Communication method, communication device, communication system, and program product

By introducing non-access stratum-related security contexts and key mechanisms into the communication system, the signaling security issue between the terminal and core network equipment is resolved, signaling protection is achieved, and the security and reliability of communication are improved.

CN122642046APending Publication Date: 2026-08-25BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202680001149.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-04
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

In existing communication systems, the security of signaling between terminals and core network equipment is difficult to guarantee effectively, and there is a risk of tampering or eavesdropping.

Method used

By introducing first network function, second network function, terminal and security anchor point functions, and utilizing non-access stratum related security context and key mechanism, signaling protection between the terminal and core network equipment is achieved.

Benefits of technology

It improves the signaling security between terminals and core network equipment, prevents signaling tampering and eavesdropping, and ensures the security and reliability of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122642046A_ABST
    Figure CN122642046A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a communication method, a communication device, a communication system and a program product. The communication method comprises: receiving a first message sent by a terminal, the first message comprising: an identifier of the terminal and first information sent to a second network function; and sending a second message to the terminal, the second message comprising: response information of the first information sent by the second network function to the terminal; wherein the response information of the first information is protected by using a first security context, and the first security context is a security context related to a non-access stratum related to the second network function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a communication method, communication device, communication system and program product. Background Technology

[0002] In communication systems, using a key mechanism to ensure the security of signaling can guarantee that the signaling between the terminal and the core network equipment is not tampered with or eavesdropped on. Summary of the Invention

[0003] This disclosure provides a communication method, communication device, communication system, and program product.

[0004] In a first aspect, embodiments of this disclosure provide a communication method executed by a first network function, the communication method comprising:

[0005] The receiving terminal sends a first message, the first message including: the identifier of the terminal and first information sent to the second network function;

[0006] Send a second message to the terminal, the second message including: response information of the first information sent to the terminal by the second network function;

[0007] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0008] Secondly, this disclosure also provides a communication method executed by a second network function, the communication method comprising:

[0009] Receive a first request message sent by a first network function, the first request message including: first information sent to the second network function and an identifier of the terminal, the identifier of the terminal being used to generate a first identifier assigned to the terminal by the second network function;

[0010] Send a first response message to the first network function. The first response message includes a first security-related message, which is a non-access stratum security-related message related to the second network function.

[0011] The first request message is sent by the first network function after receiving the first message sent by the terminal, and the first message includes the identifier of the terminal and the first information.

[0012] Thirdly, this disclosure also provides a communication method executed by a terminal, the communication method comprising:

[0013] Send a first message to a first network function, the first message including: the identifier of the terminal and first information to be sent to a second network function;

[0014] Receive a second message sent by the first network function, the second message including: response information of the first information sent by the second network function to the terminal;

[0015] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0016] Fourthly, embodiments of this disclosure also provide a communication method executed by a security anchor function, the communication method comprising:

[0017] Receive a third request message sent by the second network function, the third request message including: the identifier of the terminal and the second identifier of the second network function;

[0018] Based on the security anchor key, the identifier of the terminal, and the second identifier, a key related to the second network function is generated. The key is used to generate a first security context, which is a non-access stratum related security context associated with the second network function.

[0019] Send a third response message to the second network function, the third response message including a key related to the second network function;

[0020] The first security context is used to protect the response information of the first information sent by the second network function to the terminal.

[0021] Fifthly, embodiments of this disclosure also provide a first network function, which includes:

[0022] The transceiver module is used to receive a first message sent by a terminal, the first message including: the identifier of the terminal and first information sent to a second network function; and to send a second message to the terminal, the second message including: response information of the first information sent to the terminal by the second network function;

[0023] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0024] Sixthly, embodiments of this disclosure also provide a second network function, including:

[0025] The transceiver module is configured to receive a first request message sent by a first network function, the first request message including: first information to be sent to the second network function and an identifier of a terminal, the identifier of the terminal being used to generate a first identifier assigned to the terminal by the second network function; and to send a first response message to the first network function, the first response message including a first security-related message, the first security-related message being a non-access stratum security-related message related to the second network function.

[0026] The first request message is sent by the first network function after receiving the first message sent by the terminal, and the first message includes the identifier of the terminal and the first information.

[0027] In a seventh aspect, embodiments of this disclosure also provide a terminal, which includes:

[0028] The transceiver module is configured to send a first message to a first network function, the first message including: the identifier of the terminal and first information sent to a second network function; and to receive a second message sent by the first network function, the second message including: response information of the first information sent by the second network function to the terminal;

[0029] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0030] Eighthly, embodiments of this disclosure also provide a security anchor point function, including:

[0031] The transceiver module is used to receive a third request message sent by the second network function. The third request message includes: the identifier of the terminal and the second identifier of the second network function.

[0032] The processing module is configured to generate a key related to the second network function based on the security anchor key, the identifier of the terminal, and the second identifier. The key is used to generate a first security context, which is a non-access stratum related security context associated with the second network function.

[0033] The transceiver module is further configured to send a third response message to the second network function, the third response message including a key related to the second network function;

[0034] The first security context is used to protect the response information of the first information sent by the second network function to the terminal.

[0035] In a ninth aspect, embodiments of this disclosure also provide a first network function, including:

[0036] One or more processors;

[0037] The first network function is used to execute the communication method described in the embodiments of the first aspect of this disclosure.

[0038] In a tenth aspect, embodiments of this disclosure also provide a second network function, including:

[0039] One or more processors;

[0040] The second network function is used to perform the communication method described in the embodiments of the second aspect of this disclosure.

[0041] In an eleventh aspect, embodiments of this disclosure also provide a terminal, including:

[0042] One or more processors;

[0043] The terminal is used to execute the communication method described in the embodiments of the third aspect of this disclosure.

[0044] In a twelfth aspect, embodiments of this disclosure also provide a security anchor point function, including:

[0045] One or more processors;

[0046] The security anchor function is used to execute the communication method described in the embodiments of the fourth aspect of this disclosure.

[0047] In a thirteenth aspect, embodiments of this disclosure also provide a communication system, including: a first network function, a second network function, a terminal, and a security anchor function; wherein the first network function is configured to implement the communication method described in the embodiments of the first aspect of this disclosure, the second network function is configured to implement the communication method described in the embodiments of the second aspect of this disclosure, the terminal is configured to implement the communication method described in the embodiments of the third aspect of this disclosure, and the security anchor function is configured to implement the communication method described in the embodiments of the fourth aspect of this disclosure.

[0048] In a fourteenth aspect, embodiments of this disclosure also provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the communication method as described in the embodiments of the first, second, third, or fourth aspects of this disclosure.

[0049] Additional aspects and advantages of embodiments of this disclosure will be set forth in part in the description which follows, and will become apparent from the description or may be learned by practice of this disclosure. Attached Figure Description

[0050] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.

[0051] Figure 1a This is a schematic diagram of the architecture of the communication system provided in the embodiments of this disclosure;

[0052] Figure 1b This is a schematic diagram of the signaling interaction of the communication system provided in the embodiments of this disclosure;

[0053] Figure 1c This is a schematic diagram of the signaling interaction of the communication system provided in the embodiments of this disclosure;

[0054] Figure 1d This is a schematic diagram of the key hierarchy structure provided in the embodiments of this disclosure;

[0055] Figure 1e This is a schematic diagram of the key hierarchy structure provided in the embodiments of this disclosure;

[0056] Figure 2a This is one of the interactive schematic diagrams of the communication method provided in the embodiments of this disclosure;

[0057] Figure 2b This is the second interactive schematic diagram of the communication method provided in the embodiments of this disclosure;

[0058] Figure 3 This is one of the flowcharts illustrating the communication method in the embodiments of this disclosure;

[0059] Figure 4a This is a second schematic flowchart of the communication method shown in the embodiments of this disclosure;

[0060] Figure 4b This is the third flowchart illustrating the communication method in the embodiments of this disclosure;

[0061] Figure 4c This is the fourth flowchart illustrating the communication method in the embodiments of this disclosure;

[0062] Figure 5 This is the third interactive schematic diagram of the communication method provided in this embodiment of the disclosure;

[0063] Figure 6a This is a schematic diagram of the structure of the first network function proposed in the embodiments of this disclosure;

[0064] Figure 6b This is a schematic diagram of the structure of the second network function proposed in the embodiments of this disclosure;

[0065] Figure 6c This is a schematic diagram of the structure of the security anchor point function proposed in the embodiments of this disclosure;

[0066] Figure 6d This is a schematic diagram of the structure of the network device proposed in the embodiments of this disclosure;

[0067] Figure 7 This is a schematic diagram of the structure of the communication device proposed in the embodiments of this disclosure;

[0068] Figure 8 This is a schematic diagram of the chip structure proposed in the embodiments of this disclosure. Detailed Implementation

[0069] This disclosure provides a communication method, communication device, communication system, and program product.

[0070] In a first aspect, embodiments of this disclosure provide a communication method executed by a first network function, the communication method comprising:

[0071] The receiving terminal sends a first message, the first message including: the identifier of the terminal and first information sent to the second network function;

[0072] Send a second message to the terminal, the second message including: response information of the first information sent to the terminal by the second network function;

[0073] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0074] In this embodiment, the security of the non-access stratum connection between the terminal and the second network function can be achieved through the first network function, thereby protecting the NAS signaling between the terminal and the second network function.

[0075] In conjunction with some embodiments of the first aspect, in some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0076] In conjunction with some embodiments of the first aspect, in some embodiments, the response information of the first information includes a first identifier assigned to the terminal by the second network function.

[0077] In conjunction with some embodiments of the first aspect, in some embodiments, the first identifier is a temporary terminal identifier.

[0078] In conjunction with some embodiments of the first aspect, in some embodiments, the communication method further includes:

[0079] Send a first request message to the second network function. The first request message includes the first information and the identifier of the terminal. The identifier of the terminal is used to generate the first identifier.

[0080] The system receives a first response message sent by the second network function. The first response message includes a first security-related message, which is a non-access stratum security-related message related to the second network function.

[0081] In this embodiment, the first network function interacts with the second network function to obtain security-related non-access stratum messages associated with the second network function, so as to forward them to the terminal and realize the security of the non-access stratum connection between the terminal and the second network function.

[0082] In conjunction with some embodiments of the first aspect, in some embodiments, the first request message further includes: a second identifier assigned to the second network function, the second identifier being used to generate a key associated with the second network function, the key being used to generate the first security context.

[0083] In conjunction with some embodiments of the first aspect, in some embodiments, the second identifier is a routing ID.

[0084] In this embodiment, the first network function sends a second identifier assigned to it to the second network function to generate a key related to the second network function, and further generates a non-access stratum related security context based on the key, thereby providing security protection for NAS signaling between the terminal and the second network function and realizing the security of the non-access stratum connection between the terminal and the second network function.

[0085] In conjunction with some embodiments of the first aspect, in some embodiments, the first response message further includes the first identifier.

[0086] In conjunction with some embodiments of the first aspect, in some embodiments, the communication method further includes:

[0087] Send a third message to the terminal, the third message including at least one of the following: the second identifier, the first security-related message, and the first identifier;

[0088] Receive a fourth message sent by the terminal, the fourth message including a second security-related message, the second security-related message being a response message to the first security-related message;

[0089] The first identifier is protected using a second security context, which is a non-access stratum-related security context associated with the first network function.

[0090] In this embodiment, the first network function interacts with the terminal to provide the terminal with a first identifier protected by a security context related to the non-access stratum associated with the first network function, and obtains a response message from the terminal for security-related messages of the non-access stratum associated with the second network function. This allows the first network function to further interact with the second network function and achieve security of the non-access stratum connection between the terminal and the second network function.

[0091] In conjunction with some embodiments of the first aspect, in some embodiments, the second security-related message includes: second information sent to the second network function, the second information being protected using the first security context.

[0092] In conjunction with some embodiments of the first aspect, in some embodiments, the second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function;

[0093] The second information is used by the second network function to verify the first information.

[0094] In this embodiment, the terminal sends NAS messages or NAS containers protected by a non-access stratum-related security context associated with the second network function to the second network function through the first network function, so that the second network function can verify unprotected NAS messages or NAS containers to ensure the security of NAS signaling.

[0095] In conjunction with some embodiments of the first aspect, in some embodiments, the communication method further includes:

[0096] Send a second request message to the second network function, the second request message including the second security-related message;

[0097] Receive a second response message sent by the second network function, the second response message including response information of the first information sent by the second network function to the terminal;

[0098] The second message is sent after the second response message is received.

[0099] In this embodiment, the first network function sends a response message to the second network function containing a "security-related non-access stratum message associated with the second network function" obtained from the terminal. This allows the first network function to obtain information protected by a security context associated with the non-access stratum (e.g., NAS messages or NAS containers) and perform security verification, thereby ensuring the security of the non-access stratum connection between the terminal and the second network function.

[0100] Secondly, this disclosure also provides a communication method executed by a second network function, the communication method comprising:

[0101] Receive a first request message sent by a first network function, the first request message including: first information sent to the second network function and an identifier of the terminal, the identifier of the terminal being used to generate a first identifier assigned to the terminal by the second network function;

[0102] Send a first response message to the first network function. The first response message includes a first security-related message, which is a non-access stratum security-related message related to the second network function.

[0103] The first request message is sent by the first network function after receiving the first message sent by the terminal, and the first message includes the identifier of the terminal and the first information.

[0104] In conjunction with some embodiments of the second aspect, in some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0105] In conjunction with some embodiments of the second aspect, in some embodiments, the first request message further includes: a second identifier assigned by the first network function to the second network function, the second identifier being used to generate a key related to the second network function;

[0106] The key is used to generate a first security context, which is a non-access stratum-related security context associated with the second network function. The first security context is used to protect the response information of the first information.

[0107] In conjunction with some embodiments of the second aspect, in some embodiments, the second identifier is a routing ID.

[0108] In conjunction with some embodiments of the second aspect, in some embodiments, the communication method further includes:

[0109] The first identifier is generated based on the identifier of the terminal;

[0110] Alternatively, generate the second identifier.

[0111] In conjunction with some embodiments of the second aspect, in some embodiments, the first response message further includes the first identifier.

[0112] In conjunction with some embodiments of the second aspect, in some embodiments, the first identifier is a temporary terminal identifier.

[0113] In conjunction with some embodiments of the second aspect, in some embodiments, the communication method further includes:

[0114] Receive a second request message sent by the first network function, the second request message including a second security-related message;

[0115] Send a second response message to the first network function, the second response message including response information of the first information sent by the second network function to the terminal;

[0116] Wherein, the second security-related message is received by the first network function from the terminal, and the second security-related message is a response message to the first security-related message;

[0117] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0118] In conjunction with some embodiments of the second aspect, in some embodiments, the response information of the first information further includes the first identifier.

[0119] In conjunction with some embodiments of the second aspect, in some embodiments, the second security-related message includes second information sent to a second network function, the second information being protected using the first security context.

[0120] In conjunction with some embodiments of the second aspect, in some embodiments, the second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function;

[0121] The second information is used by the second network function to verify the first information.

[0122] In conjunction with some embodiments of the second aspect, in some embodiments, the communication method further includes:

[0123] Send a third request message to the security anchor function, the third request message including: the identifier of the terminal and the second identifier, wherein the second identifier is used to generate a key related to the second network function, and the key is used to generate a first security context;

[0124] Receive a third response message sent by the security anchor function, the third response message including a key related to the second network function;

[0125] The first response message is sent after the third response message is received.

[0126] In conjunction with some embodiments of the second aspect, in some embodiments, the first identifier is a temporary terminal identifier.

[0127] Thirdly, this disclosure also provides a communication method executed by a terminal, the communication method comprising:

[0128] Send a first message to a first network function, the first message including: the identifier of the terminal and first information to be sent to a second network function;

[0129] Receive a second message sent by the first network function, the second message including: response information of the first information sent by the second network function to the terminal;

[0130] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0131] In conjunction with some embodiments of the third aspect, in some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0132] In conjunction with some embodiments of the third aspect, in some embodiments, the response information of the first information includes a first identifier assigned to the terminal by the second network function.

[0133] In conjunction with some embodiments of the third aspect, in some embodiments, the first identifier is a temporary terminal identifier.

[0134] In conjunction with some embodiments of the third aspect, in some embodiments, the communication method further includes:

[0135] Receive a third message sent by the first network function, the third message including at least one of the following: the second identifier, the first identifier, and a first security-related message, wherein the first security-related message is a non-access stratum security-related message related to the second network function;

[0136] In conjunction with some embodiments of the third aspect, in some embodiments, the second identifier is a routing ID.

[0137] Send a fourth message to the first network function, the fourth message including a second security-related message, the second security-related message being a response message to the first security-related message;

[0138] The first identifier is protected using a second security context, which is a security context related to the first network function non-access stratum.

[0139] In conjunction with some embodiments of the third aspect, in some embodiments, the communication method further includes:

[0140] Based on the security anchor key, the identifier of the terminal, and the second identifier of the second network function, a key related to the second network function is generated, and the key is used to generate the first security context.

[0141] In conjunction with some embodiments of the third aspect, in some embodiments, the second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function;

[0142] The second information is used by the second network function to verify the first information.

[0143] In conjunction with some embodiments of the third aspect, in some embodiments, the second identifier is assigned by the first network function, or the second identifier is generated by the second network function.

[0144] Fourthly, embodiments of this disclosure also provide a communication method executed by a security anchor function, the communication method comprising:

[0145] Receive a third request message sent by the second network function, the third request message including: the identifier of the terminal and the second identifier of the second network function;

[0146] Based on the security anchor key, the identifier of the terminal, and the second identifier, a key related to the second network function is generated. The key is used to generate a first security context, which is a non-access stratum related security context associated with the second network function.

[0147] Send a third response message to the second network function, the third response message including a key related to the second network function;

[0148] The first security context is used to protect the response information of the first information sent by the second network function to the terminal.

[0149] In conjunction with some embodiments of the fourth aspect, in some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0150] In conjunction with some embodiments of the fourth aspect, in some embodiments, the response information of the first information includes a first identifier assigned to the terminal by the second network function.

[0151] In conjunction with some embodiments of the fourth aspect, in some embodiments, the first identifier is a temporary terminal identifier.

[0152] In conjunction with some embodiments of the fourth aspect, in some embodiments, the second identifier is a routing ID.

[0153] Fifthly, embodiments of this disclosure also provide a first network function, which includes:

[0154] The transceiver module is used to receive a first message sent by a terminal, the first message including: the identifier of the terminal and first information sent to a second network function; and to send a second message to the terminal, the second message including: response information of the first information sent to the terminal by the second network function;

[0155] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0156] Sixthly, embodiments of this disclosure also provide a second network function, including:

[0157] The transceiver module is configured to receive a first request message sent by a first network function, the first request message including: first information to be sent to the second network function and an identifier of a terminal, the identifier of the terminal being used to generate a first identifier assigned to the terminal by the second network function; and to send a first response message to the first network function, the first response message including a first security-related message, the first security-related message being a non-access stratum security-related message related to the second network function.

[0158] The first request message is sent by the first network function after receiving the first message sent by the terminal, and the first message includes the identifier of the terminal and the first information.

[0159] In a seventh aspect, embodiments of this disclosure also provide a terminal, which includes:

[0160] The transceiver module is configured to send a first message to a first network function, the first message including: the identifier of the terminal and first information sent to a second network function; and to receive a second message sent by the first network function, the second message including: response information of the first information sent by the second network function to the terminal;

[0161] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0162] Eighthly, embodiments of this disclosure also provide a security anchor point function, including:

[0163] The transceiver module is used to receive a third request message sent by the second network function. The third request message includes: the identifier of the terminal and the second identifier of the second network function.

[0164] The processing module is configured to generate a key related to the second network function based on the security anchor key, the identifier of the terminal, and the second identifier. The key is used to generate a first security context, which is a non-access stratum related security context associated with the second network function.

[0165] The transceiver module is further configured to send a third response message to the second network function, the third response message including a key related to the second network function;

[0166] The first security context is used to protect the response information of the first information sent by the second network function to the terminal.

[0167] In a ninth aspect, embodiments of this disclosure also provide a first network function, including:

[0168] One or more processors;

[0169] The first network function is used to execute the communication method described in the embodiments of the first aspect of this disclosure.

[0170] In a tenth aspect, embodiments of this disclosure also provide a second network function, including:

[0171] One or more processors;

[0172] The second network function is used to perform the communication method described in the embodiments of the second aspect of this disclosure.

[0173] In an eleventh aspect, embodiments of this disclosure also provide a terminal, including:

[0174] One or more processors;

[0175] The terminal is used to execute the communication method described in the embodiments of the third aspect of this disclosure.

[0176] In a twelfth aspect, embodiments of this disclosure also provide a security anchor point function, including:

[0177] One or more processors;

[0178] The security anchor function is used to execute the communication method described in the embodiments of the fourth aspect of this disclosure.

[0179] In a thirteenth aspect, embodiments of this disclosure also provide a communication system, including: a first network function, a second network function, a terminal, and a security anchor function; wherein the first network function is configured to implement the communication method described in the embodiments of the first aspect of this disclosure, the second network function is configured to implement the communication method described in the embodiments of the second aspect of this disclosure, the terminal is configured to implement the communication method described in the embodiments of the third aspect of this disclosure, and the security anchor function is configured to implement the communication method described in the embodiments of the fourth aspect of this disclosure.

[0180] In a fourteenth aspect, embodiments of this disclosure also provide a communication system, including: a first network function, a second network function, and a security anchor function; wherein the first network function is configured to implement the communication method described in the embodiments of the first aspect of this disclosure, the second network function is configured to implement the communication method described in the embodiments of the second aspect of this disclosure, and the security anchor function is configured to implement the communication method described in the embodiments of the fourth aspect of this disclosure.

[0181] In a fifteenth aspect, embodiments of this disclosure also provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the communication method as described in the embodiments of the first, second, third, or fourth aspects of this disclosure.

[0182] In a sixteenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in an optional implementation of the first, second, third, or fourth aspect.

[0183] In a seventeenth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described according to optional implementations of the first, second, third, or fourth aspects above.

[0184] It is understood that the aforementioned terminals, network devices, communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0185] This disclosure provides communication methods, communication devices, and storage media. In some embodiments, the terms "communication method" and "signal processing method," "signal transmission method," etc., can be used interchangeably, as can the terms "information processing system," "communication system," etc.

[0186] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0187] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0188] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0189] In the embodiments disclosed herein, "multiple" refers to two or more.

[0190] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0191] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.

[0192] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.

[0193] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0194] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0195] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.

[0196] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.

[0197] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0198] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.

[0199] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).

[0200] In addition, terms such as "uplink" and "downlink" can be replaced with terms corresponding to inter-terminal communication (e.g., "side"). For example, uplink channel and downlink channel can be replaced with side channel, and uplink link and downlink link can be replaced with side link.

[0201] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cellgroup," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)," etc.

[0202] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.

[0203] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0204] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0205] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0206] like Figure 1a As shown, the communication system 100 includes a terminal 101 and a network device 102.

[0207] In some embodiments, terminal 101 may be, for example, a user equipment (UE) or an artificial intelligence (AI) agent. Examples include, but are not limited to, at least one of the following: mobile phone, wearable device, IoT device, car with communication capabilities, smart car, tablet, computer with wireless transceiver capabilities, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.

[0208] In some embodiments, a network device can be a functional network element within a core network device. A core network device can be a single device comprising one or more network elements, or it can be multiple devices or a group of devices, each comprising all or part of one or more network elements. Network elements can be virtual or physical. The core network includes, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0209] In some embodiments, the network device may include at least one of an access network device and a core network device.

[0210] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.

[0211] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.

[0212] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.

[0213] In some embodiments, a core network device may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, each comprising all or part of the aforementioned one or more network elements. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), or a Next Generation Core (NGC).

[0214] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.

[0215] The following embodiments of this disclosure can be applied to Figure 1a The communication system shown, or part of the main body, but not limited to it. Figure 1a The entities shown are illustrative; a communication system may include... Figure 1a All or part of the main body, or may include Figure 1a Other entities besides the main body, the number and form of each entity are arbitrary, each entity can be physical or virtual, the connection relationship between the entities is illustrative, the entities can be unconnected or connected, and the connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.

[0216] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), 6th generation mobile communication system (6G), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).

[0217] The new 6G system architecture should support simplified network functions (NFs) to improve efficiency in areas such as capacity, coverage, signaling overhead, scalability, and energy consumption. Dependencies between network functions can lead to unnecessary complexity and even latency. By redesigning network functions, dependencies and the number of processing points can be reduced.

[0218] In current 5G systems, Non-Access Stratum (NAS) signaling is only supported between User Equipment (UE) and the Access and Mobility Management Function (AMF) in the core network (transparently transmitted through Radio Access Network (RAN) nodes). For example... Figure 1b As shown, for the signaling exchanged between the UE and other 5G core network functions (5GC NF), the AMF is responsible for processing the NAS signaling and forwarding the NAS container to the target 5GC NF.

[0219] like Figure 1b As shown, the 5G core network access connection endpoint is established on top of the AMF, which can be regarded as the anchor of the 5GC (5G corenetwork). Other signaling, such as SM (Session Management), SMS (Short Message Service), UE Policy, and LCS (Location Services), are carried on top of NAS-MM (Non-Access Stratum-Mobility Management). The current NAS protocol design has the following technical limitations:

[0220] The single anchor point of the protocol leads to signaling routing: NAS connections are established via the AMF, and all uplink and downlink service processing must pass through the AMF. Typically, the AMF is deployed at a high location, which causes signaling routing in 5G networks.

[0221] Unclear Functionality: Mobility management is a basic function of AMF. Other functions (such as session management and UE policies) are closely related to AMF. Modifications to other functions will affect the functionality of AMF.

[0222] To overcome the limitations of current NAS designs, a distributed NAS connectivity architecture is proposed for 6G networks. The goal of the distributed NAS mechanism is to enable user equipment (UE) to establish a NAS connection with the target 6GC NF, thereby improving the performance of the 6G system.

[0223] In some embodiments, a routing function (RF) is proposed in conjunction with distributed NAS connections, aiming to extend the traditional single-AMF anchor model to support each UE in establishing multiple concurrent connections simultaneously in heterogeneous access (3GPP, WiFi, satellite, sensing) and diverse network slices. For example... Figure 1c As shown, the RF dynamically routes NAS messages to appropriate Network Function (NF) instances based on real-time factors such as NSSAI, UE location, access type, network load, and service requirements. Simultaneously, it achieves load balancing among distributed core nodes and ensures low-latency processing through intelligent path selection. Without this centralized routing intelligence, the distributed architecture would face problems such as connection state fragmentation, suboptimal NF selection, increased signaling overhead, and inability to support dynamic slice switching and multi-access coordination—all fundamental to 6G's service-oriented architecture.

[0224] However, the introduction of routing functionality (RF) presents challenges to the security architecture of distributed NAS connections. Currently, NAS security is only supported by the UE and AMF. Figure 1d The key hierarchy in the key, key access management function (K AMF (As the root of NAS security) is derived from the UE and the Security Anchor Function (SEAF), while K is used for NAS integrity protection and NAS confidentiality protection. NASint and K NASenc These are derived from the UE and AMF respectively. Furthermore, no other core network function (NF) can derive the NAS security key.

[0225] Because other core network functions (NFs) cannot support Non-Access Stratum (NAS) security through the current key hierarchy design, NAS signaling between user equipment (UE) and other core network functions cannot be protected. If NAS signaling between the UE and network functions is not protected, then NAS signaling information is at risk of being spoofed or eavesdropped if the radio access network (RAN) node forwarding the NAS signaling is compromised.

[0226] If routing functionality (RF) is introduced, the non-access stratum (NAS) architecture has two options:

[0227] 1) There are two layers of e2e NAS connections. One layer is the low-level end-to-end NAS connection between the UE and the RF, and the other layer is the high-level end-to-end NAS connection between the UE and other core network functions (core NFs).

[0228] 2) One layer of NAS connection. All NAS messages terminate at the RF, while control information between the UE and other core NFs is contained in different NAS containers dedicated to specific NFs, which are routed to the corresponding NFs by the RF.

[0229] For both of these approaches, it is necessary to investigate how to enable security protection for a 6G distributed NAS architecture with routing capabilities.

[0230] The existing 5G security key hierarchy does not support NAS signaling between the UE and core network functions (NFs) other than the AMF.

[0231] In response, some solutions have proposed different methods to protect multiple NAS connections between the UE and different Network Functions (NFs), but these methods are all based on architectures without Routing Functions (RFs). This means that the NAS connections between the UE and the RF are unprotected, and existing methods cannot be directly used in distributed NAS architectures with RFs.

[0232] Therefore, this disclosure provides a communication method that enables NAS security between a UE and network functions in specific network services within a 6G distributed NAS architecture.

[0233] Therefore, this application provides a communication method in its embodiments, as detailed in the following description in conjunction with the accompanying drawings.

[0234] To support multiple NAS connections, there are two options for protecting NAS connections:

[0235] Option 1: One layer of NAS security. The NAS connection between the UE and the RF is protected by NAS security. NAS messages or NAS containers received from the UE for specific network services and destined for specific NFs are terminated and decoded by the RF and forwarded to the corresponding NF. This forwarding process is protected by the Service-Based Architecture (SBA) security between the RF and the NF.

[0236] Option 2: Two-layer NAS security. The lower-layer NAS security is located between the UE and the RF, while the upper-layer NAS security is located between the UE and a specific NF (including Mobility Management Function (MMF) or Access Management Function (AMF)). The lower-layer NAS security protects the entire NAS message between the UE and the RF, while the upper-layer NAS security protects NAS messages or NAS containers contained in NAS messages that terminate the routing function for different NFs.

[0237] In embodiments of this disclosure, a key generation and configuration method for establishing NAS security between the UE and the NF is introduced. Since there is no higher-level NAS security between the UE and the NF in Option 1, the solution in embodiments of this disclosure addresses the problem in Option 2.

[0238] For option 2, in order to support higher-level NAS security, each other specific NF needs to have its own root key K. NF For NAS security between the UE and the corresponding NF, such as the K of the Sensing Function (SF). NF For K SF Therefore, the new key hierarchy structure proposed in this disclosure is as follows: Figure 1e As shown.

[0239] Figure 2a This is one of the interactive schematic diagrams of the communication method provided in this embodiment of the disclosure. For example... Figure 2a The communication methods shown include:

[0240] S20, The terminal sends the first message to the first network function.

[0241] In some embodiments, the first message includes: the identifier of the terminal and first information to be sent to the second network function.

[0242] In some embodiments, the first network function may be a routing function (RF), but the naming of the first network function is not limited to this.

[0243] In some embodiments, the second network function may be a core network function, such as, but not limited to, a Mobility Management Function (MMF) or Access Management Function (AMF), a Sensing Function (SF), etc.

[0244] In some embodiments, the first information includes a Non-Access Stratum (NAS) message sent to the second network function, or the first information includes a NAS container sent to the second network function.

[0245] S21. The first network function sends a second message to the terminal.

[0246] In some embodiments, the second message includes: response information to the first information sent by the second network function to the terminal.

[0247] In some embodiments, the response information of the first information is protected using a first security context. Optionally, the first security context is a non-access stratum-related security context associated with a second network function.

[0248] In some embodiments, the response information of the first information includes the first identifier.

[0249] In some embodiments, the first identifier may be a temporary UE identifier assigned to the terminal by the second network function, such as GUTI (Globally Unique Temporary UE Identity), but the naming of the first identifier is not limited to this.

[0250] The solution in this embodiment of the disclosure can provide secure protection for NAS messages between the terminal and the second network function.

[0251] Figure 2b This is the second interactive schematic diagram of the communication method provided in this embodiment. For example... Figure 2b The communication methods shown include:

[0252] S201, The terminal sends the first message to the first network function.

[0253] In some embodiments, the first message includes the identifier of the terminal and first information to be sent to the second network function.

[0254] In some embodiments, the first message may be an initial uplink NAS message, but the message name is not limited to this.

[0255] In some embodiments, the first message includes: the identifier of the terminal and first information to be sent to the second network function.

[0256] Optionally, the terminal identifier may include a SUCI (Subscription Concealed Identifier) ​​or a GUTI (Globally Unique Temporary UE Identity) for the first network function. If a GUTI for the second network function is available, the terminal identifier may include the GUTI for the second network function. The naming of the temporary identifier is not limited to GUTI.

[0257] In some embodiments, the first network function may be a routing function (RF), but the naming of the first network function is not limited to this.

[0258] In some embodiments, the first information includes a Non-Access Stratum (NAS) message sent to the second network function, or the first information includes a NAS container sent to the second network function.

[0259] Optionally, if the second network function is NF, the first message may include: NAS container to NF.

[0260] In some embodiments, the first message is used to request a specific network service provided by an NF (such as a sensing function). Through this step, the first network function is able to access network service requests for a second network function or a NAS container.

[0261] In some embodiments, the second network function may be a core network function, such as, but not limited to, a Mobility Management Function (MMF) or Access Management Function (AMF), a Sensing Function (SF), etc.

[0262] S202, The first network function sends a first request message to the second network function.

[0263] In some embodiments, the first request message includes first information and an identifier of the terminal. Optionally, the identifier of the terminal is used to generate a first identifier. Optionally, the first identifier may be a temporary terminal identifier assigned to the terminal by a second network function, such as a GUTI, but not limited thereto.

[0264] In some embodiments, after receiving the first message, the first network function can select an appropriate second network function (e.g., an NF instance). Optionally, the first network function can assign a second identifier to the selected second network function. Optionally, the second identifier can be a routing ID, but is not limited to this, and routes the first message to the selected second network function.

[0265] In some embodiments, the first request message may be a network service operation request message, such as the Nnf_NetworkService_Operation Request message, but the message name is not limited to this.

[0266] In some embodiments, if the terminal identifier included in the first message is a terminal temporary identifier (such as an RF GUTI) of a first network function, the first network function can map the terminal temporary identifier (such as an RF GUTI) of the first network function to the unique user equipment identifier (SUPI) of the UE. Then, the first network function can send a network service operation request message (e.g., containing a NAS container) to a selected second network function.

[0267] Optionally, the message may also include: SUPI, and a temporary terminal identifier for the first network function (such as RF GUTI).

[0268] Optionally, the message may also include a second identifier for the second network function (such as a routing ID).

[0269] S203, The second network function generates its own temporary terminal identifier (such as NF GUTI).

[0270] In some embodiments, if a second network function receives a temporary terminal identifier of the first network function from the first network function, the second network function can create a temporary terminal identifier of the second network function based on the received temporary terminal identifier of the first network function.

[0271] In some embodiments, if the first request message in step S202 does not include a second identifier, that is, the second network function has not received a second identifier from the first network function, the second network function may also create its own second identifier (such as a route ID).

[0272] It should be noted that step S203 is optional.

[0273] S204. The second network function sends a third request message to the security anchor function.

[0274] In some embodiments, the third request message includes: the terminal's identifier and a second identifier.

[0275] Optionally, the second identifier is used to generate a key related to the second network function.

[0276] Optionally, the second identifier can be the routing ID of the second network function.

[0277] Optionally, the second network function-related key is used to generate the first security context. For example, the second network function-related key can be denoted as: K NF .

[0278] Optionally, the first security context is a non-access stratum-related security context associated with the second network function. For example, the first security context could be a NAS NF security context.

[0279] Optionally, the first security clause is used to protect the response information of the first information.

[0280] In some embodiments, the third request message may be a key request message, such as an Nseaf_NAS_Key request message, but the message name is not limited to this.

[0281] In some embodiments, the second network function sends an Nseaf_NAS_Key request to the Security Anchor Function (SEAF), which may include the terminal's identifier (e.g., the terminal temporary identifier GUTI created by the second network function and / or the SUPI received from the first network function), and / or a second identifier (such as the routing ID of the network function).

[0282] S205, The security anchor function generates keys related to the second network function.

[0283] In some embodiments, after receiving a third request message, the security anchor function determines the security anchor key based on the terminal's identifier, and then generates a key related to the second network function based on the security anchor key, the terminal's identifier, and the second identifier.

[0284] In some embodiments, after receiving the Nseaf_NAS_Key request, the security anchor function first retrieves the security anchor key K based on the received SUPI. SEAF Then, based on the key derivation function KDF, using the terminal temporary identifier GUTI of SUPI or the second network function and a second identifier (such as the route ID), from K... SEAF Derive the key K related to the second network function NF .

[0285] S206, The security anchor function sends a third response message to the second network function.

[0286] In some embodiments, the third response message includes the key associated with the second network function.

[0287] In some embodiments, the third response message may be an Nseaf_NAS_Key Response message, but the message name is not limited to this.

[0288] Optionally, the security anchor feature can transmit the derived K via the Nseaf_NAS_Key Response message. NF Return to the second network function.

[0289] S207. The second network function stores the key associated with the second network function.

[0290] In some embodiments, the second network function stores the received K NF .

[0291] In some embodiments, if the second network function does not perform step S203 as described above, then step S208 is performed as described below.

[0292] S208, The second network function generates its own temporary terminal identifier (such as GUTI).

[0293] In some embodiments, if the second network function does not create a temporary terminal identifier for the second network function in step S203, a temporary terminal identifier for the second network function can be created based on SUPI in this step.

[0294] In some embodiments, if the first request message in step S202 does not include a second identifier (such as a route ID) for the second network function, the second network function may also create its own second identifier.

[0295] S209, The second network function sends a first response message to the first network function.

[0296] In some embodiments, the first response message includes a first security-related message. Optionally, the first security-related message is a non-access stratum security-related message related to a second network function.

[0297] Optionally, the first security-related message may be a Non-Access Stratum Network Functional Safety Mode Command (SMC) message (NAS NF SMC message), but the message name is not limited to this.

[0298] In some embodiments, the first response message may be a network service operation response message, such as the Nnf_NetworkService_Operation Response message, but the message name is not limited to this.

[0299] In some embodiments, the second network function initiates a NAS NF SMC procedure to the UE by sending a NAS NF SMC message, which is embedded in the network service operation response. Optionally, the NAS NF SMC message is based on the received key (K). NF It is protected by the security context.

[0300] In some embodiments, if a temporary terminal identifier for a second network function has been created, the second network function will also send it to the first network function.

[0301] In some embodiments, if the second identifier of the second network function is not received from the first network function in step S202, the created second identifier is sent to the first network function.

[0302] S2010, The first network function sends a third message to the terminal.

[0303] In some embodiments, the third message may include at least one of the following: a second identifier of the second network function, a first security-related message, and a temporary terminal identifier of the second network function.

[0304] In some embodiments, the third message may be a downlink NAS message, but the message name is not limited to this.

[0305] In some embodiments, the first network function may forward the NAS NF SMC message to the terminal in a downlink NAS message. Optionally, the message may also include a second identifier of the second network function.

[0306] In some embodiments, if the first network function receives the terminal temporary identifier of the second network function from the second network function, the first network function will encrypt the terminal temporary identifier of the second network function using a second security context, and then send the encrypted terminal temporary identifier of the second network function to the UE together with the NAS NF SMC message.

[0307] Optionally, the second security context is a non-access stratum-related security context associated with the first network function. For example, the second security context could be a NAS RF security context.

[0308] S2011, The terminal generates a key related to the second network function.

[0309] In some embodiments, after receiving a NAS NF SMC message, the terminal can, according to the key derivation function KDF, use the terminal temporary identifier of SUPI or the second network function and the second identifier to derivate from K... SEAF Derive the key K related to the second network function NF .

[0310] In some embodiments, if the terminal receives any information encrypted by the first network function, the terminal will use the NAS RF security context to decrypt the information (e.g., the terminal temporary identifier of the second network function).

[0311] S2012, The terminal sends a fourth message to the first network function.

[0312] In some embodiments, the fourth message includes a second security-related message. Optionally, the second security-related message is a response message to the first security-related message.

[0313] In some embodiments, the second security-related message is a response message to a security-related message from a non-access stratum associated with a second network function.

[0314] Optionally, the second security-related message can be a completion message or a rejection message. For example, if the first security-related message is a NAS NF SMC message, the second security-related message can be a NAS NF SMC Completemessage or a NAS NF SMC reject message, but the message name is not limited to these.

[0315] In some embodiments, the terminal may create a NAS NF security context and return a NASNF SMC completion message to the first network function.

[0316] In some embodiments, the second security-related message includes second information sent to the second network function. Optionally, the second information is protected using a first security context.

[0317] In some embodiments, the second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function; wherein the second information is used by the second network function to verify the first information.

[0318] In some embodiments, if in step S209 the second network function requests the terminal to send a complete NAS message or NAS container for a specific network service, the terminal includes the complete NAS message or NAS container in the NAS NF SMC completion message. It should be noted that this message cannot be terminated or decoded by the first network function. That is, the first network function cannot decode the message and can only pass it through to the second network function.

[0319] S2013, The first network function sends a second request message to the second network function.

[0320] In some embodiments, the second request message includes the aforementioned second security-related message.

[0321] In some embodiments, the second request message may be a network service operation request message, such as the Nnf_NetworkService_Operation Request message, but the message name is not limited to this.

[0322] In some embodiments, the first network function forwards the NAS NF SMC completion message to the second network function.

[0323] S2014, The second network function sends a second response message to the first network function.

[0324] In some embodiments, the second response message may be a network service operation response message, such as Nnf_NetworkService_Operation Response, but the message name is not limited to this.

[0325] In some embodiments, after receiving the NAS NF SMC completion message, the second network function completes the NAS security establishment. Then, the second network function returns a network service operation response protected by NAS security.

[0326] In some embodiments, if a temporary terminal identifier for the second network function is not created in step S203 or step S208 above, the second network function will create a temporary terminal identifier for the second network function in this step and send the temporary terminal identifier for the second network function encrypted with a NASNF security context (which may correspond to the first security context mentioned above) to the second response message.

[0327] S2015, The first network function sends a second message to the terminal.

[0328] In some embodiments, the second message includes response information to the first information sent by the second network function to the terminal.

[0329] Optionally, the response information of the first information is protected using a first security context. Optionally, the first security context is a non-access stratum-related security context related to the second network function.

[0330] In some embodiments, the response information of the first information includes a terminal temporary identifier of the second network function.

[0331] In some embodiments, the second message may be a downlink NAS message, but the message name is not limited to this.

[0332] In some embodiments, the first network function forwards a downlink NAS message to the terminal, the message including a terminal temporary identifier of the second network function protected by a first security context.

[0333] In some embodiments of this disclosure, in steps S205 and S2011 above, from K SEAF-S Derive K RF The following parameters can be used to construct the input S of the KDF:

[0334] FC = Pending

[0335] P0 = User Equipment Identifier (e.g., SUPI or First Identifier (e.g., NF GUTI))

[0336] The length of L0 = P0

[0337] P1 = Second identifier (e.g., NF route ID)

[0338] The length of L1 = P1

[0339] P2 = Preset parameters (e.g., ABBA parameters)

[0340] The length of L2 = P2

[0341] The input key is K. SEAF-S .

[0342] It should be noted that using the NF route ID as an input parameter is for the following purpose:

[0343] When the NF changes, key isolation is performed on the different network access service (NAS) connections between the UE and different NF instances;

[0344] Key isolation is performed between the UE and different NAS connections between the same NF built at different times.

[0345] For preset parameters (such as ABBA parameters), a new value was added for KRF derivation in 6G.

[0346]

[0347] It should be understood that the steps involved in the methods of this disclosure can be arbitrarily rearranged or combined without conflict.

[0348] It should also be understood that the steps involved in the methods of this disclosure can be implemented individually or in any order and combination without contradiction. For example, the steps in the embodiments of this disclosure can be combined, or the steps in the embodiments of this disclosure can be combined with one or more steps in other embodiments.

[0349] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0350] In some embodiments, terms such as “moment,” “point in time,” “time,” and “time location” can be used interchangeably, as can terms such as “duration,” “segment,” “time window,” “window,” and “time.”

[0351] In some embodiments, terms such as wireless access scheme and waveform can be used interchangeably.

[0352] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.

[0353] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (boolean), or by a comparison of numerical values ​​(e.g., a comparison with a predetermined value), but is not limited thereto.

[0354] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the receiver to respond to the sent content.

[0355] Figure 3 This is one of the flowcharts illustrating the communication method provided in this embodiment. For example... Figure 3 The communication method shown can be performed by a first network function, and the communication method includes:

[0356] S301, Get the first message.

[0357] In some embodiments, obtaining a message can be understood as receiving a message. Optionally, receiving a first message sent by the receiving terminal.

[0358] In some embodiments, the first message includes: the identifier of the terminal and first information to be sent to the second network function.

[0359] In some embodiments, the response information of the first information includes a first identifier assigned to the terminal by the second network function.

[0360] In some embodiments, the first identifier is a temporary terminal identifier.

[0361] For optional implementations of step S301, please refer to... Figure 2a In step S20 or Figure 2b The optional implementation methods related to step S201 will not be elaborated here.

[0362] S302, Send the second message.

[0363] In some embodiments, a second message is sent to the terminal. Optionally, the second message includes response information to the first information sent to the terminal by the second network function.

[0364] In some embodiments, the response information of the first information is protected using a first security context, which is a non-access stratum-related security context associated with the second network function.

[0365] In some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0366] For optional implementations of step S302, please refer to... Figure 2a In step S21 or Figure 2b The optional implementation methods related to step S2015 will not be described in detail here.

[0367] In some embodiments, the communication method further includes:

[0368] Send a first request message to the second network function.

[0369] Optionally, the first request message includes the first information and the identifier of the terminal, wherein the identifier of the terminal is used to generate the first identifier;

[0370] Receive the first response message sent by the second network function.

[0371] Optionally, the first response message includes a first security-related message, which is a non-access stratum security-related message related to the second network function.

[0372] In some embodiments, the first request message further includes: a second identifier assigned to the second network function. Optionally, the second identifier is used to generate a key associated with the second network function. Optionally, the key is used to generate the first security context.

[0373] In some embodiments, the second identifier is a route ID.

[0374] In some embodiments, the first response message may further include the first identifier.

[0375] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to steps S202 and S209 will not be elaborated here.

[0376] In some embodiments, the communication method further includes:

[0377] Send a third message to the terminal, the third message including at least one of the following: the second identifier, the first security-related message, and the first identifier;

[0378] The terminal sends a fourth message, which includes a second security-related message, and the second security-related message is a response message to the first security-related message.

[0379] In some embodiments, the first identifier is protected using a second security context, which is a non-access stratum-related security context associated with the first network function.

[0380] In some embodiments, the second security-related message includes: second information sent to the second network function, the second information being protected using the first security context.

[0381] In some embodiments, the second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function.

[0382] In some embodiments, the second information is used by the second network function to verify the first information.

[0383] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to steps S2010 and S2012 will not be described in detail here.

[0384] In some embodiments, the communication method further includes:

[0385] Send a second request message to the second network function, the second request message including the second security-related message;

[0386] The terminal receives a second response message sent by the second network function, the second response message including response information of the first information sent by the second network function to the terminal.

[0387] In some embodiments, the second message is sent after the second response message is received.

[0388] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to steps S2013 and S2014 will not be elaborated here.

[0389] It should be understood that the steps involved in the methods of this disclosure can be arbitrarily rearranged or combined without conflict.

[0390] It should also be understood that the steps involved in the methods of this disclosure can be implemented individually or in any order and combination without contradiction. For example, the steps in the embodiments of this disclosure can be combined, or the steps in the embodiments of this disclosure can be combined with one or more steps in other embodiments.

[0391] Figure 4a This is a second schematic flowchart of the communication method provided in this embodiment. Figure 4a The communication method shown can be performed by a second network function, which includes:

[0392] S401, Obtain the first request message.

[0393] In some embodiments, obtaining a message can be understood as receiving a message. Optionally, receiving a first request message sent by a first network function.

[0394] In some embodiments, the first request message includes: first information sent to the second network function and an identifier of the terminal, wherein the identifier of the terminal is used to generate a first identifier assigned to the terminal by the second network function.

[0395] In some embodiments, the first identifier may be a temporary terminal identifier, such as GUTI.

[0396] For optional implementations of step S401, please refer to... Figure 2b The optional implementation methods related to step S202 will not be described in detail here.

[0397] S402, Send the first response message.

[0398] In some embodiments, a first response message is sent to the first network function.

[0399] In some embodiments, the first response message includes a first security-related message, which is a non-access stratum security-related message related to the second network function.

[0400] In some embodiments, the first request message is sent by the first network function after receiving a first message sent by the terminal, and the first message includes the identifier of the terminal and the first information.

[0401] In some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0402] In some embodiments, the first request message further includes: a second identifier assigned by the first network function to the second network function. Optionally, the second identifier is used to generate a key associated with the second network function. Optionally, the second identifier is a route ID.

[0403] In some embodiments, the key is used to generate a first security context. Optionally, the first security context is a non-access stratum-related security context associated with the second network function. Optionally, the first security context is used to protect response information of the first information.

[0404] For optional implementations of step S402, please refer to... Figure 2b The optional implementation methods related to step S209 will not be described in detail here.

[0405] In some embodiments, the communication method further includes:

[0406] The first identifier is generated based on the identifier of the terminal;

[0407] Alternatively, generate a second identifier for the second network function.

[0408] In some embodiments, the first response message may further include the first identifier.

[0409] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to steps S203 or S208 will not be described in detail here.

[0410] In some embodiments, the communication method further includes:

[0411] Receive a second request message sent by the first network function, the second request message including a second security-related message;

[0412] Send a second response message to the first network function, the second response message including response information of the first information sent by the second network function to the terminal.

[0413] In some embodiments, the second security-related message is received by the first network function from the terminal, and the second security-related message is a response message to the first security-related message.

[0414] In some embodiments, the response information of the first information is protected using a first security context, which is a non-access stratum-related security context associated with the second network function.

[0415] In some embodiments, the response information of the first information may further include the first identifier.

[0416] In some embodiments, the second security-related message includes second information sent to a second network function, the second information being protected using the first security context.

[0417] In some embodiments, the second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function.

[0418] In some embodiments, the second information is used by the second network function to verify the first information.

[0419] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to steps S2013 and S2014 will not be elaborated here.

[0420] In some embodiments, the communication method further includes:

[0421] A third request message is sent to the security anchor function. The third request message includes: the identifier of the terminal and the second identifier of the second network function, wherein the second identifier of the second network function is used to generate a key related to the second network function, and the key is used to generate a first security context.

[0422] Receive a third response message sent by the security anchor function, the third response message including the key related to the second network function.

[0423] In some embodiments, the first response message is sent after the third response message is received.

[0424] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to steps S204 and S206 will not be elaborated here.

[0425] It should be understood that the steps involved in the methods of this disclosure can be arbitrarily rearranged or combined without conflict.

[0426] It should also be understood that the steps involved in the methods of this disclosure can be implemented individually or in any order and combination without contradiction. For example, the steps in the embodiments of this disclosure can be combined, or the steps in the embodiments of this disclosure can be combined with one or more steps in other embodiments.

[0427] Figure 4b This is the third flowchart illustrating the communication method provided in this embodiment. Figure 4b The communication method shown can be executed by a terminal, and the communication method includes:

[0428] S411, Send the first message.

[0429] In some embodiments, a first message is sent to a first network function.

[0430] In some embodiments, the first message includes: the identifier of the terminal and first information to be sent to the second network function.

[0431] In some embodiments, the response information of the first information includes a first identifier of the second network function. Optionally, the first identifier is a temporary terminal identifier.

[0432] For optional implementations of step S411, please refer to... Figure 2a In step S20 or Figure 2b The optional implementation methods related to step S201 will not be elaborated here.

[0433] S412, Get the second message.

[0434] In some embodiments, obtaining a message can be understood as receiving a message. Optionally, receiving a second message sent by the first network function.

[0435] In some embodiments, the second message includes: response information to the first information sent by the second network function to the terminal.

[0436] In some embodiments, the response information of the first information is protected using a first security context, which is a non-access stratum-related security context associated with the second network function.

[0437] In some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0438] For optional implementations of step S412, please refer to... Figure 2a In step S21 or Figure 2b The optional implementation methods related to step S2015 will not be described in detail here.

[0439] In some embodiments, the communication method further includes:

[0440] Receive a third message sent by the first network function, the third message including at least one of the following: the second identifier, the first identifier, and the first security-related message.

[0441] Optionally, the first security-related message is a non-access stratum security-related message related to the second network function.

[0442] A fourth message is sent to the first network function, the fourth message including a second security-related message. Optionally, the second security-related message is a response message to the first security-related message.

[0443] In some embodiments, the first identifier is protected using a second security context, which is a security context associated with the first network function non-access stratum.

[0444] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to steps S2010 and S2012 will not be described in detail here.

[0445] In some embodiments, the communication method further includes:

[0446] Based on the security anchor key, the identifier of the terminal, and the second identifier of the second network function, a key related to the second network function is generated. Optionally, the key is used to generate the first security context.

[0447] The above optional implementation methods can be referred to Figure 2b The optional implementation methods related to step S2011 will not be described in detail here.

[0448] In some embodiments, the second security-related message includes second information sent to the second network function, the second information being protected using the first security context.

[0449] In some embodiments, the second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function.

[0450] In some embodiments, the second information is used by the second network function to verify the first information.

[0451] In some embodiments, the second identifier of the second network function is assigned by the first network function, or the second identifier of the second network function is generated by the second network function. Optionally, the second identifier is a route ID.

[0452] It should be understood that the steps involved in the methods of this disclosure can be arbitrarily rearranged or combined without conflict.

[0453] It should also be understood that the steps involved in the methods of this disclosure can be implemented individually or in any order and combination without contradiction. For example, the steps in the embodiments of this disclosure can be combined, or the steps in the embodiments of this disclosure can be combined with one or more steps in other embodiments.

[0454] Figure 4c This is the fourth flowchart illustrating the communication method provided in this embodiment. Figure 4c The communication method shown can be performed by the security anchor function, and the communication method includes:

[0455] S421. Obtain the third request message.

[0456] In some embodiments, obtaining a message can be understood as receiving a message. Optionally, a third request message sent by a second network function is received. Optionally, the third request message includes: an identifier of the terminal and a second identifier of the second network function. Optionally, the second identifier is a routing ID.

[0457] For optional implementations of step S421, please refer to... Figure 2b The optional implementation methods related to step S204 will not be elaborated here.

[0458] S422, Generate the key related to the second network function.

[0459] In some embodiments, a key related to the second network function is generated based on the security anchor key, the identifier of the terminal, and the second identifier of the second network function.

[0460] In some embodiments, the key is used to generate a first security context. Optionally, the first security context is a non-access stratum-related security context associated with the second network function.

[0461] For optional implementations of step S422, please refer to... Figure 2b The optional implementation methods related to step S205 will not be described in detail here.

[0462] S423, Send the third response message.

[0463] In some embodiments, a third response message is sent to the second network function. Optionally, the third response message includes a key associated with the second network function.

[0464] In some embodiments, the first security context is used to protect the response information of the first information sent by the second network function to the terminal.

[0465] In some embodiments, the first information includes a non-access stratum message sent to the second network function, or the first information includes a non-access stratum container sent to the second network function.

[0466] In some embodiments, the response information of the first information includes a first identifier assigned to the terminal by the second network function.

[0467] In some embodiments, the first identifier is a terminal temporary identifier, such as GUTI.

[0468] For optional implementations of step S423, please refer to... Figure 2b The optional implementation methods related to step S206 will not be described in detail here.

[0469] The following is combined Figure 5 Regarding the solution proposed in this disclosure embodiment, specifically for the K stage in the NAS security establishment process between the UE and NF... NF The generation process is described in detail.

[0470] For each specific NF (which can correspond to the second network function mentioned above) except for MMF, K NF It is generated during the corresponding network service request process, such as... Figure 5 As shown.

[0471] S501, the UE sends an initial uplink NAS message (which can correspond to the first message mentioned above). This message contains a network service request, which is used to request a specific network service provided by the NF (such as the sensing function).

[0472] Optionally, the message includes the terminal's identifier (e.g., SUCI or RF GUTI, or NF GUTI (if available)). This step enables the RF to access network service requests or NAS containers targeting the NF.

[0473] S502. After receiving an uplink NAS message for a specific network service, the RF (which can correspond to the first network function mentioned above) selects an appropriate NF instance.

[0474] Optionally, the RF can assign a routing ID to the selected NF and route uplink NAS messages to the selected NF instance.

[0475] In some embodiments, if the RF receives an RF GUTI from the UE, it can first map the RF GUTI to the UE's Unique User Equipment Identifier (SUPI). Then, the RF sends a Network Service Operation Request message (which may correspond to the first request message mentioned above, for example, containing a NAS container) to the selected NF. Optionally, this message may also include the SUPI, RF GUTI, or the NF's routing ID sent to the NF.

[0476] S503. If the NF receives an RF GUTI from the RF, the NF can create a new NF GUTI based on the received RF GUTI.

[0477] Optionally, if the NF does not receive a route ID from the RF, the NF will create the route ID itself.

[0478] It should be noted that step S503 is optional.

[0479] S504, the NF sends an Nseaf_NAS_Key request (which can correspond to the third request message mentioned above) to the Security Anchor Function (SEAF). This request includes the created NF GUTI, the SUPI received from the RF, or the route ID.

[0480] S505. Upon receiving the Nseaf_NAS_Key request, SEAF first retrieves the Key based on the received SUPI. SEAF Then, based on KDF, use SUPI or NF GUTI, and the route ID from K... SEAF Derive K NF .

[0481] S506, SEAF uses the Nseaf_NAS_Key Response message (which corresponds to the third response message mentioned above) to retrieve the derived K. NF Return to NF.

[0482] S507, NF stores the received K NF .

[0483] S508. If NF-GUTI was not created in step S503, NF-GUTI may be created based on SUPI in this step.

[0484] S509, NF sends a key (K) based on the received key. NF The NAS NF SMC message with security context protection initiates the NAS NF SMC procedure to the UE. This message is embedded in the network service operation response (which can correspond to the first response message mentioned above).

[0485] In some embodiments, if an NF-GUTI has been created, the NF will also send it to the RF; if a route ID is not received from the RF in step S502, the created route ID will be sent to the RF.

[0486] In the downlink NAS message (which can correspond to the third message mentioned above), S5010 and RF forward the NAS NF SMC message (which can correspond to the first security-related message mentioned above) to the UE. This message also contains the routing ID of the NF.

[0487] In some embodiments, if the RF receives an NF GUTI from the NF, the RF will first encrypt the NF GUTI using the NAS RF security context (which may correspond to the second security context mentioned above), and then send the encrypted NF GUTI to the UE together with the NASNF SMC message.

[0488] S5011, after receiving the NAS NF SMC message, the UE, based on KDF, uses SUPI or NF-GUTI and the routing ID to retrieve the data from K... SEAF Derive K NF .

[0489] In some embodiments, if the UE receives any information encrypted by RF, the user equipment will use the NAS RF security context to decrypt the information (e.g., NF-GUTI).

[0490] S5012, The UE creates a NAS NF security context (which can correspond to the first security context mentioned above) and returns a NAS NF SMC completion message to the NF (which can correspond to the fourth message mentioned above).

[0491] In some embodiments, if in step S509 the NF requests the UE to send a complete NAS message / container for a specific network service, the user equipment will include the complete NAS message / container in the NAS NF SMC completion message, which cannot be decoded by the RF.

[0492] S5013, RF forwards the network service operation request message (which can correspond to the second request message mentioned above) containing the NAS NF SMC completion message to NF.

[0493] After receiving the NAS NF SMC completion message, S5014 and NF complete the NAS security establishment. Then, NF returns a network service operation response protected by NAS security (which can correspond to the second response message mentioned above).

[0494] In some embodiments, if an NF GUTI is not created in step S503 or step S508, the NF will create an NF GUTI in this step and include the NF GUTI encrypted with the NAS NF security context in the network service operation response.

[0495] S5015 and RF forward the downlink NAS message (which can correspond to the second message mentioned above) to the UE.

[0496] In some embodiments, the downlink NAS message includes an NF GUTI encrypted using the NAS NF security context.

[0497] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0498] This disclosure also proposes an apparatus (also referred to as a communication device, etc.) for implementing any of the above methods. For example, an apparatus is proposed that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another apparatus is proposed that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.

[0499] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through a configuration file, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0500] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be hardware circuits designed for artificial intelligence, which can be understood as ASICs, such as Neural Network Processing Units (NPUs), Tensor Processing Units (TPUs), and Deep Learning Processing Units (DPUs).

[0501] Figure 6a This is a schematic diagram of the structure of the first network function proposed in an embodiment of this disclosure. The first network function is used to perform any of the above methods. In some embodiments, such as Figure 6a As shown, the first network function may include at least one of the following: transceiver module 601, processing module 602, etc.

[0502] In some embodiments, the transceiver module 601 is configured to receive a first message sent by a terminal, the first message including: the identifier of the terminal and first information sent to a second network function; and to send a second message to the terminal, the second message including: response information of the first information sent to the terminal by the second network function;

[0503] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0504] Optionally, the transceiver module 601 is used to perform the transceiver steps of the first network function in any of the above methods (e.g.: Figure 2a Steps S20 and S21 are shown. Figure 2b At least one of the steps S201, S202, S209, S2010, S2012 to S2015 shown (but not limited to these) will not be described in detail here.

[0505] In some embodiments, the processing module can be interchanged with the determining module and the processor, and the transceiver module can be interchanged with the sending module, the receiving module, and the transceiver.

[0506] Figure 6b This is a schematic diagram of the structure of the second network function proposed in an embodiment of this disclosure. The second network function is used to perform any of the above methods. In some embodiments, such as Figure 6b As shown, the second network function may include at least one of the following: transceiver module 611, processing module 612, etc.

[0507] In some embodiments, the transceiver module 611 is configured to receive a first request message sent by a first network function, the first request message including: first information sent to the second network function and an identifier of a terminal, the identifier of the terminal being used to generate a first identifier assigned to the terminal by the second network function; and to send a first response message to the first network function, the first response message including a first security-related message, the first security-related message being a non-access stratum security-related message related to the second network function.

[0508] The first request message is sent by the first network function after receiving the first message sent by the terminal, and the first message includes the identifier of the terminal and the first information.

[0509] Optionally, the transceiver module 611 is used to perform the transceiver steps of the second network function in any of the above methods (e.g., step...). Figure 2b At least one of the steps S202, S204, S206, S209, S2013, and S2014 shown (but not limited to these) will not be described in detail here.

[0510] Optionally, the processing module 612 is used to execute the key generation step (e.g., step 1) of the second network function in any of the above methods. Figure 2b At least one of the steps S203, S207, and S208 shown (but not limited to these) will not be described in detail here.

[0511] In some embodiments, the processing module can be interchanged with the determining module and the processor, and the transceiver module can be interchanged with the sending module, the receiving module, and the transceiver.

[0512] Figure 6c This is a schematic diagram of the structure of a terminal according to an embodiment of this disclosure. The terminal is used to execute any of the above methods. In some embodiments, such as Figure 6c As shown, the terminal may include at least one of the following: transceiver module 621, processing module 622, etc.

[0513] In some embodiments, the transceiver module 621 is configured to send a first message to a first network function, the first message including: the identifier of the terminal and first information sent to a second network function; and receive a second message sent by the first network function, the second message including: response information of the first information sent by the second network function to the terminal;

[0514] The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

[0515] Optionally, the transceiver module 621 is used to execute the transceiver steps performed by the terminal in any of the above methods (e.g., Figure 2a Steps S20 and S21 are shown. Figure 2b At least one of the steps S201, S2010, S2012, and S2015 shown (but not limited to these) will not be described in detail here.

[0516] Optionally, the processing module 622 is used to execute the key generation step performed by the terminal in any of the above methods (e.g., step...). Figure 2b At least one of the steps S2011 shown, but not limited to, will not be described further here.

[0517] In some embodiments, the processing module can be interchanged with the determining module and the processor, and the transceiver module can be interchanged with the sending module, the receiving module, and the transceiver.

[0518] Figure 6d This is a schematic diagram of the security anchor function proposed in an embodiment of this disclosure. The security anchor function is used to perform any of the above methods. In some embodiments, such as Figure 6d As shown, the security anchor point function may include at least one of the following: transceiver module 631, processing module 632, etc.

[0519] In some embodiments, the transceiver module 631 is configured to receive a third request message sent by a second network function, the third request message including: an identifier of the terminal and a second identifier of the second network function; the processing module 632 is configured to generate a key related to the second network function based on a security anchor key, the identifier of the terminal and the second identifier of the second network function, the key being used to generate a first security context, the first security context being a non-access stratum related security context associated with the second network function; the transceiver module 631 is further configured to send a third response message to the second network function, the third response message including the key related to the second network function;

[0520] The first security context is used to protect the response information of the first information sent by the second network function to the terminal.

[0521] In some embodiments, the processing module can be interchanged with the determining module and the processor, and the transceiver module can be interchanged with the sending module, the receiving module, and the transceiver.

[0522] Figure 7 This is a schematic diagram of the structure of the communication device 700 proposed in this embodiment. The communication device 700 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 700 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0523] like Figure 7 As shown, the communication device 700 is used to execute any of the above methods. In some embodiments, the communication device 700 includes one or more processors 701. The processor 701 may be a general-purpose processor or a special-purpose processor, such as a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, and the central processing unit may be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 700 is used to execute any of the above methods. Optionally, one or more processors 701 are used to invoke instructions to cause the communication device 700 to execute any of the above methods.

[0524] In some embodiments, the communication device 700 further includes one or more transceivers 702. When the communication device 700 includes one or more transceivers 702, the transceivers 702 perform communication steps such as sending and / or receiving in the above-described method (e.g., ...). Figure 2aSteps S20 and S21 are shown. Figure 2b In at least one of the steps S201, S202, S204, S206, S209, S2010, S2012 to S2015 shown, but not limited thereto, the processor 701 performs other steps (e.g.: Figure 2b The transceiver may include at least one of the steps S203, S205, S207, S208, and S2011 shown, but is not limited thereto. In optional embodiments, the transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface can be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit can be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit can be used interchangeably.

[0525] In some embodiments, the communication device 700 further includes one or more memories 703 for storing data and / or instructions. Optionally, one or more processors 701 are used to invoke instructions stored in the memory 703 to cause the communication device 700 to perform any of the above methods. Optionally, all or part of the memory 703 may also be located outside the communication device 700. In optional embodiments, the communication device 700 may include one or more interface circuits 704. Optionally, the interface circuit 704 is connected to the memory 703 and can be used to receive data and / or instructions from the memory 703 or other devices, and can be used to send data and / or instructions to the memory 703 or other devices. For example, the interface circuit 704 can read data and / or instructions stored in the memory 703 and send the data and / or instructions to the processor 701.

[0526] The communication device 700 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 700 described in this disclosure is not limited thereto, and the structure of the communication device 700 may vary. Figure 7 The limitations. The communication device may be a standalone device or part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally including storage components for storing data, programs and / or instructions; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0527] Figure 8This is a schematic diagram of the structure of chip 800 according to an embodiment of this disclosure. For cases where the communication device can be a chip or a chip system, please refer to... Figure 8 The diagram shown is a schematic representation of the structure of chip 800, but is not limited to this.

[0528] Chip 800 includes one or more processors 801. Chip 800 is used to perform any of the above methods.

[0529] In some embodiments, chip 800 further includes one or more interface circuits 802. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 800 further includes one or more memories 803 for storing data and / or instructions. Optionally, all or part of the memories 803 may be located outside chip 800. Optionally, interface circuit 802 is connected to memory 803, and interface circuit 802 can be used to receive data and / or instructions from memory 803 or other devices, and interface circuit 802 can be used to send data and / or instructions to memory 803 or other devices. For example, interface circuit 802 can read data and / or instructions stored in memory 803 and send the data and / or instructions to processor 801.

[0530] In some embodiments, the interface circuit 802 performs communication steps such as sending and / or receiving in the above method (e.g.: Figure 2a Steps S20 and S21 are shown. Figure 2b At least one of the steps S201, S202, S204, S206, S209, S2010, S2012 to S2015 shown, but not limited thereto. The interface circuit 802 performing the communication steps such as sending and / or receiving in the above method refers, for example, to the interface circuit 802 performing data and / or instruction interaction between the processor 801, chip 800, memory 803, or transceiver device. In some embodiments, the processor 801 performs other steps (e.g.: Figure 2b At least one of the steps S203, S205, S207, S208, S2011 shown, but not limited to these.

[0531] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0532] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0533] This disclosure also proposes a program product, including a program and / or instructions, which, when executed by a communication device, cause the communication device to perform any of the above methods. Optionally, the program product is a computer program product. Optionally, the program product is stored on the storage medium.

[0534] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method, characterized in that, The communication method is executed by a first network function, and the communication method includes: The receiving terminal sends a first message, the first message including: the identifier of the terminal and first information sent to the second network function; Send a second message to the terminal, the second message including: response information of the first information sent to the terminal by the second network function; The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

2. The communication method according to claim 1, characterized in that, The first information may include a non-access stratum message sent to the second network function, or the first information may include a non-access stratum container sent to the second network function.

3. The communication method according to claim 1 or 2, characterized in that, The response information of the first information includes a first identifier assigned to the terminal by the second network function.

4. The communication method according to claim 3, characterized in that, The first identifier is a temporary identifier for the terminal.

5. The communication method according to claim 3 or 4, characterized in that, The communication method further includes: Send a first request message to the second network function. The first request message includes the first information and the identifier of the terminal. The identifier of the terminal is used to generate the first identifier. The system receives a first response message sent by the second network function. The first response message includes a first security-related message, which is a non-access stratum security-related message related to the second network function.

6. The communication method according to claim 5, characterized in that, The first request message further includes: a second identifier assigned to the second network function, the second identifier being used to generate a key associated with the second network function, the key being used to generate the first security context.

7. The communication method according to claim 6, characterized in that, The second identifier is the route ID.

8. The communication method according to any one of claims 5-7, characterized in that, The first response message also includes the first identifier.

9. The communication method according to any one of claims 5-7, characterized in that, The communication method further includes: Send a third message to the terminal, the third message including at least one of the following: the second identifier, the first security-related message, and the first identifier; Receive a fourth message sent by the terminal, the fourth message including a second security-related message, the second security-related message being a response message to the first security-related message; The first identifier is protected using a second security context, which is a non-access stratum-related security context associated with the first network function.

10. The communication method according to claim 9, characterized in that, The second security-related message includes: second information sent to the second network function, the second information being protected using the first security context.

11. The communication method according to claim 10, characterized in that, The second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function; The second information is used by the second network function to verify the first information.

12. The communication method according to any one of claims 9-11, characterized in that, The communication method further includes: Send a second request message to the second network function, the second request message including the second security-related message; Receive a second response message sent by the second network function, the second response message including response information of the first information sent by the second network function to the terminal; The second message is sent after the second response message is received.

13. A communication method, characterized in that, The communication method is executed by a second network function, and the communication method includes: Receive a first request message sent by a first network function, the first request message including: first information sent to the second network function and an identifier of the terminal, the identifier of the terminal being used to generate a first identifier assigned to the terminal by the second network function; Send a first response message to the first network function. The first response message includes a first security-related message, which is a non-access stratum security-related message related to the second network function. The first request message is sent by the first network function after receiving the first message sent by the terminal, and the first message includes the identifier of the terminal and the first information.

14. The communication method according to claim 13, characterized in that, The first information may include a non-access stratum message sent to the second network function, or the first information may include a non-access stratum container sent to the second network function.

15. The communication method according to claim 13 or 14, characterized in that, The first request message further includes: a second identifier assigned by the first network function to the second network function, the second identifier being used to generate a key related to the second network function; The key is used to generate a first security context, which is a non-access stratum-related security context associated with the second network function. The first security context is used to protect the response information of the first information.

16. The communication method according to claim 13 or 14, characterized in that, The communication method further includes: The first identifier is generated based on the identifier of the terminal; Alternatively, generate the second identifier.

17. The communication method according to claim 16, characterized in that, The first response message also includes the first identifier.

18. The communication method according to any one of claims 15-17, characterized in that, The second identifier is the route ID.

19. The communication method according to any one of claims 13-18, characterized in that, The communication method further includes: Receive a second request message sent by the first network function, the second request message including a second security-related message; Send a second response message to the first network function, the second response message including response information of the first information sent by the second network function to the terminal; Wherein, the second security-related message is received by the first network function from the terminal, and the second security-related message is a response message to the first security-related message; The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

20. The communication method according to claim 19, characterized in that, The response information of the first information includes the first identifier.

21. The communication method according to claim 19, characterized in that, The second security-related message includes second information sent to the second network function, the second information being protected using the first security context.

22. The communication method according to claim 21, characterized in that, The second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function; The second information is used by the second network function to verify the first information.

23. The communication method according to any one of claims 13-22, characterized in that, The communication method further includes: Send a third request message to the security anchor function, the third request message including: the identifier of the terminal and the second identifier, wherein the second identifier is used to generate a key related to the second network function, and the key is used to generate a first security context; Receive a third response message sent by the security anchor function, the third response message including a key related to the second network function; The first response message is sent after the third response message is received.

24. The communication method according to any one of claims 13-23, characterized in that, The first identifier is a temporary identifier for the terminal.

25. A communication method, characterized in that, The communication method is executed by the terminal, and the communication method includes: Send a first message to a first network function, the first message including: the identifier of the terminal and first information to be sent to a second network function; Receive a second message sent by the first network function, the second message including: response information of the first information sent by the second network function to the terminal; The response information of the first information is protected using a first security context, which is a non-access stratum security context related to the second network function.

26. The communication method according to claim 25, characterized in that, The first information may include a non-access stratum message sent to the second network function, or the first information may include a non-access stratum container sent to the second network function.

27. The communication method according to claim 25 or 26, characterized in that, The response information of the first information includes a first identifier assigned to the terminal by the second network function.

28. The communication method according to claim 27, characterized in that, The communication method further includes: Receive a third message sent by the first network function, the third message including at least one of the following: the second identifier, the first identifier, and a first security-related message, wherein the first security-related message is a non-access stratum security-related message related to the second network function; Send a fourth message to the first network function, the fourth message including a second security-related message, the second security-related message being a response message to the first security-related message; The first identifier is protected using a second security context, which is a security context related to the first network function non-access stratum.

29. The communication method according to claim 28, characterized in that, The communication method further includes: Based on the security anchor key, the identifier of the terminal, and the second identifier of the second network function, a key related to the second network function is generated, and the key is used to generate the first security context.

30. The communication method according to claim 28 or 29, characterized in that, The second security-related message includes second information sent to the second network function, the second information being protected using the first security context.

31. The communication method according to claim 30, characterized in that, The second information includes a non-access stratum message sent to the second network function, or the second information includes a non-access stratum container sent to the second network function; The second information is used by the second network function to verify the first information.

32. The communication method according to any one of claims 28-31, characterized in that, The second identifier is assigned by the first network function, or the second identifier is generated by the second network function.

33. The communication method according to any one of claims 28-32, characterized in that, The second identifier is the route ID.

34. The communication method according to any one of claims 27-33, characterized in that, The first identifier is a temporary identifier for the terminal.

35. A communication method, characterized in that, The communication method is performed by the security anchor function, and the communication method includes: Receive a third request message sent by the second network function, the third request message including: the identifier of the terminal and the second identifier of the second network function; Based on the security anchor key, the identifier of the terminal, and the second identifier, a key related to the second network function is generated. The key is used to generate a first security context, which is a non-access stratum related security context associated with the second network function. Send a third response message to the second network function, the third response message including a key related to the second network function; The first security context is used to protect the response information of the first information sent by the second network function to the terminal.

36. The communication method according to claim 35, characterized in that, The first information may include a non-access stratum message sent to the second network function, or the first information may include a non-access stratum container sent to the second network function.

37. The communication method according to claim 36 or 37, characterized in that, The response information of the first information includes a first identifier assigned to the terminal by the second network function.

38. The communication method according to claim 37, characterized in that, The first identifier is a temporary identifier for the terminal.

39. The communication method according to any one of claims 35-38, characterized in that, The second identifier is the route ID.

40. A communication device, characterized in that, The communication device is used to perform the communication method according to any one of claims 1 to 12, or the communication method according to any one of claims 13 to 24, or the communication method according to any one of claims 25 to 34, or the communication method according to any one of claims 35 to 39.

41. A communication system, characterized in that, include: First network function, second network function, and security anchor function; Wherein, the first network function is configured to implement the communication method of any one of claims 1 to 12, the second network function is configured to implement the communication method of any one of claims 13 to 24, and the security anchor function is configured to implement the communication method of any one of claims 35 to 39.

42. A communication system, characterized in that, include: First network function, second network function, terminal and security anchor point function; Wherein, the first network function is configured to implement the communication method of any one of claims 1 to 12, the second network function is configured to implement the communication method of any one of claims 13 to 24, the terminal is configured to implement the communication method of any one of claims 25 to 34, and the security anchor function is configured to implement the communication method of any one of claims 35 to 39.

43. A storage medium storing instructions, characterized in that, When the instruction is executed on the communication device, the communication device performs the communication method as described in any one of claims 1 to 12, or the communication method as described in any one of claims 13 to 24, or the communication method as described in any one of claims 25 to 34, or the communication method as described in any one of claims 35 to 39.

44. A program product comprising at least one of a program and instructions, characterized in that, When at least one of the programs or instructions is executed by the communication device, it implements the communication method according to any one of claims 1 to 12, or the communication method according to any one of claims 13 to 24, or the communication method according to any one of claims 25 to 34, or the communication method according to any one of claims 35 to 39.