Communication method and communication device
By verifying the identity of the network element and establishing a secure connection, the problem of attackers' disguising identity requests is solved, and the security of the communication system is improved.
Patent Information
- Application Number
- CN202110194700.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-02-21
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2041-02-21
AI Technical Summary
The attacker disguises his identity and requests to perform operations on the communication device, affecting the security of the communication.
By verifying whether the network element sending the request message has permissions, it is determined whether it is a malicious attacker, including using identity verification and secure connection establishment, ensuring the operation request of the legitimate network element and terminal equipment.
Reduces the impact of system services due to attacker requests and improves the security of communication systems.
Smart Images

Figure CN114980094B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and more specifically, to a communication method and a communication device. Background Art
[0002] In some scenarios, attackers can request to perform some operations on other communication devices by disguising their identities. For example, after the terminal device and network slice authentication process is completed, the attacker can disguise himself as the authentication, authorization, accounting server (AAA-S) to request re-authentication or revocation of authentication from the network slice-specific authentication and authorization function (NSSAAF); for another example, after the drone authentication and authorization process, the attacker can disguise himself as the uncrewed aerial system traffic management (UTM) / unmanned aerial system service supplier (USS) to request the revocation of authentication authorization from the network element with drone function (such as the uncrewed aerial vehicle network function (UAV-NF)), which seriously affects the security of communication. Therefore, it is hoped to provide a technology that can improve the security of communication. Summary of the Invention
[0003] The communication method and communication device of the embodiments of the present application can improve the security of communication.
[0004] In a first aspect, a communication method is provided, which includes: a first network element receives a first request message from a second network element, wherein the first request message is used to request to perform a first operation on a first terminal device; the first network element determines whether the second network element has the authority to request to perform the first operation on the first terminal device based on the first request message.
[0005] Exemplarily, the second network element requests the first network element to perform an operation on other communication devices, for example, the second network element requests the first network element to perform a first operation on a first terminal device.
[0006] As an example, in a network slicing scenario, the second network element is, for example, an AAA-S, the first network element is, for example, an NSSAAF, the first terminal device is, for example, a user equipment UE, and the first operation is, for example, network slice re-authentication. That is, the AAA-S sends a first request message to the NSSAAF to request network slice re-authentication of the UE. The first operation includes network slice re-authentication or revocation of network slice authentication.
[0007] As another example, in a drone scenario, the second network element is, for example, a UTM, the first network element is, for example, a UAV-NF, and the first terminal device is, for example, a UAV. The first operation is, for example, revoking drone authentication authorization. That is, the UTM sends a first request message to the UAV-NF to request revoking drone authentication authorization for the UAV. The first operation includes revoking authentication authorization or revoking pairing authentication authorization.
[0008] Therefore, the communication method of the embodiment of the present application verifies whether the network element that sends the request message has the authority to request to perform related operations to determine whether the network element is a malicious attacker, thereby reducing the situation where system services are affected by the attacker's request and improving the security of the system.
[0009] It should be understood that the second network element requests the first network element to perform the first operation on the first terminal device through the first request message, which can be understood as: the second network element requests through the first request message to perform the first operation on all parameters related to the first request used by the first terminal device, or it can be understood as the second network element requests through the first request message to perform the first operation on a certain parameter related to the first request used by the first terminal device. Exemplarily, in a network slicing scenario, the first control device is, for example, AAA-S, the first communication device is, for example, NSSAAF, the first terminal device is, for example, user equipment UE, the parameter corresponding to the UE is at least 1 S-NSSAI, and the first operation is, for example, network slice re-authentication. That is, AAA-S sends a first request message to NSSAAF to request network slicing and re-authentication of all S-NSSAIs of the UE, or AAA-S sends a first request message to NSSAAF to request network slicing and re-authentication of the network slice corresponding to a certain S-NSSAI of the UE.
[0010] In combination with the first aspect, in some implementations of the first aspect, the first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, and the second identifier is associated with the second network element.
[0011] The first identifier and the second identifier are used to verify whether the second network element has the authority to perform the first operation on the first terminal device. It can be understood that the first identifier and the second identifier are used to verify whether the second network element has an association relationship with the first identifier.
[0012] It should be understood that the first identifier associated with the first terminal device can be an identifier used to identify the first terminal device, or it can be a service identifier used for the first terminal device; the second identifier associated with the second network element can be information used to identify the second network element, such as the address information or identity information of the second network element, or it can be information related to the service of the second network element. This information should be information that cannot be obtained by an attacker. Therefore, the identity of the second network element can be verified by verifying the second identifier associated with the second network element, thereby improving the security of the system.
[0013] With reference to the first aspect, in certain implementations of the first aspect, the second identifier includes at least one of the following information: an identity identification number (ID) of the second network element, an Internet Protocol (IP) address of the second network element, and a fully qualified domain name (FQDN) of the second network element; and the first identifier includes single network slice selection assistance information (S-NSSAI). It should be understood that the second identifier in this implementation can be combined with the example in the above slicing scenario.
[0014] With reference to the first aspect, in certain implementations of the first aspect, the second identifier includes at least one of the following information: an ID number of the second network element and a Civil Aviation Administration-level drone identifier of the first terminal device; and the first identifier includes the ID number of the first terminal device. It should be understood that the second identifier in this implementation can be combined with the example in the drone scenario described above.
[0015] In combination with the first aspect, in some implementations of the first aspect, the method also includes: the first network element stores a mapping relationship between a third identifier and the first identifier; the first network element determines whether the second network element has the authority to perform the first operation on the first terminal device based on the first request message, including: the first network element obtains the mapping relationship based on the first identifier; when the second identifier matches the third identifier, the first network element determines that the second network element has the authority to request to perform the first operation on the first terminal device; otherwise, the first network element determines that the second network element does not have the authority to perform the first operation on the first terminal device.
[0016] It should be understood that the mapping relationship represents a legal association relationship. Specifically, the mapping relationship can be used to obtain a legal association object (such as an FQDN, an IP address) of the first identifier. The mapping relationship is used to indicate that the legal association object, such as the third identifier, corresponds to a network element that has permission to perform the first operation on the first terminal device. The network element corresponding to the same identifier as the legal association object has permission to perform the first operation on the first terminal device.
[0017] It should be noted that the second identifier matches the third identifier, which means that the second identifier and the third identifier are the same, or an identifier that is the same as the second identifier can be determined based on the third identifier. For example, the second identifier is the IP address #1 of the second network element, and the third identifier is the IP address #2 of the third network element. When IP address #1 is the same as IP address #2, it means that the second identifier and the third identifier match, otherwise it means that the second identifier and the third identifier do not match. For another example, the second identifier is the IP address #1 of the second network element, and the third identifier is the FQDN of the third network element. The first network element determines the IP address #2 of the third network element based on the FQDN. When IP address #1 is the same as IP address #2, it means that the second identifier and the third identifier match, otherwise it means that the second identifier and the third identifier do not match.
[0018] When the first network element determines that the second network element has the authority to request to perform the first operation on the first terminal device, the first network element performs the first operation on the first terminal device according to the first request message; when the first network element determines that the second network element does not have the authority to request to perform the first operation on the first terminal device, the first network element terminates the first operation process, for example, the first network element ignores or discards the first request message, or the first network element sends a response message to the second network element, and the response message is used to reject the first request message.
[0019] It should be understood that the first network element can be a system pre-configured mapping relationship between multiple identifiers associated with multiple control devices and multiple identifiers associated with multiple terminal devices, or it can be a mapping relationship between multiple identifiers associated with multiple control devices and multiple identifiers associated with multiple terminal devices determined based on other relevant identifiers within the system and then stored locally.
[0020] It should be understood that the same attributes of the third identifier and the second identifier indicate that the third identifier and the second identifier are identifiers of the same type. For example, if the third identifier and the second identifier are both IP addresses, then the third identifier is the IP address of the third network element, and the second identifier is the IP address of the second network element.
[0021] In combination with the first aspect, in certain implementations of the first aspect, the first operation includes network slice re-authentication or revocation of network slice authentication.
[0022] Therefore, the communication method of the embodiment of the present application can improve the security in the network slice re-authentication scenario, that is, reduce the situation where the terminal device and the network slice are repeatedly re-authenticated or revoked due to the attacker's request.
[0023] In combination with the first aspect, in some implementations of the first aspect, the first operation includes revoking an authentication authorization or revoking a pairing authentication authorization.
[0024] Therefore, the communication method of the embodiment of the present application can improve the security in the drone scenario, that is, it can reduce the situation where the drone's authentication authorization is revoked due to the attacker's request.
[0025] In combination with the first aspect, in certain implementations of the first aspect, the method further includes: the first network element obtaining timestamp information, where the timestamp information is used to indicate the validity period of the second identifier.
[0026] That is, the second identifier is bound to the timestamp information, which indicates a valid time. When the valid time expires, the first network element deletes the second identifier. This can prevent verification failures caused by invalid identifier information, thereby improving system security.
[0027] In combination with the first aspect, in some implementations of the first aspect, before the first network element receives the first request message from the second network element, the method further includes: the first network element establishing a secure connection with the second network element.
[0028] Establishing a secure link may include, when the network is being built, establishing a secure connection between the first network element and the second network element according to device pre-configuration or manual triggering, or establishing a secure connection when the first network element establishes communication with the second network element for the first time. It may also be a secure connection established when the first network element and the second network element communicate with the opposite end again. The difference is that when the first network element and the second network element establish a secure connection for the first time, it is a connection establishment process initiated by the first network element. For example, in the NSSAA process, the first network element initiates a secure connection establishment process with the second network element. The process of establishing a secure connection again may be initiated by the second network element. For example, in the network slice re-authentication process, the second network element initiates a secure connection establishment process with the first network element.
[0029] In combination with the first aspect, in certain implementations of the first aspect, the first network element establishes a secure connection with the second network element, including: the first network element obtains security certificate information of the second network element; the first network element establishes an Internet Protocol security IPsec tunnel with the second network element based on the security certificate information.
[0030] In combination with the first aspect, in certain implementations of the first aspect, the first communication device establishes a secure link with the second control device, including: the first network element obtains security certificate information of the second network element; the first network element establishes a Transport Layer Security Protocol TLS / Datagram Transport Layer Security Protocol DTLS connection with the second network element based on the security certificate information.
[0031] During the process of establishing the secure connection or after the secure connection is established, the first network element saves the fourth identifier, and the fourth identifier is associated with the second network element and the secure connection. It should be understood that the fourth identifier is associated with the second network element and the secure connection, which can be understood as the fourth identifier being a securely protected or provably associated identifier with the second network element. For example, the first network element obtains the security certificate of the second network element during the secure connection establishment process and obtains the fourth identifier from the security certificate of the second network element, or the fourth identifier is associated with the identifier of the secure connection. Therefore, the fourth identifier can be considered to be an authentic and untampered identifier associated with the second network element.
[0032] The first network element receives a first request message from the second network element via the secure connection and obtains a second identifier from the first request message. When the first network element determines that the second identifier and the fourth identifier are the same, the first network element continues to execute the current process; when the first network element determines that the second identifier and the fourth identifier are different, the first network element terminates the process, for example, by ignoring or discarding the first request message, or by sending a response message to the second network element, where the response message is used to reject the first request message.
[0033] The first network element receives a first request message from the second network element through the secure connection and obtains a first identifier from the first request message. When the first network element determines that the third identifier is associated with the first identifier, or the mapping relationship corresponding to the third identifier is the same as the fourth identifier, the first network element continues to execute the current process; when the first network element determines that the third identifier and the fourth identifier are different, the first network element terminates the process, for example, the first network element ignores or discards the first request message, or the first network element sends a response message to the second network element, where the response message is used to reject the first request message.
[0034] According to a second aspect, a communication method is provided, which includes: a second network element generates a first request message; the second network element sends the first request message to the first network element, the first request message is used to request to perform a first operation on the first terminal device, and the first request message is used to determine whether the second network element has the authority to request to perform the first operation on the first terminal device.
[0035] In combination with the second aspect, in certain implementations of the second aspect, the second identifier includes at least one of the following information: the identity identification number ID of the second network element, the Internet Protocol IP address of the second network element, and the fully qualified domain name FQDN of the second network element; the first identifier includes single network slice selection auxiliary information S-NSSAI.
[0036] In combination with the second aspect, in certain implementations of the second aspect, the second identification includes at least one of the following information: the identity identification number ID of the second network element, the Civil Aviation Administration-level drone identification of the first terminal device; the first identification includes the identity identification number ID of the first terminal device.
[0037] In combination with the second aspect, in certain implementations of the second aspect, the first operation includes network slice re-authentication or revocation of network slice authentication.
[0038] In combination with the second aspect, in some implementations of the second aspect, the first operation includes revoking the authentication authorization of the first terminal device or revoking the pairing authentication authorization of the first terminal device.
[0039] In combination with the second aspect, in certain implementations of the second aspect, before the second network element sends the first request message to the first network element, the method also includes: the second network element establishes a secure connection with the first network element; the second network element sends the first request message to the first network element, including: the second network element sends the first request message to the first network element through the secure connection.
[0040] Establishing a secure link may include, when the network is being built, establishing a secure connection between the first network element and the second network element according to device pre-configuration or manual triggering, or establishing a secure connection when the first network element establishes communication with the second network element for the first time. It may also be a secure connection established when the first network element and the second network element communicate with the opposite end again. The difference is that when the first network element and the second network element establish a secure connection for the first time, it is a connection establishment process initiated by the first network element. For example, in the NSSAA process, the first network element initiates a secure connection establishment process with the second network element. The process of establishing a secure connection again may be initiated by the second network element. For example, in the network slice re-authentication process, the second network element initiates a secure connection establishment process with the first network element.
[0041] In combination with the second aspect, in certain implementations of the second aspect, the second network element establishes a secure connection with the first network element, including: the second network element sends the security certificate information of the second network element to the first network element; the second network element establishes an Internet Protocol security IPsec tunnel with the first network element based on the security certificate information.
[0042] In combination with the second aspect, in certain implementations of the second aspect, the second network element establishes a secure link with the first network element, including: the second network element sends the security certificate information of the second network element to the first network element; the second network element establishes a Transport Layer Security Protocol TLS / Datagram Transport Layer Security Protocol DTLS link with the first network element based on the security certificate information.
[0043] According to a third aspect, a communication method is provided, which includes: a first network element receives a first request message from a second network element, where the first request message is used to request network slice re-authentication or revocation of network slice authentication for a first terminal device; the first network element determines whether the second network element has the authority to request network slice re-authentication or revocation of network slice authentication for the first terminal device based on the first request message.
[0044] In combination with the third aspect, in certain implementations of the third aspect, the first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, and the second identifier is associated with the second network element, and the first identifier and the second identifier are used to determine whether the second network element has the authority to request network slice re-authentication or revocation of network slice authentication for the first terminal device.
[0045] In combination with the third aspect, in certain implementations of the third aspect, the second identifier includes at least one of the following information: the identity identification number ID of the second network element, the Internet Protocol IP address of the second network element, and the fully qualified domain name FQDN of the second network element; the first identifier includes single network slice selection auxiliary information S-NSSAI.
[0046] In combination with the third aspect, in certain implementations of the third aspect, the first network element includes an NSSAAF, the second network element includes an AAA-S, and the first terminal device includes a user equipment UE.
[0047] In combination with the third aspect, in certain implementations of the third aspect, the method further includes: the first network element obtains security certificate information of the second network element; and the first network element establishes an Internet Protocol security IPsec tunnel with the second network element based on the security certificate information.
[0048] Therefore, in the communication method provided in the embodiment of the present application, the first request message sent by AAA-S to NSSAAF carries the address information and / or identity information of AAA-S, and the address information and / or identity information of the AAA-S is verified to determine whether the identity of the AAA-S is correct, thereby reducing the situation where the terminal device and the network slice are repeatedly re-authenticated or revoked due to the attacker's request.
[0049] In a fourth aspect, a communication method is provided, which includes: a first network element receives a first request message from a second network element, the first request message being used to request authentication authorization revocation / pairing authentication authorization revocation for a first terminal device; the first network element determines whether the second network element has the authority to request authentication authorization revocation / pairing authentication authorization revocation for the first terminal device based on the first request message.
[0050] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, and the second identifier is associated with the first terminal device or the second network element, and the first identifier and the second identifier are used to determine whether the second network element has the authority to request authentication authorization revocation / pairing authentication authorization revocation for the first terminal device.
[0051] In combination with the fourth aspect, in certain implementations of the fourth aspect, the second identifier includes at least one of the following information: the identity identification number ID of the second network element, the Civil Aviation Administration-level UAV identification CAA-Level UAV ID of the first terminal device; the first identifier includes the identity identification number ID of the first terminal device.
[0052] In combination with the fourth aspect, in some implementations of the fourth aspect, the first network element includes a UAV-NF or an AAA-P, the second network element includes a UTM / USS, and the first terminal device includes a UAV.
[0053] In combination with the fourth aspect, in certain implementations of the fourth aspect, the method also includes: the first network element obtains security certificate information of the second network element; the first network element establishes a Transport Layer Security Protocol TLS or Datagram Transport Layer Security Protocol DTLS connection with the second network element based on the security certificate information.
[0054] Therefore, in the communication method provided in the embodiment of the present application, the first request message sent by the UTM / USS to the UAV-NF carries the CAA-Level UAV ID and / or UTM / USS ID, and the CAA-Level UAV ID and / or UTM / USS ID are verified to determine whether the identity of the UTM / USS is correct, thereby reducing the situation where the drone's authentication authorization is revoked due to the attacker's request. That is, the communication method provided in the embodiment of the present application allows the UAV-NF to detect whether the identity of the UTM / USS that sends the authentication authorization revocation request is correct, that is, to detect whether the UTM / USS is an authorized UTM / USS, thereby reducing the situation where the drone's authentication authorization is revoked without reason due to the attacker's request, thereby improving the security of the system.
[0055] In a fifth aspect, a communication method is provided, which includes: a first network element receives a first request message from a second network element, the first request message being used to request authentication authorization revocation / pairing authentication authorization revocation for a first terminal device; the first network element determines whether a secure connection has been established with the second network element and whether integrity protection is enabled; when a secure connection has been established between the first network element and the second network element and integrity protection is enabled, the first network element determines whether the second network element has the authority to request authentication authorization revocation / pairing authentication authorization revocation for the first terminal device based on the first request message.
[0056] In combination with the fifth aspect, in some implementations of the fifth aspect, the first network element includes a UAV-NF or AAA-P, the second network element includes a UTM / USS, and the first terminal device includes a UAV.
[0057] In conjunction with the fifth aspect, in certain implementations of the fifth aspect, the method further includes: the UAV-NF obtaining identification information of the UTM / USS and identification information of the TLS connection during the process of establishing a TLS secure connection with the UTM / USS; and after the UAV-NF successfully establishes the TLS connection with the UTM / USS, saving the association between the TLS connection identifier and the UTM / USS identification information. Upon receiving a message carrying an authentication authorization revocation / paired authentication authorization revocation from the UTM / USS via the TLS connection, the UAV-NF obtains the UTM / USS identification information based on the TLS connection identifier and verifies the identity of the UTM / USS to determine whether the UTM / USS is correct, thereby reducing the possibility of the drone's authentication authorization being revoked due to an attacker's request. Establishing the TLS connection may include establishing the TLS connection between the UAV-NF and the UTM / USS during network setup, based on device pre-configuration or manual triggering, or establishing the TLS connection when the UTM / USS and UAV-NF communicate with each other for the first time. Alternatively, the secure connection may be established when the UTM / USS and UAV-NF communicate with each other again. That is, the communication method provided in the embodiment of the present application allows the UAV-NF to detect whether the identity of the UTM / USS that sends the authentication authorization revocation request is correct, that is, to detect whether the UTM / USS is an authorized UTM / USS, thereby reducing the situation where the authentication authorization of the drone is revoked for no reason due to the request of an attacker, thereby improving the security of the system.
[0058] Therefore, in the communication method provided in the embodiment of the present application, the UAV authentication revocation process is performed only after it is determined that a TLS connection has been established between the UAV-NF and the UTM / USS and integrity protection is enabled. Otherwise, the identity of the UTM / USS needs to be verified, thereby reducing the situation where the drone's authentication authorization is revoked for no reason due to the attacker's request.
[0059] In the sixth aspect, a communication device is provided, which includes: a transceiver module for receiving a first request message from a second network element, wherein the first request message is used to request to perform a first operation on a first terminal device; and a processing module for determining whether the second network element has the authority to request to perform the first operation on the first terminal device based on the first request message.
[0060] The transceiver module can perform the reception and transmission processing in the aforementioned first aspect, and the processing module can perform other processing except reception and transmission in the aforementioned first aspect.
[0061] In the seventh aspect, a communication device is provided, which includes: a transceiver module for sending a first request message to a first network element, the first request message is used to request to perform a first operation on the first terminal device, the first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, the second identifier is associated with the second network element, and the second identifier is used to determine whether the second network element has the authority to request to perform the first operation on the first terminal device.
[0062] The transceiver module can perform the receiving and sending processing in the second aspect mentioned above; the device also includes a processing module, which can perform other processing in addition to the receiving and sending in the second aspect mentioned above.
[0063] In an eighth aspect, a communication device is provided, comprising: a processor for executing a computer program stored in a memory, so that the communication device executes any possible implementation of the first aspect to the second aspect.
[0064] In a ninth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program runs on a computer, the computer is enabled to execute any possible implementation of the first to second aspects.
[0065] In a tenth aspect, a chip system is provided, which includes: a processor for calling and running a computer program from a memory, so that a communication device equipped with the chip system executes any possible implementation method of the first to second aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] Figure 1 It is a schematic diagram of a network architecture suitable for the method provided in the embodiment of the present application.
[0067] Figure 2 This is a schematic diagram of another network architecture suitable for the method provided in the embodiment of the present application.
[0068] Figure 3 This is a schematic flowchart of a communication method provided by an embodiment of the present application.
[0069] Figure 4 It is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0070] Figure 5 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0071] Figure 6 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0072] Figure 7 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0073] Figure 8 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0074] Figure 9 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0075] Figure 10 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0076] Figure 11 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0077] Figure 12 This is a schematic flowchart of a communication method provided by another embodiment of the present application.
[0078] Figure 13 This is a schematic block diagram of an example of a communication device of the present application.
[0079] Figure 14 It is a schematic block diagram of another example of the communication device of the present application. DETAILED DESCRIPTION
[0080] The technical solution in this application will be described below with reference to the accompanying drawings.
[0081] The technical solution provided in this application can be applied to various communication systems, such as: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, universal mobile telecommunication system (UMTS), world-wide interoperability for microwave access (WiMAX) communication system, fifth generation (5G) system or new radio (NR), etc.
[0082] It should be understood that the embodiments of the present application do not specifically limit the specific structure of the execution subject of the method provided in the embodiments of the present application. As long as it is possible to communicate according to the method provided in the embodiments of the present application by running a program that records the code of the method provided in the embodiments of the present application, for example, the execution subject of the method provided in the embodiments of the present application can be a terminal or a network device, or a functional module in the UE or network device that can call and execute the program.
[0083] To facilitate understanding of the embodiments of this application, first Figure 1 An application scenario of an embodiment of the present application is described in detail.
[0084] Figure 1 It is a schematic diagram of a network architecture suitable for the method provided in the embodiment of the present application. Figure 1 The network architecture shown may specifically include the following network elements:
[0085] 1. User Equipment (UE): This term may also refer to terminal equipment, terminal, access terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent, or user device. A UE may also be a cellular phone, cordless phone, Session Initiation Protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, vehicle-mounted device, wearable device, terminal device in a 5G network or terminal device in a future-evolved public land mobile network (PLMN), etc. It may also be an end device, a logical entity, an intelligent device such as a mobile phone, a smart terminal, or a communication device such as a server, gateway, base station, or controller, or an Internet of Things (IoT) device such as a sensor, electricity meter, or water meter. A UE may also be a wired device such as a computer or laptop computer. This is not limited in the embodiments of the present application. The UE stores long-term keys and related functions. When the UE performs two-way authentication with core network elements (such as AMF and AUSF), it will use the long-term keys and related functions to verify the authenticity of the network.
[0086] 2. Access network (AN): Provides network access for authorized users in a specific area and can use transmission tunnels of different qualities based on user levels, business requirements, etc. The access network can be an access network that uses different access technologies. Currently, there are two types of wireless access technologies: 3rd Generation Partnership Project (3GPP) access technology (such as the wireless access technology used in 3G, 4G or 5G systems) and non-3GPP access technology. 3GPP access technology refers to access technology that complies with 3GPP standards and specifications. The access network that uses 3GPP access technology is called a radio access network (RAN). Among them, the access network equipment in the 5G system is called the next generation Node Base station (gNB). Non-3GPP access technology refers to access technology that does not comply with 3GPP standards and specifications, for example, the air interface technology represented by the access point (AP) in WiFi.
[0087] An access network that implements access network functions based on wired communication technology can be called a wired access network.
[0088] An access network that implements network access functions based on wireless communication technologies is called a radio access network (RAN). The RAN manages radio resources, provides access services to terminals, and forwards control signals and user data between terminals and the core network.
[0089] The wireless access network can be, for example, a base station (NodeB), an evolved NodeB (eNB or eNodeB), a base station (gNB) in a 5G mobile communication system, a base station in a future mobile communication system, or an AP in a WiFi system, etc. It can also be a wireless controller in a cloud radio access network (CRAN) scenario, or the access network device can be a relay station, an access point, a vehicle-mounted device, a wearable device, and a network device in a future 5G network or a network device in a future evolved PLMN network, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted by the wireless access network device.
[0090] 3. Access and Mobility Management Function (AMF) entity: This entity is primarily used for mobility management and access management, and can be used to implement other functions of the Mobility Management Entity (MME) in addition to session management, such as lawful interception or access authorization (or authentication). In the embodiment of the present application, it can be used to implement the functions of the access and mobility management network element.
[0091] 4. Session Management Function (SMF) entity: This entity is primarily responsible for session management, UE Internet Protocol (IP) address allocation and management, selection of endpoints for manageable user plane functions, policy control, or charging function interfaces, and downlink data notification. In embodiments of the present application, this entity can be used to implement the functions of a session management network element.
[0092] 5. User Plane Function (UPF) Entity: This entity is also known as the data plane gateway. This entity can be used for packet routing and forwarding, or for quality of service (QoS) processing of user plane data. User data can be connected to the data network (DN) through this network element. In this embodiment of the present application, this entity can be used to implement the functions of a user plane gateway.
[0093] 6. Data Network (DN): A network used to transmit data, such as a carrier's service network, the Internet, or a third-party service network.
[0094] 7. Authentication server function (AUSF) entity: mainly used for user authentication, etc.
[0095] 8. Network exposure function (NEF) entity: used to securely expose services and capabilities provided by 3GPP network functions to the outside world.
[0096] 9. Network function (NF) repository function (NRF) entity: used to store descriptions of network function entities and the services they provide, and to support service discovery, network element entity discovery, etc.
[0097] 10. Policy control function (PCF) entity: A unified policy framework used to guide network behavior and provide policy rule information to control plane functional network elements (such as AMF, SMF network elements, etc.).
[0098] 11. Unified data management (UDM) entity: used to handle user identification, access authentication, registration, or mobility management, etc.
[0099] 12. Application Function (AF) entity: used for data routing affected by applications, accessing network open function elements, or interacting with the policy framework for policy control.
[0100] In this network architecture, the N1 interface is the reference point between the terminal and the AMF entity; the N2 interface is the reference point between the AN and the AMF entity, used for sending non-access stratum (NAS) messages, etc.; the N3 interface is the reference point between the (R)AN and the UPF entity, used for transmitting user plane data, etc.; the N4 interface is the reference point between the SMF entity and the UPF entity, used for transmitting information such as tunnel identification information of the N3 connection, data cache indication information, and downlink data notification messages; the N6 interface is the reference point between the UPF entity and the DN, used for transmitting user plane data, etc.
[0101] Figure 1 The interface names between the various network elements in the embodiment are only examples. The names of the interfaces in the specific implementation may be other names, and this application does not specifically limit this. In addition, the names of the messages (or signaling) transmitted between the above-mentioned network elements are only examples and do not constitute any limitation on the function of the messages themselves.
[0102] It should be understood that the above-mentioned network architecture applied to the embodiment of the present application is only an example of the network architecture described from the perspective of traditional point-to-point architecture and service-oriented architecture. The network architecture applicable to the embodiment of the present application is not limited to this. Any network architecture that can realize the functions of the above-mentioned network elements is applicable to the embodiment of the present application.
[0103] It should also be understood that Figure 1 The AMF network element, SMF network element, UPF network element, NSSF network element, NEF network element, AUSF network element, NRF network element, PCF network element, and UDM network element shown in the figure can all be understood as network elements used to implement different functions in the core network, for example, they can be combined into network slices as needed. These core network network elements can be independent devices or integrated into the same device to implement different functions, which is not limited in this application. The device that performs the core network network element function can also be called a core network device or a network device.
[0104] The above naming is only used to distinguish different functions and does not mean that these network elements are independent physical devices. This application does not limit the specific form of the above network elements. For example, they can be integrated into the same physical device or they can be different physical devices. In addition, the above naming is only for the convenience of distinguishing different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other future networks. For example, in a 6G network, some or all of the above network elements may use the terminology in 5G, or may use other names, etc. A unified explanation is given here and will not be repeated below.
[0105] Figure 2It is a schematic diagram of another network architecture suitable for the method provided in the embodiment of the present application. Figure 2 The network architecture shown may specifically include the following network elements:
[0106] 1. Uncrewed aerial vehicle (UAV): Sometimes also called unmanned aerial vehicle (UAV), also known as unmanned aircraft or aerial robot, it is an unmanned aircraft that uses radio remote control equipment and self-contained program control devices, and can complete aerial flight missions and various load-bearing tasks under unmanned conditions. The UAV in the embodiments of the present application can be an unmanned helicopter, fixed-wing aircraft, multi-rotor aircraft, unmanned airship, unmanned paraglider; it can also include near-space aircraft such as stratospheric airships, high-altitude balloons, solar-powered drones, etc.; it can also be a variety of drones with four axes, six axes, single axes, vector control, etc. The UAV in the embodiments of the present application can be used in military, industrial, civil, agricultural, construction, film and television, environmental protection and other fields as well as special industries that use UAV operations, such as using UAVs for military reconnaissance, inspections, aerial photography, environmental monitoring, border control, express delivery, power inspections, property rights confirmation, flood control and drought relief, post-disaster rescue, etc. The embodiments of the present application are not limited to this.
[0107] It should be understood that this document does not limit the specific types of drones. With the advancement of intelligent technology, the names of devices with drone functionality may vary to suit different scenarios or fulfill different aerial missions. For ease of description, in all embodiments of this application, the aforementioned devices capable of drone functionality are collectively referred to as drones.
[0108] The drone can be equipped with a variety of sensors or functional modules, such as a gyroscope (flight attitude perception), an accelerometer, a geomagnetic sensor, an air pressure sensor (rough hovering height control), an ultrasonic sensor (precise low-altitude height control or obstacle avoidance), an optical flow sensor (precise determination of the hovering horizontal position), a global positioning system (GPS) module (rough horizontal position height positioning), a control circuit, a compass, etc. By collecting the drone's angular rate, attitude, position, acceleration, altitude, and airspeed, etc., it is possible to automatically maintain the drone's normal flight attitude. It should be understood that the module or hardware name configured in the above drone is merely an example. In specific implementations, each functional module may have other names, and the embodiments of the present application are not limited to this. The drone in the embodiments of the present application may also have more or fewer functional modules, and may also implement more or fewer functions, etc., and the embodiments of the present application do not impose any limitations on this.
[0109] 2. Uncrewed aerial vehicle controller (UAVC): used to control drone 202, such as controlling the drone's flight status or maneuvers. A drone controller can be a smartphone, tablet, laptop, smartwatch, smart remote control, traditional remote control, or dedicated remote controller. It can also be a wristband, finger ring, glove, armband, watch, or other device that can be used to control the drone using gestures. It can also be a headgear or other device that can be used to control the drone with thoughts. It can also be a smart jacket or coat that can be used to control the drone using body movements.
[0110] It should be understood that this document does not limit the specific type of drone controller. With the development of intelligent technology, the name and form of devices with drone controller functions may vary. For ease of description, in all embodiments of this application, the above-mentioned devices capable of drone controller functions or capable of controlling drones are collectively referred to as drone controllers.
[0111] The drone controller can control the flight status of the drone. For example, the drone controller can control the direction, ailerons, lift, tilt, speed, throttle, flaps, etc. of the drone. It can also control the drone's turning, climbing, diving, rolling, hovering, takeoff, landing and other actions. The embodiments of this application do not impose any restrictions on this.
[0112] 3. Uncrewed Aerial System (UAS): A general term for unmanned aerial vehicles (UAVs) and their associated communication stations, takeoff (launch) and recovery equipment, as well as transportation, storage, and detection equipment for UAVs. In this application, a UAS consists of one UAV and one UAVC. For example, a UAV controller can control one or more UAVs, a UAV can be controlled by one or more UAV controllers, and multiple UAV controllers can collaboratively control multiple UAVs. This is not limited to the embodiments of this application.
[0113] 4. UAS service supplier (USS): An entity that provides services to UAS operators or pilots to meet UAS operational requirements and support the safe and efficient use of airspace. A USS may provide any subset of functionality to meet the provider's business objectives. It should be noted that this nomenclature is for convenience only and does not constitute any limitation for this application. This application does not exclude the possibility of adopting other nomenclature in future standards.
[0114] 5. Uncrewed Aerial System Traffic Management (UTM): A set of functions and services for managing a range of automated device operations (e.g., drone authentication, drone service authorization, drone policy management, and airspace drone traffic control). It should be noted that this nomenclature is for convenience only and does not limit this application. This application does not exclude the possibility of adopting other nomenclatures in future standards.
[0115] In addition, the entities of USS and UTM may be one entity, may be in a containment relationship, or may be in a parallel relationship, which is not limited in this application.
[0116] 6. Third party authorized entity (TPAE): can identify and / or track UAVs and check whether there are illegal UAVs within a certain range.
[0117] In such Figure 3 In the architecture shown, PLMN-a and PLMN-b are PLMNs belonging to different operators, and UAV1 to UAV9 identify interfaces connecting various network elements or other components in the above architecture.
[0118] In addition to the network elements introduced above, this application also includes a UAV network function (UAV network function, UAV-NF) and a UAV flight enablement subsystem (UFES). UAV-NF or UFES provides a separate interface for USS or UTM, executes commands issued by USS or UTM, and is responsible for information transmission inside and outside the UAV system. It should be noted that this naming is only for the convenience of indicating its function and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in future standards. In addition, UAV-NF or UFES can be an existing network element or a new network element, and may also be deployed together with NEF or service capability exposure function (SCEF), or NEF can assume the functions that UAV-NF is responsible for. In addition, the entities of UAV-NF and UFES can be one entity, can be an inclusion relationship, or can be a parallel relationship, and this application does not limit this.
[0119] To facilitate understanding, before describing the embodiments of the present application, a brief introduction is first given to some network elements or terms involved in the present application.
[0120] The network slice-specific authentication and authorization function (NSSAAF) interacts with the AMF and AAA-S (or AAA-P). The interface between the NSSAAF and AMF is service-based, while the interface between the NSSAAF and AAA-S or AAA-P is AAA. Therefore, the NSSAAF is responsible for converting data between the service-based interface and the AAA protocol.
[0121] Authentication, Authorization, and Accounting Server (AAA-S): The primary purpose of an AAA-S server is to manage which users can access network servers, what services are available to authorized users, and how to bill users using network resources. An AAA-S server can be located either inside or outside the 3GPP network. Inside a 3GPP network, the AAA-S server is deployed by the operator. Outside a 3GPP network, the server is deployed by a third party (not the operator).
[0122] Authentication, authorization, accounting proxy (AAA-P): AAA-P is mainly used for message communication between NSSAAF and AAA-S outside the 3GPP network.
[0123] UAV network function (UAV-NF): UAV-NF leverages existing network open services for UUAA, drone pairing authentication authorization and related revocation processes, and drone position reporting.
[0124] Figure 3 FIG. 3 shows a schematic flow chart of a communication method 300 provided in an embodiment of the present application. Figure 3 As shown, the method 300 includes:
[0125] S310, the second network element sends a first request message to the first network element, where the first request message is used to request to perform a first operation on the first terminal device.
[0126] As a specific example, in a network slicing scenario, the second network element is, for example, an AAA-S, the first network element is, for example, an NSSAAF, the first terminal device is, for example, a user equipment UE, and the first operation is, for example, network slice re-authentication. That is, the AAA-S sends a first request message to the NSSAAF to request network slice re-authentication for the UE. The first operation includes network slice re-authentication or revocation of network slice authentication.
[0127] As another specific example, in a drone scenario, the second network element is, for example, a UTM, the first network element is, for example, a UAV-NF, and the first terminal device is, for example, a UAV. The first operation is, for example, revoking the drone's authentication authorization. Specifically, the UTM sends a first request message to the UAV-NF, requesting that the drone's authentication authorization be revoked for the UAV. This first operation includes revoking the authentication authorization or revoking the pairing authentication authorization.
[0128] It should be understood that the second network element requests the first network element to perform the first operation on the first terminal device through the first request message, which can be understood as: the second network element requests through the first request message to perform the first operation on all parameters related to the first request used by the first terminal device, or it can be understood as the second network element requests through the first request message to perform the first operation on the first terminal device using a certain parameter related to the first request. Exemplarily, in a network slicing scenario, the first control device is, for example, AAA-S, the first communication device is, for example, NSSAAF, the first terminal device is, for example, user equipment UE, the parameter corresponding to the UE is at least 1 S-NSSAI, and the first operation is, for example, network slice re-authentication. That is, AAA-S sends a first request message to NSSAAF to request network slicing and re-authentication of all S-NSSAIs of the UE, or AAA-S sends a first request message to NSSAAF to request network slicing and re-authentication of the network slice corresponding to a certain S-NSSAI of the UE.
[0129] Optionally, before S310, the first network element performs a second operation on the second network element, where the second operation is associated with the first operation. For example, in a network slicing scenario, the second operation is network slice authentication, and the first operation is network slice re-authentication; for another example, in a drone scenario, the second operation is authentication authorization, and the first operation is revocation of authentication authorization.
[0130] S320: The first network element determines whether the second network element has the authority to request to perform the first operation on the first terminal device.
[0131] It should be understood that the second network element authorized to request the first operation on the first terminal device can be understood as a network element with a correct or legal identity, or a network element whose identity information is associated with relevant service information, where "associated" means having a legal association. For example, satisfying a certain predefined association relationship can be understood as a legal association relationship. Optionally, the first request message includes a first identifier and a second identifier, which are used to verify whether the second network element has the authority to perform the first operation on the first terminal device. The first identifier is associated with the first terminal device, and the second identifier is associated with the second network element. It should be understood that the first identifier associated with the first terminal device can be an identifier used to identify the first terminal device. For example, in a drone scenario, the first identifier can be the UAV's 3GPP UAV ID. The first identifier can also be the service identifier of the first terminal device. For example, in a network slicing scenario, the first identifier is the single network slice selection assistance information (S-NSSAI). The second identifier associated with the second network element can be identification information of the second network element, such as the second network element's address information or identity information, or information associated with the second network element's service. This information should be difficult for an attacker to obtain.
[0132] As a specific example, in a network slicing scenario, the second identifier may include at least one of the following information: the identity identification number ID of the second network element, the Internet Protocol IP address of the second network element, and the fully qualified domain name FQDN of the second network element; the first identifier includes single network slice selection auxiliary information S-NSSAI.
[0133] As another specific example, in a drone scenario, the second identifier may include the identity number of the second network element and / or the Civil Aviation Administration-level drone identifier of the first terminal device; the first identifier includes the identity number of the first terminal device. Optionally, at S330, the first network element stores a mapping relationship between the third identifier and the first identifier, and the third identifier is associated with the third network element.
[0134] It should be understood that the mapping relationship may represent an authorization relationship, and the mapping relationship is used to indicate that the network element corresponding to the third identifier has the authority to perform the first operation on the first terminal device.
[0135] It should be understood that the third identifier has the same attributes as the second identifier, that is, the third identifier and the second identifier are identifiers of the same type. For example, if the third identifier and the second identifier are both IP addresses, then the third identifier is the IP address of the third network element, and the second identifier is the IP address of the second network element. There is a mapping relationship between the third identifier and the first identifier, that is, the third network element is associated with the first identifier, indicating that the third network element has the authority to perform the first operation on the first terminal device. The network element that has a mapping relationship with the terminal device has the authority to request the execution of the first operation on the terminal device. It can be understood that when there is a mapping relationship between the two identifiers, and the two identifiers respectively identify a terminal device and a network element, it means that the network element has the authority to request the execution of the first operation on the terminal device. Among them, identifying a terminal device can be understood as the identifier being the identifier of a terminal device, or the identifier of one or more parameters corresponding to the terminal device. For example, in a slicing scenario, the identifier of a terminal device refers to S-NSSAI, and the identifier of a network element refers to IP address, FQDN and other content. For example, in a drone scenario, the identifier of a terminal device refers to the 3GPP UAV ID, and the identifier of a network element refers to the UTM / USS ID or CAA-Level UAV ID.
[0136] It should be understood that the second network element and the third network element may be the same or different. For example, when the second network element is an attacker, the second network element is not a control device associated with the first identifier.
[0137] It should be understood that the first network element can be a system pre-configured mapping relationship between multiple identifiers associated with multiple control devices and multiple identifiers associated with multiple terminal devices, or it can be a mapping relationship between multiple identifiers associated with multiple control devices and multiple identifiers associated with multiple terminal devices determined based on other relevant identifiers within the system and then stored locally.
[0138] Exemplarily, after receiving the first request message, the first network element determines whether the second network element has the authority to perform the first operation on the first terminal device based on the first identifier, the second identifier and the mapping relationship.
[0139] Exemplarily, the first network element locally stores a mapping relationship between the third identifier and the first identifier. When the first network element receives the first request message and obtains the first identifier from the first request message, it determines the third identifier based on the first identifier and the mapping relationship. When the second identifier matches the third identifier, the first network element determines that the second network element has the authority to request the first operation to be performed on the first terminal device; otherwise, the first network element determines that the second network element does not have the authority to perform the first operation on the first terminal device.
[0140] It should be noted that the second identifier matches the third identifier, which means that the second identifier and the third identifier are the same, or an identifier that is the same as the second identifier can be determined based on the third identifier, or an identifier that is the same as the second identifier can be determined based on the third identifier. For example, the second identifier is the IP address #1 of the second network element, and the third identifier is the IP address #2 of the third network element. When IP address #1 is the same as IP address #2, it means that the second identifier and the third identifier match, otherwise it means that the second identifier and the third identifier do not match; for another example, the second identifier is the IP address #1 of the second network element, and the third identifier is the FQDN of the third network element. The first network element determines the IP address #2 of the third network element based on the FQDN. When IP address #1 is the same as IP address #2, it means that the second identifier and the third identifier match, otherwise it means that the second identifier and the third identifier do not match. For another example, the second identifier is the IP address #1 of the second network element, the third identifier is the FQDN of the third network element, and the first network element determines the FQDN#2 of the third network element based on the IP address #1. When FQDN#1 and FQDN#2 are the same, it means that the second identifier and the third identifier match, otherwise it means that the second identifier and the third identifier do not match.
[0141] When the first network element determines that the second network element has the authority to request to perform the first operation on the first terminal device, the first network element performs the first operation on the first terminal device according to the first request message; when the first network element determines that the second network element does not have the authority to request to perform the first operation on the first terminal device, the first network element terminates the first operation process, for example, the first network element ignores or discards the first request message, or the first network element sends a response message to the second network element, and the response message is used to reject the first request message.
[0142] Optionally, the first network element establishes a secure connection with the second network element.
[0143] Establishing a secure link may include, when the network is being set up, establishing a secure connection between the first communication device and the second control device according to device pre-configuration or manual triggering, or establishing a secure connection when the first communication device establishes communication with the second control device for the first time. It may also be a secure connection established when the first network element and the second network element communicate with the opposite end again. The difference is that when the first network element and the second network element establish a secure connection for the first time, it is a connection establishment process initiated by the first network element. For example, in the NSSAA process, the first network element initiates a secure connection establishment process with the second network element. The process of establishing a secure connection again may be initiated by the second network element. For example, in the network slice re-authentication process, the second network element initiates a secure connection establishment process with the first network element.
[0144] Exemplarily, the first network element obtains security certificate information of the second network element, and establishes an Internet Protocol security IPsec tunnel with the second network element according to the security certificate information.
[0145] The first network element saves the fourth identifier during the process of establishing the secure connection or after the secure connection is established. The fourth identifier is associated with the second network element and the secure connection.
[0146] It should be understood that the fourth identifier is associated with the second network element and the secure connection, so the fourth identifier can be considered to be a real, untampered identifier associated with the second network element.
[0147] The first network element receives the first request message from the second network element via the secure connection and obtains the second identifier from the first request message. When the first network element determines that the second identifier and the fourth identifier are the same, the first network element continues to execute the process of S320; when the first network element determines that the second identifier and the fourth identifier are different, the first network element terminates the process, for example, the first network element ignores or discards the first request message, or the first network element sends a rejection message to the second network element.
[0148] The first network element receives a first request message from the second network element through the secure connection and obtains a first identifier from the first request message. When the first network element determines that the third identifier is associated with the first identifier, or the mapping relationship corresponding to the third identifier is the same as the fourth identifier, the first network element continues to execute the process of S320; when the first network element determines that the third identifier and the fourth identifier are different, the first network element terminates the process, for example, the first network element ignores or discards the first request message, or the first network element sends a response message to the second network element, where the response message is used to reject the first request message.
[0149] Therefore, the communication method of the embodiment of the present application verifies whether the network element sending the request message has the authority to make the request to determine whether the network element is a malicious attacker, thereby reducing the situation where system services are affected by the attacker's request and improving the security of the system.
[0150] After the network device completes slice authentication for the terminal device, the AAA-S may initiate a re-authentication process or an authentication revocation process for certain reasons. However, when a AAA-S is a malicious attacker, or the third-party network where the AAA-S is located is compromised, the attacker can maliciously forge the S-NSSAI and GPSI and initiate a deauthentication or re-authentication operation to the AMF. For example, the attacker arbitrarily generates an S-NSSAI based on the GPSI corresponding to the S-NSSAI stored in this network. If the arbitrarily generated S-NSSAI and GPSI happen to be paired, then the network slice used by the terminal device corresponding to the arbitrarily generated S-NSSAI will either be repeatedly re-authenticated or revoked for no reason, resulting in a reduced user experience for the terminal device or the inability to use a certain network slice. Therefore, how to identify whether a AAA-S is a malicious attacker is an urgent problem that needs to be solved.
[0151] Figure 4 A schematic flowchart of a communication method 400 in a network slicing scenario provided by an embodiment of the present application is shown.
[0152] It should be understood that before method 400, the network side completes the slice authentication process.
[0153] Exemplarily, the AMF initiates a network slice-specific authentication and authorization (NSSAA) process, for example, the AMF initiates the NSSAA process based on a change in subscription data or a triggering of the first AAA-S.
[0154] After AMF obtains single network slice selection assistance information (S-NSSAI) from the terminal device, it sends an authentication request message to NSSAAF. The authentication request message includes an extensible authentication protocol identity document (EAPID), a generic public subscription identifier (GPSI) and S-NSSAI.
[0155] It should be noted that if there are multiple GPSIs in the subscription data of the terminal device, the AMF selects one GPSI from the multiple GPSIs at random, and then sends the selected GPSI, EAP ID, and S-NSSAI to the NSSAAF through an authentication request message.
[0156] NSSAAF determines the first AAA-S based on the address of the locally deployed first AAA-S and the association relationship between S-NSSAI (local configuration of AAA-S address per S-NSSAI), and uses the AAA protocol to send an authentication request message to the first AAA-S. It should be noted that if the first AAA-S is outside the 3GPP network, the NSSAAF needs to communicate with the first AAA-S through AAA-P. That is, the NSSAAF first sends the authentication request message to AAA-P, and then AAA-P sends the message to AAA-P. Similarly, if the first AAA-S outside the 3GPP network wants to send a message to the NSSAAF, it also needs to be transferred through AAA-P. For the sake of brevity, similar processes in subsequent solutions will not be repeated in this application.
[0157] The network side completes the slice authentication process based on the above information.
[0158] It should be noted that the NSSAAF is locally pre-configured with an association between the address information #1 of the first AAA-S and the S-NSSAI. The address information #1 can be understood as information that can be used to find the AAA-S. Exemplarily, the address information of the first AAA-S is the IP address of the first AAA-S, so the NSSAAF can directly send a message to the first AAA-S. Exemplarily, the address information of the first AAA-S can be, for example, a fully qualified domain name (FQDN). The FQDN is an index. The index can, for example, indicate "AAA-S of the first network". Therefore, the NSSAAF can obtain the IP address of the first AAA-S through the FQDN, and then send a message to the first AAA-S. Exemplarily, the address information of the first AAA-S is the data network name (DN) of the application where the first AAA-S is located, such as "goolge" or "baidu". The NSSAAF may use the data network name to obtain the IP address of the first AAA-S from a domain name server (DNS), or the IP address of the gateway on the network side where the first AAA-S is located, and thus find the first AAA-S.
[0159] The identity information #1 of the first AAA-S is used to uniquely identify the first AAA-S. For example, the identity information #1 of the first AAA-S is the Internet Protocol (IP) address of the AAA-S, or the globally unique identity document (ID) of the first AAA-S, or the identity information carried in the certificate.
[0160] In summary, the address information #1 of the first AAA-S can be the same as or different from the identity information #1 of the first AAA-S. It can be understood that if the address information #1 of the first AAA-S can be the same as the identity information #1 of the first AAA-S, then the address information #1 of the first AAA-S can directly reflect the identity of the first AAA-S. If the address information of the first AAA-S can be different from the identity information of the first AAA-S, then the address information #1 of the first AAA-S cannot directly reflect the identity of the first AAA-S. In this case, the address information #1 of the first AAA-S can be used to obtain the identity information #1 of the first AAA-S.
[0161] When the address information #1 of the first AAA-S cannot directly reflect the identity of the first AAA-S, the NSSAAF can determine the identity information #1 of the first AAA-S based on the address information #1 of the first AAA-S, and optionally save the association between the identity information #1 of the first AAA-S and the S-NSSAI. For example, when the address information of the first AAA-S is an FQDN, the FQDN is not the identity information of the first AAA-S (such as an IP address), the NSSAAF can determine the identity information #1 of the first AAA-S based on the FQDN, and optionally save the association between the identity information #1 of the first AAA-S and the S-NSSAI.
[0162] Optionally, the NSSAAF obtains timestamp information, which is bound to the identity information #1 of the first AAA-S. The timestamp is used to indicate the validity period of the identity information of the first AAA-S. For example, the identity information #1 of the first AAA-S is the IP address of the first AAA-S, and the IP address will be updated after the validity period. In this case, the NSSAAF can determine the validity period of the IP address based on the timestamp information. When the validity period expires, the NSSAAF deletes the identity information #1 of the first AAA-S.
[0163] like Figure 4 As shown, the method 400 includes:
[0164] S410: The second AAA-S sends a first request message, which is used to request network slice re-authentication or revocation of network slice authentication for a terminal device (not shown in the figure). The first request message includes the GPSI and S-NSSAI of the terminal device. Optionally, the first request message also includes the identity information #2 of the second AAA-S or the address information #2 of the second AAA-S. Correspondingly, the NSSAAF receives the first request message from the second AAA-S.
[0165] It should be noted that the second AAA-S may be the same as or different from the first AAA-S in the slice authentication process. For example, if the second AAA-S is a malicious attacker, the second AAA-S is not the same as the first AAA-S.
[0166] S420: The NSSAAF determines whether the identity of the second AAA-S is correct. This means the NSSAAF determines whether the second AAA-S is associated with the S-NSSAI. If so, the second AAA-S can legally initiate the slice authentication process associated with the S-NSSAI. If not, the second AAA-S is not the actual controller of the S-NSSAI, meaning it can be considered malicious and controlled by an attacker.
[0167] Exemplarily, the NSSAAF obtains information used to identify the AAA-S identity, such as AAA-S identity information #2 or AAA-S address information #2, based on the first request message, and then verifies whether the association relationship between the identity information used to identify the AAA-S and the S-NSSAI is correct. If the identity of the AAA-S is correct, it means that the AAA-S has the authority to request network slice re-authentication or revocation of network slice authentication for the NSSAI.
[0168] As an example, the NSSAAF pre-configures the association between the address information #1 of the first AAA-S and the S-NSSAI. In S410, the first request message sent by the AAA-S carries the GPSI, S-NSSAI, and the address information #2 of the second AAA-S. It should be noted that the address information #1 is the address information stored in the NSSAAF pre-configuration information, so it can be considered that the address information #1 is the address information of the real AAA-S; the address information #2 is the address information of the second AAA-S requesting re-authentication or deauthentication, and the second AAA-S may be disguised by an attacker. The NSSAAF receives the first request message and obtains address information #2 from the first request message. It then obtains address information #1 associated with the S-NSSAI from the local storage based on the S-NSSAI carried in the first request message, and compares the address information #1 with the address information #2. If the address information #2 is the same as the address information #1, the NSSAAF determines that the identity of the second AAA-S is correct, that is, the second AAA-S can be associated with the S-NSSAI; otherwise, the NSSAAF determines that the identity of the second AAA-S is incorrect, that is, the second AAA-S cannot be associated with the S-NSSAI. It should be noted that it is assumed here that the attacker can control the second AAA-S but cannot control the address information #2 of the second AAA-S. Therefore, it can be considered that the address information #2 is the real address information of the second AAA-S requesting re-authentication or deauthentication.
[0169] As another example, during the slice authentication process or after the slice authentication process succeeds, the NSSAAF determines the identity information #1 of the first AAA-S based on the address information #1 of the locally pre-configured first AAA-S. For example, the NSSAAF obtains the identity information #1 based on the address information #1 of the first AAA-S. Specifically, for example, the NSSAAF requests the identity information #1 of the first AAA-S from the network management system or the DNS server based on the address information #1 of the first AAA-S. After the NSSAAF obtains the identity information #1, it saves the association between the identity information #1 of the first AAA-S and the S-NSSAI. The first request message sent by the second AAA-S in S410 carries the GPSI, S-NSSAI and the address information #2 of the second AAA-S. The NSSAAF receives the first request message and obtains the address information #2 from the first request message. Then, the NSSAAF determines the identity information #2 corresponding to the address information #2 based on the address information #2. The identity information #2 is the identity information of the second AAA-S that sends the first request message. NSSAAF obtains the identity information #1 associated with the S-NSSAI based on the S-NSSAI in the first request message, and compares the identity information #1 with the identity information #2. If the identity information #1 is the same as the identity information #2, the NSSAAF determines that the identity of the second AAA-S is correct, that is, the second AAA-S can be associated with the S-NSSAI; otherwise, the NSSAAF determines that the identity of the second AAA-S is incorrect, that is, the second AAA-S cannot be associated with the S-NSSAI. The method of this embodiment is applicable to a method in which the address information #1 stored by the NSSAAF is different from the address information #2 stored by the AAA-S, but the two address information can obtain the same identity information. For example, the address information #1 stored by the NSSAAF is stored in the form of FQDN, and the address information #2 sent by the second AAA-S is sent in the form of DN, but the same IP address can be obtained through both the FQDN and the DN.
[0170] As another example, NSSAAF pre-configures the association relationship between the address information #1 of the first AAA-S and the S-NSSAI. The first request message sent by the second AAA-S in S410 carries GPSI, S-NSSAI and identity information #2 of the second AAA-S. NSSAAF receives the first request message and obtains identity information #2. Based on the S-NSSAI in the first request message, NSSAAF obtains the address information #1 corresponding to the S-NSSAI in the local storage, and obtains the identity information #1 corresponding to the address information #1 based on the address information #1. NSSAAF compares the identity information #1 with the identity information #2. If the identity information #1 is the same as the identity information #2, the NSSAAF determines that the identity of the second AAA-S is correct, that is, the second AAA-S can be associated with the S-NSSAI; otherwise, the NSSAAF determines that the identity of the second AAA-S is incorrect, that is, the second AAA-S cannot be associated with the S-NSSAI.
[0171] As another example, during the slice authentication process or after the slice authentication process succeeds, the NSSAAF determines the identity information #1 of the AAA-S based on the address information #1 of the locally pre-configured first AAA-S, and saves the association between the identity information #1 of the first AAA-S and the S-NSSAI after the slice authentication process succeeds. The first request message sent by the second AAA-S in S410 carries the GPSI, S-NSSAI and the identity information #2 of the AAA-S. The NSSAAF receives the first request message and obtains the identity information #2. Based on the S-NSSAI in the first request message, the NSSAAF obtains the identity information #1 corresponding to the S-NSSAI from the local storage. The NSSAAF compares the identity information #1 with the identity information #2. If the identity information #1 is the same as the identity information #2, the NSSAAF determines that the identity of the second AAA-S is correct, that is, the second AAA-S can be associated with the S-NSSAI; otherwise, the NSSAAF determines that the identity of the second AAA-S is incorrect, that is, the second AAA-S cannot be associated with the S-NSSAI.
[0172] As another example, the first request message sent by the second AAA-S in S410 carries the GPSI and S-NSSAI. After receiving the first request message, the NSSAAF determines address information #2 or identity information #2 of the second AAA-S based on the first request message. For example, the NSSAAF obtains the source IP address in the first request message and determines the source IP address as identity information #2. The NSSAAF receives the first request message and, based on the S-NSSAI in the first request message, retrieves address information #1 corresponding to the S-NSSAI from local storage. The NSSAAF compares the address information #1 with the address information #2, or the NSAAF obtains the identity information #1 based on the address information #1 and compares it with the identity information #2. If the address information #1 is the same as the address information #2, or the identity information #1 is the same as the identity information #2, the NSSAAF determines that the identity of the second AAA-S is correct, that is, the second AAA-S can be associated with the S-NSSAI; otherwise, the NSSAAF determines that the identity of the second AAA-S is incorrect, that is, the second AAA-S cannot be associated with the S-NSSAI.
[0173] Optionally, at S430, if the NSSAAF determines that the identity of the second AAA-S is incorrect, the NSSAAF terminates the re-authentication process / authentication revocation process. Optionally, further, the NSSAAF initiates an alarm and records it in a log. For example, if the NSSAAF determines that the identity of the second AAA-S is incorrect, the NSSAAF directly discards the first request message; for another example, if the NSSAAF determines that the identity of the second AAA-S is incorrect, the NSSAAF sends a first response message to the second AAA-S, the first response message including the GPSI and S-NSSAI, and the first response message is used to indicate a re-authentication failure / authentication revocation failure.
[0174] If the NSSAAF determines that the identity of the second AAA-S is correct, the NSSAAF continues to perform the re-authentication process or the deauthentication process. For example, at S440, the NSSAAF requests the UDM to query the AMF ID, determines the AMF corresponding to the terminal device based on the AMF ID, and sends a second request message to the AMF, requesting re-authentication / deauthentication. The AMF performs re-authentication / deauthentication based on the first request message.
[0175] Therefore, in the communication method provided in the embodiment of the present application, the first request message sent by AAA-S to NSSAAF carries the address information and / or identity information of AAA-S, and the address information and / or identity information of the AAA-S is verified to determine whether the identity of the AAA-S is correct, thereby reducing the situation where the terminal device and the network slice are repeatedly re-authenticated or revoked due to the attacker's request.
[0176] Figure 5 A schematic flow chart of a communication method 500 in a network slicing scenario provided in an embodiment of the present application is shown. In the method 500, the AAA-S is outside the 3GPP network, and the AAA-S communicates with the NSSAAF through the AAA-P.
[0177] It should be understood that before method 500, the network side and the first AAA-S complete the slice authentication process, which is similar to the slice authentication process before method 400. For the sake of brevity, it will not be repeated.
[0178] like Figure 5 As shown, the method 500 includes:
[0179] Optionally, in S510, the AAA-P saves the mapping relationship between the identity information #1 of the first AAA-S and the S-NSSAI.
[0180] Exemplarily, during the slice authentication process, or after the slice authentication process, AAA-P saves the mapping relationship between the identity information #1 of the first AAA-S and the S-NSSAI. The identity information #1 can be, for example, the first AAA-S ID or the first AAA-S IP.
[0181] S520: The second AAA-S sends a first request message, which is used to request network slice re-authentication or revocation of network slice authentication for the terminal device. The request message includes the GPSI and the S-NSSAI of the terminal device. Optionally, the first request message also includes the identity information #2 of the second AAA-S or the address information #2 of the second AAA-S. Correspondingly, the AAA-P receives the first request message from the second AAA-S.
[0182] It should be understood that when AAA-P does not execute S510, that is, AAA-P does not save the mapping relationship between the identity information #1 of the first AAA-S and the S-NSSAI before S520, then optionally, in S530, AAA-P sends a second request message to NSSAAF, where the second request message includes the S-NSSAI, and the second request message is used to request the address information #1 or identity information #1 of the first AAA-S.
[0183] S540: NSSAAF sends a second response message to AAA-P.
[0184] Exemplarily, the NSSAAF receives the second request message sent by the AAA-P and obtains the S-NSSAI carried in the second request message. The NSSAAF determines, based on the S-NSSAI, the identity information #1 or address information #1 corresponding to the S-NSSAI. The NSSAAF then sends a second response message to the AAA-P, where the second response message includes the identity information #1 or address information #1, and the identity information #1 and address information #1 are associated with the S-NSSAI.
[0185] As an example, in S520, the first request message sent by the second AAA-S includes the GPSI, S-NSSAI, and address information #2. After receiving the first request message, the AAA-P sends a second request message to the NSSAAF. The second request message includes the S-NSSAI. The NSSAAF determines, from local storage, address information #1 associated with the S-NSSA based on the S-NSSAI. The NSSAAF then sends a second response message to the AAA-P. The second response message includes address information #1, which is associated with the S-NSSAI.
[0186] As another example, in S520, the first request message sent by the second AAA-S includes GPSI, S-NSSAI and identity information #2. After receiving the first request message, AAA-P sends a second request message to NSSAAF, and the second request message includes S-NSSAI. NSSAAF determines the identity information #1 associated with the S-NSSAI based on the S-NSSAI. Then NSSAAF sends a second response message to AAA-P, and the second response message includes identity information #1, and the identity information #1 is associated with S-NSSAI. It should be noted that NSSAAF can locally save the mapping relationship between S-NSSAI and the identity information #1 of the first AAA-S during the slice authentication process or after the slice authentication process is completed, or after receiving the second request message, first determine the address information #1 of the first AAA-S based on S-NSSAI, and then determine the identity information #1 based on the address information #1. This application does not limit this.
[0187] S550: The AAA-P determines whether the identity of the second AAA-S is correct.
[0188] It should be understood that S560 in method 500 is similar to S420 in method 400 and will not be described in detail in this application for the sake of brevity.
[0189] Optionally, at S560 , if the AAA-P determines that the identity of the second AAA-S is incorrect, the AAA-P terminates the re-authentication process / authentication revocation process.
[0190] It should be understood that S560 in method 500 is similar to S430 in method 400 and will not be described in detail in this application for the sake of brevity.
[0191] If the AAA-P determines that the identity of the second AAA-S is correct, the AAA-P continues to perform the re-authentication process or the authentication revocation process. For example, at S570, the AAA-P forwards a first request message to the NSSAAF, requesting re-authentication or authentication revocation. The first request message includes the GPSI and S-NSSAI of the terminal device.
[0192] It should be understood that S580-S590 in method 500 are similar to S440-S450 in method 400, and for the sake of brevity, this application will not elaborate on them.
[0193] Therefore, in the communication method provided in the embodiment of the present application, the first request message sent by AAA-S to AAA-P carries the address information and / or identity information of AAA-S, and verifies the address information and / or identity information of the AAA-S to determine whether the identity of the AAA-S is correct, thereby reducing the situation where the terminal device and the network slice are repeatedly re-authenticated or revoked due to the attacker's request.
[0194] Some attackers may also forge the address or identity information of a legitimate AAA-S. For example, in methods 400 and 500, the attacker's forged address information #2 is associated with the GPSI and S-NSSAI, and address information #2 is the same as address information #1. Alternatively, the attacker's forged identity information #2 is associated with the GPSI and S-NSSAI, and identity information #2 is the same as address information #1. In this case, the NSSAAF or AAA-P may believe that the attacker's identity is legitimate. Therefore, preventing attackers from circumventing detection by forging AAA-S address information or identity information is a technical issue that needs to be addressed.
[0195] Figure 6 A schematic flowchart of a communication method 600 in a network slicing scenario provided by an embodiment of the present application is shown.
[0196] It should be understood that before method 600, the network side and the first AAA-S complete the slice authentication process, which is similar to the slice authentication process before method 400. For the sake of brevity, it will not be repeated.
[0197] like Figure 6 As shown, the method 600 includes:
[0198] S610: Establish a security connection between the NSSAAF and the second AAA-S.
[0199] As an example, the NSSAAF obtains a security certificate of a second AAA-S, which carries the identity information #2 of the second AAA-S. The NSSAAF establishes an Internet Protocol Security (IPsec) tunnel with the second AAA-S based on the security certificate of the second AAA-S, where the IPsec tunnel is authenticated using the security certificate.
[0200] As another example, an application layer connection such as transport layer security (TLS) / datagram transport layer security (DTLS) is established between the NSSAAF and the second AAA-S.
[0201] This application does not limit the method for establishing a secure connection.
[0202] It should also be noted that establishing a secure connection may include, when the network is being built, establishing a secure connection between the NSSAAF and the second AAA-S based on device pre-configuration or manual triggering, or establishing a secure connection when the NSSAAF and the second AAA-S communicate with the other end for the first time. It may also be a secure connection established when the first network element and the second network element communicate with the other end again. The difference is that when the first network element and the second network element establish a secure connection for the first time, it is a connection establishment process initiated by the first network element. For example, in the NSSAA process, the first network element initiates a secure connection establishment process with the second network element. The process of establishing a secure connection again may be initiated by the second network element. For example, in the network slice re-authentication process, the second network element initiates a secure connection establishment process with the first network element.
[0203] It should also be noted that after the secure connection between the NSSAAF and the second AAA-S is established, messages transmitted between the NSSAAF and the second AAA-S are integrity protected. This means that data is transmitted using the negotiated key between the NSSAAF and the AAA-S, effectively preventing attackers from spoofing their identities. The AAA-S security certificate cannot be forged or tampered with, and therefore the identity information contained in the security certificate cannot be forged or tampered with either. In other words, the identity information #2 contained in the second AAA-S security certificate is the true identity information of the second AAA-S.
[0204] Optionally, NSSAAF obtains the identity information #2 of the second AAA-S and the identification information of the security connection during the process of establishing a security connection with the second AAA-S. After NSSAAF successfully establishes a security connection with the second AAA-S, it saves the association between the security connection identification and identity information #2. After receiving the first request message sent by the second AAA-S through the security connection, NSSAAF obtains the S-NSSAI in the first request message. NSSAAF also obtains identity information #2 based on the identification of the security connection. NSSAAF determines identity information #1 based on S-NSSAI. The specific method is similar to method 400-method 600 and will not be repeated here. NSSAAF compares identity information #1 with identity information #2. If identity information #1 is the same as identity information #2, NSSAAF determines that the identity of the second AAA-S is correct; otherwise, NSSAAF determines that the identity of the second AAA-S is incorrect.
[0205] S620, the second AAA-S sends a first request message to the NSSAAF, where the first request message is used to request network slice re-authentication or revocation of network slice authentication for the terminal device (not shown in the figure). The first request message includes GPSI and S-NSSAI.
[0206] S630: The NSSAAF determines whether the identity of the second AAA-S is correct.
[0207] As an example, the NSSAAF obtains the security certificate of the second AAA-S at S610 and obtains the identity information #2 of the second AAA-S from the security certificate. The NSSAAF receives the first request message and obtains the S-NSSAI from the first request message. The NSSAAF determines the address information #1 of the first AAA-S associated with the S-NSSAI in the local pre-configured information based on the S-NSSAI, and determines the identity information #1 of the AAA-S based on the address information #1. The NSSAAF compares the address information #1 with the address information #2. If the address information #2 is the same as the address information #1, the NSSAAF determines that the identity of the second AAA-S is correct; otherwise, the NSSAAF determines that the identity of the second AAA-S is incorrect.
[0208] As another example, the method for verifying the identity of the second AAA-S in method 400 is used to determine whether the identity of the second AAA-S is correct. For example, the first request message in S620 also carries address information #2 of the second AAA-S. The NSSAAF determines address information #1 of the first AAA-S associated with the S-NSSAI based on the S-NSSAI in the first request message, and then compares address information #1 with address information #2. If address information #2 is the same as address information #1, the NSSAAF determines that the identity of the second AAA-S is correct; otherwise, the NSSAAF determines that the identity of the second AAA-S is incorrect.
[0209] It should be understood that other exemplary methods for determining whether the identity of the second AAA-S is correct provided in method 400 are also applicable to method 600 and are not described in detail.
[0210] S640 to S660 in method 600 are similar to S430 to S450 in method 400 and are not described again here.
[0211] It should be noted that step S630 in method 600 can also be performed by AAA-P. In this case, at S610, a secure connection is established between AAA-P and the second AAA-S. Similarly, AAA-P receives a first request message from the second AAA-S. The first request message is used to request network slice re-authentication or revocation of network slice authentication for a terminal device (not shown in the figure). The first request message includes GPSI and S-NSSAI. Then AAA-P determines whether the identity of the second AAA-S is correct. The specific process is similar to the process of NSSAAF determining whether the identity of the second AAA-S is correct in S630, and this application will not repeat it here.
[0212] It should be understood that the verification method provided in method 500 may also be combined with method 600. In this case, the judgment operation is performed by AAA-P. The specific verification method can be found in S520 to S550 of method 500 and will not be described again.
[0213] Therefore, the communication method provided in the embodiment of the present application establishes a secure connection between the NSSAAF and the AAA-S, so that the communication between the NSSAAF and the AAA-S can be securely protected, thereby making it difficult for an attacker to request re-authentication or revocation of authentication by impersonating the address information or identity information of the real AAA-S.
[0214] Figure 7 FIG2 shows a schematic flow chart of a communication method 700 in a network slicing scenario provided by an embodiment of the present application. Figure 7 As shown, the method 700 includes:
[0215] S710, the network side completes the slice authentication process.
[0216] It should be understood that S710 is similar to S410 in method 400 and will not be described again for the sake of brevity.
[0217] In the slice authentication process, at S711, the AMF assigns a different GPSI to each S-NSSAI.
[0218] As an example, during the slice authentication process, AMF temporarily allocates a GPSI in the external identifier format to the terminal device when initiating slice authentication. The GPSI is different for each terminal device, each slice, and each access.
[0219] It should be noted that the GPSI in the external identifier format is assigned by the operator. It is an identifier associated with the international mobile subscriber identity (IMSI) of the terminal device, and there may be one or more. The external identifier is in the format of username@realm, where the username must contain a local identifier and the realm part must have a domain name. For example, in the slice authentication process, the domain name can be the address information of AAA-S or the data network name (DNN) information.
[0220] As another example, UDM generates a GPSI based on the number of S-NSSAIs accessed by the terminal device, where the number of generated GPSIs is greater than or equal to the number of S-NSSAIs. In the slice authentication process, UDM sends all generated GPSIs and subscription information to AMF. When AMF determines the S-NSSAI for slice authentication based on the subscription data, it can obtain the GPSI to be used from the GPSI sent by UDM. Since the number of GPSIs is greater than or equal to the number of S-NSSAIs, the GPSIs corresponding to different S-NSSAIs are different.
[0221] Steps S720 - S740 are similar to steps S630 - S650 in method 600 and will not be described in detail in this application for the sake of brevity.
[0222] It should be understood that method 700 may be implemented alone or in combination with other methods, for example, in combination with method 400 , method 500 , or method 600 .
[0223] As an example, after the AMF assigns a different GPSI to each S-NSSAI, it verifies whether the address information #2 or identity information #2 of the AAA-S is correct according to any method from method 400 to method 600. If correct, the AMF verifies again whether the GPSI is correct when receiving the S-NSSAI and GPSI. If correct, the process continues; otherwise, the process is terminated.
[0224] As another example, during or after the slice authentication process, the NSSAAF stores the association between GPSI, S-NSSAI, and AAA-S address information. The NSSAAF obtains GPSI#2 from the first request message and, based on the S-NSSAI, retrieves GPSI#1 corresponding to the S-NSSAI from local storage. The NSSAAF compares GPSI#1 with GPSI#2. If GPSI#1 and GPSI#2 are different, the NSSAAF terminates the process. If GPSI#1 and GPSI#2 are the same, the NSSAAF verifies whether AAA-S address information #2 is correct according to any of methods 400 to 600. If so, the process continues; otherwise, the process terminates.
[0225] Therefore, the communication method provided in the embodiment of the present application greatly increases the difficulty of attackers in disguising themselves by allocating a different GPSI to each terminal device for each slice and each access. That is, the probability that the S-NSSAI and GPSI randomly generated by the attacker can be paired and used is greatly reduced, thereby improving the security of the system.
[0226] UAVs can perform the USS UAV authorization / authentication (UUAA) process with the UTM / USS through the 3GPP system. The UUAA process is used for mutual authentication and authorization between the UTM / USS and the UAV. This authentication and authorization is used to determine whether the UAV can send UAV-related business data (such as flight control, video return, drone identification, and other business data) to the UTM / USS. This authentication and authorization is also used to determine whether the UTM / USS has the authority to control the UAV flight. Based on the results of the UUAA, the 3GPP network needs to determine whether it can provide UAV-related business communication services to the UAV, including the UAV sending UAV business data to the UTM / USS via the 3GPP network and the UTM / USS controlling the UAV flight via the 3GPP network. After the UUAA process, if the USS / UTM decides that a UAV no longer needs to perform UAV services, for example, when the UAV flight certificate expires or the USS / UTM detects that the UAV is a malicious user, the USS / UTM can revoke the UAV that has completed UAV authentication and authorization to prevent the UAV from continuing to use UAV services; or after the pairing authentication and authorization process, the USS / UTM can revoke the UAV that has completed UAV pairing authentication and authorization. For the sake of convenience, the subsequent embodiments of this application use the example of USS / UTM revoking a UAV that has completed UAV authentication and authorization as an example. The revocation process for a UAV that has completed UAV pairing authentication and authorization is similar and will not be repeated. For a UAV connected to a UTM / USS via 3GPP and having completed UUAA with the UTM / USS through the 3GPP network, the UTM / USS must use the 3GPP UAV ID to trigger the 3GPP network to execute the UUAA revocation process for the UAV corresponding to the 3GPP UAV ID. For example, the 3GPP UAV ID can be the GPSI assigned to the UAV by the 3GPP network. However, a malicious UTM / USS can obtain the 3GPP UAV ID assigned by the 3GPP network from other sources, such as through eavesdropping. This malicious UTM / USS is unauthorized. A malicious UTM / USS can impersonate the UTM / USS serving the UAV and revoke the UUAA simply by sending the UAV's 3GPP UAV ID. This can lead to the unwarranted revocation of the UAV's authentication authorization, impacting the use of related services. Therefore, identifying whether a UTM / USS is a malicious attacker is a pressing issue.
[0227] Figure 8 A schematic flowchart of a communication method 800 in a drone scenario provided by an embodiment of the present application is shown.
[0228] It should be understood that prior to method 800, the UAV registers with the first UTM / USS.
[0229] For example, a UAV (not shown) registers with the UTM / USS and obtains a civil aviation authority level UAV ID (CAA-Level UAV ID) during the registration process. The CAA-Level UAV ID is an external identifier of the 3GPP network and is issued by the Civil Aviation Administration to uniquely identify a UAV.
[0230] It should also be understood that before method 800, the UAV performs a drone authentication and authorization process / drone pairing authentication and authorization process with the first UTM / USS.
[0231] Before accessing the UAS service through the 3GPP network, the UAV requests authentication and authorization to use the UAS service from the first USS / UTM, i.e., performs the UUAA process. The UUAA process can be triggered by the AMF or SMF.
[0232] As an example, the UAV carries the CAA-Level UAV ID in the registration process, and the access and mobility management function (AMF) determines that UUAA is required based on the CAA-Level UAV ID, the UAV's contract information in the unified data management function (UDM), and the operator's local configuration. In the UUAA process, the AMF generates a 3GPP UAV ID for the UAV, which can be used to identify the UAV within and / or outside the 3GPP network and can be a GPSI.
[0233] As another example, the UAV carries the CAA-Level UAV ID in the protocol data unit (PDU) session establishment process. The session management function (SMF) determines that UUAA is required based on the CAA-Level UAV ID, the UAV's subscription information in the UDM, and the operator's local configuration. In the UUAA process, the SMF generates a 3GPP UAV ID for the UAV. The 3GPP UAV ID can be used to identify the UAV within and / or outside the 3GPP network and can be a GPSI.
[0234] In the UUAA process, AMF or SMF sends a UUAA request message to the UAV-NF. The request message includes the 3GPP UAV ID and CAA-Level UAV ID.
[0235] The UAV-NF determines the address information of the UTM / USS according to the CAA-Level UAV ID. For example, the UAV-NF determines the UTM / USS ID according to the CAA-Level UAV ID, and then determines the UTM / USS address according to the UTM / USS ID.
[0236] If the UAV obtains the address information of the UTM / USS in S810, the UUAA request message may include the address information of the UTM / USS. At this time, the UAV-NF no longer needs to determine the address information of the UTM / USS based on the CAA-Level UAV ID, but instead obtains the UTM / USS address information from the UUAA request message.
[0237] After the drone authentication and authorization process is completed and the UAV and UTM / USS successfully authenticate and authorize each other, the UTM / USS sends a UUAA reply message to the UAV-NFAMF or SMF. The UUAA reply is used to indicate that the result of the 3GPP network UUAA is UUAA success. The UAV-NF sends a UUAA reply message to the AMF or SMF. The UUAA reply is used to indicate that the result of the UUAA is UUAA success. Figure 8 As shown, method 800 includes:
[0238] S830: The UAV-NF saves the mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID#1 and / or the UTM / USS ID#1.
[0239] Illustratively, during or after the drone registration process / drone authentication and authorization process, the UAV-NF saves the mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID#1; or, the UAV-NF saves the mapping relationship between the 3GPP UAV ID and the UTM / USS ID#1, where the UTM / USS ID#1 is the identity of the first UTM / USS; or, the UAV-NF saves the mapping relationship between the 3GPP UAV ID, the CAA-Level UAV ID#1, and the UTM / USS ID#1.
[0240] It should be understood that the first UTM / USS also stores the mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID and / or UTM / USS ID.
[0241] Exemplarily, during or after the drone registration process and the drone authentication and authorization process, the first UTM / USS saves the mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID#1; or, the first UTM / USS saves the mapping relationship between the 3GPP UAV ID and the UTM / USS ID#1; or, the first UTM / USS saves the mapping relationship between the 3GPP UAV ID, CAA-Level UAV ID#1 and UTM / USS ID#1.
[0242] It should be noted that the UTM / USS ID#1 is the information stored in the UAV-NF pre-configuration information or the information determined according to the pre-configuration information, and the CAA-Level UAV ID#1 can be the information stored in the UAV-NF configuration information. Therefore, the CAA-Level UAV ID#1 and UTM / USS ID#1 can be considered as the internal identification of the real UTM / USS and the identification of the real UTM / USS.
[0243] S820, the second UTM / USS sends a third request message to the UAV-NF, where the third request message includes 3GPP UAVID, CAA-Level UAV ID#2 and / or UTM / USS ID#2, where UTM / USS ID#2 is the identity of the second UTM / USS. The third request message is used to request the revocation of the drone authentication authorization.
[0244] It should be noted that the second UTM / USS may be the same as or different from the first UTM / USS in the drone registration process and drone authentication and authorization process. For example, the second UTM / USS may be a malicious attacker or other unauthorized communication device. In this case, the second UTM / USS is different from the first UTM / USS.
[0245] S830, the UAV-NF determines whether the identity of the second UTM / USS is correct.
[0246] It should be understood that the UAV-NF determines whether the identity of the second UTM / USS is correct, which means that the UAV-NF determines whether the second UTM / USS has the authority to request the revocation of the drone authentication authorization. Specifically, it can be understood that the UAV-NF determines whether the second UTM / USS has an association with the 3GPP UAV ID. If so, the second UTM / USS can legally initiate the revocation of the drone authentication authorization related to the 3GPP UAV ID; if not, the second UTM / USS can be considered to be a malicious UTM / USS controlled by the attacker.
[0247] As an example, in S810, the UAV-NF saves the mapping relationship between the 3GPP UAV ID and CAA-Level UAV ID#1; in S820, the third request message carries the 3GPP UAV ID and CAA-Level UAV ID#2. The UAV-NF obtains the 3GPP UAV ID and CAA-Level UAV ID#2 from the third request message, and obtains the CAA-Level UAV ID#1 corresponding to the 3GPP UAV ID in the local storage based on the 3GPP UAV ID. The UAV-NF compares the CAA-Level UAV ID#1 with the CAA-Level UAV ID#2. If the CAA-Level UAV ID#1 is the same as the CAA-Level UAV ID#2, the UAV-NF determines that the identity of the second UTM / USS is correct; otherwise, the UAV-NF determines that the identity of the second UTM / USS is incorrect.
[0248] As another example, in S810, the UAV-NF stores the mapping relationship between the 3GPP UAV ID and UTM / USS ID#1; in S840, the third request message carries the 3GPP UAV ID and CAA-Level UAV ID#2, or the third request message carries the 3GPP UAV ID and UTM / USS ID#2. In the case where the third request message carries the 3GPP UAV ID and CAA-Level UAV ID#2, the UAV-NF obtains the 3GPP UAV ID and CAA-Level UAV ID#2 from the third request message, and obtains the UTM / USS ID#2 corresponding to the CAA-Level UAV ID#2 based on the CAA-Level UAV ID#2. The UAV-NF obtains the UTM / USS ID#1 corresponding to the 3GPP UAV ID from the local storage based on the 3GPP UAV ID. The UAV-NF compares UTM / USS ID#1 with UTM / USS ID#2. If UTM / USS ID#1 and UTM / USS ID#2 are the same, the UAV-NF determines that the identity of the second UTM / USS is correct; otherwise, the UAV-NF determines that the identity of the second UTM / USS is incorrect. When the third request message carries the 3GPP UAV ID and UTM / USS ID#2, the UAV-NF obtains the 3GPP UAV ID and UTM / USS ID#2 from the third request message, and obtains the UTM / USS ID#1 corresponding to the 3GPP UAV ID from the local storage based on the 3GPP UAV ID. The UAV-NF compares UTM / USS ID#1 with UTM / USS ID#2. If UTM / USS ID#1 and UTM / USS ID#2 are the same, the UAV-NF determines that the identity of the second UTM / USS is correct; otherwise, the UAV-NF determines that the identity of the second UTM / USS is incorrect.
[0249] As another example, in S810, the UAV-NF stores the mapping relationship between the 3GPP UAV ID, CAA-Level UAV ID#1, and UTM / USS ID#1. In S840, the third request message carries the 3GPP UAV ID and CAA-Level UAV ID#2, or the third request message carries the 3GPP UAV ID and UTM / USS ID#2, or the third request message carries the 3GPP UAV ID, UTM / USS ID#2, and CAA Level UAV ID#2. In the case where the third request message carries the 3GPP UAV ID and UTM / USS ID#2, the UAV-NF obtains the 3GPP UAV ID and UTM / USS ID#2 from the third request message, and obtains the UTM / USS ID#1 corresponding to the 3GPP UAV ID from the local storage based on the 3GPP UAV ID. The UAV-NF compares UTM / USSID#1 with UTM / USS ID#2. If UTM / USS ID#1 is the same as UTM / USS ID#2, the UAV-NF determines that the identity of the second UTM / USS is correct; otherwise, the UAV-NF determines that the identity of the second UTM / USS is incorrect. When the third request message carries the 3GPP UAV ID and CAA-Level UAV ID#2, the UAV-NF obtains the 3GPP UAVID and CAA-Level UAV ID#2 from the third request message, and obtains the CAA-Level UAV ID#1 corresponding to the 3GPP UAV ID in the local storage according to the 3GPP UAV ID. The UAV-NF compares CAA-Level UAV ID#1 with CAA-Level UAV ID#2. If CAA-Level UAV ID#1 is the same as CAA-Level UAV ID#2, the UAV-NF determines that the identity of the second UTM / USS is correct; otherwise, the UAV-NF determines that the identity of the second UTM / USS is incorrect. When the third request message carries 3GPP UAV ID, UTM / USS ID#2 and CAA Level UAV ID#2, the UAV-NF obtains 3GPP UAVID, UTM / USS ID#2 and CAA-Level UAV ID#2 from the third request message, and obtains UTM / USS ID#1 and CAA-Level UAV ID#1 corresponding to the 3GPP UAV ID in the local storage according to the 3GPP UAV ID.The UAV-NF compares UTM / USS ID#1 with UTM / USS ID#2, and the UAV-NF compares CAA-Level UAV ID#1 with CAA-Level UAV ID#2. If UTM / USS ID#1 and UTM / USS ID#2 are identical, and CAA-Level UAV ID#1 and CAA-Level UAV ID#2 are also identical, the UAV-NF determines that the identity of the second UTM / USS is correct; otherwise, the UAV-NF determines that the identity of the second UTM / USS is incorrect.
[0250] It should be understood that the identifier carried in the third request message in S820 should be stored in at least the first UTM / USS. For example, if the third request message carries the 3GPP UAV ID and CAA-Level UAV ID#2, the first UTM / USS stores the mapping relationship between the 3GPP UAV ID and CAA-Level UAV ID#1 during or after the drone registration process and the drone authentication and authorization process, or the UTM / USS stores the mapping relationship between the 3GPP UAV ID, CAA-Level UAV ID#1, and UTM / USS ID#1.
[0251] Optionally, at S840, if the UAV-NF determines that the identity of the second UTM / USS is incorrect, the UAV-NF terminates the UUAA revocation process. For example, if the UAV-NF determines that the identity of the second UTM / USS is incorrect, the UAV-NF directly discards the third request message. For another example, if the UAV-NF determines that the identity of the second UTM / USS is incorrect, the UAV-NF sends a third response message to the UTM / USS, where the third response message includes a 3GPP UAV ID and / or a CAA-Level UAV ID. The first response message is used to indicate that the UUAA revocation failed.
[0252] When the UAV-NF determines that the identity of the second UTM / USS is correct, the UAV-NF continues to execute the UUAA revocation process. For example, at S850, the UAV-NF requests the UDM to query the AMF ID or SMF ID, wherein the request message may carry the 3GPP UAV ID and / or the subscription permanent identifier (SUPI) information of the UAV. The UDM queries the AMF ID or SMF ID serving the UAV based on the 3GPP UAV ID and / or the SUPI of the UAV. The UAV-NF determines the AMF or SMF serving the terminal device based on the AMF ID or SMF ID, and sends a fourth request message to the AMF or SMF at S860. The fourth request message is used to revoke the UUAA. The AMF or SMF performs the UUAA revocation based on the fourth request message.
[0253] Therefore, in the communication method provided in the embodiment of the present application, the third request message sent by the UTM / USS to the UAV-NF carries the CAA-Level UAV ID and / or UTM / USS ID, and verifies the CAA-Level UAV ID and / or UTM / USS ID to determine whether the identity of the UTM / USS is correct, thereby reducing the situation where the drone's authentication authorization is revoked due to the attacker's request. That is, the communication method provided in the embodiment of the present application allows the UAV-NF to detect whether the identity of the UTM / USS that sends the authentication authorization revocation request is correct, that is, to detect whether the UTM / USS is an authorized UTM / USS, thereby reducing the situation where the drone's authentication authorization is revoked for no reason due to the attacker's request, thereby improving the security of the system.
[0254] Figure 9 A schematic flow chart of a communication method 900 in a drone scenario provided by an embodiment of the present application is shown. It should be understood that before method 900, the UAV performs drone registration and drone authentication authorization with the first UTM / USS. The specific process is similar to the drone registration and drone authentication authorization process described in method 800, and will not be repeated in this application.
[0255] like Figure 9 As shown, the method includes:
[0256] At step S910, the AMF or SMF stores the mapping relationship between the 3GPP UAV ID and CAA-Level UAV ID #1 and / or UTM / USS ID #1. The first UTM / USS also stores the mapping relationship between the 3GPP UAV ID and CAA-Level UAV ID #1 and / or UTM / USS ID #1. The specific solution is similar to step S830 in method 800 and will not be elaborated on again.
[0257] S920: The second UTM / USS sends a third request message to the UAV-NF.
[0258] Optionally, in S940, when the second UTM / USS carries the 3GPP UAV ID and CAA-Level UAV ID#2 in the third request message but does not carry UTM / USS ID#2, the UAV-NF obtains CAA-Level UAVID#2 from the third request message and obtains the UTM / USS ID#2 corresponding to the CAA-Level UAV ID#2 based on the CAA-Level UAV ID#2. It should be understood that S920 is similar to S820 in method 800, and the exemplary solution in S820 is also applicable to S920. For the sake of brevity, it is not repeated here.
[0259] S930, UAV-NF requests UDM to query the AMF ID or SMF ID. The request message may carry 3GPP UAV ID and / or UAV SUPI information. UDM queries the AMF ID or SMF ID serving the UAV based on the 3GPP UAV ID and / or UAV SUPI. UAV-NF determines the AMF or SMF serving the terminal device based on the AMF or SMF ID, and sends a fourth request message to the AMF or SMF at S940. The fourth request message is used to revoke UUAA. Optionally, in S940, the second UTM / USS carries 3GPP UAV ID and CAA-Level UAV ID#2 in the third request message, and does not carry UTM / USS ID#2. The UAV-NF obtains CAA-Level UAV ID#2 from the third request message and obtains the UTM / USS ID#2 corresponding to the CAA-Level UAV ID#2 based on the CAA-Level UAV ID#2. The fourth request message also carries the UTM / USS ID#2.
[0260] S950, AMF or SMF determines whether the identity of the UTM / USS is correct.
[0261] S950 in method 900 is similar to S830 in method 800, except that UAV-NF is replaced by AMF or SMF, and the third request message is replaced by the fourth request message. For the sake of brevity, they are not repeated here.
[0262] Optionally, at S950, if the AMF or SMF determines that the identity of the UTM / USS is incorrect, the UAV-NF terminates the UUAA revocation process. If the AMF or SMF determines that the identity of the UTM / USS is correct, the UAV-NF continues to execute the UUAA revocation process.
[0263] Therefore, the communication method provided in the embodiment of the present application reduces the situation where the drone's authentication authorization is revoked due to the attacker's request by allowing the AMF or SMF to verify whether the UTM / USS identity is correct during the authentication and authorization revocation process.
[0264] Figure 10 The following is a schematic flow chart of a communication method 1000 in a drone scenario provided in an embodiment of the present application.
[0265] It should be understood that before method 1000, the UAV performs drone registration and drone authentication authorization with the first UTM / USS. The specific process is similar to the drone registration and drone authentication authorization process introduced in method 800, and this application will not repeat it here.
[0266] like Figure 10 As shown, the method 1000 includes:
[0267] S1010, the UAV-NF sends the mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID#1 and / or the UTM / USS ID#1 to the UDM.
[0268] Exemplarily, the UAV-NF sends a registration request message to the UDM, which includes a mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID#1 and / or UTM / USS ID#1. The registration request message is used to request that the mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID#1 and / or UTM / USS ID#1 be registered to the UDM. Correspondingly, the UDM receives the registration request message, and at S1020, the UDM saves the mapping relationship between the 3GPP UAV ID and the CAA-Level UAV ID#1 and / or UTM / USS ID#1. It should be understood that the first UTM / USS also saves the mapping relationship between the 3GPP UAV ID, CAA-Level UAV ID#1 and / or UTM / USS ID#1 during or after the UAV registration process and the UAV authentication and authorization process.
[0269] S1030, UTM / USS sends a third request message to UAV-NF, where the third request message includes 3GPP UAV ID, CAA-Level UAV ID#2 and / or UTM / USS ID#2. The third request message is used to request the revocation of the UAV authentication authorization.
[0270] S1040, the UAV-NF sends a fourth request message to the UDM, where the fourth request message includes the 3GPP UAV ID, and CAA-Level UAV ID#2 and / or UTM / USS ID#2. The fourth request message is used to request the revocation of the UAV authentication authorization.
[0271] It should be noted that when UDM saves the mapping relationship between 3GPP UAV ID and UTM / USS ID#1 in S1020, the mapping relationship does not include CAA-Level UAV ID#1, and the third request message in S1060 carries 3GPP UAV ID and CAA-Level UAV ID#2 but does not carry UTM / USS ID#2, after UAV-NF receives the third request message in S1030, it obtains 3GPP UAV ID and CAA-Level UAV ID#2 from the third request message, and determines the UTM / USS ID#2 corresponding to the CAA-Level UAV ID#2 based on CAA-Level UAV ID#2, and then sends a fourth request message to UDM in S1040, which carries 3GPP UAV ID and UTM / USS ID#2.
[0272] S1050, the UDM determines whether the identity of the second UTM / USS is correct.
[0273] Step S1050 is similar to step S830 in method 800, except that UAV-NF is replaced by UDM, which will not be described in detail in this application.
[0274] Optionally, the UDM sends a fourth response message to the UAV-NF, where the fourth response message is used to feedback the verification result of the UTM / USS identity.
[0275] Optionally, if the UAV-NF determines that the identity of the UTM / USS is incorrect, the UAV-NF terminates the UUAA revocation procedure. If the UAV-NF determines that the identity of the UTM / USS is correct, the UAV-NF continues to perform the UUAA revocation procedure.
[0276] Therefore, the communication method provided in the embodiment of the present application reduces the situation where the drone's authentication authorization is revoked for no reason due to the attacker's request by having the UDM verify whether the UTM / USS identity is correct during the authentication and authorization revocation process.
[0277] Figure 11 The following is a schematic flow chart of a communication method 1100 in a drone scenario provided in an embodiment of the present application.
[0278] It should be understood that before method 1100, the UAV performs drone registration and drone authentication authorization with the UTM / USS. The specific process is similar to the drone registration and drone authentication authorization process introduced in method 800, and this application will not repeat it here.
[0279] like Figure 11 As shown, the method 1100 includes:
[0280] At S1110, the AMF or SMF stores the mapping relationship between the 3GPP UAV ID and CAA-Level UAV ID#1 and / or UTM / USS ID#1. The UTM / USS also stores the mapping relationship between the 3GPP UAV ID and CAA-Level UAV ID#1 and / or UTM / USS ID#1. The specific solution is similar to S830 in method 800 and will not be elaborated again.
[0281] S1120 in method 1100 is similar to S920 in method 900 and will not be described again.
[0282] S1130 , the UAV-NF determines whether a TLS connection has been established between the UAV-NF and the UTM / USS, and whether integrity protection is enabled.
[0283] It should be noted that if the UAV-NF communicates with the UTM / USS via the network exposure function (NEF), the NEF and the UTM / USS establish a TLS connection. If the UAV-NF and NEF are co-located or the same network element performs both the NEF and UAV-NF functions, the UAV-NF and the UTM / USS establish a TLS connection. When the same network element performs both the NEF and UAV-NF functions, the UAV-NF is used to represent the network element in method 1100. Establishing a TLS connection may include establishing a TLS connection between the UAV-NF and the UTM / USS during network setup based on device pre-configuration or manual triggering, or establishing a TLS connection when the UTM / USS and UAV-NF communicate with each other for the first time. Alternatively, a secure connection may be established when the UTM / USS and the UAV-NF communicate with each other again.
[0284] When a TLS connection has been established between the UAV-NF and the UTM / USS, and integrity protection and / or confidentiality protection have been enabled, the communication between the UAV-NF and the UTM / USS can be considered secure, and an attacker cannot pretend to be the UTM / USS to request the revocation of the UUAA.
[0285] Optionally, when establishing a TLS connection between the UAV-NF and the UTM / USS, integrity protection and / or confidentiality protection is forcibly enabled, that is, a non-NULL integrity and / or confidentiality protection is selected.
[0286] If the UAV-NF determines that a TLS connection has been established between the UAV-NF and the UTM / USS, and integrity protection has been enabled, the UAV-NF continues the revocation process without the need for additional verification. For example, when the UAV-NF determines that a TLS connection has been established between the UAV-NF and the UTM / USS, and integrity protection has been enabled, at S1160, the UAV-NF requests the UDM to query the AMF ID or SMF ID, determines the AMF or SMF serving the terminal device based on the AMF ID or SMF ID, and sends a fourth request message to the AMF or SMF at S1170, which is used to revoke the UUAA. The AMF or SMF revokes the UUAA based on the fourth request message. Otherwise, the UAV-NF terminates the revocation process or uses any of methods 800-1000 to verify the identity of the UTM / USS.
[0287] Optionally, the UAV-NF obtains the UTM / USS ID#2 of the UTM / USS and the identification information of the TLS connection during the process of establishing a TLS secure connection with the UTM / USS. After the UAV-NF successfully establishes a TLS connection with the UTM / USS, the UAV-NF saves the association between the TLS connection identifier and the UTM / USS ID#2. After receiving the third request message carrying the 3GPP UAV ID sent by the UTM / USS via the TLS connection, the UAV-NF obtains the 3GPP UAV ID. The UAV-NF obtains UTM / USS ID#2 based on the TLS connection identifier, and the UTM / USS obtains UTM / USS ID#1 through the 3GPP UAV ID. The specific method is similar to that in methods 800-1000 and will not be repeated here. The UAV-NF compares the UTM / USS ID#1 with the UTM / USS ID#2. If the UTM / USS ID#1 is identical to the UTM / USS ID#2, the UAV-NF determines that the identity of the UTM / USS is correct; otherwise, the UAV-NF determines that the identity of the UTM / USS is incorrect.
[0288] Therefore, in the communication method provided in the embodiment of the present application, the UAV authentication revocation process is performed only after it is determined that a TLS connection has been established between the UAV-NF and the UTM / USS and integrity protection is enabled. Otherwise, the identity of the UTM / USS needs to be verified, thereby reducing the situation where the drone's authentication authorization is revoked for no reason due to the attacker's request.
[0289] Figure 12 FIG1 shows a schematic flow chart of a communication method 1200 in a drone scenario provided by an embodiment of the present application. Figure 12 As shown, the method 1200 includes:
[0290] S1210-S1220 in method 1200 are similar to the drone registration process and drone authentication and authorization process in method 800, and are not repeated here.
[0291] In the drone authentication and authorization process, at S1221, the AMF or SMF assigns different 3GPP UAV IDs to different terminal devices in the drone authentication and authorization process.
[0292] For example, in the drone authentication and authorization process, when initiating drone authentication and authorization, AMF or SMF temporarily allocates a GPSI in the external identifier format to the terminal device. The GPSI is different for each terminal device and each access, and the GPSI is used as the 3GPP UAV ID.
[0293] Steps S1230-S1250 are similar to steps S920-S940 in method 900 and will not be described in detail in this application for the sake of brevity.
[0294] It should be understood that method 1200 can be implemented alone or in combination with other methods, and this application does not limit this.
[0295] Therefore, the communication method provided in the embodiment of the present application greatly increases the difficulty for attackers to disguise themselves by allocating a different 3GPP UAV ID to each terminal device for each access, thereby improving the security of the system.
[0296] Above, combined Figures 3 to 12 The method provided in the embodiment of the present application is described in detail. Figures 13 and 14 The device provided in the embodiments of the present application is described in detail.
[0297] Figure 13 1 is a schematic block diagram of a communication device 10 provided in an embodiment of the present application. Figure 13 As shown, the communication device 10 may include a transceiver module 11 and a processing module 12 .
[0298] In one possible design, the communication device 10 may correspond to the first network element or NSSAAF or AAA-P or UAV-NF or AMF / SMF in the above method embodiment.
[0299] Exemplarily, the communication device 10 may correspond to the first network element in the method 300 according to the embodiment of the present application, or the NSSAAF in the methods 400, 600, and 700, or the AAA-P in the method 500, or the UAV-NF in the methods 800, 1100, and 1200, or the AMF / SMF in the method 900, or the UDM in the method 1000. The communication device 10 may include a method for performing Figure 3 Method 300 or Figure 4 Method 400 or Figure 5 Method 500 or Figure 6 Method 600 or Figure 7 Method 700 or Figure 8 Method 800 or Figure 9 Method 900 or Figure 10 Method 1000 or Figure 11 Method 1100 or Figure 12 The module of the method performed by the first network element, NSSAAF, AAA-P, UAV-NF, or AMF / SMF in method 1200 is described above. Furthermore, the various units and other operations and / or functions in the communication device 10 are respectively for implementing the corresponding processes of methods 300 to 1200. The transceiver module 11 in the communication device 10 performs the receiving and transmitting operations performed by the first network element, NSSAAF, AAA-P, UAV-NF, or AMF / SMF in the above-mentioned method embodiments, while the processing module 12 performs operations other than the receiving and transmitting operations.
[0300] In another possible design, the communication device 10 may correspond to the third network element or AAA-S or UTM / USS in the above method embodiment.
[0301] For example, Figure 13 The communication device 20 may correspond to the third network element in the method 300 according to the embodiment of the present application or the AAA-S in the methods 400 to 700 or the UTM / USS in the methods 800 to 1200, and the communication device 20 may include a method for performing Figure 3 Method 300 or Figure 4 Method 400 or Figure 5 Method 500 or Figure 6 Method 600 or Figure 7 Method 700 or Figure 8 Method 800 or Figure 9 Method 900 or Figure 10Method 1000 or Figure 11 Method 1100 or Figure 12 The module of the method executed by the third network element or AAA-S or UTM / USS in the method 1200. In addition, each unit in the communication device 20 and the above-mentioned other operations and / or functions are respectively for implementing the corresponding processes of methods 200 to 1000.
[0302] The transceiver module 21 in the communication device 20 performs the receiving and sending operations performed by the third network element, AAA-S, or UTM / USS in the above-mentioned method embodiments, and the processing module 22 performs operations other than the receiving and sending operations.
[0303] According to the aforementioned method, in one possible design, Figure 14 A schematic diagram of a communication device 20 provided in an embodiment of the present application is shown in FIG. Figure 14 As shown, the device 20 can be a communication device such as a network device, including the first network element or NSSAAF or AAA-P or UAV-NF or AMF / SMF in the above method embodiment.
[0304] According to the aforementioned method, in another possible design, Figure 14 This is a schematic diagram of a communication device 20 provided in an embodiment of the present application. The communication device 40 may be the third network element, AAA-S, or UTM / USS in the above method embodiment.
[0305] The device 20 may include a processor 21 (ie, an example of a processing module) and a memory 22. The memory 22 is used to store instructions, and the processor 21 is used to execute the instructions stored in the memory 22, so that the device 30 can implement the following Figure 3-Figure 12 The steps performed in the corresponding method.
[0306] Furthermore, the device 20 may also include an input port 24 (i.e., an example of a transceiver module) and an output port 24 (i.e., another example of a transceiver module). Furthermore, the processor 21, memory 22, input port 23, and output port 24 may communicate with each other through an internal connection path to transmit control and / or data signals. The memory 22 is used to store a computer program, and the processor 21 may be used to call and execute the computer program from the memory 22 to control the input port 23 to receive signals and the output port 24 to send signals, thereby completing the steps of the network device in the above method. The memory 22 may be integrated into the processor 21 or provided separately from the processor 21.
[0307] Alternatively, if the communication device 20 is a communication device, the input port 23 is a receiver and the output port 24 is a transmitter. The receiver and transmitter may be the same or different physical entities. When they are the same physical entity, they may be collectively referred to as a transceiver.
[0308] Optionally, if the communication device 20 is a chip or a circuit, the input port 23 is an input interface, and the output port 24 is an output interface.
[0309] As an implementation method, the functions of the input port 23 and the output port 24 can be implemented by a transceiver circuit or a dedicated transceiver chip. The processor 21 can be implemented by a dedicated processing chip, a processing circuit, a processor or a general-purpose chip.
[0310] As another implementation, it is possible to use a general-purpose computer to implement the communication device provided in the embodiments of the present application. Specifically, the program code that implements the functions of the processor 21, the input port 23, and the output port 24 is stored in the memory 22, and the general-purpose processor executes the code in the memory 22 to implement the functions of the processor 31, the input port 23, and the output port 24.
[0311] For the concepts, explanations, detailed descriptions and other steps involved in the device 20 and related to the technical solutions provided in the embodiments of the present application, please refer to the descriptions of these contents in the aforementioned methods or other embodiments, which will not be repeated here.
[0312] An embodiment of the present application further provides a computer-readable storage medium storing computer instructions for implementing the method executed by the first network device in the above method embodiment.
[0313] For example, when the computer program is executed by a computer, the computer can implement the method performed by the network device in the above method embodiment.
[0314] An embodiment of the present application also provides a computer program product comprising instructions, which, when executed by a computer, enables the computer to implement the method executed by the first device or the method executed by the second device in the above method embodiment.
[0315] An embodiment of the present application further provides a communication system, which includes the network device in the above embodiment.
[0316] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above, which will not be repeated here.
[0317] In an embodiment of the present application, a network device may include a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer may include hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also known as main memory). The operating system of the operating system layer may be any one or more computer operating systems that implement business processing through processes, such as a Linux operating system, a Unix operating system, an Android operating system, an iOS operating system, or a Windows operating system. The application layer may include applications such as browsers, address books, word processing software, and instant messaging software.
[0318] The embodiments of the present application do not specifically limit the specific structure of the execution subject of the method provided in the embodiments of the present application; as long as it is capable of communicating according to the method provided in the embodiments of the present application by running a program that records the code of the method provided in the embodiments of the present application, it is sufficient. For example, the execution subject of the method provided in the embodiments of the present application may be a network device, or a functional module in the network device that is capable of calling and executing a program.
[0319] Various aspects or features of the present application may be implemented as a method, apparatus, or article of manufacture using standard programming and / or engineering techniques. As used herein, the term "article of manufacture" may encompass a computer program accessible from any computer-readable device, carrier, or medium. For example, a computer-readable medium may include, but is not limited to, magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical disks (e.g., compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memory (EPROM), cards, sticks, or key drives, etc.).
[0320] The various storage media described herein may represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0321] It should be understood that the processor mentioned in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0322] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM may include the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0323] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) can be integrated into the processor.
[0324] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0325] Those skilled in the art will appreciate that the units and steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel may use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of protection of this application.
[0326] Those skilled in the art will clearly understand that, for the sake of convenience and brevity in description, the specific working processes of the above-described devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0327] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0328] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to implement the solutions provided in this application.
[0329] In addition, each functional unit in each embodiment of the present application may be integrated into one unit, each unit may exist physically separately, or two or more units may be integrated into one unit.
[0330] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, or a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk (SSD)). For example, the available medium may include, but is not limited to, various media that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0331] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims and the description.
Claims
1. A communication method, characterized in that: include: The network slice authentication and authorization function network element receives a first request message from the authentication, authorization and accounting server, where the first request message is used to request a first operation to be performed on a first terminal device, where the first operation includes network slice re-authentication or revocation of network slice authentication; The network slice authentication and authorization function network element determines whether the authentication, authorization and billing server has the authority to request the first operation to be performed on the first terminal device based on the first request message.
2. The method according to claim 1, characterized in that The first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, and the second identifier is associated with the authentication, authorization and accounting server.
3. The method according to claim 2, characterized in that The method further comprises: The network slice authentication and authorization function network element stores a mapping relationship between the third identifier and the first identifier; The network slice authentication and authorization function network element determines, according to the first request message, whether the authentication, authorization and accounting server has the authority to perform the first operation on the first terminal device, including: The network slice authentication and authorization function network element obtains the mapping relationship according to the first identifier; When the second identifier matches the third identifier, the network slice authentication and authorization function network element determines that the authentication, authorization and billing server has the authority to request to perform the first operation on the first terminal device; otherwise, the network slice authentication and authorization function network element determines that the authentication, authorization and billing server does not have the authority to perform the first operation on the first terminal device.
4. The method according to claim 2 or 3, characterized in that The second identifier includes at least one of the following information: The identity identification number ID of the authentication authorization accounting server, the Internet Protocol IP address of the authentication authorization accounting server, and the fully qualified domain name FQDN of the authentication authorization accounting server; The first identifier includes single network slice selection auxiliary information S-NSSAI.
5. The method according to any one of claims 1 to 3, characterized in that Before the network slice authentication and authorization function network element receives the first request message from the authentication, authorization and accounting server, the method further includes: The network slice authentication and authorization function network element performs a second operation on the first terminal device, and the second operation is associated with the first operation.
6. The method according to claim 5, characterized in that The second operation is network slice authentication.
7. The method according to any one of claims 1 to 3, characterized in that The first terminal device is a user equipment.
8. A communication method, characterized in that: include: The authentication, authorization and accounting server generates a first request message; The authentication, authorization and billing server sends the first request message to the network slice authentication and authorization function network element. The first request message is used to request to perform a first operation on the first terminal device. The first request message is used to determine whether the authentication, authorization and billing server has the authority to request to perform the first operation on the first terminal device. The first operation includes network slice re-authentication or revocation of network slice authentication.
9. The method according to claim 8, characterized in that The first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, and the second identifier is associated with the authentication, authorization and accounting server.
10. The method according to claim 9, characterized in that The second identifier includes at least one of the following information: The identity identification number ID of the authentication authorization accounting server, the Internet Protocol IP address of the authentication authorization accounting server, and the fully qualified domain name FQDN of the authentication authorization accounting server; The first identifier includes single network slice selection auxiliary information S-NSSAI.
11. The method according to any one of claims 8 to 10, characterized in that The first terminal device is a user equipment.
12. A communication device, characterized in that: include: A transceiver module, configured to receive a first request message from an authentication, authorization and accounting server, where the first request message is used to request a first operation to be performed on a first terminal device, where the first operation includes network slice re-authentication or revocation of network slice authentication; A processing module is used to determine whether the authentication, authorization and accounting server has the authority to request to perform the first operation on the first terminal device according to the first request message.
13. The device according to claim 12, characterized in that The first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, and the second identifier is associated with the authentication, authorization and accounting server.
14. The device according to claim 13, characterized in that The processing module is further configured to: Storing a mapping relationship between a third identifier and the first identifier; The processing module is further configured to: Acquire the mapping relationship according to the first identifier; and If the second identifier matches the third identifier, it is determined that the authentication authorization accounting server has the authority to request execution of the first operation on the first terminal device; otherwise, it is determined that the authentication authorization accounting server does not have the authority to execute the first operation on the first terminal device.
15. The device according to claim 13 or 14, characterized in that The second identifier includes at least one of the following information: The identity identification number ID of the authentication authorization accounting server, the Internet Protocol IP address of the authentication authorization accounting server, and the fully qualified domain name FQDN of the authentication authorization accounting server; The first identifier includes single network slice selection auxiliary information S-NSSAI.
16. The device according to any one of claims 12 to 14, characterized in that The processing module is further configured to: A second operation is performed on the first terminal device, where the second operation is associated with the first operation.
17. The device according to claim 16, characterized in that The second operation is network slice authentication.
18. The device according to any one of claims 12 to 14, characterized in that The first terminal device is a user equipment.
19. A communication device, characterized in that: include: A processing module, configured to generate a first request message; The transceiver module is used to send a first request message to the network slice authentication and authorization function network element, where the first request message is used to request a first operation to be performed on a first terminal device. The first request message is used to determine whether the authentication, authorization and billing server has the authority to request the first operation to be performed on the first terminal device. The first operation includes network slice re-authentication or revocation of network slice authentication.
20. The device according to claim 19, characterized in that The first request message includes a first identifier and a second identifier, the first identifier is associated with the first terminal device, and the second identifier is associated with the authentication, authorization and accounting server.
21. The device according to claim 20, characterized in that The second identifier includes at least one of the following information: The identity identification number ID of the authentication authorization accounting server, the Internet Protocol IP address of the authentication authorization accounting server, and the fully qualified domain name FQDN of the authentication authorization accounting server; The first identifier includes single network slice selection auxiliary information S-NSSAI.
22. The device according to any one of claims 19 to 21, characterized in that The first terminal device is a user equipment.
23. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is run on a computer, the computer is caused to execute the method according to any one of claims 1 to 11.
24. A chip, characterized in that: The system comprises a processor and a memory, wherein the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the method according to any one of claims 1 to 11.
25. A computer program product, characterized in that The computer program product stores a program or instructions, and when the program or instructions are executed, the method according to any one of claims 1 to 11 is implemented.
26. A communication system, characterized in that: The communication system comprises the apparatus according to any one of claims 12 to 18 and the apparatus according to any one of claims 19 to 22.
27. A communication method, characterized in that: include: The authentication, authorization and accounting server generates a first request message; The authentication, authorization and accounting server sends a first request message to the network slice authentication and authorization function network element, where the first request message is used to request a first operation to be performed on a first terminal device. The first request message is used to determine whether the authentication, authorization and accounting server has the authority to request the first operation to be performed on the first terminal device, where the first operation includes network slice re-authentication or revocation of network slice authentication; The network slice authentication and authorization function network element receives the first request message; The network slice authentication and authorization function network element determines whether the authentication, authorization and billing server has the authority to request the first operation to be performed on the first terminal device based on the first request message.
Citation Information
Patent Citations
Command and control interface for uavs communication through a mobile wireless network
US20160371987A1
Cited By
Communication method and communication apparatus
WO2022174794A1