains the first key K of the first network element NF .
[0250] In step S2104, the first network element 1021 triggers an SMC procedure.
[0251] In some embodiments, the first network element triggers the SMC procedure in response to a NAS connection request (the first message) of the terminal. For example, if the first message received by the first network element is unprotected, the first network element determines to initiate the SMC to establish the NAS security with the UE. For example, if the first message received by the first network element is protected by the terminal, the first network element can also initiate the SMC to update and reactivate the NAS security.
[0252] In some embodiments, in the case where the first network element obtains the first key K of the first network element NF , the K NF and / or K NF_INT can be derived from the first key K of the first network element NF_ENC to protect the SMC message. Wherein, K NF_INT is the key for integrity protection, which is derived from K NF . And K NF_ENC is the encryption protection key derived from K NF .
[0253] In step S2105, the terminal 101 creates or activates a first NAS security context for the first network element 1021 in the case where the SMC procedure is successfully performed.
[0254] It should be noted that the number of the first network elements is one or more. If the number of the first network elements is more than one, the terminal can create or activate a first NAS security context for each of the first network elements in the case where the SMC procedure corresponding to the first network element is successfully performed. Different first network elements correspond to different first NAS security contexts.
[0255] In some embodiments, the first NAS security context created or activated by the terminal for the first network element corresponds to a second NAS security context created or activated by the first network element for the terminal. The first NAS security context is stored on the terminal, and the second NAS security context is stored on the first network element.
[0256] In some embodiments, the first NAS security context comprises at least one of:
[0257] a NAS connection identifier;
[0258] a security algorithm;
[0259] a first key K NF of the first network element;
[0260] a first NAS count comprising an uplink NAS count and / or a downlink NAS count;
[0261] a first identifier being a common identifier of the first NAS security context and a NAS security context corresponding to the second network element;
[0262] a second identifier being an identifier of the first NAS security context;
[0263] an encryption protection key;
[0264] an integrity protection key;
[0265] a status item, a value of the status item being a first value, the first value indicating a current state.
[0266] For example, the first NAS security context comprises the security algorithm, the first NAS count, the encryption protection key, the integrity protection key, and the status item.
[0267] For example, the first NAS security context comprises the NAS connection identifier, the security algorithm, the first key of the first network element, the first NAS count, the first identifier, the encryption protection key, the integrity protection key, and the status item.
[0268] For example, the first NAS security context comprises the NAS connection identifier, the security algorithm, the first key of the first network element, the first NAS count, the second identifier, the encryption protection key, the integrity protection key, and the status item.
[0269] In some embodiments, a value of the first NAS count in the first NAS security context is set to 0 after the SMC procedure is successfully performed. It can be understood that the terminal sets the value of the first NAS count to 0 when creating or activating the first NAS security context for the first network element 1021 in the case that the SMC procedure is successfully performed.
[0270] In some embodiments, the first key of the first network element in the first NAS security context is generated by the terminal according to a vertical derivation manner or a horizontal derivation manner.
[0271] Optionally, the input parameter of the vertical derivation manner used by the terminal comprises at least one of the following:
[0272] an identifier of the terminal;
[0273] an ABBA parameter;
[0274] an identifier of the first network element;
[0275] a key of the second network element;
[0276] a second NAS count stored in a NAS security context corresponding to the second network element in the terminal;
[0277] a first random number provided by the terminal;
[0278] a second random number provided by the first network element.
[0279] For example, the input parameter of the vertical derivation manner is the identifier of the terminal, the ABBA parameter, the identifier of the first network element, and the key of the second network element.
[0280] In some embodiments, the key of the second network element in the input parameter of the vertical derivation manner can be obtained by determining a security context corresponding to the second network element according to the first identifier or the second identifier obtained in the SMC process (sent by the first network element or the second network element to the terminal), and determining the key of the second network element from the security context corresponding to the second network element.
[0281] In some embodiments, the key of the second network element in the input parameter of the vertical derivation manner can be determined by the terminal according to the currently used NAS security context between the terminal and the second network element, i.e., the terminal determines the currently used NAS security context between the terminal and the second network element, and provides the first identifier or the second identifier of the NAS security context in the first message, and the second network element retrieves the corresponding security context according to the first identifier or the second identifier, thereby determining the key of the second network element.
[0282] Optionally, the input parameter of the horizontal derivation manner used by the terminal comprises at least one of the following:
[0283] a transmission direction, the transmission direction comprising an uplink transmission direction and / or a downlink transmission direction;
[0284] a third NAS count determined from a third NAS security context;
[0285] a second key of the first network element, the second key of the first network element being determined from the third NAS security context.
[0286] It should be explained that if the value of the transmission direction is 0x01, the third NAS count is the value of the NAS count corresponding to the downlink. If the value of the transmission direction is 0x00, the third NAS count is the value of the NAS count corresponding to the uplink. The third NAS count is identical to the fifth NAS count in the fourth NAS security context.
[0287] The third NAS count includes a third uplink NAS count and a third downlink NAS count.
[0288] For example, the input parameters of the horizontal derivation manner are the uplink transmission direction, the third uplink NAS count, and the second key of the first network element.
[0289] For example, the input parameters of the horizontal derivation manner are the downlink transmission direction, the third downlink NAS count, and the second key of the first network element.
[0290] In some embodiments, the encryption protection key and / or the integrity protection key in the first NAS security context are derived according to the first key K NF of the first network element.
[0291] It should also be noted that in the case where the terminal generates the first key K NF of the first network element in the first NAS security context using the horizontal derivation manner, the first NAS security context can be understood as being obtained after updating and activating the third NAS security context. Alternatively, updating and activating the third NAS security context to obtain the first NAS security context includes: updating the second key K NF’ of the first network element in the third NAS security context to obtain the first key K NF of the first network element in the first NAS security context; deriving the encryption protection key and the integrity protection key according to the first key K NF of the first network element; and updating the value of the third NAS count in the third NAS security context to 0 in the case where the SMC procedure is successfully executed.
[0292] In the case where the terminal generates the first key K NF of the first network element in the first NAS security context using the vertical derivation manner, the first NAS security context can be understood as being newly created.
[0293] In step S2106, the first network element 1021 creates or activates the second NAS security context for the terminal 101 in the case where the SMC procedure is successfully executed.
[0294] It should be noted that the number of terminals is one or more. In the case where the number of terminals is more than one, the first network element can create or activate one second NAS security context for each terminal, and different terminals correspond to different second NAS security contexts.
[0295] In some embodiments, the second NAS security context comprises at least one of:
[0296] an identifier of the terminal;
[0297] a NAS connection identifier;
[0298] a security algorithm;
[0299] a first key of the first network element;
[0300] a first NAS count comprising an uplink NAS count and / or a downlink NAS count;
[0301] a first identifier which is a common identifier of the second NAS security context and a NAS security context corresponding to the second network element;
[0302] a second identifier which is an identifier of the second NAS security context;
[0303] an encryption protection key;
[0304] an integrity protection key;
[0305] a status item, a value of the status item being a first value, the first value indicating a current state.
[0306] For example, the second NAS security context comprises the security algorithm, the first NAS count, the encryption protection key, the integrity protection key, and the status item.
[0307] For example, the second NAS security context comprises the NAS connection identifier, the security algorithm, the first key of the first network element, the first NAS count, the first identifier, the encryption protection key, the integrity protection key, and the status item.
[0308] For example, the second NAS security context comprises the NAS connection identifier, the security algorithm, the first key of the first network element, the first NAS count, the second identifier, the encryption protection key, the integrity protection key, and the status item.
[0309] In the second NAS security context, the identifier of the terminal can be obtained by the first network element from the first message or the second message. The first key of the first network element is obtained in step S2103. Moreover, in the case where the first key K NF of the first network element is obtained in step S2103, the K NF may be derived according to the first key K NF_INTand / or K NF_ENC .
[0310] The first identifier and the second identifier can be generated by the first network element or the second network element. For example, the second network element can provide the first identifier KSI and / or the second identifier KSI NF to the first network element in the case that the first network element receives the first message from the terminal. NF For example, the first network element can also generate the second identifier KSI NF . AMF / SEAF / AUSF The value of KSI NF may be determined according to KSI AMF / SEAF / AUSF . For example, the value of KSI AMF / SEAF / AUSF may be the same as or different from the value of KSI NF . For example, the first network element or the second network element can derive KSI NF from KSI AMF / SEAF / AUSF .
[0311] In some embodiments, the value of the first NAS count in the second NAS security context is set to 0 after the SMC procedure is successfully performed. It can be understood that the first network element sets the value of the first NAS count to 0 when creating or activating the second NAS security context for the terminal in the case that the SMC procedure is successfully performed.
[0312] It should also be noted that in the case that the first network element generates the first key K NF of the first network element in the second NAS security context using the horizontal derivation manner, the second NAS security context can be understood as being obtained by updating and activating the fourth NAS security context. Optionally, updating and activating the fourth NAS security context to obtain the second NAS security context comprises: updating and obtaining the first key K NF’ of the first network element in the fourth NAS security context according to the second key K NF of the first network element in the fourth NAS security context; deriving the encryption protection key and the integrity protection key according to the first key K NF of the first network element; and updating the value of the fifth NAS count in the fourth NAS security context to 0 in the case that the SMC procedure is successfully performed.
[0313] In the case that the first network element obtains the first key K NF of the first network element in the second NAS security context generated by the second network element using the vertical derivation manner, the second NAS security context can be understood as being re-created.
[0314] In step S2107, the first network element 1021 sends a third message protected by the second NAS security context to the terminal 101.
[0315] In some embodiments, the terminal receives a third message. Wherein the third message is protected by the first network element according to the encryption protection key and / or the integrity protection key in the second NAS security context, and the third message is a response to the first message.
[0316] Step S2108, the terminal 101 verifies the third message according to the first NAS security context to determine whether the NAS connection with the first network element 1021 is successfully established.
[0317] In some embodiments, the terminal verifies the third message according to the first NAS security context to determine whether the NAS connection with the first network element is successfully established.
[0318] In the case that the NAS connection between the terminal and the first network element is successfully established, steps S2109-S2112 are performed.
[0319] Step S2109, the terminal 101 increases the value of the uplink NAS count in the first NAS security context by 1 in the case that the terminal sends a fourth message to the first network element 1021.
[0320] In some embodiments, the first network element receives the fourth message. Wherein the fourth message includes the first SQN, and the first SQN is used by the first network element to update the uplink NAS count in the second NAS security context.
[0321] In some embodiments, the first network element updates the value of the uplink NAS count in the second NAS security context according to the SQN in the fourth message in the case that the fourth message sent by the terminal is received, for example, increases the value of the uplink NAS count in the second NAS security context by 1.
[0322] Step S2110, the first network element 1021 increases the value of the downlink NAS count in the second NAS security context by 1 in the case that the first network element sends a fifth message to the terminal 101.
[0323] In some embodiments, the terminal receives the fifth message. Wherein the fifth message includes the second SQN, and the second SQN is used by the terminal to update the downlink NAS count in the first NAS security context.
[0324] In some embodiments, the terminal updates the value of the downlink NAS count in the first NAS security context according to the second SQN in the fifth message in the case that the fifth message sent by the first network element is received, for example, increases the value of the downlink NAS count in the first NAS security context by 1.
[0325] Step S2111, the terminal 101 updates the value of the state item in the first NAS security context to a non-current state in the case where the NAS connection is released, obtaining a third NAS security context.
[0326] In some embodiments, in the case where the NAS connection is released, the terminal updates the value of the state item in the first NAS security context to a non-current state, and the state of the first NAS security context is updated to obtain a third NAS security context.
[0327] Step S2112, the first network element 1021 updates the value of the state item in the second NAS security context to a non-current state in the case where the NAS connection is released, obtaining a fourth NAS security context.
[0328] In some embodiments, in the case where the NAS connection is released, the first network element updates the value of the state item in the second NAS security context to a non-current state, obtaining a fourth NAS security context.
[0329] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "code point", "bit", "data", "program", "chip", and the like can be replaced with each other.
[0330] In some embodiments, terms such as "uplink", "uplink", "physical uplink", and the like can be replaced with each other, and terms such as "downlink", "downlink", "physical downlink", and the like can be replaced with each other.
[0331] In some embodiments, terms such as "radio", "wireless", "radio access network (RAN)", "access network (AN)", "RAN-based", and the like can be replaced with each other.
[0332] In some embodiments, "acquire", "obtain", "get", "receive", "transmit", "bidirectionally transmit", "send and / or receive" can be replaced by each other, which can be interpreted as receiving from other subjects, acquiring from protocols, acquiring from higher layers, obtaining by self-processing, autonomously implementing, and the like.
[0333] In some embodiments, the terms "send", "transmit", "report", "issue", "transmit", "bidirectionally transmit", "send and / or receive" can be replaced by each other.
[0334] In some embodiments, the terms "certain", "preset", "preset", "set", "indicated", "certain", "arbitrary", "first", and the like can be replaced by each other. "Certain A", "preset A", "preset A", "set A", "indicated A", "certain A", "arbitrary A", "first A" can be interpreted as A specified in advance in protocols and the like, A obtained by setting, configuration, or indication, and the like, A specific, certain, arbitrary, or first A, but not limited thereto.
[0335] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101-S2112. For example, step S2105 can be implemented as an independent embodiment, step S2106 can be implemented as an independent embodiment, step S2104 and step S2105 can be implemented as independent embodiments, step S2104 and step S2106 can be implemented as independent embodiments, step S2104, step S2105 and step S2106 can be implemented as independent embodiments, but not limited thereto.
[0336] In some embodiments, the order of any two steps in steps S2101-S2112 can be exchanged or executed simultaneously. For example, step S2105 and step S2106 can be exchanged or executed simultaneously.
[0337] In some embodiments, steps S2101-S2104, S2106-S2112 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0338] In some embodiments, steps S2101-S2105, S2107-S2112 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0339] In some embodiments, steps S2101-S2103, S2106-S2112 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0340] In some embodiments, steps S2101-S2103, S2105, S2107-S2112 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0341] In some embodiments, steps S2101-S2103, S2107-S2112 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0342] In some embodiments, other optional implementations described before or after the description of FIG. 2A can be referred to.
[0343] FIG. 2E is an interaction diagram of a communication method according to an embodiment of the present disclosure. In the embodiment of FIG. 2E, the state item is not included in the NAS security context. The relationship between similar terms in the embodiment of FIG. 2E is explained as follows: the NAS security context between the terminal and the first network element created by the terminal side is referred to as the first NAS security context. The NAS security context between the terminal and the first network element created by the first network element side is referred to as the second NAS security context. The first NAS security context and the second NAS security context correspond to each other. The first NAS security context and the second NAS security context correspond to each other means that for the NAS connection between the terminal and the first network element, the terminal side uses the first NAS security context to protect the NAS connection, and correspondingly the first network element side uses the second NAS security context to protect the NAS connection. The first NAS security context and the second NAS security context can have one or more same contents. For example, the first NAS security context and the second NAS security context have the same NAS connection identifier (the connection identifier includes 3GPP access and non-3GPP access). For example, the first NAS security context and the second NAS security context have the same security algorithm. For example, the first NAS security context and the second NAS security context have the same encryption protection key or integrity protection key, etc. It is worth noting that the NAS count in the first NAS security context and the second NAS security context can be asynchronous in a short time due to poor network state, etc.
[0344] In the embodiment of FIG. 2E, in the case of establishing the NAS connection between the terminal and the first network element, the NAS security context stored at the terminal side can refer to FIG. 2F and FIG. 2G, and the NAS security context stored at the first network element side can refer to FIG. 2H.
[0345] As shown in FIG. 2F, the NAS security context stored at the terminal side can include at least one of the NAS security context corresponding to the second network element (AMF / AUSF / SEAF), the first NAS security context, and a common identifier KSI of the NAS security context corresponding to the second network element and the first NAS security context. Wherein the NAS security context corresponding to the second network element includes at least one of the NAS connection identifier, the security algorithm, the key of the first network element, the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key. The first NAS security context includes at least one of the NAS connection identifier, the security algorithm, the key of the first network element, the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key.
[0346] As shown in FIG. 2G, the NAS security context stored at the terminal side can include at least one of the NAS security context corresponding to the second network element (AMF / AUSF / SEAF) and the first NAS security context. Wherein the NAS security context corresponding to the second network element includes at least one of the NAS connection identifier, the security algorithm, the key of the first network element, the context identifier (KSI AMF / SEAF / AUSF ), the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key. The first NAS security context includes at least one of the NAS connection identifier, the security algorithm, the key of the first network element, the context identifier (KSI NF ), the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key.
[0347] As shown in FIG. 2H, the NAS security context stored at the first network element side can include the second NAS security context. The second NAS security context includes at least one of the UE identifier, the NAS connection identifier, the security algorithm, the key of the first network element, the context identifier (KSI / KSI NF ), the uplink NAS count, the downlink NAS count, the integrity protection key, and the encryption protection key.
[0348] As shown in FIG. 2E, the embodiment of the present disclosure relates to a communication method, which is executed by the communication system 100, and the communication method of FIG. 2E includes the following steps:
[0349] Step S2201, the terminal 101 sends a first message to the second network element 1022.
[0350] In some embodiments, the second network element receives the first message. For example, the second network element receives the first message sent by the terminal.
[0351] In some embodiments, the first message is used by the terminal to request establishment of a NAS connection with the first network element. The first message can be transmitted to the first network element through the second network element.
[0352] In some embodiments, the name of the first message is not limited, which is, for example, initial NAS signaling, NAS connection request, etc.
[0353] In some embodiments, the first message can be protected according to the NAS security context corresponding to the second network element stored on the terminal; or the first message is not protected.
[0354] It should be explained that, before the NAS security context between the terminal and the first network element is created, i.e., before the communication method of the present disclosure is performed, the NAS security context between the terminal and the second network element has been created or activated by default. For example, the terminal can obtain the NAS security context corresponding to the second network element in the process of accessing the network. The NAS security context corresponding to the second network element stored on the terminal refers to the NAS security context between the terminal and the second network element that is currently available on the terminal. The NAS security context between the terminal and the second network element is used to protect the NAS connection communication between the terminal and the second network element.
[0355] For example, assuming that the first message is protected according to the NAS security context corresponding to the second network element stored on the terminal, the second network element can verify the first message according to the NAS security context between the terminal and the second network element stored on the second network element (i.e., the NAS security context corresponding to the terminal stored on the second network element) upon receiving the first message. Optionally, the first message can include an identifier for the second network element to determine the corresponding NAS security context, such as an identifier of the terminal, a first identifier, a second identifier, etc. If the second network element verifies the first message successfully, step S2202 is performed. If the second network element fails to verify the first message, step S2202 is not performed.
[0356] In step S2202, the second network element 1022 sends the first message or the second message to the first network element 1021.
[0357] In some embodiments, the first network element receives the first message or the second message sent by the second network element.
[0358] In some embodiments, the second message comprises the original first message or comprises the processed first message. For example, the second message comprises one or more fields in the first message. For example, the second message comprises content extracted from the first message.
[0359] In some embodiments, the first message can comprise an identifier of the first network element (e.g. an instance ID or a type of the first network element). In this way, the second network element facilitates sending the first message or the second message to the first network element.
[0360] In some embodiments, the second message comprises the first message and at least one of the first identifier, the second identifier, and the first key of the first network element. Optionally, the first identifier, the second identifier, and the first key of the first network element can all be generated by the second network element. Optionally, the first identifier and the second identifier can also be provided by the terminal in the first message. In this way, the first network element obtains at least one of the following from the second message sent by the second network element:
[0361] the first identifier;
[0362] the second identifier;
[0363] the first key of the first network element.
[0364] For example, the second message comprises the first key of the first network element.
[0365] For example, the second message comprises the first identifier and the first key of the first network element.
[0366] For example, the second message comprises the second identifier and the first key of the first network element.
[0367] The first identifier, the second identifier, and the first key of the first network element are used by the first network element to generate a NAS security context between the terminal and the first network element (i.e. the second NAS security context on the first network element side).
[0368] It should be explained that the first identifier (KSI) is used to identify the NAS security context between the terminal and the first network element (i.e. the first NAS security context on the terminal side / the second NAS security context on the first network element side) and the NAS security context corresponding to the second network element (i.e. the NAS security context corresponding to the second network element stored by the terminal / the NAS security context corresponding to the terminal stored by the second network element). The second identifier (KSI NF ) is used to identify the NAS security context between the terminal and the first network element (i.e. the first NAS security context on the terminal side / the second NAS security context on the first network element side).
[0369] It should be noted that the KSI can be a common identifier of the NAS security context of the terminal with the second network element and the NAS security context of the terminal with the first network element. In some embodiments, the KSI AMF / SEAF / AUSF and the value of the KSI NF may be the same or different, for example, the KSI NF may be derived from the KSI AMF / SEAF / AUSF , the KSI AMF / SEAF / AUSF may be mapped to the KSI NF , that is, the KSI NF = NF instance ID / NF type: KSI AMF / SEAF / AUSF .
[0370] In some embodiments, the second network element is a relay node between the terminal and the first network element, and the second network element only has the function of forwarding, so that the second network element sends the first message to the first network element in the case of receiving the first message sent by the terminal.
[0371] For example, the first message is not protected.
[0372] In some embodiments, steps S2201 and S2202 can be omitted. The terminal 101 can directly send the first message to the first network element 1021, and the first network element receives the first message sent by the terminal.
[0373] In some embodiments, the first message sent directly by the terminal to the first network element is not protected.
[0374] In some embodiments, if the first message is not protected, the first message can include a NAS context identifier with a value of 111. The NAS context identifier with a value of 111 indicates that there is no available NAS security context.
[0375] Step S2203, the first network element 1021 determines the first key of the first network element.
[0376] Among them, the first key of the first network element determined by the first network element is one of the contents in the second NAS security context generated by the first network element.
[0377] In some embodiments, the first network element requests the first key K NF of the first network element from the second network element. The first network element receives at least one of the first key of the first network element, the first identifier, and the second identifier returned by the second network element.
[0378] In some embodiments, the first network element obtains at least one of the first key of the first network element, the first identifier, and the second identifier from the second message sent by the second network element.
[0379] In some embodiments, the first key of the first network element is generated by the second network element through a vertical derivation manner. Optionally, the input parameters of the vertical derivation manner include at least one of the following:
[0380] an identifier of the terminal (such as IMSI or NAI or GCI or GLI or GPSI or SUPI or SUCI);
[0381] an ABBA parameter;
[0382] an identifier of the first network element (such as instance ID);
[0383] a key (such as K AUSF / K SEAF / K AMF ) of the second network element;
[0384] a fourth NAS count stored in the NAS security context corresponding to the terminal on the second network element;
[0385] a first random number provided by the terminal;
[0386] a second random number provided by the first network element.
[0387] For example, the input parameters of the vertical derivation manner include the identifier of the terminal, the ABBA parameter, the identifier of the first network element, the key of the second network element, the fourth NAS count.
[0388] For example, the input parameters of the vertical derivation manner include the identifier of the terminal, the ABBA parameter, the identifier of the first network element, the key of the second network element, the first random number provided by the terminal, and the second random number provided by the first network element.
[0389] In some embodiments, the first random number provided by the terminal can be included in the first message.
[0390] In some embodiments, the random number provided by the first network element can be included in the request message in which the first network element requests the first key of the first network element from the second network element, or the first network element actively or passively sends the first random number (from the first message) and the second random number to the second network element.
[0391] In some embodiments, if the terminal sends the first message to the second network element, the first random number provided by the terminal can be included in the first message, and the second network element obtains the first random number from the first message. Of course, the terminal can also send the first random number to the second network element through other messages in addition to the first message, which is not limited in the present disclosure.
[0392] In some embodiments, if the terminal sends the first message to the first network element, the first message can include a first random number provided by the terminal, and the first network element can carry the first random number obtained from the first message and / or a second random number generated by the first network element in a key request message sent by the first network element to the second network element to send to the second network element. Of course, the first network element can also send the first random number and / or the second random number to the second network element through other messages, which is not limited by the present disclosure.
[0393] After the second network element obtains the first random number and the second random number, the first key of the first network element can be generated.
[0394] That is, the second network element can actively (i.e., by sending the second message) or passively (i.e., according to the request of the first network element) send at least one of the first key of the first network element, the first identifier, and the second identifier to the first network element.
[0395] In some embodiments, step S2204 is performed when the first network element obtains the first key K NF of the first network element.
[0396] Step S2204: The first network element 1021 triggers an SMC procedure.
[0397] In some embodiments, the first network element triggers the SMC procedure in response to the NAS connection request (the first message) of the terminal. For example, if the first message received by the first network element is unprotected, the first network element determines to initiate SMC to establish NAS security with the UE. For example, if the first message received by the first network element is protected by the terminal, the first network element can also initiate SMC to activate NAS security.
[0398] In some embodiments, when the first network element obtains the first key K NF of the first network element, the first key K NF of the first network element can be used to derive K NF_INT and / or K NF_ENC to protect the SMC message. Wherein K NF_INT is the key for integrity protection, derived from K NF . And K NF_ENC is the encryption protection key derived from K NF .
[0399] In some embodiments, the first network element can send a random number generated by the first network element to the terminal through the SMC procedure, so that the terminal uses it to generate the first key of the first network element.
[0400] Step S2205: The terminal 101 creates a first NAS security context for the first network element 1021 when the SMC procedure is successfully performed.
[0401] It should be noted that the number of the first network elements is one or more. If the number of the first network elements is more than one, the terminal can create or activate one first NAS security context for each of the first network elements in the case that the SMC procedure is successfully performed. Different first network elements correspond to different first NAS security contexts.
[0402] In some embodiments, the first NAS security context created by the terminal for the first network element corresponds to a second NAS security context created by the first network element for the terminal. The first NAS security context is stored in the terminal, and the second NAS security context is stored in the first network element.
[0403] In some embodiments, the first NAS security context includes at least one of the following:
[0404] a NAS connection identifier;
[0405] a security algorithm;
[0406] a first key K NF of the first network element;
[0407] a first NAS count including an uplink NAS count and / or a downlink NAS count;
[0408] a first identifier being a common identifier of the first NAS security context and a NAS security context corresponding to the second network element;
[0409] a second identifier being an identifier of the first NAS security context;
[0410] an encryption protection key;
[0411] an integrity protection key.
[0412] For example, the first NAS security context includes the security algorithm, the first NAS count, the encryption protection key, the integrity protection key, and the state item.
[0413] For example, the first NAS security context includes the NAS connection identifier, the security algorithm, the first key of the first network element, the first NAS count, the first identifier, the encryption protection key, the integrity protection key, and the state item.
[0414] For example, the first NAS security context includes the NAS connection identifier, the security algorithm, the first key of the first network element, the first NAS count, the second identifier, the encryption protection key, the integrity protection key, and the state item.
[0415] In some embodiments, the value of the first NAS COUNT in the first NAS security context is set to 0 after the SMC procedure is successfully performed. It can be understood that the terminal sets the value of the first NAS COUNT to 0 when creating the first NAS security context for the first network element 1021 in the case that the SMC procedure is successfully performed.
[0416] In some embodiments, the first key of the first network element in the first NAS security context is generated by the terminal according to a vertical derivation manner.
[0417] Optionally, the input parameters of the vertical derivation manner used by the terminal include at least one of the following:
[0418] an identifier of the terminal;
[0419] an ABBA parameter;
[0420] an identifier of the first network element;
[0421] a key of the second network element;
[0422] a second NAS COUNT stored in a NAS security context corresponding to the second network element in the terminal;
[0423] a first random number provided by the terminal;
[0424] a second random number provided by the first network element.
[0425] For example, the input parameters of the vertical derivation manner include the identifier of the terminal, the ABBA parameter, the identifier of the first network element, the key of the second network element, and the second NAS COUNT.
[0426] For example, the input parameters of the vertical derivation manner include the identifier of the terminal, the ABBA parameter, the identifier of the first network element, the key of the second network element, the first random number provided by the terminal, and the second random number provided by the first network element.
[0427] The NAS security context corresponding to the terminal stored on the second network element and the NAS security context corresponding to the second network element stored in the terminal correspond to each other, i.e., the fourth NAS COUNT is equal to the second NAS COUNT.
[0428] For example, the input parameters of the vertical derivation manner include the identifier of the terminal, the ABBA parameter, the identifier of the first network element, the key of the second network element, and the fourth NAS COUNT.
[0429] For example, the input parameters of the vertical derivation manner include the identifier of the terminal, the ABBA parameter, the identifier of the first network element, the key of the second network element, the first random number provided by the terminal, and the second random number provided by the first network element.
[0430] In some embodiments, the second random number provided by the first network element can be included in the SMC message for transmission to the terminal.
[0431] In some embodiments, the key of the second network element in the input parameter of the vertical derivation manner can be obtained by determining the security context corresponding to the second network element according to the first identifier or the second identifier obtained in the SMC process (sent by the first network element or the second network element to the terminal), and determining the key of the second network element from the security context corresponding to the second network element.
[0432] In some embodiments, the key of the second network element in the input parameter of the vertical derivation manner can be determined by the terminal according to the currently used NAS security context between the terminal and the second network element, i.e., the terminal determines the currently used NAS security context between the terminal and the second network element, and provides the first identifier or the second identifier of the NAS security context in the first message, and the second network element retrieves the corresponding security context according to the first identifier or the second identifier, so as to determine the key of the second network element.
[0433] In some embodiments, the encryption protection key and / or the integrity protection key in the first NAS security context are derived according to the first key K NF derivation.
[0434] Step S2206, the first network element 1021 creates a second NAS security context for the terminal 101 in the case that the SMC process is successfully executed and completed.
[0435] It should be noted that the number of terminals is one or more. In the case that the number of terminals is more than one, the first network element can create or activate one second NAS security context for each terminal, and different terminals correspond to different second NAS security contexts.
[0436] In some embodiments, the second NAS security context includes at least one of the following:
[0437] the identifier of the terminal;
[0438] the NAS connection identifier;
[0439] the security algorithm;
[0440] the first key of the first network element;
[0441] the first NAS count, including the uplink NAS count and / or the downlink NAS count;
[0442] the first identifier, which is a common identifier of the second NAS security context and the NAS security context corresponding to the second network element;
[0443] a second identifier, which is an identifier of the second NAS security context;
[0444] an encryption protection key;
[0445] an integrity protection key.
[0446] The second NAS security context may include, for example, a security algorithm, a first NAS count, an encryption protection key, an integrity protection key, and a state item.
[0447] The second NAS security context may include, for example, a NAS connection identifier, a security algorithm, a first key of the first network element, a first NAS count, a first identifier, an encryption protection key, an integrity protection key, and a state item.
[0448] The second NAS security context may include, for example, a NAS connection identifier, a security algorithm, a first key of the first network element, a first NAS count, a second identifier, an encryption protection key, an integrity protection key, and a state item.
[0449] The identifier of the terminal in the second NAS security context may be obtained by the first network element from the first message or the second message. The first key of the first network element is obtained in step S2203. In the case where the first network element obtains the first key K NF of the first network element, K NF may be derived according to the first key K NF_INT of the first network element and / or K NF_ENC The first identifier and the second identifier may be generated by the first network element or the second network element.
[0450] In some embodiments, the value of the first NAS count in the second NAS security context is set to 0 after the SMC procedure is successfully performed. It can be understood that, in the case where the SMC procedure is successfully performed, the first network element sets the value of the first NAS count to 0 when creating the second NAS security context for the terminal.
[0451] In step S2207, the first network element 1021 sends a third message protected by the second NAS security context to the terminal 101.
[0452] In some embodiments, the terminal receives the third message. The third message is protected by the first network element according to the encryption protection key and / or the integrity protection key in the second NAS security context, and the third message is a response to the first message.
[0453] In step S2208, the terminal 101 verifies the third message according to the first NAS security context to determine whether the NAS connection with the first network element 1021 is successfully established.
[0454] In some embodiments, the terminal verifies the third message according to the first NAS security context to determine whether the NAS connection with the first network element is successfully established.
[0455] In case that the NAS connection between the terminal and the first network element is successfully established, steps S2209-S2212 are performed.
[0456] In step S2209, the terminal 101 increases the value of the uplink NAS count in the first NAS security context by 1 in case that the fourth message is sent to the first network element 1021.
[0457] In some embodiments, the first network element receives the fourth message. The fourth message includes the first SQN, which is used by the first network element to update the uplink NAS count in the second NAS security context.
[0458] In some embodiments, the first network element updates the value of the uplink NAS count in the second NAS security context according to the SQN in the fourth message in case that the fourth message sent by the terminal is received, e.g., increases the value of the uplink NAS count in the second NAS security context by 1.
[0459] In step S2210, the first network element 1021 increases the value of the downlink NAS count in the second NAS security context by 1 in case that the fifth message is sent to the terminal 101.
[0460] In some embodiments, the terminal receives the fifth message. The fifth message includes the second SQN, which is used by the terminal to update the downlink NAS count in the first NAS security context.
[0461] In some embodiments, the terminal updates the value of the downlink NAS count in the first NAS security context according to the second SQN in the fifth message in case that the fifth message sent by the first network element is received, e.g., increases the value of the downlink NAS count in the first NAS security context by 1.
[0462] In step S2211, the terminal 101 deletes the first NAS security context in case that the NAS connection is released.
[0463] In some embodiments, the terminal removes the first NAS security context in case that the NAS connection is released.
[0464] In step S2212, the first network element 1021 deletes the second NAS security context in case that the NAS connection is released.
[0465] In some embodiments, the first network element deletes the second NAS security context in case that the NAS connection is released.
[0466] In some embodiments, the names of information and the like are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", "chip", and the like can be replaced with each other.
[0467] In some embodiments, terms such as "uplink", "uplink", "physical uplink", and the like can be replaced with each other, and terms such as "downlink", "downlink", "physical downlink" and the like can be replaced with each other.
[0468] In some embodiments, terms such as "radio", "wireless", "radio access network (RAN)", "access network (AN)", "RAN-based" and the like can be replaced with each other.
[0469] In some embodiments, "acquire", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other, which can be interpreted as receiving from other subjects, obtaining from protocols, obtaining from higher layers, processing to obtain, and various meanings such as autonomous implementation.
[0470] In some embodiments, terms such as "send", "transmit", "report", "issue", "transmit", "bidirectional transmission", "send and / or receive" can be replaced with each other.
[0471] In some embodiments, the terms "certain", "preset", "pre-set", "set", "indicated", "a certain", "any", "first", and the like can be replaced with each other, "certain A", "preset A", "pre-set A", "set A", "indicated A", "a certain A", "any A", "first A" can be interpreted as A predetermined in a protocol or the like, can be interpreted as A obtained by setting, configuration, or indication, or the like, can be interpreted as certain A, a certain A, any A, or first A, and the like, but are not limited thereto.
[0472] The communication method related to the embodiments of the present disclosure can include at least one of steps S2201-S2212. For example, step S2205 can be implemented as an independent embodiment, step S2206 can be implemented as an independent embodiment, step S2204 and step S2505 can be implemented as independent embodiments, step S2204 and step S2506 can be implemented as independent embodiments, step S2204, step S2205, and step S2206 can be implemented as independent embodiments, but are not limited thereto.
[0473] In some embodiments, the order of any two steps among steps S2201-S2212 can be exchanged or executed simultaneously. For example, step S2205 and step S2206 can be exchanged or executed simultaneously.
[0474] In some embodiments, steps S2201-S2204, S2206-S2212 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0475] In some embodiments, steps S2201-S2205, S2207-S2212 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0476] In some embodiments, steps S2201-S2203, S2206-S2212 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0477] In some embodiments, steps S2201-S2203, S2205, S2207-S2212 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0478] In some embodiments, steps S2201-S2203 and steps S2207-S2212 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0479] In some embodiments, other optional implementations can be found in the description before or after the description of FIG. 2E.
[0480] FIG. 3A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiment of the present disclosure relates to a communication method, which is performed by a terminal side, and the above method comprises:
[0481] Step S3101: sending a first message.
[0482] Optional implementations of step S3101 can be found in the optional implementations of step S2101 of FIG. 2A, step S2201 of FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which will not be described here.
[0483] In some embodiments, the terminal 101 sends the first message to the first network element 1021, but is not limited thereto, and the terminal can also send the first message to other subjects.
[0484] Step S3102: creating or activating a first NAS security context for the first network element in the case that the SMC procedure is successfully performed.
[0485] Optional implementations of step S3102 can be found in the optional implementations of step S2105 of FIG. 2A, step S2205 of FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which will not be described here.
[0486] Step S3103: receiving a third message.
[0487] Optional implementations of step S3103 can be found in the optional implementations of step S2107 of FIG. 2A, step S2207 of FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which will not be described here.
[0488] In some embodiments, the terminal 101 receives the third message sent by the first network element 1021, but is not limited thereto, and can also receive the third message sent by other subjects.
[0489] In some embodiments, the terminal 101 obtains the third message specified by a protocol.
[0490] In some embodiments, the terminal 101 obtains the third message from an upper layer.
[0491] In some embodiments, the terminal 101 processes to obtain the third message.
[0492] In some embodiments, the step S3103 is omitted, and the terminal 101 autonomously implements the function indicated by the third message, or the function is default or default.
[0493] In step S3104, the third message is verified according to the first NAS security context to determine whether the NAS connection with the first network element is successfully established.
[0494] The optional implementation of step S3104 can refer to the optional implementation of step S2108 in FIG. 2A, the optional implementation of step S2208 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0495] In step S3105, the value of the uplink NAS count in the first NAS security context is increased by 1 in the case of sending the fourth message to the first network element.
[0496] The optional implementation of step S3105 can refer to the optional implementation of step S2109 in FIG. 2A, the optional implementation of step S2209 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0497] In step S3106, the downlink NAS count in the first NAS security context is updated according to the SQN in the fifth message in the case of receiving the fifth message sent by the first network element.
[0498] The optional implementation of step S3106 can refer to the optional implementation of step S2110 in FIG. 2A, the optional implementation of step S2210 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0499] In step S3107, the value of the state item in the first NAS security context is updated to a non-current state in the case of releasing the NAS connection.
[0500] The optional implementation of step S3107 can refer to the optional implementation of step S2111 in FIG. 2A and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.
[0501] Alternatively, step S3107 can be replaced by deleting the first NAS security context in the case of releasing the NAS connection. The optional implementation of the replaced step S3107 can refer to the optional implementation of step S2211 in FIG. 2B and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.
[0502] The communication method related to the embodiments of the present disclosure can include at least one of steps S3101-S3107. For example, step S3102 can be implemented as an independent embodiment, steps S3101 and S3102 can be implemented as independent embodiments, steps S3102 and S3107 can be implemented as independent embodiments, but are not limited thereto.
[0503] In some embodiments, the order between any two of steps S3101-S3107 can be exchanged or executed simultaneously.
[0504] In some embodiments, steps S3101, S3103-S3107 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0505] In some embodiments, steps S3103-S3107 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0506] In some embodiments, steps S3101, S3103-S3106 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0507] FIG. 3B is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to a communication method, which is performed by a terminal side, and the above method includes:
[0508] Step S3201, sending a first message.
[0509] Optional implementation of step S3201 can refer to optional implementation of step S2101 in FIG. 2A, step S2201 in FIG. 2E, step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 3A, which will not be repeated here.
[0510] Step S3202, creating or activating a first NAS security context for the first network element in the case that the SMC procedure is successfully executed.
[0511] Optional implementation of step S3202 can refer to step S2105 in FIG. 2A, step S2205 in FIG. 2E, optional implementation of step S3102 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 3A, which will not be repeated here.
[0512] Step S3203, updating the value of the state item in the first NAS security context to a non-current state in the case that the NAS connection is released.
[0513] The optional implementation of step S3203 can refer to the optional implementation of step S2111 in FIG. 2A, step S3107 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A and FIG. 3A, which are not described herein again.
[0514] The communication method related to the embodiments of the present disclosure can include at least one of steps S3201-S3203. For example, step S3202 can be implemented as an independent embodiment, steps S3201 and S3202 can be implemented as independent embodiments, and steps S3202 and S3203 can be implemented as independent embodiments, but are not limited thereto.
[0515] In some embodiments, the order between any two of steps S3201-S3203 can be exchanged or executed simultaneously.
[0516] In some embodiments, steps S3201 and S3203 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0517] In some embodiments, step S3203 is optional, and this step can be omitted or replaced in different embodiments.
[0518] In some embodiments, step S3201 is optional, and this step can be omitted or replaced in different embodiments.
[0519] In the embodiments of the present disclosure, step S3202 can be combined with one or more of steps S3103-S3106 in FIG. 3A.
[0520] FIG. 3C is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3C, the embodiments of the present disclosure relate to a communication method, which is performed by a terminal side, and the above method includes:
[0521] Step S3301, sending a first message.
[0522] The optional implementation of step S3301 can refer to the optional implementation of step S2101 in FIG. 2A, step S2201 in FIG. 2E, and step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 3A, which are not described herein again.
[0523] Step S3302, creating or activating a first NAS security context for the first network element in a case that the SMC procedure is successfully executed.
[0524] The optional implementation of step S3302 can refer to step S2105 in FIG. 2A, step S2205 in FIG. 2E, the optional implementation of step S3102 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 3A, which are not described here again.
[0525] Step S3303, in the case that the NAS connection is released, deleting the first NAS security context.
[0526] The optional implementation of step S3303 can refer to step S2211 in FIG. 2B, the optional implementation of step S3107 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2B and FIG. 3A, which are not described here again.
[0527] The communication method related to the embodiments of the present disclosure can include at least one of steps S3301 to S3303. For example, step S3302 can be implemented as an independent embodiment, steps S3301 and S3302 can be implemented as independent embodiments, and steps S3302 and S3303 can be implemented as independent embodiments, but are not limited thereto.
[0528] In some embodiments, the order between any two of steps S3301 to S3303 can be exchanged or executed simultaneously.
[0529] In some embodiments, steps S3301 and S3303 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0530] In some embodiments, step S3303 is optional, and this step can be omitted or replaced in different embodiments.
[0531] In some embodiments, step S3301 is optional, and this step can be omitted or replaced in different embodiments.
[0532] In the embodiments of the present disclosure, step S3302 can be combined with one or more of steps S3103 to S3106 in FIG. 3A.
[0533] FIG. 3D is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 3D, the embodiments of the present disclosure relate to a communication method, which is executed by a terminal side, and the above method includes:
[0534] Step S3401, sending a first message.
[0535] The optional implementation of step S3401 can refer to the optional implementation of step S2101 in FIG. 2A, step S2201 in FIG. 2E, step S3101 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 3A, which are not described here again.
[0536] Step S3402, creating or activating the first NAS security context for the first network element in the case of successful execution of the SMC procedure.
[0537] The optional implementation of step S3402 can refer to step S2105 in FIG. 2A, step S2205 in FIG. 2E, the optional implementation of step S3102 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 3A, which are not described here again.
[0538] The communication method related to the embodiments of the present disclosure can include at least one of step S3401 and step S3402. For example, step S3401 can be implemented as an independent embodiment, and step S3402 can be implemented as an independent embodiment, but is not limited thereto.
[0539] In some embodiments, step S3401 and step S3402 can be exchanged in order or executed simultaneously.
[0540] In some embodiments, step S3401 is optional, and this step can be omitted or replaced in different embodiments.
[0541] In the embodiments of the present disclosure, step S3402 can be combined with one or more of steps S3103 to S3107 in FIG. 3A.
[0542] FIG. 4A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4A, the embodiments of the present disclosure relate to a communication method, which is executed by a first network element side, and the above method includes:
[0543] Step S4101, receiving a first message.
[0544] The optional implementation of step S4101 can refer to step S2101, step S2102 in FIG. 2A, the optional implementation of step S2201, step S2202 in FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which are not described here again.
[0545] In some embodiments, the first network element 1021 receives the first message sent by the terminal 101, but is not limited thereto, and the first network element can also receive the first message forwarded by other subjects or the first message or the second message sent by other subjects.
[0546] In some embodiments, the first network element 1021 acquires the first message as specified by a protocol.
[0547] In some embodiments, the first network element 1021 acquires the first message from upper layer(s).
[0548] In some embodiments, the first network element 1021 processes to obtain the first message.
[0549] In some embodiments, step S4101 is omitted, and the first network element 1021 autonomously implements the function indicated by the first message, or the above function is default or default.
[0550] Step S4102, determining the first key of the first network element.
[0551] The optional implementation of step S4102 can refer to the optional implementation of step S2103 in FIG. 2A, step S2203 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0552] Step S4103, triggering the SMC procedure, and creating or activating the second NAS security context for the terminal in the case that the SMC procedure is successfully executed.
[0553] The optional implementation of step S4103 can refer to the optional implementation of step S2104, step S2106 in FIG. 2A, step S2204, step S2206 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0554] Step S4104, sending the third message.
[0555] The optional implementation of step S4104 can refer to the optional implementation of step S2107 in FIG. 2A, step S2207 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0556] In some embodiments, the first network element 1021 sends the third message to the terminal 101, but is not limited thereto, and can also send the third message to other subjects.
[0557] Step S4105, in the case that the fourth message sent by the terminal is received, updating the uplink NAS count in the second NAS security context according to the SQN in the fourth message.
[0558] The optional implementation of step S4105 can refer to the optional implementation of step S2109 in FIG. 2A, step S2209 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0559] In step S4106, in the case that the fifth message is sent to the terminal, the value of the downlink NAS count in the second NAS security context is increased by 1.
[0560] The optional implementation of step S4106 can refer to the optional implementation of step S2110 in FIG. 2A, the optional implementation of step S2210 in FIG. 2E, and other associated parts in the embodiments involved in FIG. 2A and FIG. 2E, which will not be repeated here.
[0561] In step S4107, in the case that the NAS connection is released, the value of the state item in the second NAS security context is updated to the non-current state.
[0562] The optional implementation of step S4107 can refer to the optional implementation of step S2112 in FIG. 2A, and other associated parts in the embodiments involved in FIG. 2A, which will not be repeated here.
[0563] Optionally, step S4107 can be replaced by deleting the second NAS security context in the case that the NAS connection is released. The optional implementation of the replaced step S4107 can refer to the optional implementation of step S2212 in FIG. 2B, and other associated parts in the embodiments involved in FIG. 2B, which will not be repeated here.
[0564] The communication method involved in the embodiments of the present disclosure can include at least one of steps S4101 to S4107. For example, step S4103 can be implemented as an independent embodiment, steps S4101 and S4103 can be implemented as independent embodiments, and steps S4103 and S4107 can be implemented as independent embodiments, but are not limited thereto.
[0565] In some embodiments, the order between any two of steps S4101 to S4107 can be exchanged or executed simultaneously.
[0566] In some embodiments, steps S4101, S4102, S4104 to S4107 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0567] In some embodiments, steps S4102, S4104 to S4107 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0568] In some embodiments, steps S4101, S4102, S4104 to S4106 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0569] FIG. 4B is a flow diagram illustrating a communication method according to some embodiments of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure relate to a communication method, which is performed by a first network element side, and the above method comprises the following steps:
[0570] In step S4201, a first message is received.
[0571] The optional implementation of step S4201 can refer to the optional implementation of step S2101, step S2102 of FIG. 2A, step S2201, step S2202 of FIG. 2E, step S4101 of FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E and FIG. 4A, which are not described here.
[0572] In step S4202, an SMC procedure is triggered, and a second NAS security context is created or activated for the terminal in the case that the SMC procedure is successfully executed.
[0573] The optional implementation of step S4202 can refer to step S2104, step S2106 of FIG. 2A, step S2204, step S2206 of FIG. 2E, the optional implementation of step S4103 of FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E and FIG. 4A, which are not described here.
[0574] In step S4203, the value of the state item in the second NAS security context is updated to a non-current state in the case that the NAS connection is released.
[0575] The optional implementation of step S4203 can refer to step S2112 of FIG. 2A, the optional implementation of step S4107 of FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, which are not described here.
[0576] The communication method related to the embodiments of the present disclosure can comprise at least one of steps S4201-S4203. For example, step S4202 can be implemented as an independent embodiment, steps S4201 and S4202 can be implemented as independent embodiments, steps S4202 and S4203 can be implemented as independent embodiments, but are not limited thereto.
[0577] In some embodiments, the order between any two of steps S4201-S4203 can be exchanged or executed simultaneously.
[0578] In some embodiments, steps S4201 and S4203 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0579] In some embodiments, step S4203 is optional, which can be omitted or replaced in different embodiments.
[0580] In some embodiments, step S4201 is optional, which can be omitted or replaced in different embodiments.
[0581] In the embodiments of the present disclosure, step S4202 can be combined with one or more of steps S4104-S4106 in FIG. 4A.
[0582] FIG. 4C is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4C, the embodiments of the present disclosure relate to a communication method, which is performed by a first network element side, and the above method comprises the following steps:
[0583] In step S4301, a first message is received.
[0584] The optional implementation of step S4301 can refer to the optional implementation of step S2101, step S2102 in FIG. 2A, step S2201, step S2202 in FIG. 2E, step S4101 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E and FIG. 4A, which are not described here again.
[0585] In step S4302, an SMC procedure is triggered, and a second NAS security context is created or activated for the terminal in the case that the SMC procedure is successfully executed.
[0586] The optional implementation of step S4302 can refer to step S2104, step S2106 in FIG. 2A, step S2204, step S2206 in FIG. 2E, the optional implementation of step S4103 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E and FIG. 4A, which are not described here again.
[0587] In step S4303, the second NAS security context is deleted in the case that the NAS connection is released.
[0588] The optional implementation of step S4303 can refer to step S2212 in FIG. 2B, the optional implementation of step S4107 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2B, which are not described here again.
[0589] The communication method related to the embodiments of the present disclosure can comprise at least one of steps S4301-S4303. For example, step S4302 can be implemented as an independent embodiment, steps S4301 and S4302 can be implemented as independent embodiments, steps S4302 and S4303 can be implemented as independent embodiments, but are not limited thereto.
[0590] In some embodiments, the order between any two of steps S4301-S4303 can be exchanged or performed simultaneously.
[0591] In some embodiments, steps S4301 and S4303 are optional, and one or more of the steps can be omitted or replaced in different embodiments.
[0592] In some embodiments, step S4303 is optional, and the step can be omitted or replaced in different embodiments.
[0593] In some embodiments, step S4301 is optional, and the step can be omitted or replaced in different embodiments.
[0594] In the embodiments of the present disclosure, step S4302 can be combined with one or more of steps S4104-S4106 of FIG. 4A.
[0595] FIG. 4D is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4D, the embodiments of the present disclosure relate to a communication method, which is performed by a first network element side, and the above method comprises the following steps:
[0596] In step S4401, a first message is received.
[0597] The optional implementation of step S4401 can refer to the optional implementation of step S2101, step S2102 of FIG. 2A, step S2201, step S2202 of FIG. 2E, the optional implementation of step S4101 of FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 4A, which will not be described here.
[0598] In step S4402, an SMC procedure is triggered, and a second NAS security context is created or activated for the terminal in the case that the SMC procedure is successfully executed.
[0599] The optional implementation of step S4402 can refer to the optional implementation of step S2104, step S2106 of FIG. 2A, step S2204, step S2206 of FIG. 2E, the optional implementation of step S4103 of FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 4A, which will not be described here.
[0600] The communication method related to the embodiments of the present disclosure can comprise at least one of step S4401 and step S4402. For example, step S4401 can be implemented as an independent embodiment, and step S4402 can be implemented as an independent embodiment, but is not limited thereto.
[0601] In some embodiments, step S4401 and step S4402 can be exchanged in order or performed simultaneously.
[0602] In some embodiments, step S4401 is optional, which can be omitted or replaced in different embodiments.
[0603] In the embodiments of the present disclosure, step S4402 can be combined with one or more of steps S4102, S4104-S4107 of FIG. 4A.
[0604] FIG. 5A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 5A, the embodiments of the present disclosure relate to a communication method, which is performed by a second network element side, and the above method comprises the following steps:
[0605] Step S5101: receiving a first message.
[0606] The optional implementation of step S5101 can refer to the optional implementation of step S2101 of FIG. 2A, step S2201 of FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which are not described herein again.
[0607] In some embodiments, the second network element 1022 receives the first message sent by the terminal 101, but is not limited thereto, and the second network element can also receive the first message sent by other subjects.
[0608] In some embodiments, the second network element 1022 obtains the first message specified by a protocol.
[0609] In some embodiments, the second network element 1022 obtains the first message from an upper layer.
[0610] In some embodiments, the second network element 1022 processes to obtain the first message.
[0611] In some embodiments, step S501 is omitted, and the second network element 1022 autonomously implements the function indicated by the first message, or the above function is default or default.
[0612] Step S5102: sending a second message or a second message.
[0613] The optional implementation of step S5102 can refer to the optional implementation of step S2102 of FIG. 2A, step S2202 of FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which are not described herein again.
[0614] In some embodiments, the second network element 1022 sends the second message to the first network element, but is not limited thereto, and can also send the second message to other subjects.
[0615] Step S5103, receiving a request to generate the first key of the first network element.
[0616] The optional implementation of step S5103 can refer to the optional implementation of step S2103 in FIG. 2A, step S2203 in FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which are not described here again.
[0617] Step S5104, sending the first key of the first network element.
[0618] The optional implementation of step S5104 can refer to the optional implementation of step S2103 in FIG. 2A, step S2203 in FIG. 2E, and other associated parts in the embodiments related to FIG. 2A and FIG. 2E, which are not described here again.
[0619] The communication method related to the embodiments of the present disclosure can include at least one of steps S5101-S5104. For example, step S5101 can be implemented as an independent embodiment, steps S5101 and S5102 can be implemented as independent embodiments, steps S5103 and S5104 can be implemented as independent embodiments, but are not limited to this.
[0620] In some embodiments, the order between any two steps of steps S5101-S5104 can be exchanged or executed simultaneously.
[0621] In some embodiments, steps S5102-S5104 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0622] In some embodiments, steps S5103 and S5104 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0623] In some embodiments, steps S5101 and S5102 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0624] FIG. 5B is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5B, the embodiments of the present disclosure relate to a communication method, which is executed by the second network element side, and the above method includes:
[0625] Step S5201, receiving a first message.
[0626] The optional implementations of step S5201 can be found in the optional implementations of step S2101 in Figure 2A, step S2201 in Figure 2E, and step S5101 in Figure 5A, as well as other related parts in the embodiments involved in Figures 2A, 2E, and 5A, which will not be repeated here.
[0627] Step S5202: Send a second message or a second message.
[0628] Optional implementations of step S5202 can be found in step S2102 of Figure 2A, step S2202 of Figure 2E, optional implementations of step S5102 of Figure 5A, and other related parts in the embodiments involved in Figures 2A, 2E, and 5A, which will not be repeated here.
[0629] The communication method involved in the embodiments of this disclosure may include at least one of steps S5201 and S5202. For example, step S5201 may be implemented as a separate embodiment, and step S5202 may be implemented as a separate embodiment, but are not limited thereto.
[0630] In some embodiments, step S5201 is optional and may be omitted or replaced in different embodiments.
[0631] In some embodiments, step S5202 is optional and may be omitted or replaced in different embodiments.
[0632] Figure 6A is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 6A, the embodiment of the present disclosure relates to a communication method executed by a communication system 100, the method including:
[0633] Step S6101: Terminal 101 sends the first message.
[0634] The optional implementations of step S6101 can be found in step S2101 of Figure 2A, step S2201 of Figure 2E, the optional implementations of step S3101 of Figure 3A, and other related parts in the embodiments involved in Figures 2A, 2E, and 3A, which will not be repeated here.
[0635] In step S6102, the first network element 1021 receives the first message and triggers the execution of the Security Mode Command (SMC) process.
[0636] The optional implementation of step S6102 can be found in steps S2101, S2102, and S2103 in Figure 2A, steps S2201, S2202, and S2203 in Figure 2E, the optional implementation of step S4101 in Figure 4A, and other related parts in the embodiments involved in Figures 2A, 2E, and 4A, which will not be repeated here.
[0637] Step S6103, the terminal 101 creates or activates the first NAS security context for the first network element in the case that the SMC procedure is successfully performed.
[0638] The optional implementation of step S6103 can be referred to the optional implementation of step S2105 in FIG. 2A, step S2205 in FIG. 2E, step S3102 in FIG. 3A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 3A, which are not described herein again.
[0639] Step S6104, the first network element 1021 creates or activates the second NAS security context for the terminal in the case that the SMC procedure is successfully performed, wherein the second NAS security context corresponds to the first NAS security context.
[0640] The optional implementation of step S6104 can be referred to step S2104, step S2106 in FIG. 2A, step S2204, step S2206 in FIG. 2E, the optional implementation of step S4103 in FIG. 4A, and other associated parts in the embodiments related to FIG. 2A, FIG. 2E, and FIG. 4A, which are not described herein again.
[0641] The communication method related to the embodiments of the present disclosure can include at least one of step S6101 to step S6104. For example, step S6103 can be implemented as an independent embodiment, step S6101 and step S6103 can be implemented as independent embodiments, step S6104 can be implemented as an independent embodiment, and step S6102 and step S6104 can be implemented as independent embodiments, but are not limited thereto.
[0642] In some embodiments, the order of any two steps among step S6101 to step S6104 can be exchanged or executed simultaneously. For example, the order of step S6103 and step S6104 can be exchanged or executed simultaneously.
[0643] In some embodiments, step S6101, step S6102, and step S6104 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0644] In some embodiments, step S6102 and step S6104 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0645] In some embodiments, step S6101 to step S6103 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0646] In some embodiments, steps S6101 and S6103 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0647] FIG. 6B is an interaction diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 6B, the above method includes:
[0648] Step 1: UE initiates NAS connection establishment with NF.
[0649] Optionally, the initial NAS signaling for establishing the NAS connection can be forwarded by the AMF.
[0650] In some embodiments, if the NAS signaling is forwarded by the AMF, and there is no existing NAS security context of the NF stored in the UE, the NAS signaling can be protected by the NAS security context of the AMF.
[0651] Optionally, after receiving the NAS signaling from the UE, the AMF / SEAF / AUSF can provide the K NF and KSI / KSI NF to the NF. In this case, no key request / response procedure is needed between the AMF / SEAF / AUSF and the NF.
[0652] Optionally, if the NAS signaling is sent directly to the NF, and there is no existing NAS security context of the NF stored in the UE, the NAS signaling is not protected.
[0653] In some embodiments, if the existing NAS security context of the NF is maintained in the UE, the NAS signaling is protected by the NAS security context of the NF.
[0654] It should be explained that KSI is a general identifier of the NAS security context, KSI NF is the NAS security context identifier of the NF, and KSI AMF / SEAF / AUSF is the NAS security context identifier of the AMF / SEAF / AUSF. The NAS COUNT stored in the existing NAS security context of the NF is an input of the protection algorithm.
[0655] Optionally, the values of KSI AMF / SEAF / AUSF and KSI NF may be the same or different, for example, KSI NF may be derived from KSI AMF / SEAF / AUSF , i.e., KSI NF = NF instance ID / NF type: KSI AMF / SEAF / AUSF .
[0656] Step 2. If the received NAS signaling is unprotected, the NF determines to initiate SMC to establish NAS security with the UE. If the received NAS signaling is protected by the UE, the NF can also initiate SMC to activate NAS security.
[0657] In some embodiments, if there is no existing UE NAS security context stored identified by the received KSI / KSI NF , or the value of the received KSI / KSI NF is set to 111 (which means there is no available context), the NF interacts with the SEAF / AMF / AUSF to obtain K NF (uses vertical derivation K NF ) and KSI / KSI NF , (to obtain the latest) then derives K NF_INT / K NF_ENC to protect the SMC message. After the SMC procedure is completed, the NF and the UE create a NAS security context for the NF. The UL NAS COUNT and DL NAS COUNT contained in the NAS security context of the NF are set to zero. The NAS security context of the NF is identified by KSI / KSI NF , which is generated by the AMF / SEAF / AUSF or the NF and provided to the UE. NF
[0658] In some embodiments, if KSI NF is generated by the AMF / SEAF / AUSF or the NF, the AMF / SEAF / AUSF or the NF can derive it from KSI AMF / SEAF / AUSF , for example, KSI NF = NF instance ID / NF type: KSI AMF / SEAF / AUSF .
[0659] In some embodiments, once KSI NF is received during SMC, the UE can derive KSI AMF / SEAF / AUSF and retrieve the corresponding NAS security context of the AMF / SEAF / AUSF to establish the NAS connection with the NF.
[0660] In some embodiments, if the NAS security context identified by the received KSI / KSI NF is stored, the NF will use the retrieved NAS security context based on the received KSI / KSI NF to verify the NAS signaling.
[0661] In some embodiments, if the integrity verification fails, the NF will reject the NAS signaling.
[0662] In some embodiments, if the integrity verification is successful, the NF can initiate a horizontal derivation of K NF and trigger a NAS SMC, e.g. for new algorithm negotiation or due to COUNT wrap-around or based on local policy.
[0663] In some embodiments, once the SMC procedure is completed, the NF and the UE update the NAS security context, e.g. update KNF' and K NF_INT / K NF_ENC , change the status from non-current to current, reset the UL NAS COUNT and the DL NAS COUNT to zero.
[0664] It should be interpreted that K NF_INT is the integrity protection key, derived from K NF . K NF_ENC is the encryption protection key derived from K NF .
[0665] Optionally, K NF Vertical derivation: input S to the key derivation function KDF: UE identifier (such as IMSI or NAI or GCI or GLI or GPSI or SUPI or SUCI), ABBA parameter, NF instance ID. Input key key is K AUSF / KSEAF / KAMF .
[0666] Optionally, K NF’ Horizontal derivation: input S to the KDF: direction, NAS COUNT. Input key key is K NF . If the direction is 0x01, then the NAS COUNT is the value of the downlink NAS COUNT. If the direction is 0x00, then the NAS COUNT is the value of the uplink NAS COUNT.
[0667] Step 3, the NF returns NAS signaling to the UE, which is protected with K NF_INT / K NF_ENC . The UE verifies the NAS signaling using the stored corresponding NAS security context.
[0668] In some embodiments, all subsequent communication between the UE and the NF is protected by using the established / activated NAS security context for the NF. For UL messages, the UE increments the UL NAS COUNT by 1, the NF updates the UL NAS COUNT accordingly. For DL messages, the NF increments the DL NAS COUNT by 1, the UE updates the DL NAS COUNT accordingly.
[0669] Step 4 is performed after the NAS connection is released.
[0670] Step 4, the UE and the NF change the state of the corresponding NAS security context, i.e. from the current state to the non-current state.
[0671] In some embodiments, the NAS security context stored in the UE can refer to FIG. 2B and FIG. 2C. The UE NAS security context stored in the NF can refer to FIG. 2D.
[0672] FIG. 6C is an interaction schematic diagram of a communication method according to an embodiment of the present disclosure. Compared with FIG. 6B, the difference is that:
[0673] Step 1, the NAS signaling can only be sent without protection or by using the NAS security context of the AMF.
[0674] Step 2, only the vertical derivative can be used to derive K NF Once the SMC is completed, the UE and the NF set the NAS COUNT to zero.
[0675] And K NF Vertical derivation: the input S of the KDF: UE identifier (such as IMSI or NAI or GCI or GLI or GPSI or SUPI or SUCI), ABBA parameter, NF instance ID, NAS COUNT stored in the NAS security context of the AUSF / SEAF / AMF. The input key key is K AUSF / KSEAF / KAMF .
[0676] Or K NF Vertical derivation: the input S of the KDF: UE identifier (such as IMSI or NAI or GCI or GLI or GPSI or SUPI or SUCI), ABBA parameter, NF instance ID, UE-provided random number, NF-provided random number. The input key key is K AUSF / KSEAF / KAMF . The UE-provided random number is transmitted in step 1, and the NF-provided random number is transmitted in the SMC process.
[0677] Step 4, once the NAS connection is released, the UE and the NF delete the NAS security context.
[0678] Other steps can refer to FIG. 6B, which will not be described here.
[0679] In some embodiments, the NAS security context stored in the UE can refer to FIG. 2F and FIG. 2G. The UE NAS security context stored in the NF can refer to FIG. 2H.
[0680] In some embodiments, one implementation on the UE side includes that the UE should be able to create and store different NAS security contexts for different NFs, including NAS COUNT, security algorithm, key, context state, ngKSI, etc.
[0681] Optionally, once the SMC procedure is completed, the UE shall be able to create and store the NAS security context for the NF.
[0682] Optionally, the UE shall be able to perform vertical derivation or horizontal derivation to generate KNF.
[0683] Optionally, the UE shall be able to perform SMC to activate NAS security between the UE and the NF.
[0684] Optionally, the UE shall be able to provide the first random number for key generation by sending NAS signaling.
[0685] Optionally, the UE shall be able to protect the initial NAS signaling (NAS connection request) by using the NAS security context of the AUSF / SEAF / AMF.
[0686] Optionally, the UE shall be able to maintain separate NAS COUNTs for communication with different NFs.
[0687] Optionally, once the K NF is re-generated, the UE shall be able to reset the NAS COUNT to zero.
[0688] In some embodiments, one implementation of the NF side (i.e. first network element side) includes that the NF shall be able to create and store the UE NAS security context, including NAS COUNT, security algorithms, keys, context status, ngKSI, UE identifier, etc.
[0689] Optionally, the NF shall be able to perform horizontal derivation to generate K NF .
[0690] Optionally, the NF shall be able to perform SMC to activate NAS security between the UE and the NF.
[0691] Optionally, the NF shall be able to provide KSI or KSI NF to the UE in order to create the NAS security context for the NF.
[0692] Optionally, the NF shall be able to provide the second random number for key generation in the SMC procedure.
[0693] Optionally, the NF shall be able to maintain the NAS COUNT in order to directly communicate with the UE.
[0694] Optionally, once the K NF is re-generated, the NF shall be able to reset the NAS COUNT to zero.
[0695] Optionally, the NF shall be able to interact with the AUSF / SEAF / AMF to obtain K NF .
[0696] In some embodiments, one implementation of the AUSF / SEAF / AMF side (i.e., the second network element side) includes that the AUSF / SEAF / AMF should be able to perform vertical derivation to generate K NF .
[0697] Optionally, the AUSF / SEAF / AMF should be able to ensure the freshness of K NF .
[0698] Optionally, the AUSF / SEAF / AMF should be able to obtain the random number provided by the UE and the NF.
[0699] In the embodiments of the present disclosure, part or all of the steps, and optional implementation manners thereof, can be combined with part or all of the steps in other embodiments, or can be combined with optional implementation manners of other embodiments.
[0700] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device including units or modules for implementing each step performed by the terminal in any of the above methods. For another example, another device is also proposed, including units or modules for implementing each step performed by the network equipment (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
[0701] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize the functions of any of the above methods or the units or modules of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of the hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship between the elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.
[0702] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the hardware circuit configuration. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), and the like.
[0703] FIG. 7A is a structural schematic diagram of a terminal, according to an embodiment of the present disclosure. As shown in FIG. 7A, the terminal 7100 can include at least one of a transceiver module 7101, a processing module 7102, and the like. In some embodiments, the transceiver module 7101 described above is configured to send a first message, the first message being used to request to establish a non-access stratum (NAS) connection with a first network element; and the processing module 7102 described above is configured to create or activate a first NAS security context for the first network element in a case that a security mode command (SMC) procedure is successfully performed, wherein the SMC procedure is triggered by the first network element in a case that the first message is received, and the first NAS security context corresponds to a second NAS security context created or activated by the first network element for the terminal in a case that the SMC procedure is successfully performed. Optionally, the transceiver module 7101 described above is configured to perform at least one of the communication steps (for example, steps S2101, S2102, S2107, S2109, S2110, S2201, S2202, S2207, S2209, S2210, but not limited thereto) of the sending and / or receiving performed by the terminal 101 in any of the methods described above, and details are not described herein again. Optionally, the processing module described above is configured to perform at least one of the other steps (for example, steps S2103, S2104, S2105, S2106, S2108, S2111, S2112, S2203, S2204, S2205, S2206, S2208, S2211, S2212, but not limited thereto) performed by the terminal 101 in any of the methods described above, and details are not described herein again.
[0704] FIG. 7B is a structural schematic diagram of a first network element, according to an embodiment of the present disclosure. As shown in FIG. 7B, the first network element 7200 can include at least one of a transceiver module 7201, a processing module 7202, and the like. In some embodiments, the transceiver module 7201 is configured to receive a first message, where the first message is used by a terminal to request establishment of a non-access stratum (NAS) connection with the first network element; and the processing module 7202 is configured to trigger execution of a security mode command (SMC) procedure, and create or activate a second NAS security context for the terminal in a case where the SMC procedure is successfully executed. The second NAS security context corresponds to a first NAS security context created or activated by the terminal for the first network element in the case where the SMC procedure is successfully executed. Optionally, the transceiver module is configured to perform at least one of the communication steps (for example, steps S2101, S2102, S2107, S2109, S2110, S2201, S2202, S2207, S2209, S2210, but not limited thereto) of the sending and / or receiving performed by the first network element 1021 in any of the methods described above. Details are not described herein again. Optionally, the processing module is configured to perform at least one of the other steps (for example, steps S2103, S2104, S2105, S2106, S2108, S2111, S2112, S2203, S2204, S2205, S2206, S2208, S2211, S2212, but not limited thereto) performed by the first network element 1021 in any of the methods described above. Details are not described herein again.
[0705] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be mutually replaced with a transceiver.
[0706] In some embodiments, the processing module can be one module, or can include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module, respectively. Optionally, the processing module can be mutually replaced with a processor.
[0707] FIG. 8A is a structural schematic diagram of a communication device 8100, according to an embodiment of the present disclosure. The communication device 8100 can be a network device (for example, an access network device, a core network device, and the like), a terminal (for example, a user equipment, and the like), a chip, a chip system, or a processor supporting the network device to implement any of the methods described above, or a chip, a chip system, or a processor supporting the terminal to implement any of the methods described above. The communication device 8100 can be used to implement the methods described in the above method embodiments, and details can be referred to the descriptions in the above method embodiments.
[0708] As shown in FIG. 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general processor or a special-purpose processor, etc., such as a baseband processor or a central processing unit. The baseband processor can be configured to process communication protocols and communication data, and the central processing unit can be configured to control a communication apparatus (e.g., a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. Optionally, the communication device 8100 is configured to perform any of the above methods. Optionally, the one or more processors 8101 are configured to invoke instructions to cause the communication device 8100 to perform any of the above methods.
[0709] In some embodiments, the communication device 8100 further includes one or more transceivers 8102. When the communication device 8100 includes the one or more transceivers 8102, the transceiver 8102 performs at least one of the communication steps (e.g., steps S2101, S2102, S2107, S2109, S2110, S2201, S2202, S2207, S2209, S2210, but not limited to) in the above methods, and the processor 8101 performs at least one of the other steps (e.g., steps S2103, S2104, S2105, S2106, S2108, S2111, S2112, S2203, S2204, S2205, S2206, S2208, S2211, S2212, but not limited to) in the above methods. In optional embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms transceiver, transceiving unit, transceiver, transceiving circuit, interface circuit, interface, etc. can be replaced with each other, and the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.
[0710] In some embodiments, the communication device 8100 further includes one or more memories 8103 for storing data. Optionally, all or part of the memory 8103 can also be outside the communication device 8100. In optional embodiments, the communication device 8100 can include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected to the memory 8103, and the interface circuit 8104 can be configured to receive data from the memory 8103 or other devices, and can be configured to send data to the memory 8103 or other devices. For example, the interface circuit 8104 can read data stored in the memory 8103 and send the data to the processor 8101.
[0711] The communication device 8100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by FIG. 8A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, and the like; (6) other devices, and the like.
[0712] FIG. 8B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in FIG. 8B can be referred to, but is not limited thereto.
[0713] The chip 8200 includes one or more processors 8201. The chip 8200 is configured to perform any of the above methods.
[0714] In some embodiments, the chip 8200 further includes one or more interface circuits 8202. Optionally, the terms interface circuit, interface, transceiver pin, and the like can be replaced with each other. In some embodiments, the chip 8200 further includes one or more memories 8203 for storing data. Optionally, all or part of the memory 8203 can be outside the chip 8200. Optionally, the interface circuit 8202 is connected to the memory 8203, and the interface circuit 8202 can be configured to receive data from the memory 8203 or other devices, and the interface circuit 8202 can be configured to send data to the memory 8203 or other devices. For example, the interface circuit 8202 can read data stored in the memory 8203 and send the data to the processor 8201.
[0715] In some embodiments, the interface circuit 8202 performs at least one of the communication steps (for example, steps S2101, S2102, S2107, S2109, S2110, S2201, S2202, S2207, S2209, S2210, but not limited to) of transmitting and / or receiving in the above method. The interface circuit 8202 performing the communication steps such as transmitting and / or receiving in the above method means that the interface circuit 8202 performs data interaction between the processor 8201, the chip 8200, the memory 8203, or the transceiver device. In some embodiments, the processor 8201 performs at least one of the other steps (for example, steps S2103, S2104, S2105, S2106, S2108, S2111, S2112, S2203, S2204, S2205, S2206, S2208, S2211, S2212, but not limited to).
[0716] The modules and / or devices described in each of the embodiments of the virtual device, the physical device, the chip, etc. can be combined or separated according to the situation. Optionally, part or all of the steps can also be performed by a plurality of modules and / or devices in cooperation, which is not limited here.
[0717] The disclosure also proposes a storage medium, and the above storage medium stores instructions, which, when executed on the communication device 8100, causes the communication device 8100 to perform any of the above methods. Optionally, the above storage medium is an electronic storage medium. Optionally, the above storage medium is a computer readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices. Optionally, the above storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a transitory storage medium.
[0718] The disclosure also proposes a program product, which, when executed by the communication device 8100, causes the communication device 8100 to perform any of the above methods. Optionally, the above program product is a computer program product.
[0719] The disclosure also proposes a computer program, which, when executed on a computer, causes the computer to perform any of the above methods.
Claims
1. A communication method characterized by comprising: The method is performed by a terminal, and the method comprises: sending a first message, the first message being used for requesting establishment of a non-access stratum (NAS) connection with a first network element; in a case where a security mode command (SMC) procedure is successfully performed, creating or activating a first NAS security context for the first network element, wherein the SMC procedure is triggered by a first message received by the first network element, the first NAS security context corresponds to a second NAS security context, and the second NAS security context is created or activated for the terminal by the first network element in the case where the SMC procedure is successfully performed.
2. The method of claim 1, wherein, The sending of the first message comprises: sending the first message to a second network element, so as to send, by the second network element, a message comprising the first message or a second message to the first network element, the second message being generated based on the first message; or sending the first message to the first network element.
3. The method according to claim 1 or 2, characterized in that, The first message is protected according to a fifth NAS security context, the fifth security context being a NAS security context corresponding to the second network element and stored on the terminal; or The first message is protected according to a third NAS security context corresponding to the first network element and stored on the terminal, a state of the third NAS security context being a non-current state; or The first message is unprotected.
4. The method according to any one of claims 1 to 3, characterized in that, The first NAS security context comprises at least one of: a NAS connection identifier; a security algorithm; a first key of the first network element; a first NAS count comprising an uplink NAS count and / or a downlink NAS count; a first identifier being a common identifier of the first NAS security context and a fifth NAS security context; a second identifier being an identifier of the first NAS security context; an encryption protection key; an integrity protection key; a state item, a value of the state item being a first value, the first value indicating a current state.
5. The method of claim 4, wherein, The method further comprises: after the SMC procedure is successfully performed, a value of the first NAS count is set to 0.
6. The method according to claim 4 or 5, characterized in that, The first key of the first network element is generated according to a vertical derivation manner or a horizontal derivation manner.
7. The method of claim 6, wherein, Input parameters of the vertical derivation manner comprise at least one of: an identifier of the terminal; an architecture-based key agreement (ABBA) parameter; an identifier of the first network element; a key of the second network element; a second NAS count stored in a NAS security context corresponding to the second network element in the terminal; a first random number provided by the terminal; a second random number provided by the first network element.
8. The method of claim 7, wherein, The key of the second network element is obtained by: determining a security context corresponding to the second network element according to the first identifier or the second identifier obtained in the SMC procedure; and determining the key of the second network element from the security context corresponding to the second network element.
9. The method of claim 6, wherein, Input parameters of the horizontal derivation manner comprise at least one of: a transmission direction comprising an uplink transmission direction and / or a downlink transmission direction; a third NAS count determined from a third NAS security context; and a fourth NAS count determined from a fourth NAS security context. a second key of the first network element, the second key of the first network element being determined from the third NAS security context. The method further comprises:
10. The method according to any one of claims 1-9, characterized in that, receiving a third message sent by the first network element, the third message being protected according to a ciphering protection key and / or an integrity protection key in the second NAS security context, the third message being a response to the first message; verifying the third message according to the first NAS security context to determine whether the NAS connection with the first network element is successfully established. After the NAS connection is successfully established, comprising:
11. The method according to any one of claims 1-10, characterized in that, in case that a fourth message is sent to the first network element, increasing a value of an uplink NAS count in the first NAS security context by 1, wherein the fourth message comprises a first sequence number (SQN), the first SQN being used by the first network element to update an uplink NAS count in the second NAS security context. After the NAS connection is successfully established, comprising:
12. The method according to any one of claims 1-11, characterized in that, in case that a fifth message sent by the first network element is received, updating a value of a downlink NAS count in the first NAS security context according to a second SQN in the fifth message. The method further comprises:
13. The method according to any one of claims 1-12, characterized in that, in case that the NAS connection is released, updating a value of a state item in the first NAS security context to a second value to obtain a third NAS security context, wherein the second value indicates a non-current state. The method further comprises:
14. The method according to any one of claims 1-12, characterized in that, in case that the NAS connection is released, removing the first NAS security context. The method is performed by a first network element, comprising:
15. A method of communication, comprising: receiving a first message, the first message being used by a terminal to request to establish a non-access stratum (NAS) connection with the first network element; triggering to perform a security mode command (SMC) procedure, and in case that the SMC procedure is successfully performed, creating or activating a second NAS security context for the terminal, wherein the second NAS security context corresponds to a first NAS security context, the first NAS security context being created or activated by the terminal for the first network element in case that the SMC procedure is successfully performed. The receiving the first message comprises: receiving the first message sent by the terminal; or 16. The method of claim 15, wherein, receiving the first message or a second message sent by a second network element, the second message being generated by the second network element based on the received first message. The first message is protected according to a fifth NAS security context, the fifth security context being a NAS security context corresponding to the second network element and stored on the terminal; or 17. The method according to claim 15 or 16, characterized in that, the first message is protected according to a third NAS security context corresponding to the first network element and stored on the terminal, a state of the third NAS security context being a non-current state; or the first message is unprotected. The method further comprises: 18. The method of claim 17, wherein, In a case that the first message is protected according to the third NAS security context, the first network element verifies the first message according to a fourth NAS security context, wherein the fourth NAS security context corresponds to the third security context; In response to a failure of verifying the first message, the first network element rejects to establish the NAS connection with the terminal.
19. The method according to any one of claims 15-18, characterized by, The second NAS security context comprises at least one of: an identifier of the terminal; a NAS connection identifier; a security algorithm; a first key of the first network element; a first NAS count comprising an uplink NAS count and / or a downlink NAS count; a first identifier which is a common identifier of the second NAS security context and a fifth NAS security context; a second identifier which is an identifier of the second NAS security context; an encryption protection key; an integrity protection key; a state item, a value of the state item being a first value, the first value indicating a current state.
20. The method of claim 19, wherein, The method further comprises: after the SMC procedure is successfully performed, a value of the first NAS count is set to 0.
21. The method of claim 19 or 20, wherein, The method further comprises: obtaining at least one of the following from a second message sent by the second network element: the first identifier; the second identifier; the first key of the first network element.
22. The method of claim 19 or 20, wherein, The method further comprises: requesting the second network element to send the first key of the first network element; receiving at least one of the first key of the first network element, the first identifier, and the second identifier returned by the second network element.
23. The method of claim 21 or 22, wherein, The first key of the first network element is generated by the second network element through a vertical derivation manner, wherein input parameters of the vertical derivation manner comprise at least one of: the identifier of the terminal; an inter-architecture anti-downgrade ABBA parameter; an identifier of the first network element; a key of the second network element; a fourth NAS count stored in a NAS security context corresponding to the terminal on the second network element; a first random number provided by the terminal; a second random number provided by the first network element.
24. The method of claim 19 or 20, wherein, The method further comprises: generating the first key according to a horizontal derivation manner, wherein input parameters of the horizontal derivation manner comprise at least one of: a transmission direction comprising an uplink transmission direction or / and a downlink transmission direction; a fifth NAS count determined from a fourth NAS security context; a second key of the first network element determined from the fourth NAS security context.
25. The method of any one of claims 15-24, wherein, The method further comprises: sending a third message to the terminal, the third message being protected by the first network element according to the encryption protection key and / or the integrity protection key in the second NAS security context, the third message being used to respond to the first message.
26. The method of any one of claims 15-25, wherein, After the NAS connection is successfully established, comprising: in a case that a fourth message sent by the terminal is received, updating a value of an uplink NAS count in the second NAS security context according to a first sequence number SQN in the fourth message.
27. The method of any one of claims 15-26, wherein, after the NAS connection establishment is successful, comprising: in case that a fifth message is sent to the terminal, increasing a value of a downlink NAS count in the second NAS security context by 1, wherein the fifth message comprises a second SQN, and the second SQN is used by the terminal to update a downlink NAS count in the first NAS security context.
28. The method of any one of claims 15-27, wherein, the method further comprises: in case that the NAS connection is released, updating a value of a state item in the second NAS security context to a second value to obtain a fourth NAS security context, wherein the second value indicates a non-current state.
29. The method of any one of claims 15-27, wherein, the method further comprises: in case that the NAS connection is released, removing the second NAS security context.
30. A terminal, characterized by comprising: a transceiver configured to send a first message, the first message being used to request a non-access stratum (NAS) connection to be established with a first network element; a processor configured to create or activate a first NAS security context for the first network element in case that a security mode command (SMC) procedure is successfully performed, wherein the SMC procedure is triggered by the first network element in case that the first message is received, and the first NAS security context corresponds to a second NAS security context created or activated by the first network element for the terminal in case that the SMC procedure is successfully performed.
31. A first network element, characterized by, comprising: a transceiver configured to receive a first message, the first message being used to request a non-access stratum (NAS) connection to be established with a first network element; a processor configured to trigger an execution of a security mode command (SMC) procedure, and create or activate a second NAS security context for the terminal in case that the SMC procedure is successfully performed, wherein the second NAS security context corresponds to a first NAS security context created or activated by the terminal for the first network element in case that the SMC procedure is successfully performed.
32. A terminal, characterized by comprising: one or more processors; a memory coupled to the processors, the memory having stored thereon executable instructions that, when executed by the processors, cause the communication method of any of claims 1-14 to be performed.
33. A first network element, characterized by, comprising: one or more processors; a memory coupled to the processors, the memory having stored thereon executable instructions that, when executed by the processors, cause the communication method of any of claims 15-29 to be performed.
34. A communication system, characterized by comprising a terminal, a first network element and a second network element, wherein the terminal is configured to send a first message, the first message being used to request a non-access stratum (NAS) connection to be established with a first network element; create or activate a first NAS security context for the first network element in case that a security mode command (SMC) procedure is successfully performed, wherein the SMC procedure is triggered by the first network element in case that the first message is received, and the first NAS security context corresponds to a second NAS security context. The first network element is configured to receive a first message; trigger execution of a security mode command (SMC) procedure, and create or activate a second NAS security context for the terminal in case the SMC procedure is successfully executed.
35. A storage medium, the storage medium storing instructions, wherein, The instructions, when executed on the communication device, cause the communication device to perform the communication method of any of claims 1-29.
36. A computer program product comprising computer programs and / or instructions, characterized in that, The computer program and / or instructions, when executed on the communication device, implement the communication method of any of claims 1-29.