A secure communication method, device and system
By reusing the established security context in the 5G network, the problem of resource waste and time extension when the user equipment UE registers to access new network slices is solved, and more efficient network operation is achieved.
Patent Information
- Application Number
- CN201910049372.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-01-18
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2039-01-18
AI Technical Summary
In 5G networks, when a user equipment UE registers to access new network slices, the prior art needs to re-establish a security context, resulting in waste of network resources and extended registration time.
The registered and accessed first network entity sends a message to the first network slice entity to be registered, obtains and reuses the established security context, reducing the need for reauthentication.
The UE registration access time of user equipment is reduced, the waste of network resources is avoided, and network efficiency is improved.
Smart Images

Figure CN111464324B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to but are not limited to mobile communication security technology, and in particular to a secure communication method, device and system. Background Art
[0002] 5G network architecture will introduce new information technology (IT, Internet Technology) technologies, such as network function virtualization (NFV). In 3G or 4G networks, the protection of functional network elements depends largely on the security isolation of physical devices. In 5G networks, due to the deployment of NFV technology, some functional network elements are deployed on cloud infrastructure in the form of virtual functional network elements. The virtual core network built based on network service requirements is called a network slice. A network slice constitutes a virtual core network, providing mobile network access services for a group of specific user terminals (UE, User Equipment). A typical network slice includes a set of virtualized core network functions, such as a slice control plane unit, which is mainly responsible for the mobility, session management and authentication-related functions of the slice, a slice user plane unit mainly provides users with slice user resources, a slice policy control unit is responsible for user policy functions, and a slice billing unit is responsible for user billing functions. The functions of network slices are determined by operators based on demand and operator policies. For example, some network slices may include a dedicated forwarding plane in addition to the control plane functions; while some network slices may only include some basic control plane functions, and other core network-related functions are shared with other network slices. Network slices may be created, modified, or deleted based on demand. A UE may also receive services from different network slices simultaneously.
[0003] In 5G networks, in order to meet the service needs of different types of users, there are multiple different network slices in the network. Users access the network and are authenticated by the network. If users want to use the services provided by the network, they need to access one or more network slices and be authenticated by the network slices. In each network slice, an access management function (AMF) and / or a security anchor function (SEAF) are set up to manage security-related processing of network slices, such as managing security contexts. Different network slices are isolated from each other, and the communication of one slice cannot affect the services provided by other slices.
[0004] Since the user equipment UE may access one or more network slices after accessing the 5G network, the user equipment UE may have one or more security contexts corresponding to the network and multiple network slices. In the current 5G system, when a UE with one or more security contexts registers to access a new service network or network slice, a new security context needs to be established, and the old security context previously used by the network side is stopped. Since the new registration process does not use the old security context at all, this leads to a waste of network resources and increases the time for UE registration and access. When the UE registers to access a new network slice, how to reuse the old security context to reduce the registration and access time and avoid waste of network resources is a problem that needs to be solved. Summary of the invention
[0005] The embodiments of the present invention provide a secure communication method, device and system, which can reduce the time for registration access and reduce the waste of network resources.
[0006] An embodiment of the present invention provides a secure communication method, including:
[0007] Sending a first message to the first network slice entity through a registered and connected first network entity to a first network entity of a network where the first network slice entity is located;
[0008] Receive a fourth message from the first network slicing entity.
[0009] An embodiment of the present invention provides a secure communication method, including:
[0010] Receive a first message from a user device; wherein the first message includes: an identifier of a first network slice entity to be registered and accessed; and forward the first message to the first network slice entity according to the identifier of the first network slice entity.
[0011] An embodiment of the present invention provides a secure communication method, including:
[0012] Receiving a first message sent by a user equipment to the first network slice entity through a first network entity of a network where a first network slice entity to be registered and accessed is located;
[0013] Obtain a first network slice security context established between the user equipment and the first network slice entity, and send a fourth message to the user equipment.
[0014] An embodiment of the present invention provides a secure communication method, including:
[0015] Receiving a seventh message from the first network slice entity to be registered and accessed; wherein the seventh message includes the fifth message or the second message;
[0016] Send an eighth message to the first network slice entity; wherein the eighth message includes the sixth message or the third message, and the eighth message includes a second network slice security context established between the user equipment and the registered and connected second network slice entity.
[0017] An embodiment of the present invention provides a secure communication method, including:
[0018] Receiving a second message from a first network entity of a network where a first network slice entity to be registered and accessed is located; wherein the second message includes an identifier of the first network slice entity;
[0019] Send a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment.
[0020] An embodiment of the present invention provides a secure communication method, including:
[0021] Sending a first message to a second network entity to be registered and accessed; wherein the first message includes: temporary identity information of the user equipment in the first network slice entity that has been registered and accessed, temporary identity information of the user equipment in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated;
[0022] Acquire a second network security context established with the second network entity, and receive a fourth message from the second network entity.
[0023] An embodiment of the present invention provides a secure communication method, including:
[0024] Receive a first message from a user device; wherein the first message includes: temporary identity information of the user device in the second network slice entity that has been registered and accessed, temporary identity information of the user device in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated;
[0025] Obtain verification indication information or authentication indication information of a user device, and obtain a first network security context established between the user device and the first network entity;
[0026] A second network security context established with the user equipment is acquired, and a fourth message is sent to the user equipment.
[0027] An embodiment of the present invention provides a secure communication method, including:
[0028] Receiving a second message from a second network entity to be registered and accessed;
[0029] Send a third message to the second network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment, and cancels the registration of the user equipment in the first network slice entity that has been registered and accessed.
[0030] An embodiment of the present invention provides a secure communication method, including:
[0031] receiving a fifth message from a second network entity to be registered and accessed; wherein the fifth message includes verification indication information or authentication indication information of the user equipment;
[0032] A sixth message is sent to the second network entity; wherein the sixth message includes a first network security context established between the user equipment and the registered and accessed first network entity.
[0033] An embodiment of the present invention provides a secure communication device, including a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, and when the instructions are executed by the processor, any of the above-mentioned secure communication methods is implemented.
[0034] An embodiment of the present invention provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned secure communication methods are implemented.
[0035] The embodiment of the present invention includes: sending a first message to a first network slice entity to be registered and accessed through a first network entity that has been registered and accessed; and receiving a fourth message from the first network slice entity. The embodiment of the present invention does not require a complete re-authentication process, which reduces the registration access time and reduces the waste of network resources.
[0036] An embodiment of the present invention provides a secure communication system, including:
[0037] A user device, used for sending a first message to the first network slice entity through a first network entity of the network where the first network slice entity to be registered and accessed is located; and receiving a fourth message from the first network slice entity;
[0038] A first network entity, configured to receive a first message from a user equipment; wherein the first message includes: an identifier of a first network slice entity to be registered and accessed; and forwarding the first message to the first network slice entity according to the identifier of the first network slice entity;
[0039] The first network slice entity is used to receive a first message sent by a user device through the first network entity; obtain a first network slice security context established between the user device and the first network slice entity, and send a fourth message to the user device.
[0040] An embodiment of the present invention provides a secure communication system, including:
[0041] A user device is used to send a first message to a second network entity to be registered and accessed; wherein the first message includes: temporary identity information of the user device in the first network slice entity that has been registered and accessed, temporary identity information of the user device in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated; obtain a second network security context established with the second network entity, and receive a fourth message from the second network entity;
[0042] The second network entity is used to receive a first message from a user device; obtain verification indication information of the user device, obtain a first network security context established between the user device and the first network entity; obtain a second network security context established with the user device, and send a fourth message to the user device.
[0043] Other features and advantages of the embodiments of the present invention will be described in the following description, and partly become apparent from the description, or be understood by implementing the embodiments of the present invention. The purposes and other advantages of the embodiments of the present invention can be achieved and obtained by the structures particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The accompanying drawings are used to provide a further understanding of the technical solutions of the embodiments of the present invention and constitute a part of the specification. Together with the embodiments of the embodiments of the present invention, they are used to explain the technical solutions of the embodiments of the present invention and do not constitute a limitation on the technical solutions of the embodiments of the present invention.
[0045] Figure 1 A flowchart of a secure communication method proposed by an embodiment of the present invention;
[0046] Figure 2 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0047] Figure 3 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0048] Figure 4 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0049] Figure 5 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0050] Figure 6 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0051] Figure 7 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0052] Figure 8 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0053] Fig. 9 A flowchart of a secure communication method proposed in another embodiment of the present invention;
[0054] Fig.10 A flowchart of a secure communication method proposed in Example 1 of an embodiment of the present invention;
[0055] Fig.11 A flowchart of a secure communication method proposed in Example 2 of an embodiment of the present invention;
[0056] Fig.12 A flowchart of a secure communication method proposed in Example 3 of an embodiment of the present invention;
[0057] Fig.13 A flowchart of a secure communication method proposed in Example 4 of an embodiment of the present invention;
[0058] Fig.14 A flowchart of a secure communication method proposed in Example 5 of an embodiment of the present invention;
[0059] Fig.15 A flowchart of a secure communication method proposed in Example 6 of an embodiment of the present invention;
[0060] Fig.16 This is a flowchart of a secure communication method proposed in Example 7 of an embodiment of the present invention. DETAILED DESCRIPTION
[0061] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other at will.
[0062] The steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions. Also, although a logical sequence is shown in the flowchart, in some cases, the steps shown or described can be performed in a sequence different from that shown here.
[0063] In an embodiment of the present invention, a user device may support one or more security contexts, corresponding to one or more networks and / or network slices, respectively.
[0064] In the embodiment of the present invention, only one security context is allowed to be in an active state at any time.
[0065] See also Figure 1 An embodiment of the present invention provides a secure communication method, including:
[0066] Step 100: Send a first message to the first network slice entity through the first network entity of the network where the first network slice entity to be registered and accessed is located.
[0067] In this embodiment of the present invention, sending the first message includes any one of the following:
[0068] directly sending the first message;
[0069] Sending the first message, verification indication information of the user equipment, and a message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated;
[0070] Sending the first message and verification indication information of the user equipment.
[0071] In this embodiment of the present invention, the first message includes any one of the following:
[0072] The temporary identity information of the user equipment in the first network entity, the identifier of the first network slice entity and the message authentication code (MAC) calculated based on the first network security context that is currently activated;
[0073] Temporary identity information of the user equipment in the first network entity, temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0074] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the second network slice security context that is currently activated;
[0075] The temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated.
[0076] Among them, the temporary identity information is a 5G globally unique temporary user equipment (UE, User Equipment) identifier (5G-GUTI, 5G Globally Unique Temporary UE Identity), and the identifier of the first network slice entity includes network slice selection assistance information (NSSAI, Network Slice Selection Assistance Information).
[0077] Step 101, receive the fourth message from the first network slice entity.
[0078] In another embodiment of the present invention, the steps between step 100 and step 101 further include:
[0079] Step 102: Obtain the first network slice security context established with the first network slice entity.
[0080] Specifically, step 102 includes any one of the following:
[0081] Performing authentication and a NonAccess Stratum Security Mode Command (NAS SMC) process with the first network slice entity, and establishing a first network slice security context with the first network slice entity;
[0082] The first network slice security context is obtained by horizontally dispersing the keys in the second network slice security context established with the registered and connected second network slice entity.
[0083] In the embodiment of the present invention, the first message is a registration request message, and the fourth message is a registration confirmation message.
[0084] In an embodiment of the present invention, the first network entity, the first network slice entity, and the second network slice entity belong to the same network;
[0085] Alternatively, the first network entity and the first network slice entity belong to the same network, and the first network slice entity and the second network slice entity belong to different networks.
[0086] See also Figure 2 Another embodiment of the present invention provides a secure communication method, comprising:
[0087] Step 200: Receive a first message from a user device; wherein the first message includes: an identifier of a first network slice entity to be registered and accessed; and forward the first message to the first network slice entity according to the identifier of the first network slice entity.
[0088] In an embodiment of the present invention, forwarding the first message to the first network slice entity according to the identifier of the first network slice entity includes any one of the following:
[0089] Forwarding the first message directly to the first network slice entity according to the identifier of the first network slice entity;
[0090] Obtain verification indication information or authentication indication information of the user equipment, and send the first message, the verification indication information or authentication indication information of the user equipment, and the message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated to the first network slice entity according to the identifier of the first network slice entity;
[0091] When the first message does not contain the temporary identity information of the user equipment in the second network entity, perform authentication and NAS SMC processes with the user equipment, and establish a first network security context with the user equipment; and send the first message and authentication indication information of the user equipment to the first network slice entity.
[0092] In this embodiment of the present invention, the first message further includes any one of the following:
[0093] The temporary identity information of the user equipment in the first network entity and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0094] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0095] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, and the message authentication code MAC calculated based on the second network slice security context that is currently activated;
[0096] The temporary identity information of the user equipment in the second network slice entity that has been registered and connected and the message authentication code MAC calculated based on the first network security context that is currently activated.
[0097] In another embodiment of the present invention, the method further comprises:
[0098] Step 201: Receive a second message from the first network slice entity, and send a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment; and revoke the registration of the user equipment in the first network entity.
[0099] In the embodiment of the present invention, the first message is a registration request message, the second message is a security context migration request message, and the third message is a security context migration response message.
[0100] See also Figure 3 Another embodiment of the present invention provides a secure communication method, comprising:
[0101] Step 300: Receive a first message sent by a user device to the first network slice entity through a first network entity of the network where the first network slice entity to be registered and accessed is located.
[0102] In this embodiment of the present invention, receiving the first message includes any one of the following:
[0103] directly receiving the first message;
[0104] Receiving a first message, verification indication information or authentication indication information of a user equipment, and a MAC calculated based on a first network security context or a second network slice security context that is currently activated;
[0105] A first message and authentication indication information of a user equipment are received.
[0106] In this embodiment of the present invention, the first message includes any one of the following:
[0107] Temporary identity information of the user equipment in the first network entity, the identifier of the first network slice entity and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0108] Temporary identity information of the user equipment in the first network entity, temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0109] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the second network slice security context that is currently activated;
[0110] The temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated.
[0111] Step 301: obtain the first network slice security context established between the user equipment and the first network slice entity, and send a fourth message to the user equipment.
[0112] In this embodiment of the present invention, obtaining a first network slice security context established between a user equipment and a first network slice entity includes at least one of the following:
[0113] Perform authentication and NAS SMC process with the user equipment, and establish a first network slice security context with the user equipment;
[0114] Obtain a second network slice security context established between the user equipment and a registered and connected second network slice entity; when the verification indication information of the user equipment indicates that the user equipment fails the verification, or the authentication indication information of the user equipment indicates that the user equipment fails the authentication, perform authentication and NAS SMC processes with the user equipment, and establish a first network slice security context with the user equipment;
[0115] Obtain a second network slice security context established between the user equipment and a registered and connected second network slice entity; when the verification indication information of the user equipment indicates that the user equipment has passed the authentication, or the authentication indication information of the user equipment indicates that the user equipment has passed the authentication, horizontally disperse the key in the second network slice security context to obtain the first network slice security context of the user equipment.
[0116] Among them, obtaining the second network slice security context established between the user equipment and the registered and connected second network slice entity includes any one of the following:
[0117] Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes a second network slice security context established between the user equipment and the second network slice entity;
[0118] Send a fifth message, the identifier of the first network slice entity and verification indication information or authentication indication information of the user equipment to the second network slice entity; receive a sixth message from the second network slice entity; wherein the sixth message includes a second network slice security context established between the user equipment and the second network slice entity.
[0119] The fifth message is a security context migration request message, and the sixth message is a security context migration response message.
[0120] In another embodiment of the present invention, after receiving a first message sent by the user equipment through the first network entity that has been registered and accessed, the method further includes:
[0121] Obtain verification indication information or authentication indication information of the user device.
[0122] The obtaining of verification indication information or authentication indication information of the user equipment includes any one of the following:
[0123] Sending a second message to the first network entity; receiving a third message from the first network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0124] Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0125] Sending a fifth message to the second network slice entity; receiving a sixth message from the second network slice entity; wherein the sixth message includes verification indication information or authentication indication information of the user equipment;
[0126] Sending a fifth message to the first network entity; receiving a sixth message from the first network entity; wherein the sixth message includes verification indication information of the user equipment.
[0127] In the embodiment of the present invention, the first message is a registration request message, and the fourth message is a registration confirmation message.
[0128] See also Figure 4 Another embodiment of the present invention provides a secure communication method, comprising:
[0129] Step 400: Receive the seventh message of the first network slice entity to be registered and accessed; wherein the seventh message includes the fifth message or the second message.
[0130] In this embodiment of the present invention, the seventh message received by the first network slice entity to be registered and accessed includes any one of the following:
[0131] Only the seventh message of the first network slice entity to be registered and accessed is received;
[0132] Receive the seventh message of the first network slice entity to be registered and accessed, the identifier of the first network slice entity and the verification indication information or authentication indication information of the user equipment.
[0133] In this embodiment of the present invention, the fifth message is a security context migration request message.
[0134] Step 401: Send an eighth message to the first network slice entity; wherein the eighth message includes the sixth message or the third message, and the eighth message includes a second network slice security context established between the user equipment and the registered and connected second network slice entity.
[0135] In the embodiment of the present invention, the sixth message is a security context migration response message.
[0136] In another embodiment of the present invention, the eighth message further includes verification indication information or authentication indication information of the user equipment.
[0137] In another embodiment of the present invention, the method further comprises:
[0138] Revoke the registration of the user equipment in the second network slice entity.
[0139] See also Figure 5 Another embodiment of the present invention provides a secure communication method, comprising:
[0140] Step 500: Receive a second message from a first network entity of a network where a first network slice entity to be registered and accessed is located; wherein the second message includes an identifier of the first network slice entity.
[0141] Step 501: Send a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment.
[0142] In another embodiment of the present invention, the method further includes: canceling the registration of the user equipment in itself.
[0143] See also Figure 6 Another embodiment of the present invention provides a secure communication method, comprising:
[0144] Step 600, sending a first message to the second network entity to be registered and accessed; wherein the first message includes: temporary identity information of the user equipment in the first network slice entity that has been registered and accessed, temporary identity information of the user equipment in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the security context of the first network slice that is currently activated.
[0145] Step 601: Acquire a second network security context established with the second network entity, and receive a fourth message from the second network entity.
[0146] In this embodiment of the present invention, acquiring the second network security context established with the second network entity includes:
[0147] Perform authentication and NAS SMC procedures with the second network entity, and establish the second network security context with the second network entity.
[0148] See also Figure 7 Another embodiment of the present invention provides a secure communication method, comprising:
[0149] Step 700, receiving a first message from a user device; wherein the first message includes: temporary identity information of the user device in a second network slice entity that has been registered and accessed, temporary identity information of the user device in a first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the security context of the first network slice that is currently activated.
[0150] Step 701: Acquire verification indication information or authentication indication information of a user equipment, and acquire a first network security context established between the user equipment and the first network entity.
[0151] In an embodiment of the present invention, obtaining verification indication information or authentication indication information of a user device includes:
[0152] Sending a second message to the second network slice entity;
[0153] Receive a third message from the second network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment.
[0154] In this embodiment of the present invention, acquiring a first network security context established between the user equipment and the first network entity includes:
[0155] Sending a fifth message to the first network entity; wherein the fifth message includes verification indication information or authentication indication information of the user equipment;
[0156] A sixth message from the first network entity is received; wherein the sixth message includes the first network security context.
[0157] Step 702: Acquire a second network security context established with the user equipment, and send a fourth message to the user equipment.
[0158] In this embodiment of the present invention, acquiring the second network security context established with the user equipment includes at least one of the following:
[0159] When the verification indication information of the user equipment indicates that the user equipment has been authenticated, or the authentication indication information of the user equipment indicates that the user equipment has been authenticated, horizontally dispersing the key of the first network security context to obtain the second network security context;
[0160] When the verification indication information of the user equipment indicates that the user equipment verification fails, or the authentication indication information of the user equipment indicates that the user equipment authentication fails, performing authentication and NAS SMC procedures with the user equipment, and establishing the second network security context with the user equipment.
[0161] See also Figure 8 Another embodiment of the present invention provides a secure communication method, comprising:
[0162] Step 800: Receive a second message from a second network entity to be registered and accessed.
[0163] Step 801: Send a third message to the second network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment, and cancels the registration of the user equipment in the first network slice entity that has been registered and accessed.
[0164] See also Fig. 9 Another embodiment of the present invention provides a secure communication method, comprising:
[0165] Step 900: Receive a fifth message from a second network entity to be registered and accessed; wherein the fifth message includes verification indication information or authentication indication information of the user equipment.
[0166] Step 901: Send a sixth message to the second network entity; wherein the sixth message includes a first network security context established between the user equipment and the first network entity that has been registered and accessed.
[0167] The implementation process of the method of the embodiment of the present invention is described below by using specific examples. The examples listed are not intended to limit the protection scope of the embodiment of the present invention.
[0168] Example 1
[0169] The user equipment (UE) has registered and accessed the first network, such as the UE has completed registration in the Network AMF1 (i.e., the first network entity) of the first network, and the UE and the Network AMF1 of the first network have established a first network security context. When the UE is ready to register and access the first network slice in the first network, Fig.10 A flowchart of a secure communication method provided in Example 1 of an embodiment of the present invention, the method comprising:
[0170] Step 1001, the UE sends a registration request message to Network AMF1 of the first network, where the registration request message may include the 5G-GUTI of Network AMF1 of the first network, the NSSAI of Slice AMF1 of the first network slice (i.e., the first network slice entity), and a message authentication code MAC calculated based on the first network security context that is currently activated;
[0171] Step 1002: Network AMF1 further sends a registration request message to Slice AMF1 of the first network slice in the first network according to NSSAI;
[0172] Step 1003, Slice AMF1 sends a security context transfer request (ContextTransfer Request) message to Network AMF1;
[0173] Step 1004: Network AMF1 sends a security context transfer response (ContextTransfer Response) message to Slice AMF1. The security context transfer response message may include verification indication information of the UE.
[0174] Step 1005: Network AMF1 cancels the registration of UE in Network AMF1;
[0175] Step 1006: Slice AMF1 performs authentication and NAS SMC process with the UE. After the authentication and NAS SMC process is completed, Slice AMF1 and the UE establish a first network slice security context.
[0176] Step 1007: Slice AMF1 sends a registration confirmation message Registration Accept to the UE.
[0177] After the UE completes registration with Slice AMF1 of the first network slice in the first network, if the UE attempts to access the first network and attach to Network AMF1 of the first network, Network AMF1 will reject the UE's access.
[0178] Example 2
[0179] The user equipment UE has completed registration in the first network and the first network slice of the first network. For example, the UE has completed registration in the Network AMF1 in the first network. At this time, the UE and the Network AMF1 in the first network have established a first network security context. In addition, the UE has also completed registration in the first network slice Slice AMF1 in the first network. At this time, the UE and the Slice AMF1 of the first network slice have established a first network slice security context. When the first network security context of the UE is activated and the UE is ready to register and access the second network slice in the first network, Fig.11 A flowchart of a secure communication method provided in Example 2 of an embodiment of the present invention, the method comprising:
[0180] Step 1101, the UE sends a registration request message to Network AMF1 of the first network, where the registration request message may include the 5G-GUTI of Network AMF1 of the first network, the 5G-GUTI of Slice AMF1 of the first network slice, the NSSAI of Slice AMF2 of the second network slice (i.e., the second network slice entity), and the message authentication code MAC calculated based on the first network security context;
[0181] Step 1102: Network AMF1 further sends a registration request message to Slice AMF2 of the second network slice in the first network according to NSSAI.
[0182] Step 1103, Slice AMF2 sends a security context transfer request (ContextTransfer Request) message to Network AMF1;
[0183] Step 1104: Network AMF1 sends a security context transfer response (ContextTransfer Response) message to Slice AMF2. The security context transfer response message includes the verification indication information of the UE;
[0184] Step 1105: Network AMF1 cancels the registration of UE in Network AMF1.
[0185] Step 1106, Slice AMF2 sends a security context transfer request (Context Transfer Request) message, the NSSAI of Slice AMF2 of the second network slice, the verification indication information of the UE and other information to Slice AMF1;
[0186] Step 1107: Slice AMF1 sends a security context transfer response message to Slice AMF2. The security context transfer response message includes the first network slice security context of the UE;
[0187] Step 1108, when the verification indication information of the UE indicates that the UE verification is successful, Slice AMF2 and / or the UE can horizontally disperse the KAMF (key) in the received first network slice security context to update the first network slice security context of the UE to form the second network slice security context of the UE; when the verification indication information of the UE indicates that the UE verification is unsuccessful, Slice AMF2 and the UE can perform authentication and NAS SMC processes. After the authentication and NAS SMC processes are completed, SliceAMF2 and the UE establish a second network slice security context.
[0188] Step 1109: Network AMF2 sends a registration confirmation message Registration Accept to the UE.
[0189] After the UE completes registration with Slice AMF2 of the second network slice in the first network, if the UE attempts to access the first network and attach to Network AMF1 in the first network, Network AMF1 will reject the UE's attachment.
[0190] Example 3
[0191] The user equipment UE has completed registration in the first network and the first network slice of the first network. For example, the UE has completed registration in the Network AMF1 in the first network. At this time, the UE and the Network AMF1 in the first network have established a first network security context. In addition, the UE has also completed registration in the first network slice Slice AMF1 in the first network. At this time, the UE and the Slice AMF1 of the first network slice have established a first network slice security context. When the first network slice security context of the UE is activated and the UE is ready to register and access the second network slice in the first network, Fig.12 A flowchart of a secure communication method provided in Example 3 of an embodiment of the present invention, the method comprising:
[0192] Step 1201, the UE sends a registration request message to Network AMF1 of the first network, where the registration request message may include the 5G-GUTI of Network AMF1 of the first network, the 5G-GUTI of Slice AMF1 of the first network slice, the NSSAI of Slice AMF1 of the second network slice, and the message authentication code MAC calculated based on the security context of the first network slice;
[0193] Step 1202: Network AMF1 forwards the UE's registration request message to Slice AMF2 according to NSSAI.
[0194] Step 1203: Slice AMF2 sends a security context transfer request (ContextTransfer Request) message to Slice AMF1;
[0195] Step 1204: Slice AMF1 sends a security context transfer response (ContextTransfer Response) message to Slice AMF2. The security context transfer response message includes: UE verification indication information, UE's first network slice security context;
[0196] Step 1205: Slice AMF1 cancels the registration of the UE in Slice AMF1.
[0197] Step 1206, when the verification indication information of the UE indicates that the UE verification fails, Slice AMF2 and the UE can perform authentication and NAS SMC processes. After the authentication and NAS SMC processes are completed, Slice AMF2 and the UE establish a second network slice security context; when the verification indication information of the UE indicates that the UE verification passes, Slice AMF2 may also not authenticate the UE to save time and network resources. In this case, Slice AMF2 and / or the UE can update the first network slice security context of the UE by horizontally dispersing the KAMF in the received first network slice security context to form the second network slice security context of the UE.
[0198] Step 1207: Slice AMF2 sends a registration confirmation message Registration Accept to the UE.
[0199] After the UE completes registration with Slice AMF2 of the second network slice in the first network, if the UE attempts to access the first network slice in the first network and attaches to Slice AMF1 of the first network slice in the first network, SliceAMF1 will reject the UE's attachment.
[0200] Example 4
[0201] The user equipment UE has completed registration in the first network and the first network slice of the first network. For example, the UE has completed registration in the Network AMF1 in the first network. At this time, the UE and the Network AMF1 in the first network have established a first network security context. In addition, the UE has also completed registration in the first network slice Slice AMF1 in the first network. At this time, the UE and the Slice AMF1 of the first network slice have established a first network slice security context. When the first network slice security context of the UE is in an activated state and the UE is ready to register and access the second network, Fig.13 A flowchart of a secure communication method provided in Example 4 of an embodiment of the present invention, the method comprising:
[0202] Step 1301, the UE sends a registration request message to Network AMF2 of the second network, where the registration request message may include the 5G-GUTI of Slice AMF1 of the first network slice, the 5G-GUTI of Network AMF1 of the first network, and a message authentication code MAC calculated based on the security context of the first network slice that is currently activated;
[0203] Step 1302: Network AMF2 sends a security context transfer request (ContextTransfer Request) message to Slice AMF1;
[0204] Step 1303, Slice AMF1 sends a security context transfer response (ContextTransfer Response) message to Network AMF2. The security context transfer response message may include UE verification indication information;
[0205] Step 1304: Slice AMF1 cancels the registration of the UE in Slice AMF1.
[0206] Step 1305: Network AMF2 sends a security context transfer request (Context Transfer Request) message to Network AMF1. The security context transfer request message may include verification indication information of the UE.
[0207] Step 1306: Network AMF1 sends a security context transfer response (ContextTransfer Response) message to Network AMF2. The security context transfer response message includes the first network security context of the UE;
[0208] Step 1307, when the verification indication information of the UE indicates that the UE verification is passed, Network AMF2 can horizontally disperse the KAMF in the first network security context to update the first network security context of the UE to form the second network security context of the UE; when the verification indication information of the UE indicates that the UE verification is not passed, Network AMF2 can perform authentication and NAS SMC procedures with the UE. After the authentication and NAS SMC procedures are completed, Network AMF2 and the UE establish a second network security context.
[0209] Step 1308: Network AMF2 sends a registration confirmation message Registration Accept to the UE.
[0210] After the UE completes registration with Network AMF2 of the second network, if the UE attempts to access the first network slice in the first network and attaches to Slice AMF1 of the first network slice in the first network, Slice AMF1 will reject the UE's access.
[0211] Example 5
[0212] The user equipment UE has completed registration in the first network and the first network slice of the first network. For example, the UE has completed registration in the Network AMF1 in the first network. At this time, the UE and the Network AMF1 in the first network have established a first network security context. In addition, the UE has also completed registration in the first network slice Slice AMF1 in the first network. At this time, the UE and the Slice AMF1 of the first network slice have established a first network slice security context. When the first network slice security context of the UE is activated and the UE is ready to register and access the third network slice in the second network, Fig.14 A flowchart of a secure communication method provided in Example 5 of an embodiment of the present invention, the method comprising:
[0213] Step 1401, the UE sends a registration request message to Network AMF2 of the second network, where the registration request message may include the 5G-GUTI of Network AMF1 of the first network, the 5G-GUTI of Slice AMF1 of the first network slice, the NSSAI of Slice AMF3 of the third network slice, and the message authentication code MAC calculated based on the security context of the first network slice;
[0214] Step 1402, Network AMF2 forwards the UE's registration request message to Slice AMF3 according to the NSSAI of Slice AMF3 of the third network slice.
[0215] Step 1403: Slice AMF3 sends a security context transfer request (ContextTransfer Request) message to Slice AMF1;
[0216] Step 1404: Slice AMF1 sends a security context transfer response (ContextTransfer Response) message to Slice AMF2. The security context transfer response message includes the first network slice security context of the UE and UE verification indication information;
[0217] Step 1405: Slice AMF1 cancels the registration of the UE in Slice AMF1.
[0218] Step 1406: When the verification indication information of the UE indicates that the UE verification fails, Slice AMF3 and the UE can perform authentication and NAS SMC processes. After the authentication and NAS SMC processes are completed, Slice AMF3 and the UE establish a third network slice security context.
[0219] When the UE's verification indication information indicates that the UE verification is successful, Slice AMF3 may not authenticate the UE to save time and network resources. In this case, Slice AMF3 can horizontally disperse the KAMF in the received first network slice security context to update the UE's first network slice security context to form the UE's third network slice security context.
[0220] Step 1407: Slice AMF3 sends a registration confirmation message Registration Accept to the UE.
[0221] After the UE completes registration with Slice AMF3 of the third network slice in the second network, if the UE attempts to access the first network slice in the first network and attaches to Slice AMF1 of the first network slice in the first network, SliceAMF1 will deny the UE's access.
[0222] Example 6
[0223] The user equipment UE has completed registration in the first network and the first network slice of the first network. For example, the UE has completed registration in the Network AMF1 in the first network. At this time, the UE and the Network AMF1 in the first network have established a first network security context. In addition, the UE has also completed registration in the first network slice Slice AMF1 in the first network. At this time, the UE and the Slice AMF1 of the first network slice have established a first network slice security context. When the first network security context of the UE is activated and the UE is ready to register and access the third network slice in the second network, Fig.15 A flowchart of a secure communication method provided in Example 6 of an embodiment of the present invention, the method comprising:
[0224] Step 1501, the UE sends a registration request message to Network AMF2 of the second network, where the registration request message may include the 5G-GUTI of Slice AMF1 of the first network slice, the 5G-GUTI of Network AMF1 of the first network, the NSSAI of Slice AMF3 of the third network slice, and a message authentication code MAC calculated based on the first network security context;
[0225] Step 1502: Network AMF2 sends a security context transfer request (Context Transfer Request) message to Network AMF1. The security context transfer request message may include the NSSAI of SliceAMF3 of the third network slice.
[0226] Step 1503: Network AMF1 sends a security context response (ContextTransfer Response) message to Network AMF2. The security context transfer response message may include UE verification indication information;
[0227] Step 1504: Network AMF1 cancels the registration of UE in Network AMF1.
[0228] Step 1505: Network AMF2 forwards the UE's registration request message, UE's verification indication information, MAC and other information to Slice AMF3.
[0229] Step 1506: Slice AMF3 determines to send a security context transfer request message, NSSAI, and UE verification indication information to Slice AMF1 according to the 5G-GUTI of Slice AMF1.
[0230] Step 1507: Slice AMF1 sends a security context transfer response message to Slice AMF3. The security context transfer response message includes the first network slice security context of the UE;
[0231] Step 1508, when the verification indication information of the UE indicates that the UE verification fails, Slice AMF3 can perform authentication and NAS SMC processes with the UE. After the authentication and NAS SMC processes are completed, Slice AMF3 and the UE establish a third network slice security context; when the verification indication information of the UE indicates that the UE verification passes, Slice AMF2 may also not authenticate the UE to save time and network resources. In this case, Slice AMF3 and the UE can horizontally disperse the KAMF in the received first network slice security context to update the UE's first network slice security context to form the UE's third network slice security context.
[0232] Step 1509: Network AMF2 sends a registration confirmation message Registration Accept to the UE.
[0233] After the UE completes registration with Slice AMF3 of the third network slice in the second network, if the UE attempts to access the first network and attach to Network AMF1 of the first network, Network AMF1 will reject the UE's access.
[0234] Example 7
[0235] The user equipment UE has completed registration in the first network and the first network slice of the first network. For example, the UE has completed registration in the Network AMF1 in the first network. At this time, the UE and the Network AMF1 in the first network have established a first network security context. In addition, the UE has also completed registration in the first network slice Slice AMF1 in the first network. At this time, the UE and the Slice AMF1 of the first network slice have established a first network slice security context. When the first network security context of the UE is activated and the UE is ready to register and access the third network slice in the second network, Fig.16 A flowchart of a secure communication method provided in Example 7 of an embodiment of the present invention, the method comprising:
[0236] Step 1601, the UE sends a registration request message to Network AMF2 of the second network, where the registration request message may include the 5G-GUTI of Slice AMF1 of the first network slice, the NSSAI of Slice AMF3 of the third network slice, and a message authentication code MAC calculated based on the first network security context;
[0237] Step 1602: After receiving the registration request message, Network AMF2 detects whether the registration request message contains the 5G-GUTI of Network AMF1. If it does not contain the 5G-GUTI of Network AMF1, Network AMF2 performs network authentication and NAS SMC procedures with the UE. After the authentication and NAS SMC procedures are completed, Network AMF2 and the UE establish a second network security context.
[0238] Step 1603: Network AMF2 forwards the UE's registration request message and the UE's authentication indication information to Slice AMF3.
[0239] Step 1604, Slice AMF3 determines to send a security context migration request (Context Transfer Request) message, NSSAI of Slice AMF3 of the third network slice, and authentication indication information of the UE to Slice AMF1 according to the 5G-GUTI of Slice AMF1;
[0240] Step 1605: Slice AMF1 sends a security context transfer response (ContextTransfer Response) to Slice AMF3. The security context transfer response message includes the first network slice security context of the UE;
[0241] Step 1606, when the UE's verification indication information determines that the UE verification fails, Slice AMF3 can perform authentication and NAS SMC processes with the UE. After the authentication and NAS SMC processes are completed, Slice AMF3 and the UE establish a third network slice security context; when the UE's verification indication information determines that the UE verification passes, Slice AMF3 may also not authenticate the UE to save time and network resources. In this case, Slice AMF3 and the UE can horizontally disperse the KAMF in the received first network slice security context to update the UE's first network slice security context to form the UE's third network slice security context.
[0242] Step 1607: Network AMF3 sends a registration confirmation message Registration Accept to the UE.
[0243] After the UE completes registration with Slice AMF3 of the third network slice in the second network, if the UE attempts to access the first network and attach to Network AMF1 of the first network, Network AMF1 will reject the UE's access.
[0244] Another embodiment of the present invention provides a secure communication device, comprising:
[0245] A first sending module, used to send a first message to the first network slice entity through a first network entity of the network where the first network slice entity to be registered and accessed is located;
[0246] The first receiving module is used to receive a fourth message from the first network slice entity.
[0247] In another embodiment of the present invention, it also includes:
[0248] The first acquisition module is used to obtain a first network slice security context established with the first network slice entity.
[0249] In the embodiment of the present invention, the first acquisition module is specifically used to perform any one of the following:
[0250] Perform authentication and NAS SMC procedures with the first network slicing entity, and establish a first network slicing security context with the first network slicing entity;
[0251] The first network slice security context is obtained by horizontally dispersing the keys in the second network slice security context established with the registered and connected second network slice entity.
[0252] In the embodiment of the present invention, the first sending module is specifically configured to perform any one of the following:
[0253] directly sending the first message;
[0254] Sending the first message, verification indication information of the user equipment, and a message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated;
[0255] Sending the first message and verification indication information of the user equipment.
[0256] In this embodiment of the present invention, the first message includes any one of the following:
[0257] Temporary identity information of the user equipment in the first network entity, the identifier of the first network slice entity and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0258] Temporary identity information of the user equipment in the first network entity, temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0259] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the second network slice security context that is currently activated;
[0260] The temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated.
[0261] In the embodiment of the present invention, the first message is a registration request message, and the fourth message is a registration confirmation message.
[0262] In an embodiment of the present invention, the temporary identity information is 5G-GUTI, and the identifier of the first network slicing entity includes NSSAI.
[0263] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0264] Another embodiment of the present invention provides a secure communication device, comprising:
[0265] A second receiving module is used to receive a first message from a user equipment; wherein the first message includes: an identifier of a first network slice entity to be registered and accessed;
[0266] The second sending module is used to forward the first message to the first network slice entity according to the identifier of the first network slice entity.
[0267] In the embodiment of the present invention, the second receiving module is further used for:
[0268] Receiving a second message from the first network slicing entity;
[0269] The second sending module is also used to: send a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0270] The method further includes: a first revocation module, configured to revoke the registration of the user equipment in the first network entity.
[0271] In an embodiment of the present invention, the second sending module is specifically used to implement forwarding the first message to the first network slice entity according to the identifier of the first network slice entity in any one of the following ways:
[0272] Forwarding the first message directly to the first network slice entity according to the identifier of the first network slice entity;
[0273] Obtain verification indication information or authentication indication information of the user equipment, and send the first message, the verification indication information or authentication indication information of the user equipment, and the message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated to the first network slice entity according to the identifier of the first network slice entity;
[0274] When the first message does not contain the temporary identity information of the user equipment in the second network entity, perform authentication and NAS SMC processes with the user equipment, and establish a first network security context with the user equipment; and send the first message and authentication indication information of the user equipment to the first network slice entity.
[0275] In this embodiment of the present invention, the first message further includes any one of the following:
[0276] The temporary identity information of the user equipment in the first network entity and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0277] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0278] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, and the message authentication code MAC calculated based on the second network slice security context that is currently activated;
[0279] The temporary identity information of the user equipment in the second network slice entity that has been registered and connected and the message authentication code MAC calculated based on the first network security context that is currently activated.
[0280] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0281] Another embodiment of the present invention provides a secure communication device, comprising:
[0282] A third receiving module is used to receive a first message sent by a user equipment to the first network slice entity through a first network entity of the network where the first network slice entity to be registered and accessed is located;
[0283] A second acquisition module is used to obtain a first network slice security context established between the user equipment and the first network slice entity;
[0284] The third sending module is used to send a fourth message to the user equipment.
[0285] In the embodiment of the present invention, the second acquisition module is further used for:
[0286] Obtain verification indication information or authentication indication information of the user device.
[0287] In the embodiment of the present invention, the second acquisition module is specifically used to implement the acquisition of verification indication information or authentication indication information of the user equipment in any one of the following ways:
[0288] Sending a second message to the first network entity; receiving a third message from the first network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0289] Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0290] Sending a fifth message to the second network slice entity; receiving a sixth message from the second network slice entity; wherein the sixth message includes verification indication information or authentication indication information of the user equipment;
[0291] Sending a fifth message to the first network entity; receiving a sixth message from the first network entity; wherein the sixth message includes verification indication information of the user equipment.
[0292] In this embodiment of the present invention, receiving the first message includes any one of the following:
[0293] directly receiving the first message;
[0294] Receiving a first message, verification indication information or authentication indication information of a user equipment, and a MAC calculated based on a first network security context or a second network slice security context that is currently activated;
[0295] A first message and authentication indication information of a user equipment are received.
[0296] In an embodiment of the present invention, the second acquisition module is specifically used to implement the acquisition of the first network slice security context established by the user equipment and the first network slice entity in at least one of the following ways:
[0297] Perform authentication and NAS SMC process with the user equipment, and establish a first network slice security context with the user equipment;
[0298] Obtain a second network slice security context established between the user equipment and a registered and connected second network slice entity; when the verification indication information of the user equipment indicates that the user equipment fails the verification, or the authentication indication information of the user equipment indicates that the user equipment fails the authentication, perform authentication and NAS SMC processes with the user equipment, and establish a first network slice security context with the user equipment;
[0299] Obtain a second network slice security context established between the user equipment and a registered and connected second network slice entity; when the verification indication information of the user equipment indicates that the user equipment has passed the authentication, or the authentication indication information of the user equipment indicates that the user equipment has passed the authentication, horizontally disperse the key in the second network slice security context to obtain the first network slice security context of the user equipment.
[0300] In an embodiment of the present invention, the second acquisition module is specifically used to obtain the second network slice security context established between the user equipment and the registered and connected second network slice entity in any one of the following ways:
[0301] Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes a second network slice security context established between the user equipment and the second network slice entity;
[0302] Send a fifth message, the identifier of the first network slice entity and verification indication information or authentication indication information of the user equipment to the second network slice entity; receive a sixth message from the second network slice entity; wherein the sixth message includes a second network slice security context established between the user equipment and the second network slice entity.
[0303] In the embodiment of the present invention, the fifth message is a security context migration request message, and the sixth message is a security context migration response message.
[0304] In this embodiment of the present invention, the first message includes any one of the following:
[0305] Temporary identity information of the user equipment in the first network entity, the identifier of the first network slice entity and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0306] Temporary identity information of the user equipment in the first network entity, temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0307] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the second network slice security context that is currently activated;
[0308] The temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated.
[0309] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0310] Another embodiment of the present invention provides a secure communication device, comprising:
[0311] A fourth receiving module, configured to receive a seventh message from the first network slice entity to be registered and accessed; wherein the seventh message includes the fifth message or the second message;
[0312] The fourth sending module is used to send an eighth message to the first network slice entity; wherein the eighth message includes the sixth message or the third message, and the eighth message includes a second network slice security context established between the user equipment and the second network slice entity that has been registered and connected.
[0313] In an embodiment of the present invention, it also includes:
[0314] The second revocation module is used to revoke the registration of the user equipment in the second network slice entity.
[0315] In this embodiment of the present invention, the eighth message also includes verification indication information or authentication indication information of the user equipment.
[0316] In this embodiment of the present invention, the fourth receiving module is specifically used to implement the seventh message of receiving the first network slice entity to be registered and accessed in any one of the following ways:
[0317] Only the seventh message of the first network slice entity to be registered and accessed is received;
[0318] Receive the seventh message of the first network slice entity to be registered and accessed, the identifier of the first network slice entity and the verification indication information or authentication indication information of the user equipment.
[0319] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0320] Another embodiment of the present invention provides a secure communication device, comprising:
[0321] A fifth receiving module, configured to receive a second message from a first network entity of a network where a first network slice entity to be registered and accessed is located; wherein the second message includes an identifier of the first network slice entity;
[0322] The fifth sending module is used to send a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment.
[0323] In the embodiment of the present invention, it further includes: a third revocation module, which is used to revoke the registration of the user equipment in itself.
[0324] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0325] Another embodiment of the present invention provides a secure communication device, comprising:
[0326] A sixth sending module, configured to send a first message to the second network entity to be registered and accessed; wherein the first message includes: temporary identity information of the user equipment in the first network slice entity that has been registered and accessed, temporary identity information of the user equipment in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated;
[0327] A third acquisition module, configured to acquire a second network security context established with the second network entity;
[0328] A sixth receiving module is used to receive a fourth message from the second network entity.
[0329] In the embodiment of the present invention, the third acquisition module is specifically configured to implement the acquisition of the second network security context established with the second network entity in the following manner:
[0330] Perform authentication and NAS SMC procedures with the second network entity, and establish the second network security context with the second network entity.
[0331] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0332] Another embodiment of the present invention provides a secure communication device, comprising:
[0333] A seventh receiving module, configured to receive a first message from a user device; wherein the first message includes: temporary identity information of the user device in the second network slice entity that has been registered and accessed, temporary identity information of the user device in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated;
[0334] A fourth acquisition module, configured to acquire verification indication information or authentication indication information of a user equipment, and acquire a first network security context established between the user equipment and the first network entity;
[0335] Acquire a second network security context established with the user equipment;
[0336] A seventh sending module is used to send a fourth message to the user equipment.
[0337] In the embodiment of the present invention, the fourth acquisition module is specifically used to implement the acquisition of verification indication information or authentication indication information of the user equipment in the following manner:
[0338] Sending a second message to the second network slice entity;
[0339] Receive a third message from the second network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment.
[0340] In the embodiment of the present invention, the fourth acquisition module is specifically configured to implement the acquisition of the first network security context established between the user equipment and the first network entity in the following manner:
[0341] Sending a fifth message to the first network entity; wherein the fifth message includes verification indication information or authentication indication information of the user equipment;
[0342] A sixth message from the first network entity is received; wherein the sixth message includes the first network security context.
[0343] In the embodiment of the present invention, the fourth acquisition module is specifically configured to implement the acquisition of the second network security context established with the user equipment in at least one of the following ways:
[0344] When the verification indication information of the user equipment indicates that the user equipment has been authenticated, or the authentication indication information of the user equipment indicates that the user equipment has been authenticated, horizontally dispersing the key of the first network security context to obtain the second network security context;
[0345] When the verification indication information of the user equipment indicates that the user equipment verification fails, or the authentication indication information of the user equipment indicates that the user equipment authentication fails, performing authentication and NAS SMC procedures with the user equipment, and establishing the second network security context with the user equipment.
[0346] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0347] Another embodiment of the present invention provides a secure communication device, comprising:
[0348] An eighth receiving module, configured to receive a second message from a second network entity to be registered and accessed;
[0349] An eighth sending module is used to send a third message to the second network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment, and cancels the registration of the user equipment in the first network slice entity that has been registered and accessed.
[0350] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0351] Another embodiment of the present invention provides a secure communication device, comprising:
[0352] A ninth receiving module, configured to receive a fifth message from a second network entity to be registered and accessed; wherein the fifth message includes verification indication information or authentication indication information of the user equipment;
[0353] A ninth sending module is used to send a sixth message to the second network entity; wherein the sixth message includes a first network security context established between the user equipment and the first network entity that has been registered and accessed.
[0354] The specific implementation process of the above-mentioned secure communication device is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0355] Another embodiment of the present invention provides a secure communication device, including a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, and when the instructions are executed by the processor, any of the above-mentioned secure communication methods is implemented.
[0356] Another embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the steps of any of the above-mentioned secure communication methods when executed by a processor.
[0357] Another embodiment of the present invention provides a secure communication system, comprising:
[0358] A user device, used for sending a first message to the first network slice entity through a first network entity of the network where the first network slice entity to be registered and accessed is located; and receiving a fourth message from the first network slice entity;
[0359] A first network entity, configured to receive a first message from a user equipment; wherein the first message includes: an identifier of a first network slice entity to be registered and accessed; and forwarding the first message to the first network slice entity according to the identifier of the first network slice entity;
[0360] The first network slice entity is used to receive a first message sent by a user device through the first network entity; obtain a first network slice security context established between the user device and the first network slice entity, and send a fourth message to the user device.
[0361] In the embodiment of the present invention, the user equipment is further used for:
[0362] Obtain a first network slice security context established with the first network slice entity.
[0363] In an embodiment of the present invention, the user equipment is specifically used to implement the acquisition of the first network slice security context established with the first network slice entity in any one of the following ways:
[0364] Perform authentication and NAS SMC procedures with the first network slicing entity, and establish a first network slicing security context with the first network slicing entity;
[0365] The first network slice security context is obtained by horizontally dispersing the keys in the second network slice security context established with the registered and connected second network slice entity.
[0366] In the embodiment of the present invention, the user equipment is specifically configured to send the first message in any one of the following ways:
[0367] directly sending the first message;
[0368] Sending the first message, verification indication information of the user equipment, and a message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated;
[0369] Sending the first message and verification indication information of the user equipment.
[0370] In this embodiment of the present invention, the first message includes any one of the following:
[0371] Temporary identity information of the user equipment in the first network entity, the identifier of the first network slice entity and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0372] Temporary identity information of the user equipment in the first network entity, temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated;
[0373] The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the second network slice security context that is currently activated;
[0374] The temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated.
[0375] In the embodiment of the present invention, the first message is a registration request message, and the fourth message is a registration confirmation message.
[0376] In an embodiment of the present invention, the temporary identity information is 5G-GUTI, and the identifier of the first network slicing entity includes NSSAI.
[0377] In this embodiment of the present invention, the first network entity is further configured to:
[0378] Receive a second message from the first network slice entity, and send a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment; and revoke the registration of the user equipment in the first network entity.
[0379] In an embodiment of the present invention, the first network entity is specifically used to implement forwarding the first message to the first network slice entity according to the identifier of the first network slice entity in any of the following ways:
[0380] Forwarding the first message directly to the first network slice entity according to the identifier of the first network slice entity;
[0381] Obtain verification indication information or authentication indication information of the user equipment, and send the first message, the verification indication information or authentication indication information of the user equipment, and the message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated to the first network slice entity according to the identifier of the first network slice entity;
[0382] When the first message does not contain the temporary identity information of the user equipment in the second network entity, perform authentication and NAS SMC processes with the user equipment, and establish a first network security context with the user equipment; and send the first message and authentication indication information of the user equipment to the first network slice entity.
[0383] In an embodiment of the present invention, the first network slice entity is also used to obtain verification indication information or authentication indication information of the user equipment.
[0384] In an embodiment of the present invention, the first network slice entity is specifically used to obtain verification indication information or authentication indication information of the user equipment in any of the following ways:
[0385] Sending a second message to the first network entity; receiving a third message from the first network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0386] Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0387] Sending a fifth message to the second network slice entity; receiving a sixth message from the second network slice entity; wherein the sixth message includes verification indication information or authentication indication information of the user equipment;
[0388] Sending a fifth message to the first network entity; receiving a sixth message from the first network entity; wherein the sixth message includes verification indication information of the user equipment.
[0389] In this embodiment of the present invention, the first network slice entity is specifically used to receive the first message in any one of the following ways:
[0390] directly receiving the first message;
[0391] Receiving a first message, verification indication information or authentication indication information of a user equipment, and a MAC calculated based on a first network security context or a second network slice security context that is currently activated;
[0392] A first message and authentication indication information of a user equipment are received.
[0393] In an embodiment of the present invention, the first network slice entity is specifically used to obtain the first network slice security context established between the user equipment and the first network slice entity in at least one of the following ways:
[0394] Perform authentication and NAS SMC process with the user equipment, and establish a first network slice security context with the user equipment;
[0395] Obtain a second network slice security context established between the user equipment and a registered and connected second network slice entity; when the verification indication information of the user equipment indicates that the user equipment fails the verification, or the authentication indication information of the user equipment indicates that the user equipment fails the authentication, perform authentication and NAS SMC processes with the user equipment, and establish a first network slice security context with the user equipment;
[0396] Obtain a second network slice security context established between the user equipment and a registered and connected second network slice entity; when the verification indication information of the user equipment indicates that the user equipment has passed the authentication, or the authentication indication information of the user equipment indicates that the user equipment has passed the authentication, horizontally disperse the key in the second network slice security context to obtain the first network slice security context of the user equipment.
[0397] In an embodiment of the present invention, the first network slice entity is specifically used to obtain the second network slice security context established between the user equipment and the registered and connected second network slice entity in the following manner, including any one of the following:
[0398] Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes a second network slice security context established between the user equipment and the second network slice entity;
[0399] Send a fifth message, the identifier of the first network slice entity and verification indication information or authentication indication information of the user equipment to the second network slice entity; receive a sixth message from the second network slice entity; wherein the sixth message includes a second network slice security context established between the user equipment and the second network slice entity.
[0400] The system further includes: a second network slice entity, configured to receive a seventh message from the first network slice entity to be registered and accessed; wherein the seventh message includes the fifth message or the second message;
[0401] Send an eighth message to the first network slice entity; wherein the eighth message includes the sixth message or the third message, and the eighth message includes a second network slice security context established between the user equipment and the registered and connected second network slice entity.
[0402] In an embodiment of the present invention, the second network slice entity is further used to: cancel the registration of the user equipment in the second network slice entity.
[0403] The eighth message also includes verification indication information or authentication indication information of the user equipment.
[0404] The second network slice entity is specifically used to implement receiving the seventh message of the first network slice entity to be registered and accessed in any one of the following ways:
[0405] Only the seventh message of the first network slice entity to be registered and accessed is received;
[0406] Receive the seventh message of the first network slice entity to be registered and accessed, the identifier of the first network slice entity and the verification indication information or authentication indication information of the user equipment.
[0407] In another embodiment of the present invention, the system further comprises:
[0408] A second network entity of a network where a second network slice entity is located, is used to receive a second message from a first network entity of a network where a first network slice entity to be registered and accessed is located; wherein the second message includes an identifier of the first network slice entity; and sends a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of a user device.
[0409] The second network entity is further used to: cancel the registration of the user equipment in itself.
[0410] The specific implementation process of the above-mentioned secure communication system is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0411] Another embodiment of the present invention provides a secure communication system, comprising:
[0412] A user device is used to send a first message to a second network entity to be registered and accessed; wherein the first message includes: temporary identity information of the user device in the first network slice entity that has been registered and accessed, temporary identity information of the user device in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated; obtain a second network security context established with the second network entity, and receive a fourth message from the second network entity;
[0413] The second network entity is used to receive a first message from a user device; obtain verification indication information or authentication indication information of the user device, obtain a first network security context established between the user device and the first network entity; obtain a second network security context established with the user device, and send a fourth message to the user device.
[0414] In the embodiment of the present invention, the second network entity is specifically configured to acquire the second network security context established with the user equipment by adopting at least one of the following methods:
[0415] When the verification indication information of the user equipment indicates that the user equipment has passed verification, horizontally dispersing the key of the first network security context to obtain the second network security context;
[0416] When the verification indication information of the user equipment indicates that the user equipment fails verification, performing authentication and NAS SMC procedures with the user equipment, and establishing the second network security context with the user equipment.
[0417] The user equipment is specifically configured to acquire the second network security context established with the second network entity in the following manner:
[0418] Perform authentication and NAS SMC procedures with the second network entity, and establish the second network security context with the second network entity.
[0419] In the embodiment of the present invention, the second network entity is specifically configured to obtain verification indication information or authentication indication information of the user equipment in the following manner:
[0420] Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment;
[0421] The system further comprises:
[0422] The second network slice entity is used to receive a second message from a second network entity to be registered and accessed;
[0423] Send a third message to the second network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment, and cancels the registration of the user equipment in the first network slice entity that has been registered and accessed.
[0424] In the embodiment of the present invention, the second network entity is specifically configured to acquire the first network security context established between the user equipment and the first network entity in the following manner:
[0425] Sending a fifth message to the first network entity; wherein the fifth message includes verification indication information or authentication indication information of the user equipment; receiving a sixth message from the first network entity; wherein the sixth message includes the first network security context;
[0426] The system further comprises:
[0427] A first network entity is used to receive a fifth message from a second network entity to be registered and accessed; wherein the fifth message includes verification indication information or authentication indication information of a user device; and send a sixth message to the second network entity; wherein the sixth message includes a first network security context established between the user device and the first network entity that has been registered and accessed.
[0428] The specific implementation process of the above-mentioned secure communication system is the same as that of the secure communication method in the aforementioned embodiment, which will not be repeated here.
[0429] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those of ordinary skill in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
[0430] Although the implementation methods disclosed in the embodiments of the present invention are as above, the contents described are only implementation methods adopted to facilitate understanding of the embodiments of the present invention, and are not intended to limit the embodiments of the present invention. Any technician in the field to which the embodiments of the present invention belong may make any modifications and changes in the form and details of implementation without departing from the spirit and scope disclosed in the embodiments of the present invention, but the scope of patent protection of the embodiments of the present invention shall still be subject to the scope defined in the attached claims.
Claims
1. A secure communication method, comprising: Sending a first message to the first network slice entity through a first network entity of the network where the first network slice entity to be registered and accessed is located; Obtaining a first network slice security context established with the first network slice entity; Receiving a fourth message from the first network slicing entity; The first message is a registration request message, and the fourth message is a registration confirmation message; The acquiring of the first network slice security context established with the first network slice entity comprises: The first network slice security context is obtained by horizontally dispersing the keys in the second network slice security context established with the registered and connected second network slice entity.
2. The secure communication method according to claim 1, characterized in that: in, The sending of the first message includes any one of the following: directly sending the first message; Sending the first message, verification indication information of the user equipment, and a message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated; Sending the first message and verification indication information of the user equipment.
3. The secure communication method according to claim 1, characterized in that: in, The first message includes any one of the following: Temporary identity information of the user equipment in the first network entity, the identifier of the first network slice entity and the message authentication code MAC calculated based on the first network security context that is currently activated; Temporary identity information of the user equipment in the first network entity, temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated; The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the second network slice security context that is currently activated; The temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated.
4. The secure communication method according to claim 3, characterized in that: in, The temporary identity information is the 5G globally unique temporary user equipment identifier 5G-GUTI, and the identifier of the first network slicing entity includes network slice selection auxiliary information NSSAI.
5. The secure communication method according to claim 1, characterized in that: The obtaining of the first network slice security context established with the first network slice entity further includes: Perform authentication and non-access stratum security mode process NAS SMC process with the first network slice entity, and establish the first network slice security context with the first network slice entity.
6. A secure communication method, applied to a first network entity, comprising: Receive a first message from a user device; wherein the first message includes: an identifier of a first network slice entity to be registered and accessed; forward the first message to the first network slice entity according to the identifier of the first network slice entity; the first message is a registration request message; The method further includes: the first network entity interacting with the first network slice entity, migrating the security context to the first network slice entity, and deregistering the user equipment in the first network entity; The first message also includes any one of the following: The temporary identity information of the user equipment in the first network entity and the message authentication code MAC calculated based on the first network security context that is currently activated; The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, and the message authentication code MAC calculated based on the first network security context that is currently activated; The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, and the message authentication code MAC calculated based on the second network slice security context that is currently activated; The temporary identity information of the user equipment in the second network slice entity that has been registered and connected and the message authentication code MAC calculated based on the first network security context that is currently activated.
7. The secure communication method according to claim 6, characterized in that: The method further includes: receiving a second message from the first network slice entity, and sending a third message to the first network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment; The second message is a security context migration request message, and the third message is a security context migration response message.
8. The secure communication method according to claim 6 or 7, characterized in that: in, The forwarding of the first message to the first network slice entity according to the identifier of the first network slice entity includes any one of the following: Forwarding the first message directly to the first network slice entity according to the identifier of the first network slice entity; Obtain verification indication information or authentication indication information of the user equipment, and send the first message, the verification indication information or authentication indication information of the user equipment, and the message authentication code MAC calculated based on the first network security context or the second network slice security context that is currently activated to the first network slice entity according to the identifier of the first network slice entity; When the first message does not include the temporary identity information of the user equipment in the first network entity, performing an authentication and non-access layer security mode process NAS SMC process with the user equipment, and establishing a first network security context with the user equipment; Send the first message and authentication indication information of the user equipment to the first network slice entity.
9. A secure communication method, comprising: Receiving a first message sent by a user equipment to the first network slice entity through a first network entity of a network where a first network slice entity to be registered and accessed is located; Obtain a first network slice security context established between the user equipment and the first network slice entity, and send a fourth message to the user equipment; The first message is a registration request message, and the fourth message is a registration confirmation message; The obtaining of a first network slice security context established between the user equipment and the first network slice entity comprises: obtaining a second network slice security context established between the user equipment and a registered and connected second network slice entity; When the verification indication information of the user equipment indicates that the user equipment has passed the authentication, or the authentication indication information of the user equipment indicates that the user equipment has passed the authentication, the key in the second network slice security context is horizontally dispersed to obtain the first network slice security context of the user equipment.
10. The secure communication method according to claim 9, characterized in that: The obtaining of the first network slice security context established between the user equipment and the first network slice entity further includes at least one of the following: Perform authentication and non-access layer security mode process NAS SMC process with the user equipment, and establish a first network slice security context with the user equipment; Obtaining a second network slice security context established between the user equipment and the registered and accessed second network slice entity; When the verification indication information of the user equipment indicates that the user equipment authentication fails, or the authentication indication information of the user equipment indicates that the user equipment authentication fails, authentication and NAS SMC processes are performed with the user equipment, and a first network slice security context is established with the user equipment.
11. The secure communication method according to claim 9, characterized in that: After receiving the first message sent by the user equipment through the first network entity that has been registered and accessed, the method further includes: Obtain verification indication information or authentication indication information of the user device.
12. The secure communication method according to claim 10, characterized in that: in, The obtaining of verification indication information or authentication indication information of the user equipment includes any one of the following: Sending a security context migration request message to the first network entity; receiving a security context migration response message from the first network entity; wherein the security context migration response message includes verification indication information or authentication indication information of the user equipment; Sending a security context migration request message to a second network slice entity; receiving a security context migration response message from the second network slice entity; wherein the security context migration response message includes verification indication information or authentication indication information of the user equipment; Sending a security context migration request message to the first network entity; receiving a security context migration response message from the first network entity; wherein the security context migration response message includes verification indication information of the user equipment.
13. The secure communication method according to claim 9, characterized in that: in, Receiving the first message includes any one of the following: directly receiving the first message; Receiving a first message, verification indication information or authentication indication information of a user equipment, and a MAC calculated based on a first network security context or a second network slice security context that is currently activated; A first message and authentication indication information of a user equipment are received.
14. The secure communication method according to claim 9, characterized in that: in, Obtaining a second network slice security context established between the user equipment and the registered and connected second network slice entity includes any one of the following: Sending a security context migration request message to the second network slice entity; receiving a security context migration response message from the second network slice entity; wherein the security context migration response message includes a second network slice security context established between the user equipment and the second network slice entity; and the security context migration request message includes an identifier of the first network slice entity; A security context migration request message is sent to the second network slice entity, wherein the security context migration request message includes the identifier of the first network slice entity and verification indication information or authentication indication information of the user equipment; a security context migration response message is received from the second network slice entity, wherein the security context migration response message includes the second network slice security context established between the user equipment and the second network slice entity; and the security context migration request message includes verification indication information or authentication indication information of the user equipment.
15. The secure communication method according to claim 9, characterized in that: in, The first message includes any one of the following: Temporary identity information of the user equipment in the first network entity, the identifier of the first network slice entity and the message authentication code MAC calculated based on the first network security context that is currently activated; Temporary identity information of the user equipment in the first network entity, temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated; The temporary identity information of the user equipment in the first network entity, the temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the second network slice security context that is currently activated; The temporary identity information of the user equipment in the second network slice entity that has been registered and connected, the identifier of the first network slice entity, and the message authentication code MAC calculated based on the first network security context that is currently activated.
16. A secure communication method, comprising: A seventh message is received from a first network slice entity to be registered and accessed; wherein the seventh message is a security context migration request message; and the first network slice entity is an entity that establishes a first network slice security context with a user equipment; Sending an eighth message to the first network slice entity; wherein the eighth message is a security context migration response message, and the eighth message includes a second network slice security context established between the user equipment and the registered and accessed second network slice entity; The first network slice security context is obtained by the user equipment horizontally dispersing the key in the second network slice security context established with the registered and connected second network slice entity.
17. The secure communication method according to claim 16, characterized in that: The method further includes: Revoke the registration of the user equipment in the second network slice entity.
18. The secure communication method according to claim 16 or 17, characterized in that: in, The eighth message also includes verification indication information or authentication indication information of the user equipment.
19. The secure communication method according to claim 16 or 17, characterized in that: in, The seventh message received by the first network slice entity to be registered and accessed includes any one of the following: Only the seventh message of the first network slice entity to be registered and accessed is received; Receive the seventh message of the first network slice entity to be registered and accessed, the identifier of the first network slice entity and the verification indication information or authentication indication information of the user equipment.
20. A secure communication method, applied to a second network slice entity, comprising: Receiving a security context migration request message of a first network entity of a network where a first network slice entity to be registered and accessed is located; wherein the security context migration request message includes an identifier of the first network slice entity; Send a security context migration response message to the first network slice entity; wherein the security context migration response message includes verification indication information or authentication indication information of the user equipment; the security context migration response message also includes: a first network slice security context obtained by horizontally dispersing a key in a second network slice security context established with a registered and connected second network slice entity.
21. The secure communication method according to claim 20, characterized in that: The method also includes: deregistering the user equipment in the second network slice entity.
22. A secure communication method, comprising: Send a first message to the second network entity to be registered and accessed; wherein the first message includes: temporary identity information of the user equipment in the first network slice entity that has been registered and accessed, temporary identity information of the user equipment in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated; the first network slice security context is obtained by horizontally dispersing the key in the second network slice security context established with the second network slice entity that has been registered and accessed; Acquire a second network security context established with the second network entity, and receive a fourth message from the second network entity; The first message is a registration request message, and the fourth message is a registration confirmation message.
23. The secure communication method according to claim 22, characterized in that: in, The acquiring the second network security context established with the second network entity comprises: Perform authentication and non-access stratum security mode process NAS SMC process with the second network entity, and establish the second network security context with the second network entity.
24. A secure communication method, comprising: Receive a first message from a user device; wherein the first message includes: temporary identity information of the user device in the second network slice entity that has been registered and accessed, temporary identity information of the user device in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated; the first network slice security context is obtained by horizontally dispersing a key in a second network slice security context established with the second network slice entity that has been registered and accessed; Obtain verification indication information or authentication indication information of a user device, and obtain a first network security context established between the user device and the first network entity; Acquire a second network security context established with the user equipment, and send a fourth message to the user equipment; The first message is a registration request message, and the fourth message is a registration confirmation message; The acquiring of the second network security context established with the user equipment comprises: When the verification indication information of the user equipment indicates that the user equipment has been authenticated, or the authentication indication information of the user equipment indicates that the user equipment has been authenticated, the key of the first network security context is horizontally dispersed to obtain the second network security context.
25. The secure communication method according to claim 24, characterized in that: in, The obtaining of verification indication information or authentication indication information of the user equipment includes: Sending a second message to the second network slice entity; receiving a third message from the second network slice entity; wherein the third message includes verification indication information or authentication indication information of the user equipment; The second message is a security context migration request message, and the third message is a security context migration response message.
26. The secure communication method according to claim 24, characterized in that: in, The acquiring of a first network security context established between the user equipment and the first network entity includes: Sending a fifth message to the first network entity; wherein the fifth message includes verification indication information or authentication indication information of the user equipment; receiving a sixth message from the first network entity; wherein the sixth message includes the first network security context; The fifth message is a security context migration request message, and the sixth message is a security context migration response message.
27. The secure communication method according to claim 24, characterized in that: in, The acquiring of the second network security context established with the user equipment further includes: When the verification indication information of the user equipment indicates that the user equipment verification fails, or the authentication indication information of the user equipment indicates that the user equipment authentication fails, performing authentication and NAS SMC procedures with the user equipment, and establishing the second network security context with the user equipment.
28. A secure communication method, comprising: Receiving a second message from a second network entity to be registered and accessed; Sending a third message to the second network entity; wherein the third message includes verification indication information or authentication indication information of the user equipment, and canceling the registration of the user equipment in the first network slice entity that has been registered and accessed; the first network slice entity is an entity that establishes a first network slice security context with the user equipment; The second message is a security context migration request message, and the third message is a security context migration response message; The first network slice security context is generated in the following manner: horizontally dispersing the key in the second network slice security context established with the registered and connected second network slice entity.
29. A secure communication method, comprising: Receiving a security context migration request message from a second network entity to be registered and accessed; wherein the security context migration request message includes verification indication information or authentication indication information of the user equipment; Sending a security context migration response message to the second network entity; wherein the security context migration response message includes a first network security context established between the user equipment and the first network entity that has been registered and accessed; The method further includes: when the verification indication information of the user equipment indicates that the user equipment has been authenticated, or the authentication indication information of the user equipment indicates that the user equipment has been authenticated, horizontally dispersing the key of the first network security context to obtain a second network security context.
30. A secure communication device, comprising a processor and a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, characterized in that: When the instructions are executed by the processor, the secure communication method according to any one of claims 1 to 29 is implemented.
31. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the secure communication method according to any one of claims 1 to 29 are implemented.
32. A secure communication system comprising: A user device, used to send a first message to the first network slice entity through a first network entity of the network where the first network slice entity to be registered and accessed is located; Obtaining a first network slice security context established with the first network slice entity; receiving a fourth message from the first network slice entity; The first message is a registration request message, and the fourth message is a registration confirmation message; The obtaining of the first network slice security context established with the first network slice entity comprises horizontally dispersing a key in a second network slice security context established with a registered and connected second network slice entity to obtain the first network slice security context; A first network entity, configured to receive a first message from a user equipment; wherein the first message includes: an identifier of a first network slice entity to be registered and accessed; and forwarding the first message to the first network slice entity according to the identifier of the first network slice entity; The first network slice entity is used to receive a first message sent by a user device through the first network entity; obtain a first network slice security context established between the user device and the first network slice entity, and send a fourth message to the user device.
33. A secure communication system comprising: A user equipment is used to send a first message to a second network entity to be registered and accessed; wherein the first message includes: temporary identity information of the user equipment in the first network slice entity that has been registered and accessed, temporary identity information of the user equipment in the first network entity that has been registered and accessed, and a message authentication code MAC calculated based on the first network slice security context that is currently activated; Acquire a second network security context established with the second network entity, and receive a fourth message from the second network entity; the first message is a registration request message, and the fourth message is a registration confirmation message; The second network security context is generated by: horizontally dispersing a key in a first network security context established with a registered and accessed first network entity; The second network entity is used to receive a first message from a user device; obtain verification indication information of the user device, obtain a first network security context established between the user device and the first network entity; obtain a second network security context established with the user device, and send a fourth message to the user device.
Citation Information
Patent Citations
Network registration and network slice selection system and method
US20180227873A1