A safety protection method and device

By maintaining the NAS serial numbers corresponding to 3GPP and non-3GPP access technologies in the terminal and core network equipment, and using the first parameter to distinguish different access technologies, NAS messages are securely protected, which solves the problem of poor data transmission data of NAS connection links in the 5G system, and the security protection of multiple NAS connection links is achieved.

CN111357308BActive Publication Date: 2025-05-06HUAWEI TECH CO LTD

Patent Information

Application Number
CN201880074395.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-11-17
Filing Date
2018-10-31
Publication Date
2025-05-06
Estimated Expiration
2038-10-31

AI Technical Summary

Technical Problem

In 5G systems, when the terminal accesses AMF nodes through 3GPP and non-3GPP access technology at the same time, there is a problem of poor data transmission security on the NAS connection link, especially in replay attacks.

Method used

By maintaining the NAS serial numbers corresponding to 3GPP and non-3GPP access technologies in the terminal and core network equipment, and using the first parameter to distinguish different access technologies, NAS messages are securely protected.

Benefits of technology

It effectively avoids the occurrence of replay attacks, ensures the security of multiple NAS connection links, and reduces the differences in security protection results of NAS messages transmitted through different access technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111357308B_ABST
    Figure CN111357308B_ABST
Patent Text Reader

Abstract

The present application relates to the field of wireless communication technology. The embodiments of the present application provide a method and device for security protection, which are used to implement security protection for multiple NAS connection links. The method of the present application includes: the terminal determines a first parameter, and the first parameter is used to represent the access technology used to transmit the non-access layer NAS message, wherein the terminal can support at least two access technologies, and can maintain a corresponding NAS sequence number for each of the at least two access technologies, and then the terminal performs security protection on the NAS message according to the first parameter, the NAS key and the NAS sequence number corresponding to the access technology used to transmit the NAS message. The present application is applicable to the process of security protection of NAS messages.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to a Chinese patent application filed with the State Intellectual Property Office of China on November 17, 2017, with application number 201711148926.5 and application name “A method and device for security protection”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of wireless communication technology, and in particular, to a security protection method and device. Background Art

[0003] In the fifth generation (5G) system, a terminal can access an access and mobility management function (AMF) node only through the third generation partnership project (3GPP) access technology, or can access an AMF node only through non-3GPP (non-3GPP) access technology, or the terminal can also access an AMF node through both 3GPP access technology and non-3GPP access technology. In the case where the terminal accesses the AMF node through both 3GPP access technology and non-3GPP access technology, there are two non-access stratum (NAS) connection links between the terminal and the AMF node. If the terminal uses a set of NAS keys and a set of non-access stratum sequence numbers (NAS count) to protect the two connection links respectively, the AMF node will first receive a smaller NAS count transmitted through one of the links, and then receive a larger NAS count transmitted through the other link, thereby causing a replay attack, resulting in poor data security transmitted through the NAS connection link between the terminal and the AMF node. Therefore, when there are multiple NAS connection links between the terminal and AMF, how to provide security protection for multiple NAS connection links is an urgent problem to be solved. Summary of the invention

[0004] The embodiments of the present application provide a security protection method and device, which can implement security protection for multiple NAS connection links.

[0005] In order to achieve the above objectives, the embodiments of the present application provide the following technical solutions:

[0006] An embodiment of the present application provides a security protection method, the method comprising: a terminal determines a first parameter, and then performs security protection on a NAS message according to the first parameter, a NAS key, and a NAS sequence number corresponding to an access technology used to transmit the NAS message. The first parameter is an input parameter of the terminal when performing security protection on the NAS message, and is used to indicate the access technology used to transmit the non-access layer NAS message. The terminal can support at least two access technologies, and can respectively maintain a corresponding NAS sequence number for each of the at least two access technologies.

[0007] Exemplarily, the at least two access technologies supported by the terminal may include 3GPP access technology, non-3GPP access technology, fixed network access technology, and other access technologies that can use 3GPP network core network equipment together with 3GPP access technology.

[0008] Optionally, the first parameter may also be used to indicate a transmission path used by the terminal to transmit a NAS message, and the terminal may maintain a corresponding NAS sequence number for each transmission path used to transmit the NAS message.

[0009] The first parameter may be a newly added input parameter in the encryption or integrity protection process, such as an access (ACCESS) parameter, and different access technologies may be represented by setting the bits of the ACCESS parameter to different values. For example, if the first parameter is 00, it means that a 3GPP access technology is used, and if the first parameter is 01, it means that a non-3GPP access technology is used. Alternatively, the first parameter may also be all or part of the bits of COUNT in the input parameter. Alternatively, the first parameter may also be all or part of the bits of BEARER in the input parameter.

[0010] The NAS key is a NAS key shared by at least two access technologies supported by the terminal.

[0011] By adopting this method, the terminal can maintain a corresponding NAS sequence number for each access technology of at least two access technologies respectively. When the terminal uses different access technologies to transmit NAS messages, it does not share a set of NAS sequence numbers, but uses the NAS sequence numbers maintained for the corresponding access technologies to perform security protection on the NAS messages. This can avoid the problem of replay attacks occurring when the core network device first receives a smaller NAS sequence number transmitted through one of the links and then receives a larger NAS sequence number transmitted through another link. In addition, when performing security protection on NAS messages, the present application also uses a first parameter for distinguishing different access technologies. Therefore, even if the NAS key and NAS sequence number used for security protection on NAS messages transmitted through different access technologies are the same, the results of security protection on the NAS messages are different, thereby reducing the possibility of replay attacks and achieving security protection for multiple NAS connection links.

[0012] In one possible design, at least two access technologies include a first access technology. If the access technology used to transmit the NAS message is the first access technology, before the terminal determines the first parameter, the terminal can determine the first uplink NAS sequence number corresponding to the first access technology, and then the terminal sends a first message to the core network device. The first message is securely protected by the first uplink NAS sequence number and the NAS key, and the first message carries part or all of the first uplink NAS sequence number.

[0013] Exemplarily, the first access technology may be a non-3GPP access technology.

[0014] In a possible implementation, the first uplink NAS sequence number is 0, wherein part or all of the first uplink NAS sequence number is 0. Alternatively, the first uplink NAS sequence number is a random number, specifically, part or all of the bits in the first uplink NAS sequence number are random numbers, for example, the sequence number part or the NAS overflow part in the first uplink NAS sequence number is a random number. In this case, the remaining part is 0. Alternatively, the at least two access technologies also include a second access technology, the first uplink NAS sequence number is an uplink NAS sequence number corresponding to the second access technology saved by the terminal, and if the terminal saves at least two uplink NAS sequence numbers corresponding to the second access technology, the first uplink NAS sequence number is the maximum uplink NAS sequence number corresponding to the second access technology saved by the terminal. Alternatively, the at least two access technologies also include a second access technology, the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the second access technology saved by the terminal plus 1, and if the terminal saves at least two uplink NAS sequence numbers corresponding to the second access technology, the first uplink NAS sequence number is the maximum uplink NAS sequence number corresponding to the second access technology saved by the terminal plus 1. Alternatively, the first uplink NAS sequence number is an uplink NAS sequence number corresponding to the first access technology stored in the terminal. If the terminal stores at least two uplink NAS sequence numbers corresponding to the first access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the first access technology stored in the terminal. Alternatively, the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the first access technology stored in the terminal plus 1. If the terminal stores at least two uplink NAS sequence numbers corresponding to the first access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the first access technology stored in the terminal plus 1.

[0015] In another possible design, the at least two access technologies include a first access technology and a second access technology. If the access technology used to transmit the NAS message is the first access technology, before the terminal determines the first parameter, the terminal can send a first message to the core network device. The first message is securely protected by a NAS key and an uplink NAS sequence number corresponding to the second access technology. The first message carries part or all of the uplink NAS sequence number corresponding to the second access technology.

[0016] The second access technology is a 3GPP access technology. Optionally, the premise of this design implementation is that the terminal has accessed the core network device through the 3GPP access technology.

[0017] In one possible design, the first message may carry first indication information, and the first indication information is used to indicate the access technology corresponding to part or all of the uplink NAS sequence number carried in the first message. Optionally, the first indication information may also be used to indicate the transmission path corresponding to part or all of the uplink NAS sequence number carried in the first message.

[0018] In one possible design, the terminal receives a second message from the core network device, where the second message includes one or both of a second uplink NAS sequence number and a first downlink NAS sequence number corresponding to the first access technology.

[0019] Optionally, the second message may include a first downlink NAS sequence number corresponding to the first access technology. Alternatively, the second message includes a second uplink NAS sequence number and a first downlink NAS sequence number corresponding to the first access technology.

[0020] Optionally, the second uplink NAS sequence number corresponding to the first access technology is the same as the first downlink NAS sequence number.

[0021] In a possible implementation, the second uplink NAS sequence number is 0, wherein all or part of the bits of the second uplink NAS sequence number are 0. Alternatively, the second uplink NAS sequence number is a random number, specifically, part or all of the bits in the second uplink NAS sequence number are random numbers. For example, the sequence number part or the NAS overflow part in the second uplink NAS sequence number is a random number. In this case, the remaining part is 0. Alternatively, the second uplink NAS sequence number is a downlink NAS sequence number corresponding to the second access technology stored in the core network device. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device. Alternatively, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. Alternatively, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the first access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. Alternatively, the second uplink NAS sequence number is the first uplink NAS sequence number. Alternatively, the second uplink NAS sequence number is the first uplink NAS sequence number plus 1.

[0022] In a possible design, the first downlink NAS sequence number is 0, wherein all or part of the bits of the first downlink NAS sequence number are 0. Alternatively, the first downlink NAS sequence number is a random number, specifically, part or all of the bits in the first downlink NAS sequence number are random numbers. For example, the sequence number part or the NAS overflow part in the first downlink NAS sequence number is a random number. At this time, the remaining part is 0. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the first access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1.

[0023] In one possible design, the second message carries second indication information, and the second indication information is used to indicate the access technology corresponding to the first downlink NAS sequence number carried in the second message. Optionally, the second message may also carry indication information for indicating the second uplink NAS sequence number carried in the second message.

[0024] Optionally, the second indication information is used to indicate a transmission path corresponding to the first downlink NAS sequence number carried in the second message. Optionally, the second message may also carry indication information used to indicate a transmission path corresponding to the second uplink NAS sequence number carried in the second message.

[0025] In a second aspect, an embodiment of the present application provides a security protection method, the method comprising:

[0026] The core network device determines the first parameter, and then the core network device performs security protection on the NAS message according to the first parameter, the NAS key, and the NAS sequence number corresponding to the access technology used to transmit the NAS message. The first parameter is used to indicate the access technology used to transmit the non-access layer NAS message, and the core network device can maintain a corresponding NAS sequence number for each of the at least two access technologies supported by the terminal.

[0027] Exemplarily, the at least two access technologies supported by the terminal may include 3GPP access technology, non-3GPP access technology, fixed network access technology, and other access technologies that can use 3GPP network core network equipment together with 3GPP access technology.

[0028] Optionally, the first parameter may also be used to indicate a transmission path used by the core network device to transmit a NAS message. The core network device may maintain a corresponding NAS sequence number for each transmission path used to transmit a NAS message.

[0029] The first parameter may be a newly added input parameter in the encryption or integrity protection process, such as an access (ACCESS) parameter, and different access technologies may be represented by setting the bits of the ACCESS parameter to different values. For example, if the first parameter is 00, it means that a 3GPP access technology is used, and if the first parameter is 01, it means that a non-3GPP access technology is used. Alternatively, the first parameter may also be all or part of the bits of COUNT in the input parameter. Alternatively, the first parameter may also be all or part of the bits of BEARER in the input parameter.

[0030] The NAS key is a NAS key shared by at least two access technologies supported by the terminal.

[0031] By adopting this method, the core network device can maintain a corresponding NAS sequence number for each access technology of at least two access technologies respectively. When the core network device uses different access technologies to transmit NAS messages, it does not share a set of NAS sequence numbers, but uses the NAS sequence numbers maintained for the corresponding access technologies to perform security protection on the NAS messages. This can avoid the problem of replay attacks when the terminal first receives a smaller NAS sequence number transmitted through one of the links and then receives a larger NAS sequence number transmitted through another link. In addition, when performing security protection on NAS messages, the present application also uses a first parameter for distinguishing different access technologies. Therefore, even if the NAS key and NAS sequence number used for security protection of NAS messages transmitted through different access technologies are the same, the results of security protection on the NAS messages are different, thereby reducing the possibility of replay attacks and achieving security protection for multiple NAS connection links.

[0032] In one possible design, at least two access technologies include a first access technology. If the access technology used to transmit the NAS message is the first access technology, the core network device can receive the first message before the core network device determines the first parameter. The first message is securely protected by the NAS key and the first uplink NAS sequence number corresponding to the first access technology. The first message carries the first uplink NAS sequence number.

[0033] Exemplarily, the first access technology may be a non-3GPP access technology.

[0034] In a possible implementation, the first uplink NAS sequence number is 0, wherein part or all of the first uplink NAS sequence number is 0. Alternatively, the first uplink NAS sequence number is a random number, specifically, part or all of the bits in the first uplink NAS sequence number are random numbers. For example, the sequence number part or the NAS overflow part in the first uplink NAS sequence number is a random number. At this time, the remaining part is 0. Alternatively, the at least two access technologies also include a second access technology, the first uplink NAS sequence number is an uplink NAS sequence number corresponding to the second access technology saved by the terminal, and if the terminal saves at least two uplink NAS sequence numbers corresponding to the second access technology, the first uplink NAS sequence number is the maximum uplink NAS sequence number corresponding to the second access technology saved by the terminal. Alternatively, the at least two access technologies also include a second access technology, the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the second access technology saved by the terminal plus 1, and if the terminal saves at least two uplink NAS sequence numbers corresponding to the second access technology, the first uplink NAS sequence number is the maximum uplink NAS sequence number corresponding to the second access technology saved by the terminal plus 1. Alternatively, the first uplink NAS sequence number is an uplink NAS sequence number corresponding to the first access technology stored in the terminal. If the terminal stores at least two uplink NAS sequence numbers corresponding to the first access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the first access technology stored in the terminal. Alternatively, the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the first access technology stored in the terminal plus 1. If the terminal stores at least two uplink NAS sequence numbers corresponding to the first access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the first access technology stored in the terminal plus 1.

[0035] In another possible design, the at least two access technologies include a first access technology and a second access technology. If the access technology used to transmit the NAS message is the first access technology, the core network device can receive the first message before the core network device determines the first parameter. The first message is securely protected by the NAS key and the uplink NAS sequence number corresponding to the second access technology. The first message carries part or all of the uplink NAS sequence number corresponding to the second access technology.

[0036] The second access technology is a 3GPP access technology. Optionally, the premise of this design implementation is that the terminal has accessed the core network device through the 3GPP access technology.

[0037] In one possible design, the first message carries first indication information, and the first indication information is used to indicate the access technology corresponding to part or all of the uplink NAS sequence number carried by the first message. Optionally, the first indication information can also be used to indicate the transmission path corresponding to part or all of the uplink NAS sequence number carried by the first message.

[0038] In one possible design, after the core network device receives the first message from the terminal, the core network device verifies part or all of the NAS sequence number carried by the first message according to the uplink NAS sequence number corresponding to the access technology indicated by the first indication information.

[0039] By adopting the embodiments of the present application, the core network device can independently maintain the NAS serial number of the 3GPP access technology and the NAS serial number of the non-3GPP access technology, and then verify the received uplink NAS sequence number according to the uplink NAS sequence number maintained by itself, thereby reducing the possibility of replay attacks.

[0040] In one possible design, the core network device determines one or all of the second uplink NAS sequence number and the first downlink NAS sequence number corresponding to the first access technology, and then the core network device sends a second message to the terminal, and the second message includes one or all of the second uplink NAS sequence number and the first downlink NAS sequence number corresponding to the first access technology.

[0041] Optionally, the second message may include a first downlink NAS sequence number corresponding to the first access technology. Alternatively, the second message includes a second uplink NAS sequence number and a first downlink NAS sequence number corresponding to the first access technology.

[0042] Optionally, the second uplink NAS sequence number corresponding to the first access technology is the same as the first downlink NAS sequence number.

[0043] In a possible implementation, the second uplink NAS sequence number is 0, wherein all or part of the bits of the second uplink NAS sequence number are 0. Alternatively, the second uplink NAS sequence number is a random number, specifically, part or all of the bits in the second uplink NAS sequence number are random numbers. For example, the sequence number part or the NAS overflow part in the second uplink NAS sequence number is a random number. In this case, the remaining part is 0. Alternatively, the second uplink NAS sequence number is a downlink NAS sequence number corresponding to the second access technology stored in the core network device. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device. Alternatively, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. Alternatively, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the first access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. Alternatively, the second uplink NAS sequence number is the first uplink NAS sequence number. Alternatively, the second uplink NAS sequence number is the first uplink NAS sequence number plus 1.

[0044] In a possible implementation, the first downlink NAS sequence number is 0, wherein all or part of the bits of the first downlink NAS sequence number are 0. Alternatively, the first downlink NAS sequence number is a random number, specifically, part or all of the bits in the first downlink NAS sequence number are random numbers. For example, the sequence number part or the NASoverflow part in the first downlink NAS sequence number is a random number. In this case, the remaining part is 0. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the first access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1.

[0045] In one possible design, the second message carries second indication information, and the second indication information is used to indicate the access technology corresponding to the first downlink NAS sequence number carried in the second message. Optionally, the second message may also carry indication information for indicating the second uplink NAS sequence number carried in the second message.

[0046] Optionally, the second indication information is used to indicate a transmission path corresponding to the first downlink NAS sequence number carried in the second message. Optionally, the second message may also carry indication information used to indicate a transmission path corresponding to the second uplink NAS sequence number carried in the second message.

[0047] In a third aspect, an embodiment of the present application provides a device having the function of implementing the terminal behavior in the above method design. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example, the device can be a terminal, or can be a chip in a terminal.

[0048] In one possible design, the device is a terminal, and the terminal includes a processor, and the processor is configured to support the terminal to perform the corresponding functions in the above method. Further, the terminal may also include a transmitter and a receiver, and the transmitter and the receiver are used to support communication between the terminal and the core network device. Further, the terminal may also include a memory, and the memory is used to be coupled with the processor, which stores the necessary program instructions and data of the terminal.

[0049] In a fourth aspect, an embodiment of the present application provides a device having the function of implementing the behavior of the core network device in the above method design. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example, the device can be a core network device, or can be a chip in a core network device.

[0050] In one possible design, the apparatus is a core network device, and the core network device includes a processor, and the processor is configured to support the core network device to perform corresponding functions in the above method. Further, the core network device may also include a transmitter and a receiver, and the transmitter and the receiver are used to support communication between the core network device and the terminal. Further, the core network device may also include a memory, and the memory is used to couple with the processor, and stores necessary program instructions and data of the terminal.

[0051] In a fifth aspect, an embodiment of the present application provides a communication system, which includes the terminal and core network equipment described in the above aspects. Optionally, the system may also include a base station, an N3IWF node, and the terminal and core network equipment described in the above aspects.

[0052] In a sixth aspect, an embodiment of the present application provides a computer storage medium for storing computer software instructions for use in the above-mentioned terminal, which includes a program designed for executing the above-mentioned first aspect.

[0053] In a seventh aspect, an embodiment of the present application provides a computer storage medium for storing computer software instructions for use in the above-mentioned core network device, which includes a program designed for executing the above-mentioned second aspect.

[0054] In an eighth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the method described in the first aspect above.

[0055] In a ninth aspect, an embodiment of the present application provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the method described in the second aspect above.

[0056] In the tenth aspect, an embodiment of the present application provides a chip system, which is applied to a terminal, wherein the chip system includes at least one processor, a memory and a transceiver circuit, wherein the memory, the transceiver circuit and the at least one processor are interconnected through lines, and instructions are stored in the at least one memory; the instructions are executed by the processor to perform the operation of the terminal in the method described in the first aspect above.

[0057] In the eleventh aspect, an embodiment of the present application provides a chip system for application in a core network device, wherein the chip system comprises at least one processor, a memory and a transceiver circuit, wherein the memory, the transceiver circuit and the at least one processor are interconnected via lines, and instructions are stored in the at least one memory; the instructions are executed by the processor to perform the operation of the core network device in the method described in the second aspect above.

[0058] In the security protection method provided by the embodiment of the present application, the terminal can maintain a corresponding NAS sequence number for each access technology of at least two access technologies respectively. When the terminal uses different access technologies to transmit NAS messages, it does not share a set of NAS sequence numbers, but uses the NAS sequence numbers maintained for the corresponding access technologies to perform security protection on the NAS messages. This can avoid the problem of replay attacks occurring when the core network device first receives a smaller NAS sequence number transmitted through one of the links and then receives a larger NAS sequence number transmitted through another link. In addition, when performing security protection on the NAS messages, the present application also uses a first parameter for distinguishing different access technologies. Therefore, even if the NAS key and NAS sequence number used for security protection on the NAS messages transmitted through different access technologies are the same, the results of security protection on the NAS messages are different, thereby reducing the possibility of replay attacks and achieving security protection for multiple NAS connection links. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 A possible network architecture diagram provided for an embodiment of the present application;

[0060] Figure 2 A schematic diagram of another possible network architecture provided for an embodiment of the present application;

[0061] Figure 3 An exemplary schematic diagram of an encryption and decryption method provided for an embodiment of the present application;

[0062] Figure 4 An exemplary schematic diagram of a method for integrity protection provided in an embodiment of the present application;

[0063] Figure 5A flowchart of a security protection method provided for an embodiment of the present application;

[0064] Figure 6 An exemplary schematic diagram of another encryption and decryption method provided for an embodiment of the present application;

[0065] Figure 7 An exemplary schematic diagram of another encryption and decryption method provided for an embodiment of the present application;

[0066] Figure 8 An exemplary schematic diagram of another encryption and decryption method provided for an embodiment of the present application;

[0067] Fig. 9 A flowchart of another security protection method provided for an embodiment of the present application;

[0068] Fig.10 A flowchart of another security protection method provided for an embodiment of the present application;

[0069] Fig.11 A flowchart of another security protection method provided for an embodiment of the present application;

[0070] Fig.12 A schematic diagram of the structure of a device provided in an embodiment of the present application;

[0071] Fig.13 A schematic diagram of the structure of a terminal provided in an embodiment of the present application;

[0072] Fig.14 A schematic diagram of the structure of another device provided in an embodiment of the present application;

[0073] Fig.15 A schematic diagram of the structure of a core network device provided for an embodiment of the present application. DETAILED DESCRIPTION

[0074] The present application will be further described in detail below in conjunction with the accompanying drawings. The specific operation method in the method embodiment can also be applied to the device embodiment or the system embodiment. In the description of the present application, unless otherwise specified, the meaning of "multiple" is two or more.

[0075] The system architecture and business scenarios described in this application are intended to more clearly illustrate the technical solutions of this application and do not constitute a limitation on the technical solutions provided by this application. A person of ordinary skill in the art will appreciate that, with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by this application are equally applicable to similar technical problems.

[0076] It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0077] The embodiments of the present application can be applied to the next generation wireless communication system, such as the 5G communication system. Figure 1 As shown, Figure 1 A possible network architecture diagram of the present application is shown, and the network architecture includes:

[0078] AMF node: A network element responsible for mobility management, which can be used to implement other functions of the mobility management entity (MME) except session management, such as lawful interception, access authorization, etc.

[0079] Session management function (SMF) node: used to allocate session resources for the user plane.

[0080] Authentication server function (AUSF) node: When AUSF authenticates the terminal, it is responsible for verifying the authenticity of the parameters to be authenticated and the authenticated terminal. The main functions include: receiving the authentication request sent by the security anchor function (SEAF) node; selecting the authentication method. When using the extensible authentication protocol authentication and key agreement (EAP-AKA') authentication method, the AUSF node can complete the authentication of the terminal on the network side.

[0081] SEAF node: The SEAF node can be a part of the AMF node or an independent network element. It is mainly responsible for initiating authentication requests to the AUSF and completing the network-side authentication of the terminal during the evolved packet system authentication and key agreement (EPS-AKA*) authentication process.

[0082] User plane function (UPF) node: It is the egress of user plane data and is used to connect to the external network.

[0083] Data Network (DN): A network used to provide external data, such as the Internet.

[0084] (Radio) access network ((radio) access network, (R)AN) node: (R)AN can use different access technologies. There are two types of current radio access technologies: 3GPP access technology (such as the radio access technology used in 3G, 4G or 5G systems) and non-3GPP access technology. 3GPP access technology refers to access technology that complies with 3GPP standards and specifications. The access network that uses 3GPP access technology is called a radio access network (RAN), where the access network equipment in the 5G system is called the next generation node basestation (gNB). Non-3GPP access technology refers to access technology that does not comply with 3GPP standards and specifications, such as air interface technology represented by WiFi access points (APs).

[0085] Terminal: The terminal referred to in this application is a device with wireless transceiver function, which can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on the water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons and satellites, etc.). The terminal may include various types of user equipment (UE), mobile phones, tablet computers (pads), computers with wireless transceiver functions, wireless data cards, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, machine type communication (MTC) terminal devices, terminal devices in industrial control, terminal devices in self-driving, terminal devices in remote medical, terminal devices in smart grid, terminal devices in transportation safety, terminal devices in smart city, and wearable devices (such as smart watches, smart bracelets, pedometers, etc.), etc. In systems using different wireless access technologies, the names of terminals with similar wireless communication functions may be different. For the convenience of description only, in the embodiments of the present application, the above-mentioned devices with wireless transceiver communication functions are collectively referred to as terminals.

[0086] Specifically, the terminal in the present application stores long-term keys and related functions. When the terminal performs two-way authentication with a core network node (such as an AMF node, AUSF node, SEAF node, etc.), the long-term keys and related functions can be used to verify the authenticity of the network.

[0087] Access network equipment: The access network equipment involved in the embodiments of the present application is a device that provides wireless communication functions for terminals. For example, the access network equipment may be a base station (Base Station, BS), and the base station may include various forms of macro base stations, micro base stations, relay stations, access points, etc. In systems using different wireless access technologies, the names of devices with base station functions may be different. For example, in a 5G system, it is called a next-generation base station node, which can be expressed as gNB, in a long-term evolution (Long Term Evolution, LTE) system, it is called an evolved Node B (evolved NodeB, eNB or eNodeB), in a third generation (3rd Generation, 3G) communication system, it is called Node B, etc. For the convenience of description, in the embodiments of the present invention, the above-mentioned devices that provide wireless communication functions for terminals are collectively referred to as access network equipment.

[0088] Network exposure function (NEF) node: mainly used to interact with third parties, allowing third parties to indirectly interact with certain network elements within the 3GPP network.

[0089] Network function repository function (NRF) node: used for network element discovery and maintenance of network functions (NF).

[0090] Policy control function (PCF) node: The PCF node stores the latest quality of service (QoS) rules. The base station can allocate appropriate resources for the user plane transmission channel according to the QoS rules provided by the SMF node.

[0091] Unified data management (UDM) node: used to store user contract information.

[0092] Application function (AF) node: The AF node can be located inside the DN and is a functional network element deployed on a third party. The main function of this network element is to inform the PCF node of the latest business requirements of a third-party enterprise for a certain application. The PCF node can generate corresponding QoS rules based on business requirements to ensure that the services provided by the network meet the requirements of the third party.

[0093] In an embodiment of the present application, the terminal can access the AMF node through at least two access technologies. Taking at least two access technologies including 3GPP access technology and non-3GPP access technology as an example, the embodiment of the present application also provides a possible network architecture schematic diagram, such as Figure 2 As shown, the network architecture includes AMF nodes, AUSF nodes, SMF nodes, UPF nodes, UDM nodes (or authentication credential repository and processing function (APRF) nodes), terminals and non-3GPP interworking function (non-3GPP interworking function, N3IWF) nodes.

[0094] Among them, AMF nodes, AUSF nodes, SMF nodes, UPF nodes, UDM nodes and terminals can refer to Figure 1 The description in will not be repeated here.

[0095] Among them, the N3IWF node is used to support the terminal to access the AMF node through non-3GPP access technology.

[0096] Combination Figure 2 In the network architecture shown, the terminal can access the AMF node through both 3GPP access technology and non-3GPP access technology. Among them, 3GPP access technology can be simply expressed as 3GPP, and non-3GPP access technology can be simply expressed as non-3GPP or non-3GPP. Figure 2Path 1 is the path for the terminal to access the AMF node through 3GPP, and path 2 is the path for the terminal to access the AMF node through non-3GPP, that is, the terminal can access the AMF node through N3IWF. In the case where the terminal accesses the AMF node through 3GPP and non-3GPP at the same time, if the terminal needs to send a NAS message to the AMF node, in one possible implementation, the NAS message can be split into at least two message blocks, one part of the message blocks is transmitted through 3GPP, and the other part of the message blocks is transmitted through non-3GPP. Exemplarily, the NAS message can be divided into five message blocks 1, 2, 3, 4, and 5, of which message blocks 2 and 4 are transmitted through 3GPP, and message blocks 1, 3, and 5 are transmitted through non-3GPP. In another possible implementation, the terminal can transmit an entire NAS message through 3GPP and another entire NAS message through non-3GPP.

[0097] First, the relevant terms involved in the embodiments of the present application are explained.

[0098] (1)NAS count

[0099] The NAS count consists of 24 bits, including a 16-bit overflow counter and an 8-bit sequence number.

[0100] The initial value of NAS count is 0. Each time the terminal sends a NAS message to the core network device, the uplink NAS count increases by 1. Each time the core network device sends a NAS message to the terminal, the downlink NAS count increases by 1. After the terminal completes the authentication process with the core network device, both the uplink NAS count and the downlink NAS count are set to 0.

[0101] Optionally, there are two methods for maintaining NAS count:

[0102] Method 1 is to increase the stored NAS count by 1 and store it after sending the NAS message. When the NAS message needs to be sent again, the stored NAS count is used to securely protect the NAS message.

[0103] Method 2 is to send a NAS message and then, when a NAS message needs to be sent next time, increase the stored NAS count by 1 to determine a new NAS count, and use the new NAS count to securely protect the NAS message.

[0104] After receiving the NAS message, the terminal and the core network device can verify whether the received NAS count is reused, that is, verify whether the NAS count carried in the NAS message is greater than the NAS count received last time. For example, if the AMF node receives an uplink NAS count from the terminal, it can compare whether the uplink NAS count received this time is greater than the uplink NAS count received last time. If so, the security verification of the NAS message is passed.

[0105] When using NAS count for encryption, decryption and integrity protection, the NAS count will be padded to 32 bits, that is, 8 bits are padded before the original 24-bit NAS count, and the padded 8 bits can be all 0.

[0106] (2) Encryption and decryption

[0107] like Figure 3 As shown, Figure 3 The process of encrypting and decrypting NAS messages.

[0108] Here, KEY can be a NAS key.

[0109] The serial number (COUNT) used for encryption and decryption consists of 32 bits, of which the first 8 bits are 0, the middle 16 bits are flip bits, and the last 8 bits are the serial number.

[0110] The bearer information (BEARER) consists of 5 bits, all of which are 0.

[0111] The data transmission direction (DIRECTON) is used to indicate uplink and downlink. When encrypting and decrypting an uplink NAS message, DIRECTON indicates uplink, and when encrypting and decrypting a downlink NAS message, DIRECTON indicates downlink.

[0112] The length (LENGTH) is used to indicate the data length of the NAS message that needs to be encrypted or decrypted.

[0113] The evolved packet system encryption algorithm (EEA), which may also be referred to as the EPS encryption algorithm, is an algorithm used to encrypt and decrypt NAS messages.

[0114] The encryption process is to process the input parameters (KEY, COUNT, BEARER, DIRECTON and LENGTH) through EEA to obtain the key stream (KEYSTERAM), and then perform modulo-2 addition of the key stream and plaintext (NAS message) to obtain the ciphertext (CIPHERTEXT). The decryption process is to process the above input parameters through EEA to obtain the key stream, and then perform modulo-2 addition of the key stream and ciphertext to restore the plaintext.

[0115] (3) Integrity protection

[0116] like Figure 4 As shown, Figure 4 The process of integrity protection and integrity verification for NAS messages.

[0117] The message (MESSAGE) refers to a message that needs to be integrity protected, and specifically may be a NAS message.

[0118] Evolved Packet System Integrity Algorithm (EPS)

[0119] The method of integrity protection is that the sender processes the input parameters (KEY, COUNT, MESSAGE, BEARER, DIRECTION) through EIA to obtain the expected message authentication code integrity (MAC-I) or NAS-MAC for integrity protection. The method of integrity protection verification is that the input parameters (KEY, COUNT, MESSAGE, BEARER, DIRECTION) are processed by EIA to obtain the expected message authentication code integrity (XMAC-I) or XNAS-MAC, and then XMAC-I is compared with MAC-I. If XMAC-I is consistent with MAC-I, the integrity protection verification is passed.

[0120] The technical solution proposed in this application is described in detail below.

[0121] based on Figure 1 and Figure 2 The embodiment of the present application provides a method for security protection. In this method, the encryption and decryption, as well as the integrity protection process can be referred to Figure 3 and Figure 4 Description of Figure 5 As shown, the method includes: step 501 and step 502.

[0122] Step 501: The terminal determines a first parameter.

[0123] Among them, the first parameter is an input parameter of the terminal when performing security protection for NAS messages, and is used to indicate the access technology used to transmit NAS messages. Among them, the terminal can support at least two access technologies, and can maintain a corresponding NAS sequence number for each of the at least two access technologies. For example, the at least two access technologies mentioned above can be at least two of the other access technologies that can use 3GPP network core network equipment together with 3GPP access technology, such as 3GPP access technology, non-3GPP access technology and fixed network access technology. Optionally, the first parameter indicates the access technology used to transmit NAS messages. It can also be understood that the first parameter is used to indicate the transmission path used by the terminal to transmit NAS messages. For example, the terminal and the AMF node may not distinguish between access technologies, and maintain a corresponding NAS sequence number for each transmission path. If the transmission path used to transmit the NAS message is path 1, the NAS sequence number corresponding to path 1 is used; if the transmission path used to transmit the NAS message is path 2, the NAS sequence number corresponding to path 2 is used. It can be understood that the transmission path corresponds to the access technology. For example, refer to Figure 2 The access technology used when transmitting data on path 1 is 3GPP access technology, and the access technology used when transmitting data on path 2 is non-3GPP access technology.

[0124] The first parameter may be a new input parameter added in the encryption or integrity protection process, and the parameter includes a preset number of bits. Optionally, different access technologies may be represented by setting the bits to different values.

[0125] In the first possible implementation, Figure 6 As shown, the first parameter may be an access (ACCESS) parameter. For example, if the first parameter is 00, it means that 3GPP access technology is used, and if the first parameter is 01, it means that non-3GPP access technology is used. Alternatively, 001 represents 3GPP access technology, 010 represents wireless-fidelity (wifi) technology, and 011 represents fixed network technology.

[0126] Alternatively, 001 may be used to represent the first access technology used, 010 to represent the second access technology used, and 011 to represent the third access technology used, that is, each time the access technology used is switched, the first parameter is increased by 1 until all bits of the first parameter are 1, and the first parameter can be counted again from 000. For example, if the terminal switches the access technology used for multiple times, all bits of the first parameter become 1. Assuming that the terminal needs to switch the access technology used from the first access technology to the second access technology at this time, the first parameter generated for the second access technology is 001. Optionally, in this method, the first access technology, the second access technology and the third access technology can be the same technology, that is, when re-accessing a certain access technology, the first parameter is increased by 1 until all bits of the first parameter are 1, and the first parameter can be counted again from 000.

[0127] Optionally, each time the COUNT in the input parameter is reset to 0, or the NAS sequence number is reset to 0, the first parameter may be increased by 1.

[0128] Optionally, when all bits of the first parameter are 1, a NAS key used in the next transmission of a NAS message needs to be updated.

[0129] In the second possible implementation, Figure 7 As shown, all or part of the COUNT in the input parameter can be used to indicate the access technology used to transmit the NAS message. For example, if COUNT is composed of 8 bits of all-0 padding bits and a NAS sequence number, the first parameter can be part or all of the 8 bits. For example, the first 3 bits can be selected to indicate the access technology used to transmit the NAS message. For how to distinguish different access technologies by bit values, refer to the relevant description in the first implementation.

[0130] In a third possible implementation, if Figure 8 As shown, the BEARER in the input parameter can be used to indicate the access technology used to transmit the NAS message, or to indicate the access path used to transmit the NAS message, and the first parameter can be part or all of the BEARER. Exemplarily, the first 3 bits can be selected to indicate the access technology used to transmit the NAS message. For how to distinguish different access technologies by bit values, refer to the relevant description in the first implementation.

[0131] In a fourth possible implementation, the bits of the NAS sequence number may be increased, and the first parameter is a portion of the bits of the NAS sequence number. For example, the NAS sequence number is extended from 32 bits to 64 bits (a 64-bit NAS sequence number is adapted to a key of 256 bits in length). A portion of the extended NAS sequence number is used to indicate the access technology, for example, 3 bits are reserved, 000 indicates 3GPP access technology, 001 indicates wifi access technology, and 010 indicates fixed network access technology.

[0132] In a fifth possible implementation manner, the first parameter may be a NAS sequence number, and bits of the NAS sequence number are removed, and the access technology is represented by the number of shifted bits.

[0133] Optionally, a preset number of bits are removed from the overflow counter in the existing NAS sequence number, and the number of removed bits is used to indicate the access technology. For example, if 1 bit is removed, it indicates that the access technology is 3GPP access technology; if 2 bits are removed, it indicates that the access technology is wifi access technology; if 3 bits are removed, it indicates that the access technology is fixed network access technology.

[0134] Alternatively, a preset number of bits are removed from the sequence number portion of the existing NAS sequence number, and the number of removed bits is used to indicate the access technology. For example, if 1 bit is removed, it indicates that the access technology is 3GPP access technology; if 2 bits are removed, it indicates that the access technology is wifi access technology; if 3 bits are removed, it indicates that the access technology is fixed network access technology.

[0135] Optionally, the terminal may pre-configure the first parameter corresponding to each access technology. After the terminal determines the access technology used to transmit the NAS message, the terminal may search for the corresponding first parameter based on the access technology used to transmit the NAS message; or, after determining the access technology used to transmit the NAS message, the terminal may generate the first parameter based on the access technology used to transmit the NAS message.

[0136] It should be noted that when the first parameter is a NAS sequence number, or the first parameter is a part of the bits of the NAS sequence number, the NAS sequence number maintained by the terminal for each access technology supported is different. In other cases, the NAS sequence number maintained by the terminal for each access technology supported may be the same or different.

[0137] The first parameter can be determined by the terminal itself and notified to the AMF node; it can also be determined by the AMF node and then notified to the terminal. It can also be configured in the terminal and the AMF node in advance. For example, if the first parameter is determined by the AMF node, the terminal can receive the first parameter from the AMF node. If the first parameter is part of the bits in the NAS sequence number, after the terminal receives the first parameter, it can replace the specified bits in the NAS sequence number saved by itself with the first parameter; or, if the first parameter is part of the bits in the BEARER, the terminal can replace the specified bits in the BEARER with the first parameter.

[0138] Step 502: The terminal performs security protection on the NAS message according to the first parameter, the NAS key, and the NAS sequence number corresponding to the access technology used to transmit the NAS message.

[0139] The NAS sequence number may be a NAS count, or a parameter having a function of preventing NAS message replay attacks. The NAS key is a NAS key shared by at least two access technologies that the terminal can support.

[0140] The terminal performs security protection on NAS messages, which means encrypting NAS messages to be transmitted to the core network device, decrypting received NAS messages, performing integrity protection on NAS messages to be transmitted to the core network device, or performing integrity protection verification on received NAS messages. Accordingly, the keys used for security protection of NAS messages may be encryption keys and integrity protection keys. In the embodiments of the present application, encryption keys and integrity protection keys are collectively referred to as NAS keys. The embodiments of the present application do not limit the execution order of encryption, decryption, production integrity protection, and verification integrity protection.

[0141] It can be understood that the terminal is able to maintain a corresponding NAS sequence number for each access technology of at least two access technologies. If the terminal uses 3GPP access technology to transmit NAS messages, the first parameter corresponding to the 3GPP access technology, the uplink NAS sequence number and NAS key maintained by the terminal for the 3GPP access technology are used to securely protect the NAS message.

[0142] Corresponding to the three implementations of the first parameter, the methods for encrypting the NAS message are as follows: Figure 6 , Figure 7 and Figure 8 shown.

[0143] Corresponding to the first implementation method mentioned above, combined with Figure 4 The input parameter used for security protection of NAS messages can also be ACCESS.

[0144] Corresponding to the second implementation method mentioned above, combined with Figure 4 , the COUNT in the input parameters used for security protection of NAS messages includes the first parameter.

[0145] Corresponding to the third implementation method mentioned above, combined with Figure 4 , the BEARER in the input parameters used for security protection of NAS messages includes the first parameter.

[0146] Optionally, if the terminal receives a NAS message, it can determine the first parameter corresponding to the access technology used to transmit the NAS message, and then use the downlink NAS sequence number carried in the NAS message, the first parameter corresponding to the access technology used to transmit the NAS message, and the NAS key to decrypt the NAS message and / or perform integrity protection verification.

[0147] In the security protection method provided by the embodiment of the present application, the terminal can maintain a corresponding NAS sequence number for each access technology of at least two access technologies respectively. When the terminal uses different access technologies to transmit NAS messages, it does not share a set of NAS sequence numbers, but uses the NAS sequence numbers maintained for the corresponding access technologies to perform security protection on the NAS messages. This can avoid the problem of replay attacks occurring when the core network device first receives a smaller NAS sequence number transmitted through one of the links and then receives a larger NAS sequence number transmitted through another link. In addition, when performing security protection on the NAS messages, the present application also uses a first parameter for distinguishing different access technologies. Therefore, even if the NAS key and NAS sequence number used for security protection on the NAS messages transmitted through different access technologies are the same, the results of security protection on the NAS messages are different, thereby reducing the possibility of replay attacks and achieving security protection for multiple NAS connection links.

[0148] Corresponds to Figure 5 In another implementation of the embodiment of the present application, a method for a core network device to securely protect NAS messages is also provided. The core network device may be an AMF node, a SEAF node, an MME node, or other nodes involved in the terminal authentication process, or other nodes involved in key generation and key storage. In the embodiment of the present application, the core network device is an AMF node as an example for explanation, such as Fig. 9 As shown, the method includes:

[0149] Step 901: The AMF node determines a first parameter.

[0150] The first parameter is used to indicate the access technology used to transmit the NAS message. The AMF node can maintain a corresponding NAS sequence number for each of at least two access technologies supported by the terminal.

[0151] The method for the AMF node to determine the first parameter is the same as the above Figure 5 The method for the terminal to determine the first parameter in step 501 is similar to that in step 501, and reference may be made to the relevant description in step 501.

[0152] Step 902: The AMF node performs security protection on the NAS message according to the first parameter, the NAS key, and the NAS sequence number corresponding to the access technology used to transmit the NAS message.

[0153] The NAS sequence number may be a NAS count, or a parameter having a function of preventing NAS message replay attacks.

[0154] The AMF node may perform security protection on NAS messages by encrypting NAS messages to be transmitted to the terminal, decrypting received NAS messages, performing integrity protection on NAS messages to be transmitted to the terminal, and performing integrity protection verification on received NAS messages.

[0155] Among them, the method by which the AMF node performs security protection on the NAS message is similar to the method by which the terminal performs security protection on the NAS message in the above step 502, and reference may be made to the relevant description in step 502.

[0156] In the security protection method provided by the embodiment of the present application, the core network device can maintain a corresponding NAS sequence number for each access technology of at least two access technologies respectively. When the terminal uses different access technologies to transmit NAS messages, it does not share a set of NAS sequence numbers, but uses the NAS sequence numbers maintained for the corresponding access technologies to perform security protection on the NAS messages. This can avoid the problem of replay attacks occurring when the core network device first receives a smaller NAS sequence number transmitted through one of the links and then receives a larger NAS sequence number transmitted through another link. In addition, when performing security protection on the NAS messages, the present application also uses a first parameter for distinguishing different access technologies. Therefore, even if the NAS key and NAS sequence number used for security protection on the NAS messages transmitted through different access technologies are the same, the results of security protection on the NAS messages are different, thereby reducing the possibility of replay attacks and achieving security protection for multiple NAS connection links.

[0157] Optionally, if the access technology used to transmit the NAS message is the first access technology, Figure 5 and Fig. 9 Before the process, Fig.10 As shown, the method may further include: step 1001 to step 1007.

[0158] Step 1001: The terminal determines a first uplink NAS sequence number corresponding to a first access technology.

[0159] The first uplink NAS sequence number is 0, specifically, all or part of the bits of the first uplink NAS sequence number are 0; or,

[0160] The first uplink NAS sequence number is a random number. Specifically, some or all bits in the first uplink NAS sequence number are random numbers. For example, the sequence number part or the NAS overflow part in the first uplink NAS sequence number is a random number. At this time, the rest is 0; or,

[0161] The at least two access technologies also include a second access technology, the first uplink NAS sequence number is an uplink NAS sequence number corresponding to the second access technology stored by the terminal, and if the terminal stores at least two uplink NAS sequence numbers corresponding to the second access technology, the first uplink NAS sequence number is a maximum uplink NAS sequence number corresponding to the second access technology stored by the terminal; or,

[0162] The at least two access technologies also include a second access technology, the first uplink NAS sequence number is an uplink NAS sequence number corresponding to the second access technology stored by the terminal plus 1, and if the terminal stores at least two uplink NAS sequence numbers corresponding to the second access technology, the first uplink NAS sequence number is a maximum uplink NAS sequence number corresponding to the second access technology stored by the terminal plus 1; or,

[0163] The first uplink NAS sequence number is an uplink NAS sequence number corresponding to the first access technology stored by the terminal. If the terminal stores at least two uplink NAS sequence numbers corresponding to the first access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the first access technology stored by the terminal; or,

[0164] The first uplink NAS sequence number is the uplink NAS sequence number corresponding to the first access technology saved by the terminal plus 1. If the terminal saves at least two uplink NAS sequence numbers corresponding to the first access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the first access technology saved by the terminal plus 1.

[0165] Optionally, the first access technology and the second access technology may be 3GPP access technology, non-3GPP access technology, fixed network access technology, or other technologies that can access core network equipment, or any technology that uses 3GPP network core network equipment together with 3GPP access technology. In the embodiments of the present application, the first access technology is a non-3GPP access technology and the second access technology is a 3GPP access technology.

[0166] It can be understood that before the terminal sends a NAS message to the AMF node using a non-3GPP access technology, it is necessary to determine the first uplink NAS sequence number carried when the NAS message is transmitted using the non-3GPP access technology.

[0167] If the terminal accesses the AMF node for the first time through a non-3GPP access technology, the first uplink NAS sequence number corresponding to the non-3GPP access technology can be set to 0 or a random number. Alternatively, if the terminal has accessed the AMF node through a 3GPP access technology, if the NAS sequence number maintenance method is method one described above (after sending a NAS message, add 1 to the NAS count used in the NAS message and store it, and when the NAS message needs to be sent again, use the stored NAS count to securely protect the NAS message), then the first uplink NAS sequence number can be determined to be the uplink NAS sequence number corresponding to the 3GPP access technology stored in the terminal. If the terminal stores at least two uplink NAS sequence numbers corresponding to 3GPP access technologies, and the terminal cannot determine the uplink NAS sequence number used by the previous NAS message, the largest uplink NAS sequence number corresponding to the 3GPP access technology stored in the terminal is selected to securely protect the NAS message. If the maintenance method of the NAS sequence number is the method 2 described above (after sending the NAS message, the next time the NAS message needs to be sent, the stored NAS count is increased by 1 to determine a new NAS count, and the new NAS count is used to securely protect the NAS message), the first uplink NAS sequence number can be determined to be the uplink NAS sequence number corresponding to the 3GPP access technology stored in the terminal plus 1. If the terminal stores at least two uplink NAS sequence numbers corresponding to 3GPP access technologies, and the terminal cannot determine the uplink NAS sequence number used by the previous NAS message, the largest uplink NAS sequence number corresponding to the 3GPP access technology stored in the terminal is selected and increased by 1, and the uplink NAS sequence number after the increase by 1 is used to securely protect the NAS message.

[0168] In the case where the terminal has accessed the AMF node through a non-3GPP access technology, if the NAS sequence number maintenance method is the above-mentioned method one, it can be determined that the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the non-3GPP access technology saved by the terminal; if the NAS sequence number maintenance method is the above-mentioned method two, it can be determined that the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the non-3GPP access technology saved by the terminal plus 1.

[0169] Step 1002: The terminal sends a first message to the AMF node, where the first message carries part or all of the first uplink NAS sequence number.

[0170] The first message is securely protected by the first uplink NAS sequence number and the NAS key. Optionally, the first message may carry the 24-bit first uplink sequence number, or may carry only a portion of the first uplink sequence number, for example, only the last 4 or last 8 bits of the first uplink NAS sequence number.

[0171] In another possible implementation, if the terminal accesses the AMF node for the first time through a non-3GPP access technology, and the terminal has accessed the AMF node through a 3GPP access technology, the terminal can directly temporarily determine the first uplink NAS sequence number, and first use the NAS sequence number corresponding to the non-3GPP access technology to securely protect the first message, that is, the above steps 1001 to 1002 can be replaced by step 1003.

[0172] Step 1003: The terminal sends a first message to the AMF node, where the first message carries part or all of the uplink NAS sequence number corresponding to the second access technology.

[0173] The first message is securely protected by a NAS key and an uplink NAS sequence number corresponding to the second access technology.

[0174] The uplink NAS sequence number corresponding to the second access technology carried in the first message is part or all of the uplink NAS sequence number corresponding to the second access technology stored in the terminal, or part or all of the new uplink NAS sequence number obtained by adding 1 to the uplink NAS sequence number corresponding to the second access technology stored in the terminal. If the terminal stores at least two uplink NAS sequence numbers corresponding to the second technology, the uplink NAS sequence number corresponding to the second access technology in this step is the largest uplink NAS sequence number corresponding to the second access technology stored in the terminal.

[0175] It should be noted that, optionally, the first messages of step 1002 and step 1003 both include first indication information, and the first indication information is used to indicate the access technology corresponding to part or all of the uplink NAS sequence number carried in the first message, or the first indication information is used to indicate the transmission path corresponding to all or part of the NAS sequence number carried in the first message. Exemplarily, the first indication information carried in the first message of step 1002 indicates a non-3GPP access technology, and the first indication information carried in the first message of step 1003 indicates a 3GPP access technology. For another example, the first indication information carried in the first message of step 1002 indicates access to AMF via path 1, and the first indication information carried in the first message of step 1003 indicates access to AMF via path 2.

[0176] After the above step 1002 or step 1003, the following steps may also be performed.

[0177] Step 1004: The AMF node receives the first message.

[0178] Step 1005: The AMF node verifies the NAS sequence number carried by the first message according to the uplink NAS sequence number corresponding to the access technology indicated by the first indication information.

[0179] The indication information may be a displayed indication or an implicit notification. For example, the access type information may be the access type indication information explicitly notified in the N2 message (such as the radio access technology (RAT) type access type), or the access type indication information placed in the NAS message. In the absence of access type indication information, the AMF may determine the access type based on the source of the first message. For example, if the source address of the message is a base station, it is 3GPP access; if it is an N3IWF node, it is non-3GPP access; if it is a device connected to a fixed network, it is fixed network access.

[0180] In the case where the first indication information indicates a non-3GPP access technology, if the first message carries a complete first NAS sequence number, and the AMF node determines that the terminal has previously accessed the AMF node, the AMF node determines whether the first NAS sequence number is greater than the uplink NAS sequence number corresponding to the non-3GPP access technology received last time and stored in the AMF node. If it is greater, the verification is successful; if it is less, the verification fails, the terminal access is denied, and the terminal is informed of the reason for the access failure. Optionally, if the AMF node determines that the terminal has not previously accessed the AMF node through a non-3GPP access technology, the AMF node saves the first NAS sequence number as the uplink NAS sequence number corresponding to the non-3GPP access technology, or the AMF node determines that the uplink NAS sequence number corresponding to the non-3GPP access technology is 0. If the first message carries a part of the first NAS sequence number, the AMF node first recovers the complete first NAS sequence number, and then verifies or saves the first NAS sequence number according to the above-mentioned method for processing the first NAS sequence number.

[0181] In the case where the first indication information indicates a 3GPP access technology, if the first message carries a complete NAS sequence number corresponding to the 3GPP access technology, the AMF node determines whether the first NAS sequence number is greater than the uplink NAS sequence number corresponding to the last received 3GPP access technology stored in the AMF node. If it is greater, the verification is successful, and if it is less, the verification fails. If the first message carries a part of the NAS sequence number corresponding to the 3GPP access technology, the AMF node first recovers the complete NAS sequence number, and then uses the above-mentioned method for verifying the NAS sequence number to verify the recovered complete sequence number.

[0182] Step 1006: The AMF node determines one or both of the second uplink NAS sequence number and the first downlink NAS sequence number corresponding to the first access technology.

[0183] Among them, the second uplink NAS sequence number is 0, specifically, all or part of the bits of the second uplink NAS sequence number are 0. Or, the second uplink NAS sequence number is a random number. Specifically, part or all of the bits in the second uplink NAS sequence number are random numbers. For example, the sequence number part or the NAS overflow part in the second uplink NAS sequence number is a random number. At this time, the remaining part is 0. Or, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device. Or, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. Alternatively, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the first access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. Alternatively, the second uplink NAS sequence number is the first uplink NAS sequence number. Alternatively, the second uplink NAS sequence number is the first uplink NAS sequence number plus 1.

[0184] Optionally, if the first message received by the AMF node carries the first uplink NAS sequence number, the AMF node may determine that the second uplink NAS sequence number is the first NAS sequence number, or the second uplink NAS sequence number is the first uplink NAS sequence number plus 1.

[0185] Alternatively, if the first message received by the AMF node carries the first uplink NAS sequence number, indicating that the terminal has determined the NAS sequence number corresponding to the non-3GPP access technology, the AMF node may not determine the second NAS sequence number.

[0186] The first downlink NAS sequence number is 0, specifically, all or part of the bits of the first downlink NAS sequence number are 0. Or,

[0187] The first downlink NAS sequence number is a random number. Specifically, some or all bits in the first downlink NAS sequence number are random numbers. For example, the sequence number part or the NAS overflow part in the first downlink NAS sequence number is a random number. At this time, the remaining part is 0. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the second access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the second access technology stored in the core network device plus 1. Alternatively, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1. If the core network device stores at least two downlink NAS sequence numbers corresponding to the first access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the first access technology stored in the core network device plus 1.

[0188] Optionally, if the first message received by the AMF node carries a NAS sequence number corresponding to the second access technology, the second uplink NAS sequence number determined by the AMF node may be the same as the first downlink NAS sequence number.

[0189] Step 1007: The AMF node sends a second message to the terminal, where the second message includes one or all of the second uplink NAS sequence number and the first downlink NAS sequence number corresponding to the first access technology.

[0190] Accordingly, the terminal receives the second message.

[0191] Optionally, the second message carries second indication information, and the second indication information is used to indicate the access technology corresponding to the first downlink NAS sequence number carried in the second message. Optionally, the second message may also carry indication information for indicating the second uplink NAS sequence number carried in the second message. Optionally, the second indication information is used to indicate the transmission path corresponding to the first downlink NAS sequence number carried in the second message. Optionally, the second message may also carry indication information for indicating the transmission path corresponding to the second uplink NAS sequence number carried in the second message. It can be understood that since the second message carries the first downlink NAS sequence number corresponding to the first access technology, the second indication information is used to indicate the first access technology. For example, if the first access technology is a 3GPP access technology, the second indication information is used to indicate the 3GPP access technology; if the first access technology is a non-3GPP access technology, the second indication information is used to indicate the non-3GPP access technology.

[0192] It is understandable that after receiving the second message, the terminal may save one or both of the second uplink NAS sequence number and the first downlink NAS sequence number carried in the second message. When an uplink NAS message needs to be sent through non-3GPP next time, the NAS message may be securely protected according to the second uplink NAS sequence number. Alternatively, after receiving a downlink NAS message, the downlink NAS sequence number in the received downlink NAS message may be verified according to the first downlink NAS sequence number.

[0193] The following describes the security protection method described in the above embodiment in conjunction with a specific scenario. The embodiment of the present application can be applied to a scenario where the terminal has accessed the AMF node through a 3GPP access technology, and then the terminal accesses the same AMF node through a non-3GPP access technology, such as Fig.11 As shown, Fig.11 A registration process for a terminal to access an AMF node through a non-3GPP access technology, the method comprising:

[0194] Step 1101: The terminal accesses an untrusted non-3GPP network.

[0195] For example, the terminal is connected to a WiFi that cannot be directly trusted.

[0196] In this step, the terminal accesses an untrusted non-3GPP network, and the terminal has been authenticated by the 3GPP network and has a NAS security context. The NAS security context includes a NAS key, a key identifier, and a NAS sequence number corresponding to the 3GPP access technology. Optionally, the NAS context also includes a NAS sequence number corresponding to the non-3GPP access technology. If the terminal has previously accessed an AMF node through a non-3GPP access technology, the NAS sequence number corresponding to the non-3GPP access technology is not 0. If the terminal has previously accessed an AMF node through a non-3GPP access technology, the NAS sequence number corresponding to the non-3GPP access technology is 0.

[0197] The NAS key may be one or both of an encryption key and an integrity protection key.

[0198] Step 1102: The terminal and the N3IWF node exchange internet key exchange protocol security association initial (IKE_SA_INIT) messages.

[0199] Among them, the IKE_SA_INIT message carries key material, which is information used to securely protect messages transmitted between the terminal and the N3IWF node. After the terminal and the N3IWF node exchange IKE_SA_INIT messages, the terminal and the N3IWF node can generate the same key, which is used to securely protect messages subsequently transmitted by the terminal and the N3IWF node.

[0200] Step 1103: The terminal sends an Internet Key Exchange Protocol Authentication Request (IKE_AUTH_Req) ​​message to the N3IWF node.

[0201] Accordingly, the N3IWF node receives the IKE_AUTH_Req message.

[0202] Step 1104: The N3IWF node sends an Internet key exchange protocol authentication response message (internetkey exchange protocol_authentication_response, IKE_AUTH_Res) to the terminal.

[0203] Accordingly, the terminal receives the IKE_AUTH_Res message.

[0204] Among them, the IKE_AUTH_Res message carries the 5G start (5Gstart) message of the extensible authentication protocol 5G access request (extensible authentication protocol_5th generation_request, EAP_5G_Req) ​​message. The EAP_5G_Req message is used to request the terminal to start the 5G extensible authentication protocol (EAP) process.

[0205] Step 1105: The terminal determines the first uplink NAS sequence number.

[0206] Among them, the first uplink NAS sequence number is a sequence number used to securely protect the NAS message sent by the terminal to the AMF node.

[0207] There are two ways to implement this step:

[0208] The first one is that the terminal determines the first uplink NAS sequence number according to the uplink NAS sequence number corresponding to the 3GPP access technology.

[0209] Since the terminal has accessed the AMF node through the 3GPP access technology, the terminal has stored the NAS sequence number corresponding to the 3GPP access technology. If the maintenance method of the NAS sequence number is the above method one, it can be determined that the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the 3GPP access technology stored by the terminal (if the terminal stores at least two uplink NAS sequence numbers corresponding to the 3GPP access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the 3GPP access technology stored by the terminal); if the maintenance method of the NAS sequence number is the above method two, it can be determined that the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the non-3GPP access technology stored by the terminal plus 1 (if the terminal stores at least two uplink NAS sequence numbers corresponding to the non-3GPP access technology, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the non-3GPP access technology stored by the terminal plus 1).

[0210] The second method is that the terminal generates a NAS sequence number corresponding to the non-3GPP access technology, and uses the NAS sequence number corresponding to the non-3GPP access technology as the first uplink NAS sequence number.

[0211] Specifically, the first uplink NAS sequence number may be 0, or may be a random number.

[0212] If the first uplink NAS sequence number is 0, all or part of the bits of the first uplink NAS sequence number are 0. If the first uplink NAS sequence number is a random number, part or all of the bits in the first uplink NAS sequence number are random numbers. Exemplarily, the last 8 bits (sequence number part) of the first uplink NAS sequence number are random numbers, or the NAS overflow part is a random number, and the rest are 0.

[0213] Optionally, if the terminal has accessed the AMF node through a non-3GPP access technology, the terminal can determine that the first uplink NAS sequence number is the uplink NAS sequence number corresponding to the non-3GPP access technology stored in the terminal (if at least two uplink NAS sequence numbers corresponding to the non-3GPP access technology are stored in the terminal, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the non-3GPP access technology stored in the terminal), or the terminal can determine that the first uplink NAS sequence number is the NAS sequence number corresponding to the non-3GPP access technology stored in the terminal plus 1 (if at least two uplink NAS sequence numbers corresponding to the non-3GPP access technology are stored in the terminal, the first uplink NAS sequence number is the largest uplink NAS sequence number corresponding to the non-3GPP access technology stored in the terminal plus 1).

[0214] Optionally, if the second implementation method is used to determine the first uplink NAS sequence number, in the registration process of the terminal accessing the AMF node through the non-3GPP access technology, the terminal will not send a NAS message through the 3GPP access technology.

[0215] Optionally, the terminal may also set an indicator, which is equivalent to Fig.10 The first indication information in the corresponding embodiment is used to indicate whether the first uplink NAS sequence number corresponds to a 3GPP access technology or a non-3GPP access technology. It can be understood that if the terminal determines the first uplink NAS sequence number through the first implementation method, the indicator indicates the 3GPP access technology, and if the terminal determines the first uplink NAS sequence number using the second implementation method, the indicator indicates the non-3GPP access technology.

[0216] Step 1106: The terminal sends an IKE_AUTH_Req message to the N3IWF node.

[0217] Accordingly, the N3IWF node receives the IKE_AUTH_Req message.

[0218] Among them, the IKE_AUTH Req message includes a NAS protocol data unit (PDU) and a 5G non-access layer message corresponding to the extensible authentication protocol 5G access (a 5G-NAS message corresponding to the EAP-5G-ReS message) or a 5G-NAS message. The NAS PDU includes a registration request message, which is used by the terminal to register with the AMF node through 3GPP access technology. Optionally, the first message in the above embodiment can be the registration request message.

[0219] Optionally, the registration request message may be integrity protected by the first uplink NAS sequence number, and the registration request message includes the first indication information and the first uplink NAS sequence number. Optionally, the registration request message also includes a key identifier and a temporary identity of the terminal.

[0220] Step 1107: The N3IWF node selects an AMF node.

[0221] Among them, the method for the N3IWF node to select the AMF node can refer to the existing technology.

[0222] Step 1108: The N3IWF node forwards the registration request message to the AMF node.

[0223] Accordingly, the AMF node receives the registration request message.

[0224] Step 1109: The AMF node verifies the registration request message.

[0225] The verification of the registration request message by the AMF node includes the integrity protection verification of the registration request message and the verification of the first uplink NAS sequence number carried in the registration request message. The verification of the first uplink NAS sequence number carried in the registration request message by the AMF node corresponds to the above step 1005.

[0226] The AMF node can generate an integrity protection key based on the temporary identity and key identifier in the registration request message, and perform integrity protection verification on the registration request message based on the integrity protection key.

[0227] If the first indication information indicates that the access technology corresponding to the first uplink NAS message is the 3GPP access technology, the AMF node verifies whether the first uplink NAS sequence number is larger than the NAS sequence number corresponding to the 3GPP access technology received last time. If so, the verification succeeds, otherwise the verification fails.

[0228] If the access technology corresponding to the first uplink NAS message indicated by the first indication information is a non-3GPP access technology, and the terminal has not accessed the AMF node through the non-3GPP access technology, the AMF node saves the first NAS sequence number as the uplink NAS sequence number corresponding to the non-3GPP access technology, or the AMF node determines that the uplink NAS sequence number corresponding to the non-3GPP access technology is 0. If the terminal has accessed the AMF node through the non-3GPP access technology, the AMF node verifies whether the first uplink NAS sequence number is greater than the NAS sequence number corresponding to the non-3GPP access technology received last time. If so, the verification succeeds, otherwise the verification fails.

[0229] Step 1110: The AMF node generates a key Kn3iwf for the N3IWF node.

[0230] Among them, the key Kn3iwf is used for two-way authentication between the AMF node and the terminal.

[0231] Step 1111: The AMF node determines one or both of the second uplink NAS sequence number and the first downlink NAS sequence number corresponding to the non-3GPP access technology.

[0232] Optionally, if the access technology indicated by the first indication information is a 3GPP access technology, it means that the terminal has not determined the NAS sequence number for the non-3GPP access technology, and the AMF node can determine the second uplink NAS sequence number and the first downlink NAS sequence number corresponding to the non-3GPP access technology; if the access technology indicated by the first indication information is a non-3GPP access technology, it means that the terminal has determined the uplink NAS sequence number for the non-3GPP access technology, and the AMF node only needs to determine the first downlink NAS sequence number corresponding to the non-3DPP technology, or the AMF node determines the first downlink NAS sequence number and re-determines the uplink NAS sequence number of the non-3GPP access technology.

[0233] Specifically, the second uplink NAS sequence number is 0, or the second uplink NAS sequence number is a random number.

[0234] If the second uplink NAS sequence number is 0, all or part of the bits of the second uplink NAS sequence number are 0. If the second uplink NAS sequence number is a random number, some or all of the bits in the second uplink NAS sequence number are random numbers. For example, the last 8 bits (sequence number part) of the second uplink NAS sequence number are random numbers, or the NAS overflow part is a random number, and the rest are 0. Optionally, if the second uplink NAS sequence number is a random number, the second uplink NAS sequence number needs to be greater than the downlink NAS sequence number corresponding to the 3GPP access technology stored in the AMF node (if the AMF node stores at least two downlink NAS sequence numbers corresponding to the 3GPP access technology, the second uplink NAS sequence number needs to be greater than the largest downlink NAS sequence number corresponding to the 3GPP access technology stored in the AMF node).

[0235] The second uplink NAS sequence number may also be the downlink NAS sequence number corresponding to the 3GPP access technology stored by the AMF node (if the AMF node stores at least two downlink NAS sequence numbers corresponding to the 3GPP access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the 3GPP access technology stored by the terminal); or, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the 3GPP access technology stored for the AMF node plus 1 (if the AMF node stores at least two downlink NAS sequence numbers corresponding to the 3GPP access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the 3GPP access technology stored by the terminal plus 1); or, the second uplink NAS sequence number is the downlink NAS sequence number corresponding to the non-3GPP access technology stored by the AMF node plus 1 (if the AMF node stores at least two downlink NAS sequence numbers corresponding to the non-3GPP access technology, the second uplink NAS sequence number is the largest downlink NAS sequence number corresponding to the non-3GPP access technology stored by the terminal plus 1); or, the second uplink NAS sequence number is the first uplink NAS sequence number; or, the second uplink NAS sequence number is the first uplink NAS sequence number plus 1.

[0236] Optionally, the first downlink NAS sequence number may be the same as the second uplink NAS sequence number.

[0237] Specifically, the first downlink NAS sequence number may be 0, or may be a random number.

[0238] If the first downlink NAS sequence number is 0, all bits or some bits of the first downlink NAS sequence number are 0. If the first downlink NAS sequence number is a random number, some or all bits in the first downlink NAS sequence number are random numbers. For example, the last 8 bits (sequence number part) of the first downlink NAS sequence number are random numbers, or the NAS overflow part is a random number, and the rest are 0. Optionally, if the first downlink NAS sequence number is a random number, the first downlink NAS sequence number needs to be greater than the maximum downlink NAS sequence number corresponding to the 3GPP access technology stored in the AMF node.

[0239] The first downlink NAS sequence number may also be the downlink NAS sequence number corresponding to the 3GPP access technology stored in the AMF node (if the AMF node stores at least two downlink NAS sequence numbers corresponding to the 3GPP access technology, the first downlink NAS sequence number may also be the largest downlink NAS sequence number corresponding to the 3GPP access technology stored in the AMF node); or, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the 3GPP access technology stored in the AMF node plus 1 (if the AMF node stores at least two downlink NAS sequence numbers corresponding to the 3GPP access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the 3GPP access technology stored in the AMF node plus 1); or, the first downlink NAS sequence number is the downlink NAS sequence number corresponding to the non-3GPP access technology stored in the AMF node plus 1 (if the AMF node stores the downlink NAS sequence number corresponding to the non-3GPP access technology, the first downlink NAS sequence number is the largest downlink NAS sequence number corresponding to the non-3GPP access technology stored in the AMF node plus 1).

[0240] It should be noted that the AMF node can save one or all of the generated second uplink NAS sequence number and the first downlink NAS sequence number. The AMF node can maintain the uplink NAS sequence number and the downlink NAS sequence number corresponding to the 3GPP access technology, and can also maintain the uplink NAS sequence number and the downlink NAS sequence number corresponding to the non-3GPP access technology. If the AMF node generates the second uplink NAS sequence number and the first downlink NAS sequence number, the second uplink NAS sequence number and the first downlink NAS sequence number are saved. If the AMF node only generates the first downlink NAS sequence number, the first downlink NAS sequence number is saved. At this time, the uplink NAS sequence number corresponding to the non-3GPP access technology maintained by the terminal is the first uplink NAS sequence number.

[0241] It can be understood that the AMF node independently maintains a set of NAS sequence numbers for 3GPP access technology and non-3GPP access technology, that is, the size of the NAS sequence number maintained by the AMF node for 3GPP access technology and the NAS sequence number maintained for non-3GPP access technology will not affect each other. When receiving an uplink NAS message, the AMF node can determine the access technology or transmission path used by the terminal to transmit the uplink NAS message based on the bit information in the uplink NAS message or the information in the N2 message. If the access technology used is 3GPP access technology, the uplink NAS sequence number carried in the uplink NAS message can be compared to see whether it is greater than the maximum uplink NAS sequence number maintained for the 3GPP access technology; if the access technology used is non-3GPP access technology, the uplink NAS sequence number carried in the uplink NAS message can be compared to see whether it is greater than the maximum uplink NAS sequence number maintained for the non-3GPP access technology to prevent replay attacks.

[0242] Step 1112: The AMF node sends a NAS security mode command (SMC) message to the terminal through the N3IWF node.

[0243] Accordingly, the terminal receives the NAS SMC message.

[0244] Among them, the second message in the above embodiment may be the NAS SMC message.

[0245] The NAS SMC message carries one or both of the second uplink NAS sequence number and the first downlink NAS sequence number. It can be understood that if the AMF node only determines the first downlink NAS sequence number, the NAS SMC message carries the first downlink NAS sequence number. If the AMF node determines the second uplink NAS sequence number and the first downlink NAS sequence number, the NAS SMC message carries the second uplink NAS sequence number and the first downlink NAS sequence number.

[0246] Optionally, if the NAS message carries only the first downlink NAS sequence number, the NAS message may also carry indication information for instructing the terminal to continue using the uplink NAS sequence number determined by the terminal itself.

[0247] Optionally, the NAS SMC message also includes second indication information, and the second indication information is used to indicate the access technology or transmission path corresponding to the NAS sequence number carried by the NAS SMC message. In the scenario of this embodiment, the access technology indicated by the second indication information is a non-3GPP access technology.

[0248] Step 1113: The terminal determines the uplink NAS sequence number and the downlink NAS sequence number corresponding to the non-3GPP access technology according to the NAS SMC message.

[0249] Among them, the terminal may also independently maintain a set of NAS sequence numbers for 3GPP access technology and non-3GPP access technology respectively. In the scenario of this embodiment, the terminal has stored the uplink NAS sequence number and the downlink NAS sequence number corresponding to the 3GPP access technology. The terminal can also determine the uplink NAS sequence number and the downlink NAS sequence number maintained by non-3GPP according to the NAS SMC message received in this step.

[0250] Optionally, if the NAS SMC message includes only the first downlink NAS sequence number, the terminal determines that the uplink NAS sequence number corresponding to the non-3GPP access technology is still the first uplink NAS sequence number, and the downlink NAS sequence number corresponding to the non-3GPP access technology is the first downlink NAS sequence number; if the NAS SMC message includes the second uplink NAS sequence number and the first downlink NAS sequence number, the terminal can determine that the uplink NAS sequence number corresponding to the non-3GPP access technology is the second uplink NAS sequence number, and the downlink NAS sequence number corresponding to the non-3GPP access technology is the first downlink NAS sequence number.

[0251] It can be understood that when the terminal receives a downlink NAS message, it can determine the access technology or transmission path used by the terminal to transmit the downlink NAS message based on the bit information in the downlink NAS message. If the access technology used is 3GPP access technology, the downlink NAS sequence number carried in the downlink NAS message can be compared to see whether it is greater than the maximum downlink NAS sequence number maintained for the 3GPP access technology; if the access technology used is non-3GPP access technology, the downlink NAS sequence number carried in the downlink NAS message can be compared to see whether it is greater than the maximum downlink NAS sequence number maintained for the non-3GPP access technology to prevent replay attacks.

[0252] Step 1114: The terminal sends a NAS security mode complete (SMP) message to the AMF node through the N3IWF node.

[0253] Accordingly, the AMF node receives the NAS SMP message.

[0254] Optionally, the NAS message in the above step 502 may be a NAS SMP message in this step.

[0255] The terminal can perform integrity protection on the NAS SMP message through the first parameter, the uplink NAS sequence number and the NAS key. The first parameter is used to indicate that the access technology used to transmit the NAS SMP message is a non-3GPP access technology or to indicate that the transmission path for transmitting the NAS SMP message is Figure 2 In path 2, the uplink NAS sequence number is the uplink NAS sequence number corresponding to the non-3GPP access technology determined by the terminal in step 1113 or the uplink NAS sequence number corresponding to path 2. The NAS SMP message carries the uplink NAS sequence number.

[0256] It can be understood that after receiving the NAS SMP message, the AMF node can verify whether the uplink NAS sequence number carried in the NAS SMP message is greater than the uplink NAS sequence number corresponding to the non-3GPP access technology stored in the AMF node, or whether it is greater than the uplink NAS sequence number corresponding to path 2. If it is greater, it can be determined that the access technology used to transmit the NAS SMP message is a non-3GPP access technology based on the bit information in the NAS message, and then the first parameter corresponding to the non-3GPP access technology is determined, and then the NAS SMP message is integrity checked based on the first parameter, the NAS key and the uplink NAS sequence number carried in the NAS SMP message. If the check is successful, execute step 1115. Optionally, if the AMF stores multiple uplink NAS sequence numbers, it can be verified whether the uplink NAS sequence number carried in the NAS SMP message is greater than the largest uplink NAS sequence number corresponding to the non-3GPP access technology stored in the AMF node.

[0257] Step 1115: The AMF node sends an N2 message to the N3IWF node, wherein the N2 message carries the key Kn3iwf and the registration completion message.

[0258] Accordingly, the N3IWF node receives the N2 message.

[0259] Step 1116: The N3IWF node sends an EAP-5G-Success message to the terminal.

[0260] Accordingly, the terminal receives the EAP-5G-Success message.

[0261] Step 1117: The terminal and the N3IWF node complete the calculation of authentication parameters through Kn3iwf.

[0262] Step 1118: Establish an internet protocol security (IPsec) connection between the terminal and the N3IWF node.

[0263] Step 1119: The N3IWF node sends a registration completion message to the terminal.

[0264] Through the method provided in the embodiment of the present application, the terminal can access the network through a non-3GPP access technology, and the terminal can independently maintain the NAS serial number of the 3GPP access technology and the NAS serial number of the non-3GPP access technology, thereby reducing the possibility of a replay attack.

[0265] In a possible implementation of the embodiment of the present application, the security context of the terminal may be bound to the operator information. For example, the operator information may be the PLMN ID. Fig.11 During the corresponding process, it can be determined whether the N3IWF node corresponding to the non-3GPP access technology is still operator A. If so, it can continue Fig.11 The corresponding process.

[0266] In another possible implementation, the security context of the terminal on the non-3GPP access technology side may be bound to other information, such as subscription information, location area information, etc. Exemplarily, if the terminal moves from the coverage of base station A to the coverage of base station B, if non-3GPP access technology C is supported within the coverage of terminal A, and base station B supports non-3GPP access technology D, if the terminal accesses the network through non-3GPP access technology C, when the terminal moves from the coverage of base station A to the coverage of base station B, if the subscription information of the terminal indicates that the terminal does not have the authority to use non-3GPP access technology D, then the terminal cannot access the network through non-3GPP access technology D.

[0267] Optionally, in the above embodiment, the AMF node may determine the access technology used to transmit the NAS message based on the first indication information. The embodiments of the present application also provide three methods for the AMF node to determine the access technology used for the N2 message or the NAS message after receiving the N2 message.

[0268] Method 1: The AMF node can determine the access technology used to transmit the N2 message based on the source of the N2 message. For example, the source of the message can be determined based on the source address information (such as the IP address), and then the access technology used to transmit the message can be determined based on the source of the message. If the N2 message comes from a device using 3GPP access technology, such as a base station, it is determined that the NAS sequence number corresponding to the 3GPP access technology can be used, that is, the AMF node can use the uplink NAS sequence number corresponding to the 3GPP access technology stored by itself to verify the uplink NAS sequence number carried in the N2 message. If the N2 message comes from a device using non-3GPP access technology, such as an N3IWF node, it is determined that the NAS sequence number corresponding to the non-3GPP access technology can be used, that is, the AMF node can use the uplink NAS sequence number corresponding to the non-3GPP access technology stored by itself to verify the uplink NAS sequence number carried in the N2 message.

[0269] Method 2: The terminal can inform the AMF node of the source of the N2 message by display. For example, the N2 message can carry bits used to indicate the access technology, such as 0 for 3GPP access technology and 1 for 3GPP access technology; or, the N2 message can carry a character string, such as "NR" for 3GPP access technology and "wifi" for non-3GPP access technology.

[0270] Method 3: The AMF node determines the access technology used to transmit the N2 message based on the access type information in the N2 message, for example, the access type information is rat type (access type) information. If the N2 message comes from a device using 3GPP access technology, such as a base station, the access type indication in the N2 message is 3GPP access, and it is determined that the NAS sequence number corresponding to the 3GPP access technology can be used, that is, the AMF node can use the uplink NAS sequence number corresponding to the 3GPP access technology stored by itself to verify the uplink NAS sequence number carried in the N2 message.

[0271] Compared with the prior art, the AMF node does not distinguish the access technology used by the received message. The embodiment of the present application enables the AMF node to determine the access technology used by the received message through the above two methods, thereby selecting the NAS sequence number corresponding to the access technology used by the received message.

[0272] Optionally, in another implementation provided in the embodiment of the present application, in combination with Fig.11 Corresponding method flow, if in step 1111, the AMF node determines the second uplink NAS sequence number and the first downlink NAS sequence number corresponding to the non-3GPP access technology, the AMF node can also update the NAS key. The embodiments of the present application provide the following four methods for updating the NAS key.

[0273] Method 1: Generate a new Kamf (nKamf) using the old Kamf (oKamf). After the AMF node generates nKamf, generate a new NAS key based on nKamf.

[0274] Among them, Kamf is the root key of the AMF node.

[0275] nKamf=KDF(oKamf, freshness parameter), the freshness parameter can be the uplink NAS sequence number last received by the AMF node, or COUNT, or a parameter sent by the terminal to the AMF node, or a parameter negotiated between the terminal and the AMF node.

[0276] Method 2: Use Kseaf to generate nKamf. After the AMF node generates nKamf, generate a new NAS key based on nKamf.

[0277] Among them, Kseaf is the root key of the AMF node.

[0278] nKamf = KDF (Kamf, freshness parameter), where the freshness parameter can be the uplink NAS sequence number received by the AMF node last time, or a counter value. For example, the initial value of the counter value is 0, and each time the AMF node generates a NAS key, the counter value is increased by 1, indicating that the AMF node has generated a new key.

[0279] Method 3: The AMF node can generate a new NAS key based on the old Kamf (oKamf) and algorithm.

[0280] Where nKamf = KDF (oKamff, algorithm ID, selected algorithm, other parameters), where algorithm ID is the identifier of the algorithm selected by AMF. The selected algorithm is the algorithm used for security protection of NAS messages between the terminal and AMF.

[0281] Other parameters are parameters used to indicate access technologies. Specifically, other parameters may be in the form of bits or IDs. For example, it may be specified that: other parameters corresponding to 3GPP access technologies are 0x01, other parameters corresponding to non-3GPP access technologies are 0x10, and fixed network access technologies are 0x11.

[0282] Other parameters may also be counter values. For example, the initial value of the counter value is 0, and each time the AMF node generates a NAS key, the counter value increases by 1, indicating that the AMF node has generated a new key.

[0283] Method 4: Generate a new NAS key based on the old NAS key.

[0284] Wherein, the new NAS key = (old NAS key, counter value). Exemplarily, the initial value of the counter value is 0, and each time the AMF node generates a NAS key, the counter value is increased by 1, which is used to indicate that the AMF node has generated a new key.

[0285] It should be noted that if the AMF node generates a new NAS key, it can be Fig.11 The NAS SMC message in the corresponding embodiment instructs the terminal to update the key in a displayed manner. After the terminal receives the instruction to update the key, it can update the key by one of the above four methods. Among them, the method for updating the key by the terminal is the same as the method for updating the NAS key by the AMF node, and the method for updating the NAS key is pre-configured in the AMF node and the terminal.

[0286] Optionally, the NAS key can be updated when the access technology used is switched between the AMF node and the terminal, or when switching from using multiple access technologies simultaneously to using only one access technology, or when reducing the number of access technologies used simultaneously.

[0287] By adopting this method, through key update, even if an attacker obtains the NAS key when the AMF node and the terminal use multiple access technologies to communicate at the same time, the attacker cannot obtain the plaintext when the terminal and the AMF node subsequently communicate using a single access technology, thereby improving security.

[0288] It should be noted that the embodiments of the present application are all described by taking the first access technology as a non-3GPP access technology and the second access technology as a 3GPP access technology as an example. In practical applications, it may also be that: the first access technology is a 3GPP access technology, and the second access technology is a non-3GPP access technology. In the case where the first access technology and the second access technology are two different access technologies supported by the terminal, respectively, the method provided in the above embodiment can be adopted, or in the case where the terminal accesses the core network device through multiple access technologies, the method provided in the above embodiment can also be adopted.

[0289] Exemplarily, if the first access technology is a fixed network access technology and the second access technology is a non-3GPP access technology, the implementation method is similar to the method described in the above embodiment. Fig.11 The corresponding embodiment can be applied to the scenario where the terminal has accessed the AMF node through the 3GPP access technology and then accessed the same AMF node through the fixed network access technology. Fig.11 The process can be replaced by the registration process of the terminal accessing the AMF node through the fixed network access technology. The security protection method in the registration process is the same as Fig.11 The security protection method described in the embodiment of the invention for a terminal to access an AMF node through a non-3GPP access technology is similar.

[0290] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of interaction between different network elements. It can be understood that in order to realize the above functions, the terminal and the core network equipment include hardware structures and / or software modules corresponding to the execution of each function. In combination with the units and algorithm steps of each example described in the embodiments disclosed in this application, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiment of the present application.

[0291] The embodiments of the present application can divide the functional units of the terminal and the core network equipment according to the above method examples. For example, each functional unit can be divided according to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units. It should be noted that the division of units in the embodiments of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0292] In the case of an integrated unit, Fig.12 1200 is a schematic block diagram of another device provided in an embodiment of the present application. The device 1200 may exist in the form of software, or may be a terminal, or may be a chip in a terminal. The device 1200 includes: a processing unit 1202 and a communication unit 1203. The processing unit 1202 is used to control and manage the actions of the device 1200. For example, the processing unit 1202 is used to support the device 1200 to execute Figure 5 Steps 501 to 502 in Fig.10 Step 1001 in Fig.11 The communication unit 1203 is used to support the communication between the apparatus 1200 and other network elements (e.g., core network equipment, N3IWF node). For example, the communication unit 1203 is used to support the apparatus 1200 to perform Fig.10 Steps 1002, 1003 and 1007 in Fig.11 The apparatus 1200 may further include a storage unit 1201 for storing program codes and data of the apparatus 1200.

[0293] Among them, the processing unit 1202 can be a processor or a controller, for example, a central processing unit (CPU), a general processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements a computing function, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like. The communication unit 1203 can be a transceiver, a transceiver circuit or a communication interface, etc. The storage unit 1201 can be a memory.

[0294] When the processing unit 1202 is a processor, the communication unit 1203 is a transceiver, and the storage unit 1201 is a memory, the device 1200 involved in the embodiment of the present application can be Fig.13 Terminal shown.

[0295] Fig.13 The simplified schematic diagram of a possible design structure of a terminal involved in the embodiment of the present application is shown. The terminal 1300 includes a transmitter 1301, a receiver 1302 and a processor 1303. The processor 1303 may also be a controller. Fig.13 1303 . Optionally, the terminal 1300 may further include a modem processor 1305 , wherein the modem processor 1305 may include an encoder 1306 , a modulator 1307 , a decoder 1308 and a demodulator 1309 .

[0296] In one example, the transmitter 1301 adjusts (e.g., analog conversion, filtering, amplification, up-conversion, etc.) the output sample and generates an uplink signal, which is transmitted to the base station described in the above embodiment via an antenna. On the downlink, the antenna receives the downlink signal transmitted by the base station in the above embodiment. The receiver 1302 adjusts (e.g., filters, amplifies, down-converts, and digitizes) the signal received from the antenna and provides input samples. In the modem processor 1305, the encoder 1306 receives the service data and signaling message to be sent on the uplink, and processes the service data and signaling message (e.g., formatting, encoding, and interleaving). The modulator 1307 further processes (e.g., symbol mapping and modulation) the encoded service data and signaling message and provides output samples. The demodulator 1309 processes (e.g., demodulates) the input sample and provides symbol estimation. The decoder 1308 processes (e.g., deinterleaves and decodes) the symbol estimation and provides decoded data and signaling messages sent to the terminal 1300. The encoder 1306, modulator 1307, demodulator 1309 and decoder 1308 can be implemented by the synthesized modem processor 1305. These units perform processing according to the radio access technology (e.g., LTE and other access technologies of evolved systems) adopted by the radio access network. It should be noted that when the terminal 1300 does not include the modem processor 1305, the above functions of the modem processor 1305 can also be completed by the processor 1303.

[0297] The processor 1303 controls and manages the actions of the terminal 1300, and is used to execute the processing performed by the terminal 1300 in the above-mentioned embodiment of the present application. For example, the processor 1303 is also used to execute Figure 5 ,as well as Figure 10 to Figure 11 The method shown involves the processing process of the terminal and / or other processes of the technical solution described in this application.

[0298] Furthermore, the terminal 1300 may also include a memory 1304 , and the memory 1304 is used to store program codes and data for the terminal 1300 .

[0299] In the case of an integrated unit, Fig.14 1400 is a schematic block diagram of another device provided in an embodiment of the present application. The device may exist in the form of software, may be a core network device, or may be a chip in a core network device. The device 1400 includes: a processing unit 1402 and a communication unit 1403. The processing unit 1402 is used to control and manage the actions of the device 1400. For example, the processing unit 1402 is used to support the device 1400 to execute Fig. 9 Steps 901 and 902 in Fig.10 Steps 1004 to 1006 in Fig.11 The communication unit 1403 is used to support the communication between the apparatus 1400 and other network elements (e.g., terminals, N3IWF nodes). For example, the communication unit 1403 is used to support the apparatus 1400 to perform Fig.10 Steps 1002 to 1002 and 1007 in Fig.11 The apparatus 1400 may further include a storage unit 1401 for storing program codes and data of the apparatus 1400.

[0300] Among them, the processing unit 1402 can be a processor or a controller, for example, it can be a CPU, a general processor, a DSP, an ASIC, an FPGA or other programmable logic device, a transistor logic device, a hardware component or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in combination with the contents disclosed in this application. The processor can also be a combination that implements computing functions, for example, including one or more microprocessor combinations, a combination of DSP and microprocessors, and so on. The communication unit 1403 can be a communication interface, wherein the communication interface is a general term. In a specific implementation, the communication interface can include multiple interfaces, for example, it can include: an interface between a core network device and a terminal, an interface between a core network device and an N3IWF node, and / or other interfaces. The storage unit 1401 can be a memory.

[0301] When the processing unit 1402 is a processor, the communication unit 1403 is a communication interface, and the storage unit 1401 is a memory, the structure of the device 1400 involved in the embodiment of the present application can be as follows: Fig.15 The structure of the core network equipment shown.

[0302] Fig.15 A possible structural diagram of a core network device provided in an embodiment of the present application is shown.

[0303] like Fig.15 As shown, the core network device 1500 includes: a processor 1502, a communication interface 1503, and a memory 1501. Optionally, the core network device 1500 may also include a bus 1504. The communication interface 1503, the processor 1502, and the memory 1501 may be interconnected via the bus 1504; the bus 1504 may be a PCI bus or an EISA bus, etc. The bus 1504 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.15 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0304] The steps of the method or algorithm described in conjunction with the disclosure of the present application may be implemented in hardware or by executing software instructions by a processor. The software instructions may be composed of corresponding software modules, which may be stored in a random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, mobile hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may be located in an ASIC. In addition, the ASIC may be located in a core network interface device. Of course, the processor and the storage medium may also be present in a core network interface device as discrete components.

[0305] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical or other forms.

[0306] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network devices. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0307] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each functional unit may exist independently, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0308] Through the description of the above implementation methods, the technicians in the relevant field can clearly understand that the present application can be implemented by means of software plus necessary general hardware, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a readable storage medium, such as a computer floppy disk, hard disk or optical disk, etc., and includes a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present application.

[0309] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application shall be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.

Claims

1. A security protection method, characterized in that: include: Determine a value of a first parameter, where the value of the first parameter is used to indicate an access technology used to transmit a non-access stratum NAS message, wherein the first parameter is an input parameter for security protection of the NAS message; The NAS message is securely protected according to the value of the first parameter, the NAS key, and a NAS sequence number corresponding to the access technology used to transmit the NAS message.

2. The method according to claim 1, characterized in that The first parameter is bearer information BEARER.

3. The method according to claim 2, characterized in that Before determining the value of the first parameter, the method further comprises: Determine an access technology used to transmit the NAS message.

4. The method according to any one of claims 1 to 3, characterized in that: When the access technology used to transmit the NAS message is a 3GPP access technology, the value of the first parameter is a first value; when the access technology used to transmit the NAS message is a non-3GPP access technology, the value of the first parameter is a second value.

5. The method according to any one of claims 1 to 3, characterized in that: The NAS message is a NAS message to be transmitted to a core network device, and the security protection of the NAS message includes: The NAS message is encrypted or integrity protected.

6. The method according to claim 4, characterized in that The NAS message is a NAS message to be transmitted to a core network device, and the security protection of the NAS message includes: The NAS message is encrypted, or the NAS message is integrity protected.

7. The method according to any one of claims 1 to 3, characterized in that: The NAS message is a received NAS message, and the security protection of the NAS message includes: The NAS message is decrypted or integrity protection verification is performed on the NAS message.

8. The method according to claim 4, characterized in that The NAS message is a received NAS message, and the security protection of the NAS message includes: The NAS message is decrypted or integrity protection verification is performed on the NAS message.

9. The method according to any one of claims 1 to 3, characterized in that: The method is executed by a terminal or a chip in the terminal.

10. The method according to claim 4, characterized in that The method is executed by a terminal or a chip in the terminal.

11. The method according to claim 5, characterized in that The method is executed by a terminal or a chip in the terminal.

12. The method according to claim 7, characterized in that The method is executed by a terminal or a chip in the terminal.

13. The method according to any one of claims 6 or 8, characterized in that: The method is executed by a terminal or a chip in the terminal.

14. The method according to claim 9, characterized in that The terminal or the chip supports at least two access technologies, and respectively maintains a corresponding NAS sequence number for each of the at least two access technologies.

15. The method according to any one of claims 10 to 12, characterized in that: The terminal or the chip supports at least two access technologies, and respectively maintains a corresponding NAS sequence number for each of the at least two access technologies.

16. The method according to claim 13, characterized in that The terminal or the chip supports at least two access technologies, and respectively maintains a corresponding NAS sequence number for each of the at least two access technologies.

17. The method according to any one of claims 1 to 3, characterized in that: The method is executed by a core network device.

18. The method according to claim 4, characterized in that The method is executed by a core network device.

19. The method according to claim 7, characterized in that The method is executed by a core network device.

20. The method according to claim 8, characterized in that The method is executed by a core network device.

21. The method according to claim 17, characterized in that The core network device maintains a corresponding NAS sequence number for each access technology of at least two access technologies supported by the terminal.

22. The method according to any one of claims 18 to 20, characterized in that: The core network device maintains a corresponding NAS sequence number for each access technology of at least two access technologies supported by the terminal.

23. A computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium, and when the computer-readable storage medium is executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 22.

24. A communication device, characterized in that: include: A memory and a processor coupled to the memory; The memory stores program instructions, and when the processor executes the program instructions, the communication device executes the method described in any one of claims 1 to 22.

25. A communication device, characterized in that: The method comprises a unit for executing any one of the methods of claims 1 to 22.

26. A computer program product, characterized in that Contains instructions, which, when executed on a computer, cause the method according to any one of claims 1 to 22 to be performed.

Citation Information

Patent Citations

  • Safety protection method and device

    CN109361655A

  • Safety protection method and device

    CN109803263A

Cited By

  • Security protection method and device

    CN120499662A

  • A method and apparatus for security protection

    CN120499662B