A method and system for protecting the integrity of user plane data for network slicing
By adding service information to the mapping relationship to generate network slice anchor key K1, the high traffic and low latency requirements of 5G network slices in different business scenarios are solved, adaptive user-plane data integrity protection is achieved, and data transmission delay and security are improved.
Patent Information
- Application Number
- CN202111680363.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-30
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-12-30
AI Technical Summary
The existing technology cannot adapt to the needs of high traffic, low latency, large connections and other needs of 5G network slices in different business scenarios, resulting in insufficient security protection of user surface data.
By adding service information to the mapping relationship, the network slice anchor key K1 is generated, and corresponding service information is introduced in the user plane data transmission, adaptive integrity protection is achieved, computing load is reduced, and data transmission delay is improved.
The adaptive integrity protection of network sliced user surface data is realized in different business environments, reducing early configuration, reducing computing load, and improving the delay performance of user surface data transmission.
Smart Images

Figure CN114339761B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of 5G network slice data security, and in particular, to a method and system for protecting the integrity of user plane data for network slices. Background Art
[0002] With the increasingly wide application of network technologies, the scenarios of network applications vary. Different application scenarios require different deployment methods and locations of network function units (control plane and service plane).
[0003] A network slice is a set composed of a group of network functions, resources for running the network functions, and network function-specific configurations. The network functions and their corresponding configurations form a complete logical network, including network characteristics required to meet specific services.
[0004] Since network slices involve end-to-end network elements, service capacity involves the number of network elements and network element configurations, and connection and latency involve network topologies and interface configurations and deployments. Future network slices will carry a lot of high-value application data and sensitive information such as privacy, greatly increasing the security requirements of 5G networks. Therefore, the user plane security mechanism for network slices is essential. However, only the method for protecting the integrity of user plane data based on network slices cannot meet the requirements of 5G high traffic, low latency, large connections, etc. in different service scenarios. Summary of the Invention
[0005] The purpose of the present invention is to provide a method and system for protecting the integrity of user plane data for network slices, aiming to solve the problem that in the prior art, the requirements of 5G high traffic, low latency, large connections, etc. cannot be met in different service scenarios.
[0006] In a first aspect, an embodiment of the present invention provides a method for protecting the integrity of user plane data for network slices, including:
[0007] After the user UE access authentication is successful, the AUSF generates a network slice anchoring key K1 for the user UE, forming a mapping relationship <S-NSSAI, K1>, where S-NSSAI is the network slice identifier;
[0008] The AUSF sends the mapping relationship <S-NSSAI, K i > to the AMF, and the AMF saves the mapping relationship <S-NSSAI, K i >;
[0009] The AUSF returns to the user UE the network slice identifier S-NSSAI that needs to encrypt user plane data, and an indication of data transmission security protection;
[0010] The user UE generates a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection. The user UE introduces corresponding service information for the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and saves the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1.
[0011] In a second aspect, an embodiment of the present invention provides a user plane data integrity protection system for a network slice, which operates through the user plane data integrity protection method for a network slice, and includes:
[0012] A user UE, configured to generate a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection; introduce corresponding service information for the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and save the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1;
[0013] An AUSF, configured to generate a network slice anchoring key K1 for the user UE after successful user access authentication, form a mapping relationship <S-NSSAI, K1>, where S-NSSAI is a network slice identifier; send the mapping relationship <S-NSSAI, K1> to the AMF; return the network slice identifier S-NSSAI that needs to perform user plane data encryption and the indication of data transmission security protection to the user UE;
[0014] An AMF, configured to save the mapping relationship <S-NSSAI, K1>.
[0015] By adding service information to the mapping relationship, the embodiment of the present invention adaptively protects the integrity of the data transmitted on the user plane of the network slice in different service environments, can reduce the pre-configuration to achieve the purpose of protecting the integrity of the user plane data of the network slice, and can reduce the computing load, greatly improving the latency of the user plane data transmission, and has a certain degree of practicality. Description of the Drawings
[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0017] Figure 1 It is a schematic flowchart of the user plane data integrity protection method for a network slice provided by an embodiment of the present invention;
[0018] Figure 2 This is a block diagram of the user plane data integrity protection system for network slicing provided by the embodiments of the present invention. Detailed implementation manners
[0019] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0020] It should be understood that when used in this specification and the appended claims, the terms "include" and "comprise" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0021] It should also be understood that the terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in this specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms.
[0022] It should be further understood that the term "and / or" used in this specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0023] SUCI (Subscription Concealed Identifier);
[0024] S-NSSAI (Single Network Slice Selection Assistance Information);
[0025] AMF (Access and Mobility Management Function);
[0026] AUSF (Authentication Server Function);
[0027] UDM (Unified Data Management);
[0028] SUPI (Subscription Permanent Identifier);
[0029] SMF (Session Management Function);
[0030] UPF (UserPlane Function);
[0031] gNB is a 5G base station;
[0032] NSSF (The Network Slice Selection Function)
[0033] The authentication phases before the user UE access authentication is successful are:
[0034] 1. The user UE accesses the 5G network and initiates an initial registration request, which carries the user identity SUCI, the network slice identity S-NSSAI supported by the user UE and other information;
[0035] 2. After AMF accepts the user UE registration request, it initiates an authentication request to AUSF;
[0036] 3. After receiving the authentication request, if there is no user contract information (user identity), AUSF requests the user contract information from UDM. The request message includes the user identity SUCI, and the user contract information corresponding to the user identity SUCI is matched in UDM;
[0037] 4. UDM performs the conversion from SUCI to SUPI and returns the corresponding user contract information to AUSF;
[0038] The user subscription information includes the network slices (S-NSSAI identifier) that the user is allowed to access and an indication of which network slices corresponding to the network slice identifiers S-NSSAI require user plane data security protection;
[0039] 5. UDM generates an authentication vector for the user UE's access authentication request and returns it to AUSF together with the user's subscription information;
[0040] 6. AUSF receives the user's subscription information and authentication vector, and completes the two-way authentication process for the user UE to access the network with the AMF and the user UE.
[0041] See also Figure 1, a method for protecting the integrity of user plane data in network slicing, including:
[0042] After the user UE access authentication is successful, the AUSF generates a network slice anchoring key K1 for the user UE, forming a mapping relationship <S-NSSAI, K1>, where S-NSSAI is the network slice identifier;
[0043] The AUSF sends the mapping relationship <S-NSSAI, K1> to the AMF, and the AMF saves the mapping relationship <S-NSSAI, K1>;
[0044] The AUSF returns to the user UE the network slice identifier S-NSSAI that needs to encrypt the user plane data, as well as an indication of data transmission security protection;
[0045] The user UE generates a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection. The user UE introduces corresponding service information for the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and saves the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1.
[0046] In this embodiment, after the user UE access authentication is successful, the AUSF generates an anchoring key KAUSF for the user UE, and according to the indication of user plane data security protection returned by the UDM, for the corresponding network slice identifier S-NSSAI, generates a network slice anchoring key K1 for user plane data security protection using the key generation algorithm based on KAUSF;
[0047] <S-NSSAI, K1> indicates that user plane data security protection needs to be performed for the network slice corresponding to the network slice identifier S-NSSAI accessed by the user UE.
[0048] After the AUSF saves the mapping relationship of the user UE accessing the network and completes other registration processes, it returns an authentication success response message to the user UE, and includes an indication for establishing user plane data security protection corresponding to the network slice identifier S-NSSAI that needs to establish user plane data security protection in the response message.
[0049] The user UE receives the authentication success response message returned by the network, generates an anchoring key KAUSF, and indicates that using KAUSF and the above key generation algorithm, generates a network slice anchoring key K1 for user plane data security protection for the corresponding network slice identifier S-NSSAI;
[0050] Since the same KAUSF and key generation algorithm are used, it is ensured that the network slice anchoring key K1 generated by the user UE and the AUSF is the same;
[0051] By adding service information to the mapping relationship, adaptive integrity protection can be provided for the data transmitted on the user plane of the network slice in different service environments, which can reduce the pre-configuration to achieve the purpose of protecting the integrity of the user plane data of the network slice, and can reduce the computational load, greatly improving the transmission delay of the user plane data, and has a certain degree of practicality.
[0052] In one embodiment, the service information includes data network name (DNN) information, quality of service (QoS), service priority, reserved information on the base station side, bandwidth-delay requirement indicators for 5G service transmission, etc.
[0053] In this embodiment, the service information includes data network name (DNN) information, quality of service (QoS), service priority, reserved information on the base station side, bandwidth-delay requirement indicators for 5G service transmission, etc., enabling selection based on the information in the service information in the network slice.
[0054] In one embodiment, the user UE generates a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection. The user UE introduces corresponding service information into the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and saves the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1. Then, it includes:
[0055] The user UE generates an integrity key k3′ based on the information in the mapping relationship <S-NSSAI, service information, K1> and using a one-way irreversible function according to a preset method, saves the integrity key k3′, and saves the mapping relationship <S-NSSAI, service information, k3′>.
[0056] In this embodiment, the preset method can be set according to the actual situation; the one-way irreversible function is an existing function with a one-way irreversible effect, and a function can be selected according to the actual situation; the information in the mapping relationship <S-NSSAI, service information, K1> includes service information, etc.
[0057] In one embodiment, the user UE generates a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection. The user UE introduces corresponding service information into the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and saves the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1. Then, it includes:
[0058] The user UE sends a session establishment request to the AMF during the process of accessing a network slice;
[0059] The AMF obtains the network slice identifier S-NSSAI that needs to be requested for the user UE to access according to the mapping relationship <S-NSSAI, K i >, and performs user plane data security protection;
[0060] The SMF selects the AMF, and the AMF generates an integrity key k3' for user plane data security protection for the network slice identifier S-NSSAI. The AMF saves the mapping relationship <S-NSSAI, service information, k3'>.
[0061] In this embodiment, the integrity protection of the data transmitted on the user plane of the network slice is adaptively performed in different service environments through the generated integrity key k3'.
[0062] In one embodiment, the session establishment request includes: the network slice identifier S-NSSAI requested by the user UE to access and the corresponding service information.
[0063] In this embodiment, including the network slice identifier S-NSSAI and the corresponding service information in the session request facilitates generating the mapping relationship <S-NSSAI, service information, k3'> at the next level and also facilitates the transmission and storage of service information in subsequent levels.
[0064] In one embodiment, the SMF selects the AMF, and the AMF generates an integrity key k3' for user plane data security protection for the network slice identifier S-NSSAI. The AMF saves the mapping relationship <S-NSSAI, service information, k3'>. After that, it includes:
[0065] The AMF looks up the corresponding SMF according to the network slice identifier S-NSSAI;
[0066] A session is established between the AMF and the corresponding SMF. The AMF sends the mapping relationship <S-NSSAI, service information, k3'> to the SMF, and the SMF saves the mapping relationship <S-NSSAI, service information, k3'>;
[0067] The SMF looks up the corresponding UPF according to the network slice identifier S-NSSAI;
[0068] A session is established between the SMF and the corresponding UPF. The SMF sends the mapping relationship <S-NSSAI, service information, k3'> to the UPF, and the UPF saves the mapping relationship <S-NSSAI, service information, k3'>.
[0069] In this embodiment, the UPF stores the mapping relationship and establishes a binding between k3' and the network slice session, that is, when data is transmitted using this network slice session, the integrity key k3' is used to protect the security of data transmission.
[0070] After the user UE completes the session establishment process for accessing the network slice, it can use this network slice session to carry out application services.
[0071] In one embodiment, a session is established between the SMF and the corresponding UPF, and the SMF sends the mapping relationship <S-NSSAI, service information, k3'> to the UPF. The UPF stores the mapping relationship <S-NSSAI, service information, k3'>, and then includes:
[0072] The SMF conveys messages after session authentication and authorization with the AMF from the N1N2 interface;
[0073] A session establishment request and response are carried out between the AMF and the gNB;
[0074] The gNB performs radio resource reservation;
[0075] Other sessions are established between the user UE and the SMF, and the session establishment process for accessing the network slice is completed.
[0076] In this embodiment, radio resource reservation is to divide the priorities of network slices according to service information and the corresponding network slice identifier S-NSSAI, and reserve a certain resource space for higher-priority ones for priority transmission.
[0077] In one embodiment, other sessions are established between the user UE and the SMF, and after the session establishment process for accessing the network slice is completed, it includes:
[0078] When the user UE carries out application services with the UPF through this network slice session, the user UE identifies the user plane data, and adaptively generates MAC-I for the PDCP SDU based on the mapping relationship <S-NSSAI, service information, k3'> according to the service information and the mapping relationship <S-NSSAI, service information, k3'>, and adds MAC-I to the user plane data.
[0079] In this embodiment, the data MAC-I is a delay requirement flag, which is calculated and added to the corresponding user plane data when the delay requirement is met for identification to facilitate identification of transmission.
[0080] In one embodiment, when the user UE conducts application services with the UPF through the network slice session, the user UE identifies user plane data and adaptively generates MAC-I for the PDCP SDU based on the service information and the mapping relationship <S-NSSAI, service information, k3'>, including:
[0081] Determine whether the service information corresponding to the user plane data has high latency requirements;
[0082] If so, based on the adaptive algorithm, use the service information in the concatenated information of the user plane data as the MESSAGE of the integrity key k3', generate MAC-I through the integrity key k3', and add the generated MAC-I to the tail of the user plane data;
[0083] If not, perform integrity protection based on all the information in the concatenated information.
[0084] In this embodiment, the data MAC-I is a high latency flag and is added to the tail of the user plane data in case of high latency.
[0085] Please refer to Figure 2 , a user plane data integrity protection system for network slicing, which operates through the user plane data integrity protection method for network slicing, including:
[0086] A user UE, which is used to generate a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection; introduce corresponding service information for the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and save the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1;
[0087] An AUSF, which is used to generate a network slice anchoring key K1 for the user UE after successful user access authentication, form a mapping relationship <S-NSSAI, K1>, where S-NSSAI is the network slice identifier; send the mapping relationship <S-NSSAI, K1> to the AMF; return the network slice identifier S-NSSAI that needs to encrypt user plane data and the indication of data transmission security protection to the user UE;
[0088] An AMF, which is used to save the mapping relationship <S-NSSAI, K1>.
[0089] Through the above process, the security of application service data during transmission in the network slice identified by the network slice identifier S-NSSAI can be ensured. For the S-NSSAI identifier without user plane data security protection requirements, no corresponding protection key will be generated between the user UE and the UPF. Correspondingly, the user plane data transmitted within its network slice will not be protected for transmission security.
[0090] The above is only a specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for protecting the integrity of user plane data for network slicing, characterized in that Including: After the user UE access authentication is successful, the AUSF generates a network slice anchoring key K1 for the user UE, forming a mapping relationship <S-NSSAI, K1>, where S-NSSAI is the network slice identifier; The AUSF sends the mapping relationship <S-NSSAI, K1> to the AMF, and the AMF stores the mapping relationship <S-NSSAI, K1>; The AUSF returns to the user UE the network slice identifier S-NSSAI that requires user plane data encryption and an indication of data transmission security protection; The user UE generates a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection. The user UE introduces corresponding service information for the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and stores the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1; The user UE generates a network slice anchoring key K1 for the network slice identifier S-NSSAI according to the indication of data transmission security protection. The user UE introduces corresponding service information for the mapping relationship between the network slice identifier S-NSSAI and the network slice anchoring key K1, and stores the mapping relationship among the network slice identifier S-NSSAI, the service information, and the network slice anchoring key K1. After that, it includes: The user UE generates an integrity key k3' based on the information in the mapping relationship <S-NSSAI, service information, K1> and using a one-way irreversible function based on a preset method, stores the integrity key k3', and stores the mapping relationship <S-NSSAI, service information, k3'>; The user UE initiates a session establishment request during the process of accessing the network slice to the AMF; the AMF obtains the network slice identifier S-NSSAI that the user UE needs to request access to according to the mapping relationship <S-NSSAI, K1> and performs user plane data security protection; the SMF selects the AMF, and the AMF generates an integrity key k3' for user plane data security protection for the network slice identifier S-NSSAI. The AMF stores the mapping relationship <S-NSSAI, service information, k3'>; The SMF selects the AMF, and the AMF generates an integrity key k3' for user plane data security protection for the network slice identifier S-NSSAI. The AMF stores the mapping relationship <S-NSSAI, service information, k3'>. After that, it includes: the AMF looks up the corresponding SMF according to the network slice identifier S-NSSAI; a session is established between the AMF and the corresponding SMF, and the AMF sends the mapping relationship <S-NSSAI, service information, k3'> to the SMF, and the SMF stores the mapping relationship <S-NSSAI, service information, k3'>; the SMF looks up the corresponding UPF according to the network slice identifier S-NSSAI; a session is established between the SMF and the corresponding UPF, and the SMF sends the mapping relationship <S-NSSAI, service information, k3'> to the UPF, and the UPF stores the mapping relationship <S-NSSAI, service information, k3'>; A session is established between the SMF and the corresponding UPF, and the SMF sends the mapping relationship <S-NSSAI, service information, k3'> to the UPF, and the UPF stores the mapping relationship <S-NSSAI, service information, k3'>. After that, it includes: the SMF conveys messages after session authentication and authorization with the AMF from the N1N2 interface; a session establishment request and response are carried out between the AMF and the gNB; the gNB performs radio resource reservation; other sessions are established between the user UE and the SMF, and the access network slice session establishment process is completed; Other sessions are established between the user UE and the SMF, and the access network slice session establishment process is completed. After that, it includes: when the user UE conducts application services with the UPF through the network slice session, the user UE identifies the user plane data, and based on the service information and the mapping relationship <S-NSSAI, service information, k3'>, adaptively generates a MAC-I for the PDCP SDU based on the mapping relationship <S-NSSAI, service information, k3'>, and adds the MAC-I to the user plane data; When the user UE conducts application services with the UPF through the network slice session, the user UE identifies the user plane data, and based on the service information and the mapping relationship <S-NSSAI, service information, k3'>, adaptively generates a MAC-I for the PDCP SDU based on the mapping relationship <S-NSSAI, service information, k3'>, including: judging whether the service information corresponding to the user plane data has high latency requirements; if so, based on an adaptive algorithm, taking the service information in the concatenated information of the user plane data as the MESSAGE of the integrity key k3', and generating a MAC-I through the integrity key k3', and adding the generated MAC-I to the end of the user plane data; if not, performing integrity protection based on all the information in the concatenated information.
2. The method for protecting the integrity of user plane data for network slicing according to claim 1, characterized in that: The service information includes data network name (DNN) information, quality of service (QoS), service priority, base station side reserved information, bandwidth and latency requirement indicators for 5G service transmission, etc.
3. The user plane data integrity protection method for network slicing according to claim 1, wherein The session establishment request includes: the network slice identifier (S-NSSAI) requested by the user equipment (UE) to access and the corresponding service information.
4. A user plane data integrity protection system for network slicing, which operates by the user plane data integrity protection method for network slicing according to any one of claims 1-3, characterized in that It includes: User Equipment (UE), which is used to generate a network slice anchoring key K1 for the network slice identifier (S-NSSAI) according to the indication of data transmission security protection; introduce the corresponding service information for the mapping relationship between the network slice identifier (S-NSSAI) and the network slice anchoring key K1, and save the mapping relationship among the network slice identifier (S-NSSAI), service information, and network slice anchoring key K1. Authentication Server Function (AUSF), which is used to generate a network slice anchoring key K1 for the user equipment (UE) after successful user access authentication, form a mapping relationship <S-NSSAI, K1>, where S-NSSAI is the network slice identifier; send the mapping relationship <S-NSSAI, K1> to the Access and Mobility Management Function (AMF); return to the user equipment (UE) the network slice identifier (S-NSSAI) that requires user plane data encryption and the indication of data transmission security protection. Access and Mobility Management Function (AMF), which is used to save the mapping relationship <S-NSSAI, K1>.
Citation Information
Patent Citations
Data security transmission implementation method for network slice
CN112738800A