A method, apparatus and system for acquiring terminal device identification
By working together with key management network elements and unified data management network elements, the permanent user identifier of remote devices can be obtained by using anonymization or temporary identifiers, thus solving the problem of user privacy exposure in D2D communication and realizing the transmission of secure communication parameters.
Patent Information
- Application Number
- CN202080099106.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-03-31
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2040-03-31
AI Technical Summary
In D2D communication, when a remote device interacts with the communication network through a relay device, it may directly send the user's permanent identifier over the air interface, leading to the exposure of user privacy.
The key management network element receives anonymized or temporary identifiers from the first terminal device, requests a permanent user identifier from the unified data management network element, performs authorization checks, and then sends secure communication parameters to avoid directly obtaining the user's permanent identifier.
It effectively protects the security of users' permanent identifiers, prevents privacy exposure, expands the scope of application, and is suitable for different scenarios.
Smart Images

Figure CN115336303B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus and system for obtaining a terminal device identifier. Background Technology
[0002] Currently, device-to-device (D2D) communication allows user equipment (UE) to communicate directly with each other.
[0003] When a remote device (UE) is outside the coverage area of the communication network, or when the communication quality between it and the access network device in the communication network is poor, it can establish indirect communication with the communication network through a relay device (relayUE) based on D2D communication. That is, through communication between the remote device and the relay device, and interaction between the relay device and the communication network, the remote device can obtain data from the communication network.
[0004] When a remote device establishes indirect communication with a communication network using a relay device, the relay device first needs to obtain the remote device's identifier and report it to the communication network. This allows the communication network to perform authentication, authorization checks, or service control based on the remote device's identifier, such as lawful eavesdropping. In 4G systems, the remote device can provide its persistent user identifier to the relay device in plaintext over the air interface. The remote device then forwards this persistent user identifier to the communication network. This direct transmission of the persistent user identifier in plaintext over the air interface leads to the exposure of user privacy. Summary of the Invention
[0005] This application provides a method, apparatus, and system for obtaining a terminal device identifier, in order to solve the problem of user privacy exposure caused by the transmission method of the user's permanent identifier.
[0006] In a first aspect, embodiments of this application provide a method for obtaining a terminal device identifier. This method is executed by a key management network element and includes: the key management network element receiving a first key request from a first terminal device, the first key request including a first identifier, which is an anonymized identifier or temporary identifier of a second terminal device; the key management network element parsing the first key request, and if it determines that the key request includes the first identifier, it needs to determine the permanent user identifier of the second terminal device. The key management network element can send a first request to a unified data management network element, the first request including the first identifier; subsequently, the key management network element can receive a first response from the unified data management network element, the first response including the SUPI of the second terminal device; subsequently, the key management network element can perform an authorization check on the second terminal device based on the SUPI of the second terminal device, and after the authorization check on the second terminal device passes, send a first key response to the first terminal device, the first key response including secure communication parameters, which are parameters required for the first terminal device and the second terminal device to establish secure communication.
[0007] Using the above method, the key management network element obtains the permanent user identifier of the second terminal device from the unified data management network element. The key management network element only needs to obtain the anonymized identifier or temporary identifier of the second terminal device from the first terminal device, and no longer needs to obtain the permanent user identifier of the second terminal device from the first terminal device. This can effectively ensure the security of the permanent user identifier of the second terminal device, and thus avoid the exposure of user privacy.
[0008] In one possible design, the first response and the first key response may also include the GPSI of the second terminal device, and may also include a first identifier. By carrying the first identifier or GPSI, the first response and the first key response may further instruct the second terminal device, avoiding the exposure of user privacy due to carrying a permanent user identifier.
[0009] In one possible design, the first request and first response can be information from the existing interaction process between the key management network element and the unified data management network element. For example, the first request could be a request to obtain secure communication parameters, and the first response could be a response to obtaining secure communication parameters. Alternatively, the first request and first response can be newly added information from the existing interaction process between the key management network element and the unified data management network element. Setting the first request and first response is more flexible and can effectively expand the application scope.
[0010] In one possible design, if the key management network element fails to grant authorization to the second terminal device based on the second identifier, it can notify the first terminal device to refuse or terminate service to the second terminal device. It can also notify the unified data management network element to delete the SUPI mapping between the first identifier and the second terminal device. The key management network element can promptly and conveniently notify the first terminal device or the unified data management network element to perform the corresponding operation.
[0011] In one possible design, the key management network element can also send a first instruction to the unified data management network element. This first instruction indicates the correspondence between the stored first identifier and the SUPI of the second terminal device. By sending the first instruction, the key management network element informs the unified data management network element of the correspondence between the stored first identifier and the SUPI of the second terminal device, enabling other network elements to obtain the SUPI of the second terminal device from the unified data management network element using the first identifier.
[0012] Secondly, embodiments of this application provide a method for obtaining a terminal device identifier. This method is executed by a unified data management network element. In this method, the unified data management network element can receive a first request from a key management network element. The first request includes a first identifier, which is an anonymized identifier or temporary identifier of a second terminal device. After determining that the first request includes the first identifier, the unified data management network element can obtain the SUPI of the second terminal device based on the first identifier. Subsequently, the unified data management network element sends a first response to the key management network element, which includes the SUPI of the second terminal device.
[0013] Using the above method, the key management network element can conveniently obtain the SUPI of the second terminal device by interacting with the unified data management network element.
[0014] In one possible design, when the unified data management network element determines the SUPI of the second terminal device based on its anonymized identifier, it can obtain the SUPI from the user identifier de-hiding network element based on the second terminal device's anonymized identifier. This method makes obtaining the SUPI of the second terminal device more convenient for the unified data management network element.
[0015] In one possible design, when the unified data management network element determines the SUPI of the second terminal device based on its temporary identifier, it can do so by using the stored correspondence between the terminal device's SUPI and the temporary identifier. The unified data management network element stores this correspondence, making it easier to provide the key management network element with the SUPI of the second terminal device.
[0016] In one possible design, before determining the SUPI of the second terminal device based on its temporary identifier, the unified data management network element needs to first determine the temporary identifier assigned to the second terminal. Two methods are described below:
[0017] Method 1: The unified data management network element can assign a temporary identifier to the second terminal device, and then send the temporary identifier to the second terminal device through the neighboring service network element. It can also save the correspondence between the SUPI of the second terminal device and the temporary identifier.
[0018] Method 2: The unified data management network element can also obtain the temporary identifier assigned to the second terminal device by the neighboring service network element from the neighboring service network element, and save the correspondence between the SUPI of the second terminal device and the temporary identifier.
[0019] Using the methods described above, the unified data management network element can determine the temporary identifier assigned to the second terminal in various ways, which is applicable to different scenarios.
[0020] In one possible design, after the unified data management network element obtains the SUPI of the second terminal device based on the first identifier, it can store the correspondence between the first identifier and the SUPI of the second terminal device so that other network elements can obtain the SUPI of the second terminal device from the unified data management network element through the first identifier.
[0021] In one possible design, the unified data management network element (UDI) can proactively store the mapping relationship between the first identifier and the SUPI of the second terminal device. Alternatively, the UDI can store this mapping relationship under the instruction of the key management network element (KLE). For example, the UDI receives a first instruction from the KLE, indicating the need to store the mapping relationship between the first identifier and the SUPI of the second terminal device, and then stores it. The UDI can also first determine whether it needs to store the mapping relationship, and then store it only after confirming that it does. For example, the UDI determines whether to store the mapping relationship based on the attributes of the second terminal device. There are multiple ways for the UDI to determine the storage of the mapping relationship between the first identifier and the SUPI of the second terminal device, which can be applied to different scenarios, effectively expanding the application scope.
[0022] In one possible design, after storing the correspondence between the first identifier and the SUPI of the second terminal device, the unified data management network element can also delete the correspondence between the first identifier and the SUPI of the second terminal device under the notification of the key management network element, so as to save storage space.
[0023] In one possible design, the first response may carry a first identifier, or it may carry other identifiers of the second terminal device. For example, the unified data management network element may also determine the GPSI of the second terminal device based on its SUPI and carry the GPSI of the second terminal device in the first response. In addition to the SUPI of the second terminal device, the first response may also carry other identifiers of the second terminal device, enabling the key management network element to provide more information about the second terminal device.
[0024] In one possible design, the unified data management network element can also provide the SUPI of the second terminal device to other network elements. These other network elements can be either session management network elements or mobile access management network elements, which will be described below:
[0025] (1) The unified data management network element can receive a user identity resolution request from the session management network element. The user identity resolution request includes a second identifier, which is one of the following: the anonymization identifier of the second terminal device, the temporary identifier of the second terminal device, or the GPSI of the second terminal device. Then, the unified data management network element determines the SUPI of the second terminal device based on the second identifier; then, the unified data management network element sends a user identity resolution response to the session management network element, which includes the SUPI of the second terminal device.
[0026] (2) The unified data management network element can also receive an identifier resolution request from the mobile access management network element. The identifier resolution request includes a second identifier, which is one of the following: the anonymized identifier of the second terminal device, the temporary identifier of the second terminal device, or the GPSI of the second terminal device. After that, the unified data management network element determines the SUPI of the second terminal device based on the second identifier. After that, the unified data management network element can send an identifier resolution response to the mobile access management network element, which includes the SUPI of the second terminal device.
[0027] In one possible design, the first request and first response can be information from the existing interaction process between the key management network element and the unified data management network element. For example, the first request could be a request to obtain secure communication parameters, and the first response could be a response to obtaining secure communication parameters. Alternatively, the first request and first response can be newly added information from the existing interaction process between the key management network element and the unified data management network element. Setting the first request and first response is more flexible and can effectively expand the application scope.
[0028] In one possible design, the first response also includes a first identifier.
[0029] Thirdly, embodiments of this application provide a method for obtaining a terminal device identifier. In this method, a session management network element can receive a terminal reporting message from a first terminal device. The terminal reporting message includes a second identifier and IP information allocated by the first terminal device to a second terminal device. The second identifier is one of the following: an anonymized identifier of the second terminal device, a temporary identifier of the second terminal device, or the GPSI of the second terminal device. The session management network element determines that the terminal reporting message includes the second identifier and needs to obtain the SUPI of the second terminal device. The session management network element can send a user identity resolution request to a unified data management network element, and the user identity resolution request includes the second identifier. Subsequently, the session management network element receives a user identity resolution response from the unified data management network element, and the user identity resolution response includes the SUPI of the second terminal device. After obtaining the SUPI, the session management network element can perform service control on the second terminal device based on the SUPI and IP information of the second terminal device.
[0030] Using the above method, the session management network element can obtain the permanent user identifier of the second terminal device from the unified data management network element. The session management network element only needs to obtain the anonymized identifier or temporary identifier of the second terminal device from the first terminal device, and no longer needs to obtain the permanent user identifier of the second terminal device from the first terminal device. This can effectively ensure the security of the permanent user identifier of the second terminal device, and thus avoid the exposure of user privacy.
[0031] Fourthly, embodiments of this application provide a method for obtaining a terminal device identifier. This method is executed by a mobile access management network element (MULTI). The MULTI receives a terminal-reported message from a first terminal device. The terminal-reported message includes a second identifier and IP information allocated by the first terminal device to the second terminal device. The second identifier is one of the following: an anonymized identifier of the second terminal device, a temporary identifier of the second terminal device, or a General Public User Identifier (GPSI) of the second terminal device. Subsequently, the MULTI determines that the terminal-reported message includes the second identifier and needs to obtain the second terminal device's SUPI. It can send an identifier resolution request to a unified data management network element (UDN). The identifier resolution request includes the second terminal device's SUPI. The MULTI receives an identifier resolution response from the UDN. The identifier resolution request includes the second terminal device's SUPI. Afterward, the MULTI can send the second terminal device's SUPI and IP information to a session management network element (SDN).
[0032] Using the above method, the mobile access management network element can obtain the permanent user identifier of the second terminal device from the unified data management network element, and then send the obtained permanent user identifier of the second terminal device to the session management network element. The first terminal device no longer needs to provide the permanent user identifier of the second terminal device, which can effectively ensure the security of the permanent user identifier of the second terminal device and thus avoid the exposure of user privacy.
[0033] Fifthly, embodiments of this application provide a method for obtaining a terminal device identifier. This method is executed by a first terminal device. In this method, after determining that it needs to establish direct communication with a second terminal device, the first terminal device can send a first key request to a key management network element. The first key request includes a first identifier, which is an anonymized identifier or temporary identifier of the second terminal device. Subsequently, the first terminal device can receive a second key response from the key management network element. The first key response includes secure communication parameters. Then, the first terminal device establishes secure communication with the second terminal device based on the secure communication parameters.
[0034] Using the above method, the first terminal device can obtain secure communication parameters for establishing secure communication with the second terminal device from the key management network element through the first identifier. The first terminal device no longer needs to provide the user's permanent identifier of the second terminal device, which can effectively ensure the security of the user's permanent identifier of the second terminal device and thus avoid the exposure of user privacy.
[0035] In one possible design, the first key response may also include the GPSI or first identifier of the second terminal device for indicating the second terminal device.
[0036] Sixthly, this application also provides a communication device applied to a key management network element. The beneficial effects are described in the first aspect and will not be repeated here. This device has the function of implementing the behavior in the method examples of the first aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the device structure includes a receiving unit, a processing unit, and a transmitting unit. These units can perform the corresponding functions in the method examples of the first aspect, as detailed in the method examples, and will not be repeated here.
[0037] Seventhly, this application also provides a communication device applied to a unified data management network element. The beneficial effects are described in the second aspect and will not be repeated here. This device has the function of implementing the behavior in the method examples of the second aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the device structure includes a receiving unit, a processing unit, and a transmitting unit. These units can perform the corresponding functions in the method examples of the second aspect, as detailed in the method examples, and will not be repeated here.
[0038] Eighthly, this application also provides a communication device applied to a session management network element. The beneficial effects are described in the third aspect and will not be repeated here. This device has the function of implementing the behavior in the method examples of the third aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the device structure includes a receiving unit, a processing unit, and a transmitting unit. These units can perform the corresponding functions in the method examples of the third aspect, as detailed in the method examples, and will not be repeated here.
[0039] Ninthly, embodiments of this application also provide a communication device applied to a mobile access management network element. The beneficial effects are described in the fourth aspect and will not be repeated here. This device has the function of implementing the behaviors described in the method examples of the fourth aspect. The functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In one possible design, the device structure includes a receiving unit, a processing unit, and a transmitting unit. These units can perform the corresponding functions in the method examples of the fourth aspect, as detailed in the method examples, and will not be repeated here.
[0040] Tenthly, embodiments of this application also provide a communication device applied to a first terminal device. The beneficial effects are described in the fifth aspect and will not be repeated here. This device has the function of implementing the behavior in the method examples of the fifth aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described functions. In one possible design, the device structure includes a receiving unit, a processing unit, and a transmitting unit. These units can perform the corresponding functions in the method examples of the fifth aspect, as detailed in the method examples, and will not be repeated here.
[0041] Eleventhly, embodiments of this application also provide a communication device applied to a key management network element. The beneficial effects are described in the first aspect and will not be repeated here. The communication device includes a processor and a memory. The processor is configured to support the key management network element in performing the corresponding functions described in the first aspect. The memory is coupled to the processor and stores necessary program instructions and data for the communication device. The communication device also includes a communication interface for communicating with other devices.
[0042] In a twelfth aspect, embodiments of this application also provide a communication device applied to a unified data management network element. The beneficial effects are described in the second aspect and will not be repeated here. The communication device includes a processor and a memory. The processor is configured to support the unified data management network element in performing the corresponding functions described in the second aspect. The memory is coupled to the processor and stores necessary program instructions and data for the communication device. The communication device also includes a communication interface for communicating with other devices.
[0043] In a thirteenth aspect, embodiments of this application also provide a communication device applied to a session management network element. The beneficial effects are described in the third aspect and will not be repeated here. The communication device includes a processor and a memory. The processor is configured to support the session management network element in performing the corresponding functions described in the third aspect. The memory is coupled to the processor and stores necessary program instructions and data for the communication device. The communication device also includes a communication interface for communicating with other devices.
[0044] In a fourteenth aspect, embodiments of this application also provide a communication device applied to a mobile access management network element. The beneficial effects are described in the fourth aspect and will not be repeated here. The communication device includes a processor and a memory. The processor is configured to support the mobile access management network element in performing the corresponding functions described in the fourth aspect. The memory is coupled to the processor and stores necessary program instructions and data for the communication device. The communication device also includes a communication interface for communicating with other devices.
[0045] In a fifteenth aspect, embodiments of this application also provide a communication device applied to a first terminal device. The beneficial effects are described in the first aspect and will not be repeated here. The communication device includes a processor and a memory. The processor is configured to support the first terminal device in performing the corresponding functions described in the first aspect. The memory is coupled to the processor and stores necessary program instructions and data for the communication device. The communication device also includes a transceiver for communicating with other devices.
[0046] In a sixteenth aspect, embodiments of this application also provide a communication system, the beneficial effects of which can be found in the descriptions of the previous aspects and will not be repeated here. The communication system includes a key management network element and a unified data management network element.
[0047] A key management network element is configured to receive a first key request from a first terminal device, the first key request including a first identifier; and after determining that the first key request includes a first identifier, to send a first request to a unified data management network element, the first request including a first identifier, wherein the first identifier is an anonymization identifier or temporary identifier of the second terminal device.
[0048] A unified data management network element is used to receive a first request; after determining that the first request includes a first identifier, it determines the user permanent identifier (SUPI) of the second terminal device based on the first identifier; and sends a first response to the key management network element, the first response including the SUPI of the second terminal device.
[0049] The key management network element is also used to receive the first response; to perform an authorization check on the second terminal device according to the SUPI of the second terminal device; and after the authorization check on the second terminal device is passed, to send a first key response to the first terminal device. The first key response includes secure communication parameters, which are used by the first terminal device to establish secure communication with the second terminal device.
[0050] In one possible design, the first response and the first key response also include the GPSI of the second terminal device. The unified data management network element is also used to determine the GPSI of the second terminal device based on the SUPI of the second terminal device.
[0051] In one possible design, the first response and the first key response also include a first identifier, and the unified data management network element can store the correspondence between the first identifier and the SUPI of the second terminal device.
[0052] In one possible design, the key management network element sends a first instruction to the unified data management network element. The first instruction is used to indicate the correspondence between the stored first identifier and the SUPI of the second terminal device. The unified data management network element is also used to receive the first instruction and then store the first identifier and the SUPI of the second terminal device.
[0053] In one possible design, after the key management network element fails the authorization check of the second terminal device, it notifies the unified data management network element to delete the correspondence between the first identifier and the SUPI of the second terminal device.
[0054] The unified data management network element is also used to delete the correspondence between the first identifier and the SUPI of the second terminal device under the notification of the key management network element.
[0055] In one possible design, when the unified data management network element determines the SUPI of the second terminal device based on the anonymized identifier of the second terminal device, it obtains the SUPI of the second terminal device from the user identifier de-hiding network element based on the anonymized identifier of the second terminal device.
[0056] In one possible design, when the unified data management network element determines the SUPI of the second terminal device based on the temporary identifier of the second terminal device, it determines the SUPI of the second terminal device based on the stored correspondence between the SUPI of the terminal device and the temporary identifier.
[0057] In one possible design, before determining the SUPI of the second terminal device based on its temporary identifier, the unified data management network element can assign a temporary identifier to the second terminal device, send the temporary identifier to the second terminal device through the neighboring service network element, and store the correspondence between the second terminal device's SUPI and the temporary identifier. Alternatively, it can obtain the temporary identifier assigned to the second terminal device by the neighboring service network element and store the correspondence between the second terminal device's SUPI and the temporary identifier.
[0058] In one possible design, the system also includes a session management network element.
[0059] The session management network element is used to receive information reported by the terminal device from the first terminal device. The information reported by the terminal device includes a second identifier and IP information assigned by the first terminal device to the second terminal device. The second identifier is one of the following: anonymization identifier, temporary identifier, or GPSI. After determining that the terminal reported message includes the second identifier, the user identity resolution request is sent to the unified data management network element. The user identity resolution request includes the second identifier.
[0060] The unified data management network element is also used to receive user identity resolution requests, determine the SUPI of the second terminal device based on the second identifier, and send a user resolution response to the session management network element, wherein the user resolution response includes the SUPI of the second terminal device;
[0061] The session management network element is also used to receive user resolution responses and to perform service control on the second terminal device based on the SUPI and IP information of the second terminal device.
[0062] In one possible design, the system also includes a mobile access management network element.
[0063] The mobile access management network element is used to receive terminal-reported messages from the first terminal device. The terminal-reported messages include a second identifier and IP information allocated by the first terminal device to the second terminal device. The second identifier is one of the following: the anonymized identifier of the second terminal device, the temporary identifier of the second terminal device, or the GPSI of the second terminal device. The mobile access management network element sends an identifier resolution request to the unified data management network element. The identifier resolution request includes the second identifier.
[0064] The unified data management network element is also used to receive identifier resolution requests, determine the SUPI of the second terminal device based on the second identifier, and send an identifier resolution response to the mobile access management network element, wherein the identifier resolution response includes the SUPI of the second terminal device;
[0065] The mobile access management network element is also used to receive identifier resolution responses and send the SUPI and IP information of the second terminal device to the session management network element.
[0066] In one possible design, the system also includes a first terminal device;
[0067] The first terminal device is used to send a first key request to the key management network element and receive a first key response from the key management network element; after establishing secure communication with the second terminal device based on secure communication parameters, it sends a terminal reporting message to the session management network element through the mobile access management network element.
[0068] In one possible design, the system also includes a proximity service network element; the proximity service network element is used to assign temporary identifiers to the second terminal device and send the temporary identifiers to the unified data management network element.
[0069] In a seventeenth aspect, this application also provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods described in the above aspects.
[0070] In an eighteenth aspect, this application also provides a computer program product containing instructions that, when run on a computer, cause the computer to perform the methods described in the above aspects.
[0071] In a nineteenth aspect, this application also provides a computer chip connected to a memory, the chip being used to read and execute a software program stored in the memory, and to perform the methods described in the above aspects. Attached Figure Description
[0072] Figure 1 An architecture diagram of a system provided in an embodiment of this application;
[0073] Figure 2 A schematic diagram illustrating a method for obtaining a terminal device identifier provided in an embodiment of this application;
[0074] Figure 3 A schematic diagram illustrating a first method for obtaining a terminal device identifier provided in an embodiment of this application;
[0075] Figure 4 A schematic diagram illustrating a second method for obtaining a terminal device identifier provided in an embodiment of this application;
[0076] Figure 5 A schematic diagram illustrating a third method for obtaining a terminal device identifier provided in an embodiment of this application;
[0077] Figure 6 A schematic diagram illustrating the fourth method for obtaining a terminal device identifier provided in this application embodiment;
[0078] Figure 7 A schematic diagram illustrating the fifth method for obtaining a terminal device identifier provided in this application embodiment;
[0079] Figure 8 A schematic diagram illustrating a sixth method for obtaining a terminal device identifier provided in an embodiment of this application;
[0080] Figures 9-15 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. Detailed Implementation
[0081] See Figure 1The diagram illustrates a specific network architecture applicable to this application. This network architecture is for a 5G system. The network elements in this 5G architecture include user equipment (UE). The network architecture also includes radio access network (RAN), access and mobility management function (AMF) network elements, session management function (SMF) network elements, user plane function (UPF) network elements, unified data management (UDM) network elements, application function (AF) network elements, and data network (DN), etc.
[0082] A terminal device is a device with wireless transceiver capabilities that can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as on ships); and it can be deployed in the air (such as on airplanes, balloons, and satellites). The terminal device can be a mobile phone, tablet computer, computer with wireless transceiver capabilities, virtual reality (VR) terminal, augmented reality (AR) terminal, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical care, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, etc. In the embodiments of this application, the terminal device can be divided into two types: remote UE (such as a second terminal device) and relay UE (such as a first terminal device). A remote UE refers to a UE that needs to communicate with the data network through a relay UE, while a relay UE is a UE that can communicate directly with the data network.
[0083] In this embodiment of the application, the remote UE can send the remote UE's anonymized identifier or the assigned temporary identifier to the relay UE, and the relay UE can send the anonymized identifier or the assigned temporary identifier sent by the remote UE to the PKMF network element.
[0084] The primary function of the RAN (Radio Access Network) is to control user access to the mobile communication network via radio. The RAN is part of a mobile communication system. It implements a radio access technology. Conceptually, it resides between devices (such as a mobile phone, a computer, or any remote control unit) and provides connectivity to its core network.
[0085] The AMF network element is responsible for terminal access management and mobility management. In practical applications, it includes the mobility management function in the MME of the LTE network framework, and adds access management function.
[0086] SMF network elements are responsible for session management, such as user session establishment.
[0087] UPF network elements are user plane functional network elements, mainly responsible for connecting to external networks. They include the related functions of LTE Serving Gateway (SGW) and Public Data Network Gateway (PDN-GW).
[0088] A DN is a network that provides services to terminals. For example, some DNs provide Internet access to terminals, while others provide SMS functionality.
[0089] UDM network elements can store user subscription information, similar to HSS in 4G. In this embodiment, UDM can determine the user permanent identifier (SUPI) of the terminal device based on the anonymized identifier or temporary identifier of the remote UE.
[0090] An AF network element can be a third-party application control platform or the operator's own equipment. An AF network element can provide services to multiple application servers.
[0091] Although not shown, the core network elements also include proximity-based services key management function (PKMF) network elements, subscription identifier de-concealing function (SIDF) network elements, proximity-based services (ProSe) network elements, unified data repository (UDR) network elements, and bootstrapping server function (BSF) network elements.
[0092] The PKMF network element is used to manage keys for UEs communicating with ProSe. The PKMF can be deployed independently or co-deployed with other network elements, such as the PKMF network element, which can be co-deployed with the ProSe network element.
[0093] In this embodiment, the SIDF network element is capable of decrypting SUCI to obtain SUPI. The SIDF can be deployed independently or co-deployed with other network elements, such as the SIDF network element co-deployed with the UDM network element.
[0094] The ProSe network element supports network-related actions required by ProSe. The ProSe network element has the following functions: Function 1, direct configuration, used to provide necessary parameters to the UE, such as temporary identifiers. Function 2, direct discovery name management, used to enable ProSe direct discovery and allocate ProSe application codes. In this embodiment, the ProSe network element can allocate temporary identifiers to the UE and notify the UE of the allocated temporary identifiers, which can be sent to the UDM network element.
[0095] UDR network elements are mainly used to store user-related contract data, policy data, structured data for public access, and application data.
[0096] In this embodiment, the BSF network element can provide the PKMF network element with the secure communication parameters required for the relay UE and the remote UE to establish secure communication.
[0097] In this embodiment, the key management network element can receive a first key request carrying a first identifier from the first terminal device. This first identifier is either an anonymization identifier or a temporary identifier for the second terminal device. After determining that the first key request carries the first identifier, the key management network element can request the unified data management network element to obtain the permanent user identifier of the second terminal device based on the first identifier. Then, the key management network element can perform an authorization check on the second terminal device based on the permanent user identifier. If the authorization check passes, it can send secure communication parameters to the first terminal device to establish secure communication. In this embodiment, the first terminal device no longer needs to provide its permanent user identifier to the key management network element; the key management network element can obtain the permanent user identifier from the unified data management network element for authorization checks, thus ensuring the security of the permanent user identifier of the second terminal device.
[0098] The method for obtaining the terminal device identifier provided in the embodiments of this application will be described below with reference to the accompanying drawings. Figure 2 The method includes:
[0099] Step 201: The key management network element receives a first key request from the first terminal device. The first key request includes a first identifier, which is an anonymization identifier or temporary identifier of the second terminal device.
[0100] Step 202: The key management network element determines that the first key request includes the first identifier.
[0101] After receiving the first key request, the key management network element parses the first key request and determines that the first key request includes a first identifier. In order to obtain the user permanent identifier of the second terminal device, it can execute step 203.
[0102] Step 203: The key management network element sends a first request to the unified data management network element. The first request includes a first identifier.
[0103] Step 204: The unified data management network element receives the first request from the key management network element and obtains the user permanent identifier of the second terminal device based on the first identifier.
[0104] Step 205: The unified data management network element sends a first response to the key management network element. The first response includes the user's permanent identifier of the second terminal device.
[0105] Step 206: The key management network element performs an authorization check on the second terminal device based on the user's permanent identifier.
[0106] Step 207: After the key management network element passes the authorization check of the second terminal device, it can send a first key response to the first terminal device. The first key response includes secure communication parameters.
[0107] When the second terminal device needs to communicate with the data network, it can initiate a direct communication request to the first terminal device. The direct communication request can carry the anonymized identifier or temporary identifier of the second terminal device.
[0108] Among them, the anonymized identifier or temporary identifier is an identifier pre-assigned to the second terminal device. The anonymized identifier can be a permanent identifier that hides the terminal device. Only specific network elements can obtain the information of the terminal device hidden in the anonymized identifier. For example, the anonymized identifier can be a subscription concealed identifier (SUCI), which is a privacy-protected identifier that includes a subscription permanent identifier (SUPI).
[0109] In the embodiments of this application, the temporary identifier may be an identifier with a short validity period assigned to the second terminal device by a neighboring service network element (such as a ProSe network element) or a unified data management network element.
[0110] For example, a neighboring service network element can send a temporary identifier to the second terminal device during the registration process. Specifically, this temporary identifier can be assigned to the second terminal device by the neighboring service network element when it receives the registration request from the second terminal device, and the neighboring service network element sends this temporary identifier to the second terminal device in the registration request response message. After assigning the temporary identifier to the second terminal device, the neighboring service network element can send the temporary identifier of the second terminal device to the unified data management network element. After receiving the temporary identifier of the second terminal device, the unified data management network element can locally save the correspondence between the temporary identifier of the second terminal device and the permanent identifier of the user.
[0111] For example, the unified data management network element can also assign a temporary identifier to the second terminal device during the registration process. After assigning the temporary identifier, the unified data management network element can locally store the correspondence between the temporary identifier of the second terminal device and the user's permanent identifier. The unified data management network element can also send the temporary identifier of the second terminal device to the neighboring service network element. Furthermore, the neighboring service network element sends the received temporary identifier to the second terminal device.
[0112] It should be noted that the neighboring service network element or the unified data management network element can periodically update the temporary identifier of the second terminal device. After updating the temporary identifier of the second terminal device, the neighboring service network element or the unified data management network element can send the updated temporary identifier of the second terminal device to the second terminal device. If the neighboring service network element updates the temporary identifier of the second terminal device, it can send the updated temporary identifier of the second terminal device to the unified data management network element so that the unified data management network element can update the temporary identifier of the second terminal device stored locally.
[0113] After receiving a direct communication request, in order to determine whether the second terminal device has the right to use the first terminal device for communication, the first terminal device may execute step 201 to send a first key request to the key management network element, so as to request the key management network element to perform an authorization check on the first terminal device.
[0114] If the key management network element parses the first key request and determines that the identifier carried in the first key request is the anonymized identifier or temporary identifier of the second terminal device, it cannot perform authorization checks on the second terminal device based on the anonymized identifier or temporary identifier of the second terminal device. The key management network element can then execute step 203, sending a first request carrying the first identifier to request the unified data management network element to obtain the user's permanent identifier for the second terminal device.
[0115] Upon receiving the first request, the unified data management network element can determine the permanent user identifier of the second terminal device based on the anonymized identifier or temporary identifier of the second terminal device, and send a first response including the permanent user identifier of the second terminal device to the key management network element.
[0116] The first request and the first response can be information from the existing interaction process between the key management network element and the unified data management network element.
[0117] For example, the first request could be a secure communication parameter acquisition request, which is used to request the secure communication parameters required for the first terminal device and the second terminal device to establish secure communication from the unified data management network element. The key management network element may carry the anonymized identifier or temporary identifier of the second terminal device in the secure communication parameter acquisition request. The secure communication parameter acquisition request can also be used to request the user's permanent identifier of the second terminal device from the unified data management network element.
[0118] Accordingly, the first response is a secure communication parameter acquisition response, which carries the secure communication parameters required for the first terminal device and the second terminal device to establish secure communication, as well as the user's permanent identifier of the second terminal device.
[0119] It should be noted that the above description is only based on the example that the first request is a request to obtain secure communication parameters and the first response is a response to obtain secure communication parameters. The embodiments of this application do not limit the types of the first request and the first response. The first request and the first response can also be other information in the existing interaction process between the key management network element and the unified data management network element.
[0120] The first request and the first response can also be new information added in the interaction process between the key management network element and the unified data management network element, specifically used to request the acquisition of the user's permanent identifier of the second terminal device. For example, the first request is a first user identity resolution request, and the first response is a first user identity resolution response.
[0121] The following explains how the unified data management network element determines the permanent user identifier of the second terminal device based on the anonymized or temporary identifier of the second terminal device.
[0122] I. The unified data management network element determines the permanent user identifier of the second terminal device based on the anonymized identifier of the second terminal device.
[0123] The unified data management network element locally stores the correspondence between the anonymized identifier of the second terminal device and the permanent identifier of the user. Based on the stored correspondence, the unified data management network element can determine the permanent identifier of the user of the second terminal device according to the anonymized identifier of the second terminal device.
[0124] The unified data management network element can also obtain the permanent user identifier of the second terminal device from other network elements using the anonymized identifier of the second terminal device. Other network elements can be user identifier de-hiding function network elements or unified data warehouse network elements.
[0125] After obtaining the permanent user identifier of the second terminal device from other network elements, the unified data management network element can directly store the mapping between the anonymized identifier of the second terminal device and the permanent user identifier. Alternatively, the unified data management network element can first determine the attributes of the second terminal device and then determine whether to store the mapping between the anonymized identifier of the second terminal device and the permanent user identifier based on the attributes of the second terminal device.
[0126] For example, a unified data management network element can query the subscription information of a second terminal device based on the user's permanent identifier to determine whether the second terminal device is a commercial user. If the second terminal device is a commercial user, the unified data management network element can store the corresponding relationship. If the second terminal device is not a commercial user, such as a mission-critical user, the unified data management network element does not store the corresponding relationship.
[0127] In the above description, the unified data management network element can actively store the correspondence. Of course, in practical applications, the unified data management network element can also store the correspondence under the instruction of the key management network element.
[0128] For example, a key management network element can send a first instruction to a unified data management network element. This first instruction indicates that the unified data management network element stores the correspondence between the anonymized identifier of the second terminal device and the user's permanent identifier. This application does not limit the method or timing of the key management network element sending the first instruction. The key management network element can send the first instruction to the unified data management network element independently; for example, the key management network element can send the first instruction to the unified data management network element in advance, or it can send the first instruction after sending a first request. The key management network element can also send the first instruction after receiving a first response. The key management network element can also include the first instruction in a message that needs to be sent to the unified data management network element; for example, the key management network element can include the first instruction in a first request.
[0129] Second, the unified data management network element determines the permanent user identifier of the second terminal device based on the temporary identifier of the second terminal device.
[0130] The unified data management network element locally stores the correspondence between the temporary identifier of the second terminal device and the permanent identifier of the user. Based on the stored correspondence, the unified data management network element can determine the permanent identifier of the user of the second terminal device according to the temporary identifier of the second terminal device.
[0131] The unified data management network element can also store the mapping relationship between the temporary identifier of the second terminal device and the permanent identifier of the user in other network elements, such as the unified data warehouse network element. The unified data management network element can obtain this mapping relationship from other network elements, and then determine the permanent identifier of the user of the second terminal device based on the temporary identifier of the second terminal device.
[0132] Optionally, after obtaining the permanent user identifier of the second terminal device, the unified data management network element can also determine the generic public subscription identifier (GPSI) of the second terminal device.
[0133] The method by which the unified data management network element determines the general public user identifier of the second terminal device based on the user's permanent identifier is similar to the method by which the unified data management network element determines the user's permanent identifier of the second terminal device based on the first identifier. For details, please refer to the aforementioned content, which will not be repeated here.
[0134] After receiving the first response from the unified data management network element, the key management network element obtains the permanent user identifier of the second terminal device and can then perform an authorization check on the second terminal device based on the permanent user identifier.
[0135] The key management network element can store a set of identifiers. The identifiers in this set are permanent user identifiers of terminal devices that can communicate directly with the first terminal device. In other words, the terminal devices indicated by each permanent user identifier in the identifier set can establish a connection with the communication system through the first terminal device, perform data interaction, and have the right to use the first terminal device for communication.
[0136] Based on this identifier set, the key management network element can perform an authorization check on the second terminal device according to the user's permanent identifier. In other words, the key management center determines whether the user's permanent identifier of the second terminal device is an identifier in this identifier set.
[0137] When the user permanent identifier of the second terminal device is an identifier in the identifier set, the key management network element passes the authorization check of the second terminal device.
[0138] If the first response is a secure communication parameter acquisition response, the key management network element can directly execute step 207.
[0139] If the first response is a first user identity resolution response, after the key management network element passes the authorization check of the second terminal device, it can send a secure communication parameter acquisition request to the unified data management network element to obtain the secure communication parameters from the unified data management network element, and then execute step 207. The first key response may also include a first identifier and a general public user identifier for the second terminal device. The first identifier or the general public user identifier can indicate the second terminal device; that is, the secure communication parameters carried in the first key response are the secure communication parameters required to establish secure communication with the second terminal device.
[0140] Optionally, the key management network element interacts with the unified data management network element to obtain the user's permanent identifier for the second terminal device. After the key management network element performs an authorization check on the second terminal device and passes the check, it can also use the user's permanent identifier to interact with the guidance service function network element (such as the BSF network element) to obtain secure communication parameters.
[0141] If the user's permanent identifier of the second terminal device is not an identifier in the identifier set, the key management network element fails the authorization check of the second terminal device. The key management network element can send a second instruction to the first terminal device. The second instruction is used to indicate that the authorization check of the second terminal device has failed. After receiving the second instruction, the first terminal device can terminate or refuse to communicate with the second terminal device and not provide services to the second terminal device.
[0142] The key management network element can also notify the unified data management network element to delete the correspondence between the anonymized identifier of the second terminal device and the permanent identifier of the user. Under the notification of the key management network element, the unified data management network element deletes the saved correspondence between the anonymized identifier of the second terminal device and the permanent identifier of the user.
[0143] After the key management network element passes the authorization check of the second terminal device, and the first terminal device receives the first key response, it can establish secure communication with the second terminal device based on the secure communication parameters carried in the first key response. During the establishment of secure communication, the first terminal device can send a direct security mode command to the second terminal device. This direct security mode command includes key-related information, which is determined by the secure communication parameters (for example, the secure communication parameters may include this key-related information). After receiving the direct security mode command, the second terminal device can generate a security key based on the key-related information. This security key can be used to encrypt and / or protect the integrity of the data exchanged between the second and first terminal devices. After generating the security key, the second terminal device sends a direct security mode completion message to the first terminal device to notify it that the direct security mode has been completed.
[0144] After establishing secure communication with the second terminal device, the first terminal device may send a direct communication response to the second terminal device in response to the direct communication request sent by the second terminal device.
[0145] The first terminal device can assign an Internet Protocol (IP) address to the second terminal device. This IP address is used by the second terminal device to communicate with the data network using the first terminal device. This IP address can be an Internet Protocol version 6 (IPv6) prefix or an IPv4 address.
[0146] The process by which the second terminal device communicates with the data network through the first terminal device based on the IP address is as follows: The second terminal device uses the IP address (such as an IPv6 prefix or IPv4 address) assigned to it by the first terminal device to encapsulate data and generate a data packet, and then sends the data packet to the first terminal device.
[0147] For data packets encapsulated using IPv4 addresses, the first terminal device receives the packet and converts the IPv4 address of the packet into the IPv4 address of the PDU session (the PDU session's IPv4 address is assigned to the first terminal device by the network side). This PDU session is used for trunk services. The first terminal device then sends the data packet with the converted IPv4 address through a specific port. This data packet also carries the port number of that specific port, which is assigned by the first terminal device for transmitting data packets from the second terminal device.
[0148] For data packets encapsulated using the IPv6 prefix, the first terminal device can directly send the data packet to the PDU session.
[0149] When the first terminal device receives a data packet from the data network that needs to be sent to the second terminal device, it determines that the data packet is indeed intended for the second terminal device by parsing the IP address or port number of the data packet, and then sends the data packet to the second terminal device. Specifically, for data packets encapsulated with IPv4 addresses, the first terminal device identifies the second terminal device by the port number of the data packet.
[0150] After the first terminal device assigns an IP address to the second terminal device, the first terminal device can send terminal reporting information carrying the IP information of the second terminal device to the session management network element, so that the session management network element can perform service control based on the IP information, such as legitimate eavesdropping and usage statistics.
[0151] If the IP address assigned by the first terminal device to the second terminal device is an IPv6 prefix, then the IP information is that IPv6 prefix.
[0152] If the first terminal device assigns an IPv4 address to the second terminal device, since the first terminal device usually needs to assign a port number to the second terminal device for transmitting data packets, the first terminal device will subsequently use the port number carried in the data packet to determine that the data packet comes from the second terminal device. The IP information can be the range of port numbers assigned by the first terminal device to the second terminal device.
[0153] The terminal-reported information may also include a second identifier, which can be any of the following: an anonymized identifier of the second terminal device, a temporary identifier of the second terminal device, or a general public identifier of the second terminal device, used to identify the second terminal device. The second identifier in the terminal-reported information may be obtained by the first terminal device from the key management network element, or it may be obtained from the second terminal device. After receiving the terminal-reported information, the session management network element determines that the terminal-reported information includes a second identifier. To determine the true identity of the second terminal device, the session management network element may request the user's permanent identifier of the second terminal device from the unified data management network element.
[0154] For example, the session management network element can send a second user identity resolution request to the unified data management network element, the second user identity resolution request carrying a second identifier. After receiving the second user identity resolution request, the unified data management network element determines the permanent user identifier of the second terminal device based on the second identifier, and then sends a second user identity resolution response carrying the permanent user identifier of the second terminal device to the session management network element. After receiving the second user identity resolution response, the session management network element obtains the permanent user identifier of the second terminal device.
[0155] The method by which the unified data management network element determines the permanent user identifier of the second terminal device based on the second identifier can be found in the foregoing description, and will not be repeated here.
[0156] It should be noted that, in this embodiment of the application, the second identifier can also be the permanent identifier of the user of the second terminal device. In this case, the session management network element does not need to obtain the permanent identifier of the user from the unified data management network element, and can directly perform service control based on IP information, such as legitimate eavesdropping and usage statistics.
[0157] In the above description, the session management network element needs to interact with the unified data management network element to obtain the user's permanent identifier for the second terminal device. As one possible implementation, the mobile access management network element can also interact with the unified data management network element to obtain the user's permanent identifier for the second terminal device, and then the mobile access management network element will send the obtained user's permanent identifier for the second terminal device to the session management network element.
[0158] For example, the first terminal device can send an N1 message to the Mobile Access Management Network (MAM), which includes a second identifier and an N1 SM message, the N1 SM message including IP information. Upon receiving the second identifier, the MAM can initiate an identifier resolution process, sending an identifier resolution request carrying the second identifier to the Unified Data Management Network (UDN). Upon receiving the identifier resolution request, the UDN can determine the user's permanent identifier for the second terminal device based on the second identifier. Then, the UDN sends an identifier resolution response carrying the user's permanent identifier to the MAM. The MAM then sends the user's permanent identifier and the N1 SM message to the Session Management Network (SMN). The user's permanent identifier and the N1 SM message can be carried in an Nsmf message, allowing the SMN to obtain the user's permanent identifier from the Nsmf message.
[0159] In this embodiment, the first terminal device is allowed to send a second key request to the key management network element. The second key request may contain the International Mobile Subscriber Identity (IMSI) of the second terminal device. After receiving the second key request, the key management network element can perform an authorization check on the second terminal device based on the IMSI of the second terminal device. After the authorization check on the second terminal device is passed, the key management network element can obtain secure communication parameters from the unified data management network element. After obtaining the secure communication parameters, the key management network element can send a second key response to the first terminal device, which carries the secure communication parameters.
[0160] The following is based on, Figure 1 The network architecture shown takes the key management network element as the PKMF network element, the unified data management network element as the UDM network element, the session management network element as the SMF network element, the mobile access management network element as the AMF network element, and the proximity service network element as the ProSe network element as an example. Figure 2 The method for obtaining the terminal device identifier shown will be further described.
[0161] (a) The first identifier is SUCI.
[0162] like Figure 3The image shows a method for obtaining a terminal device identifier provided in an embodiment of this application. The method includes:
[0163] Step 301: The relay UE initiates a registration process with the AMF network element through the RAN, so that the UE registers with the 5G system.
[0164] Step 302: When a remote UE needs to interact with the data network, it initiates a discovery process to discover relay UEs. In the discovery process, the remote UE detects nearby relay UEs through wireless signals and identifies the relay UE.
[0165] Step 303: After discovering the relay UE, the remote UE can send a direct communication request to the relay UE. The direct communication request is used to request the establishment of a communication connection with the relay UE. The direct communication request includes the remote UE's SUCI.
[0166] Step 304: After receiving the direct communication request, the relay UE can send a first key request to the PKMF network element, which includes SUCI.
[0167] The embodiments of this application do not limit the function of the first key request. The first key request can be used to request the PKMF network element to perform an authorization check on the remote UE, or to request the allocation of a security key for the remote UE, or to request the security communication parameters required for the remote UE to establish secure communication with the relay UE.
[0168] It should be noted that the relay UE can send the first key request directly to the PKMF network element, or it can send the first key request to the PKMF network element through other network elements.
[0169] Step 305: The PKMF network element receives the first key request, determines that the first key request carries a SUCI, selects a UDM network element according to the SUCI, and sends a first user identity resolution request carrying the SUCI to the UDM network element to request the UDM network element to resolve the SUCI.
[0170] Step 306: After receiving the first user identity resolution request, the UDM network element obtains the SUCI from the first user identity resolution request. The UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE.
[0171] This application does not limit the method by which the UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE. For example, the UDM network element itself has decryption capabilities and can directly decrypt the SUCI of the remote UE to obtain the SUPI of the remote UE. Alternatively, the UDM network element can call other network elements (such as the SIDF network element) to obtain the SUPI of the remote UE from those other network elements.
[0172] Optionally, the UDM network element can also store the correspondence between the SUCI and SUPI of the remote UE. This application embodiment does not limit the location where the UDM network element stores this correspondence. For example, the UDM network element can store the correspondence locally, or it can store it in other network elements (such as the UDR network element). When it is necessary to determine the SUCI or SUPI of the remote UE later, the stored correspondence between the SUCI and SUPI of the remote UE can be obtained from other network elements.
[0173] It should be noted that UDM network elements can proactively store the mapping relationship between the SUCI and SUPI of remote UEs. For example, after determining the SUPI of a remote UE based on its SUCI, the UDM network element can directly store the mapping relationship, or it can first determine whether to store the mapping relationship based on the attributes of the remote UE. The UDM network element can query the subscription information of a remote UE based on its SUPI, and after determining that the remote UE is a business user, it can store the mapping relationship.
[0174] UDM network elements can also save the mapping between SUCI and SUPI of remote UEs under the instruction of PKMF network elements. PKMF network elements can send a first instruction to UDM network elements to instruct them to save the mapping between SUCI and SUPI of remote UEs. Upon receiving this first instruction, UDM network elements can save the mapping between SUCI and SUPI of remote UEs. This first instruction message can be sent separately or included in a message sent by PKMF network elements to UDM network elements (such as a first user identity resolution request).
[0175] Step 307: After determining the SUPI of the remote UE, the UDM network element sends a first user identity resolution response to the PKMF network element, which carries the SUPI of the remote UE.
[0176] Optionally, the UDM network element can also determine the GPSI of the remote UE based on the SUPI of the remote UE after determining the SUPI of the remote UE, and carry the GPSI of the remote UE in the first user identity resolution response.
[0177] Step 308: After receiving the first user identity resolution response, the PKMF network element obtains the SUPI of the remote UE from the first user identity resolution response. Based on the SUPI of the remote UE, the PKMF network element performs an authorization check on the remote UE to determine whether the remote UE is authorized to connect to the network through the selected relay UE and interact with the DN for data exchange.
[0178] The PKMF network element can pre-store a set of SUPIs, which includes one or more SUPIs. The terminal device corresponding to each SUPI in the set can connect to the network through the relay UE. The PKMF network element can determine whether the SUPI of the remote UE belongs to the set of SUPIs. If it does, the PKMF network element passes the authorization check of the remote UE, and the remote UE can interact with the 5G system through the relay UE. Otherwise, the PKMF network element fails the authorization check of the remote UE.
[0179] Optionally, the first user identity resolution response may also carry the GPSI of the remote UE.
[0180] Step 309: After the PKMF network element passes the authorization check for the remote UE, the PKMF network element obtains the secure communication parameters from the UDM network element. These secure communication parameters are the parameters required for the relay UE and the remote UE to establish secure communication. These secure communication parameters may include key-related information used to generate the secure key.
[0181] Optionally, PKMF network elements can also obtain this secure communication parameter through other network elements such as BSF network elements.
[0182] If the PKMF network element fails the authorization check for the remote UE, it can send an authorization failure indication message to the relay UE, causing the relay UE to terminate or refuse to serve the remote UE. The PKMF network element can also notify the UDM network element to delete the saved mapping between the remote UE's SUCI and SUPI. Upon receiving this notification, the UDM network element will delete the mapping if it has already saved the mapping between the remote UE's SUCI and SUPI; otherwise, it will ignore the notification.
[0183] Step 310: After the PKMF network element obtains the secure communication parameters, it can send a first key response to the relay UE, which includes the secure communication parameters.
[0184] Optionally, the first key response may also carry the SUCI of the remote UE. The SUCI of the remote UE carried in the first key response is used to relay the UE to provide this information to the core network element, such as the SMF or AMF element.
[0185] It should be noted that when the first key request is used to request the PKMF network element to perform an authorization check on the remote UE, the first key response may not carry secure communication parameters. That is, the PKMF network element does not need to execute step 309. After the authorization check on the remote UE is passed, the PKMF network element directly sends the first key response, indicating that the authorization check on the remote UE has passed. When the first key request is used to request the acquisition of secure communication parameters, the first key response carries secure communication parameters including key-related information.
[0186] It should be noted that if the first user identity resolution response carries the GPSI of the remote UE, the first key response may not carry the SUCI, but may carry the GPSI of the remote UE.
[0187] Step 311: After receiving the first key response, the relay UE establishes secure communication with the remote UE based on the secure communication parameters.
[0188] Step 312: The relay UE sends a direct communication response to the remote UE, which is used to respond to the direct communication request.
[0189] Step 313: The relay UE assigns the IP address required for communication to the remote UE.
[0190] Specifically, the IP address can be an IPv6 prefix or an IPv4 address.
[0191] Step 314: The relay UE needs to send terminal reporting information to the SMF network element. This terminal reporting message includes the remote UE's SUCI and IP information. If the IP address in step 313 is an IPv6 prefix, then the IP information is the IPv6 prefix allocated by the relay UE to the remote UE. If the IP address in step 313 is an IPv4 address, then the IP information is the range of port numbers allocated by the relay UE to the remote UE.
[0192] The SUCI of the remote UE carried by the relay UE in the terminal reporting message can be obtained from the first key response or from the direct communication request.
[0193] Step 315: After receiving the terminal's reported information, the SMF network element determines that the terminal's reported information carries a SUCI, and then sends a second user identity resolution request carrying the SUCI to the UDM network element to request the UDM network element to resolve the SUCI.
[0194] Step 316: After receiving the second user identity resolution request, the UDM network element obtains the SUCI from the second user identity resolution request. The UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE.
[0195] The method by which the UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE is similar to the method by which the UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE in step 306. For details, please refer to the above content, which will not be repeated here.
[0196] It should be noted that if the UDM network element stores the correspondence between the SUCI and SUPI of the remote UE, the UDM network element can directly determine the SUPI of the remote UE based on this correspondence when determining the SUPI of the remote UE based on the SUCI.
[0197] Optionally, if the UDM network element stores the correspondence between the SUCI and SUPI of the remote UE, the UDM network element can delete the correspondence after determining the SUPI of the remote UE based on the SUCI of the remote UE.
[0198] Step 317: After determining the SUPI of the remote UE, the UDM network element sends a second user identity resolution response to the SMF network element, which carries the SUPI of the remote UE.
[0199] Step 318: After receiving the second user identity resolution response, the SMF network element obtains the remote UE's SUPI from the response. Further, the SMF network element can perform service control based on the SUPI and the received IP information, such as legitimate eavesdropping and usage statistics. No limitations are specified here.
[0200] It should be noted that if the first key response in step 310 carries the GPSI of the remote UE, the SUCI of the remote UE in steps 314 to 316 can be replaced with the GPSI of the remote UE.
[0201] In such Figure 3 In the illustrated embodiment, the PKMF network element first requests the SUPI of the remote UE from the UDM network element, and then requests security communication parameters from the UDM network element or other network elements. To further reduce signaling interactions between the PKMF and UDM network elements, the PKMF network element can request security communication parameters simultaneously with requesting the SUPI of the remote UE from the UDM network element. For details, please refer to... Figure 4 The illustrated embodiments, such as Figure 4 The image shows a method for obtaining a terminal device identifier provided in an embodiment of this application. The method includes:
[0202] Steps 401 to 404 are the same as steps 301 to 304. For details, please refer to the above content. They will not be repeated here.
[0203] Step 405: The PKMF network element receives the first key request, determines that the first key request carries a SUCI, selects a UDM network element according to the SUCI, and sends a security communication parameter acquisition request carrying the SUCI to the UDM network element. The security communication parameter acquisition request is used to request the acquisition of security communication parameters. The security communication parameter acquisition request includes the SUCI and is used to request the UDM network element to parse the SUCI.
[0204] Step 406: After receiving the security communication parameter acquisition request, the UDM network element determines the security communication parameters. The UDM network element also obtains the SUCI from the security communication parameter acquisition request. The UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE.
[0205] The method by which the UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE and saves the correspondence between the SUCI and SUPI of the remote UE can be found in the relevant description in step 306, which will not be repeated here.
[0206] Step 407: After determining the SUPI of the remote UE, the UDM network element sends a security communication parameter acquisition response back to the PKMF network element. The security communication parameter acquisition response carries the SUPI and security communication parameters of the remote UE.
[0207] Optionally, the UDM network element can also determine the GPSI of the remote UE based on the SUPI of the remote UE after determining the SUPI of the remote UE, and carry the GPSI of the remote UE in the secure communication parameter acquisition response.
[0208] Step 408: After receiving the security communication parameter acquisition response, the PKMF network element obtains the SUPI of the remote UE from the response. Based on the SUPI of the remote UE, the PKMF network element performs an authorization check on the remote UE to determine whether the remote UE is authorized to connect to the network through the selected relay UE and interact with the DN for data exchange.
[0209] Step 409: After the PKMF network element obtains the secure communication parameters, it can send a first key response to the relay UE, which includes the secure communication parameters.
[0210] Step 410: After the PKMF network element passes the authorization check of the remote UE, it establishes secure communication with the remote UE based on the secure communication parameters.
[0211] Steps 411 to 417 are the same as steps 312 to 318. For details, please refer to the above content, which will not be repeated here.
[0212] In such Figure 3 or Figure 4In the illustrated embodiment, after the PKMF network element passes the authorization check of the remote UE, the first key response sent to the relay UE carries the SUCI of the remote UE. The PKMF network element can also directly inform the relay UE of the SUPI of the remote UE. See the following embodiment for details.
[0213] like Figure 5 The image shows a method for obtaining a terminal device identifier provided in an embodiment of this application. The method includes:
[0214] Steps 501 to 509 are the same as steps 301 to 309. For details, please refer to the above content. They will not be repeated here.
[0215] Step 510: After the PKMF network element obtains the secure communication parameters, it can send a first key response to the relay UE, which includes the secure communication parameters.
[0216] Optionally, the first key response may also carry the SUPI of the remote UE.
[0217] Steps 511 to 513 are the same as steps 311 to 313. For details, please refer to the above content, which will not be repeated here.
[0218] Step 514: The relay UE needs to send terminal reporting information to the SMF network element. This terminal reporting message includes the remote UE's SUPI and IP information. If the IP address in step 513 is an IPv6 prefix, then the IP information is the IPv6 prefix allocated by the relay UE to the remote UE. If the IP address in step 513 is an IPv4 address, then the IP information is the port number range allocated by the relay UE to the remote UE. The IPv4 address corresponds to this port number range.
[0219] The SUCI of the remote UE carried by the relay UE in the terminal reporting message can be obtained from the first key response or from the direct communication request.
[0220] Step 515: The SMF network element obtains the SUPI of the remote UE from the terminal's report message. Further, the SMF network element can perform service control based on the SUPI and the received IP information, such as legitimate eavesdropping and usage statistics. No limitations are specified here.
[0221] It should be noted that, in cases such as Figure 5 In the illustrated embodiment, the PKMF network element can also directly send a security parameter retrieval request carrying the SUCI to the UDM network element. The UDM network element determines the remote SUPI based on the SUCI and determines the security communication parameters. Then, the UDM network element sends a security parameter retrieval response to the PKMF, which includes the remote SUPI and the security communication parameters.
[0222] In this embodiment, the SMF network element does not need to interact with the UDM network element to determine the SUPI of the remote UE, which further reduces signaling interaction.
[0223] (ii) The first identifier is a temporary identifier for the remote UE.
[0224] like Figure 6 The image shows a method for obtaining a terminal device identifier provided in an embodiment of this application. The method includes:
[0225] Step 601: The ProSe network element assigns a temporary identifier to the remote UE.
[0226] Step 602: The ProSe network element sends the temporary identifier assigned to the remote UE to the UDM network element.
[0227] After receiving the temporary identifier of the remote UE, the UDM network element can save the correspondence between the temporary identifier of the remote UE and the SUPI locally.
[0228] Step 603: The ProSe network element sends the temporary identifier of the remote UE to the remote UE.
[0229] Step 604: The relay UE initiates a registration process with the AMF network element through the RAN, so that the UE registers with the 5G system.
[0230] Step 605: When a remote UE needs to interact with the data network, it initiates a discovery process to discover relay UEs.
[0231] Step 606: After discovering the relay UE, the remote UE can send a direct communication request to the relay UE. The direct communication request is used to request the establishment of a communication connection with the relay UE. The direct communication request includes the temporary identifier of the remote UE.
[0232] Step 607: After receiving the direct communication request, the relay UE can send a first key request to the PKMF network element. The first key request includes a temporary identifier.
[0233] The relay UE can send the first key request directly to the PKMF network element, or it can send the first key request to the PKMF network element through other network elements.
[0234] For a description of the first key request, please refer to: Figure 3 The relevant descriptions in the illustrated embodiments will not be repeated here.
[0235] Step 608: The PKMF network element receives the first key request, determines that the first key request carries a temporary identifier, selects the UDM network element according to the temporary identifier, and sends a first user identity resolution request carrying the temporary identifier to the UDM network element to request the UDM network element to resolve the temporary identifier.
[0236] Step 609: After receiving the first user identity resolution request, the UDM network element obtains the temporary identifier from the first user identity resolution request. The UDM network element determines the SUPI of the remote UE based on the temporary identifier of the remote UE.
[0237] UDM network elements determine the SUPI of the remote UE based on the correspondence between the saved temporary identifier of the remote UE and the SUPI.
[0238] Step 610: After determining the SUPI of the remote UE, the UDM network element sends a first user identity resolution response to the PKMF network element, which carries the SUPI of the remote UE.
[0239] Steps 611 to 612 are the same as steps 308 to 309. For details, please refer to the above content. They will not be repeated here.
[0240] Step 613: After the PKMF network element obtains the secure communication parameters, it can send a first key response to the relay UE, which includes the secure communication parameters.
[0241] Optionally, the first key response may also carry a temporary identifier of the remote UE. The temporary identifier of the remote UE carried in the key response is used by the relay UE to provide this information to the core network element, such as the SMF or AMF network element.
[0242] Steps 614 to 616 are the same as steps 311 to 313. For details, please refer to the above content, which will not be repeated here.
[0243] Step 617: The relay UE needs to send terminal reporting information to the SMF network element. This terminal reporting message includes the temporary identifier and IP information of the remote UE. If the IP address in step 613 is an IPv6 prefix, then the IP information is the IPv6 prefix allocated by the relay UE to the remote UE. If the IP address in step 613 is an IPv4 address, then the IP information is the range of port numbers allocated by the relay UE to the remote UE.
[0244] The temporary identifier of the remote UE carried by the relay UE in the terminal reporting message can be obtained from the first key response or from the direct communication request.
[0245] Step 618: After receiving the terminal's reported information, the SMF network element determines that the terminal's reported information carries a temporary identifier, and then sends a second user identity resolution request carrying the temporary identifier to the UDM network element to request the UDM network element to resolve the temporary identifier.
[0246] Step 619: After receiving the second user identity resolution request, the UDM network element obtains the temporary identifier in the second user identity resolution request. The UDM network element determines the SUPI of the remote UE based on the temporary identifier of the remote UE.
[0247] The way the UDM network element determines the SUPI of the remote UE based on the temporary identifier of the remote UE is similar to the way the UDM network element determines the SUPI of the remote UE based on the temporary identifier of the remote UE in step 606. For details, please refer to the above content, which will not be repeated here.
[0248] Step 620: After determining the SUPI of the remote UE, the UDM network element sends a second user identity resolution response to the SMF network element, which carries the SUPI of the remote UE.
[0249] Step 621: After receiving the second user identity resolution response, the SMF network element obtains the remote UE's SUPI from the response. Further, the SMF network element can perform service control based on the SUPI and the received IP information, such as legitimate eavesdropping and usage statistics. No limitations are specified here.
[0250] It should be noted that, in cases such as Figure 6 In the illustrated embodiment, the PKMF network element can also directly send a security parameter acquisition request carrying a temporary identifier of the remote UE to the UDM network element. The UDM network element determines the remote SUPI and security communication parameters based on the temporary identifier. Then, the UDM network element sends a security parameter acquisition response to the PKMF, which includes the remote SUPI and security communication parameters.
[0251] Figure 6In the illustrated embodiment, the SMF network element needs to interact with the UDM network element to obtain the SUPI of the remote UE. As a possible implementation, the AMF network element can also interact with the UDM network element to obtain the SUPI of the remote UE. The remote UE can send an N1 message to the AMF network element, which includes the remote UE's temporary identifier and an N1SM message, the N1SM message including IP information. After receiving the remote UE's temporary identifier, the AMF network element can initiate an identifier resolution process, sending an identifier resolution request carrying the remote UE's temporary identifier to the UDM network element. After receiving the identifier resolution request, the UDM network element can determine the remote UE's SUPI based on the remote UE's temporary identifier. Then, the UDM network element sends an identifier resolution response carrying the remote UE's SUPI to the AMF network element. The AMF network element then sends an Nsmf message to the SMF network element, which includes the remote UE's SUPI and the N1SM message. The SMF network element can obtain the remote UE's SUPI from the Nsmf message.
[0252] In such Figure 6 In the illustrated embodiment, after the PKMF network element passes the authorization check of the remote UE, the first key response sent to the relay UE carries the temporary identifier of the remote UE. The PKMF network element can also directly inform the relay UE of the SUPI of the remote UE. See the following embodiment for details.
[0253] like Figure 7 The image shows a method for obtaining a terminal device identifier provided in an embodiment of this application. The method includes:
[0254] Steps 701 to 712 are the same as steps 601 to 612. For details, please refer to the above content. They will not be repeated here.
[0255] Steps 713 to 718 are the same as steps 510 to 515. For details, please refer to the above content. They will not be repeated here.
[0256] It should be noted that, in cases such as Figure 7 In the illustrated embodiment, the PKMF network element can also directly send a security parameter acquisition request carrying the temporary identifier of the remote UE to the UDM network element. The UDM network element determines the remote SUPI and security communication parameters based on the temporary identifier. Then, the UDM network element sends a security parameter acquisition response to the PKMF, which includes the remote SUPI and security communication parameters. In other words, the PKMF network element can request security communication parameters simultaneously with requesting the remote UE's SUPI from the UDM network element, reducing signaling interactions.
[0257] As one possible implementation, in this embodiment of the application, the relay UE may first obtain secure communication parameters, establish secure communication with the remote UE, and then request SUCI resolution from the UDM network element through the SMF network element or AMF network element.
[0258] See Figure 8 Taking the example of a relay UE requesting SUCI resolution from a UDM network element through an AMF network element, the method includes:
[0259] Steps 801 to 803 are the same as steps 301 to 303. For details, please refer to the above content. They will not be repeated here.
[0260] Step 804: After receiving a direct communication request, the relay UE can obtain secure communication parameters from the PKMF network element.
[0261] Specifically, the direct communication request includes a key identifier, which is the identifier of the security key used by the remote UE and the relay UE to encrypt and / or protect the integrity of the data during data interaction. The relay UE can obtain the corresponding secure communication parameters from the PKMF network element through this key identifier.
[0262] Step 805: The relay UE establishes secure communication with the remote UE based on the secure communication parameters.
[0263] Step 806: The relay UE sends a direct communication response to the remote UE, which is used to respond to the direct communication request.
[0264] Step 807: The relay UE assigns the IP address required for communication to the remote UE.
[0265] Specifically, the IP address can be an IPv6 prefix or an IPv4 address.
[0266] Step 808: The relay UE needs to send an N1 message to the AMF network element. The N1 message includes the remote UE's SUCI and N1SM messages. The N1SM message includes IP information.
[0267] If the IP address in step 807 is an IPv6 prefix, then the IP information is the IPv6 prefix assigned by the relay UE to the remote UE. If the IP address in step 808 is an IPv4 address, then the IP information is the range of port numbers assigned by the relay UE to the remote UE.
[0268] Step 809: After receiving the terminal's reported information, the AMF network element determines that the terminal's reported information carries a SUCI and sends an identifier resolution request carrying the SUCI to the UDM network element to request the UDM network element to resolve the SUCI.
[0269] Step 810: After receiving the identifier resolution request, the UDM network element obtains the SUCI from the identifier resolution request. The UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE.
[0270] The method by which the UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE is similar to the method by which the UDM network element determines the SUPI of the remote UE based on the SUCI of the remote UE in step 306. For details, please refer to the above content, which will not be repeated here.
[0271] Step 811: After determining the SUPI of the remote UE, the UDM network element sends an identifier resolution response to the AMF network element, which carries the SUPI of the remote UE.
[0272] Step 812: After receiving the identifier resolution response, the AMF network element obtains the SUPI of the remote UE from the identifier resolution response. The AMF network element sends an Nsmf message to the SMF network element, which includes the SUPI of the remote UE and the N1SM message.
[0273] Step 813: The SMF network element can perform service control based on the SUPI and the received IP information, such as legitimate monitoring and usage statistics. No limitations are specified here.
[0274] It should be noted that the relay UE can also request SUCI resolution from the UDM through the SMF. Specifically, the relay UE can send a terminal reporting message to the SMF through the AMF. After receiving the terminal reporting message, the SMF can request SUCI resolution from the UDM. For details, please refer to [link to relevant documentation]. Figure 3 The following is a description of steps 315 to 318 in the illustrated embodiment.
[0275] Based on the same inventive concept as the method embodiments, this application also provides a communication device for executing the method described in the above method embodiments, which is executed by a key management network user or a PKMF network element. Related features can be found in the above method embodiments, and will not be repeated here. Figure 9 As shown, the device includes a receiving unit 901, a processing unit 902, and a transmitting unit 903;
[0276] The receiving unit 901 is configured to receive a first key request from the first terminal device, wherein the first key request includes a first identifier, and the first identifier is an anonymization identifier or a temporary identifier of the second terminal device.
[0277] Processing unit 902 is configured to determine that the first key request includes a first identifier;
[0278] The sending unit 903 is configured to send a first request to the unified data management network element after the processing unit 902 determines that the key request includes the first identifier; the first request includes the first identifier.
[0279] The receiving unit 901 is also configured to receive a first response from the unified data management network element, the first response including the user permanent identifier (SUPI) of the second terminal device;
[0280] Processing unit 902 is also configured to perform an authorization check on the second terminal device according to the SUPI of the second terminal device;
[0281] The sending unit 903 is further configured to send a first key response to the first terminal device after the processing unit 902 passes the authorization check of the second terminal device. The first key response includes secure communication parameters, which are the parameters required for the first terminal device and the second terminal device to establish secure communication.
[0282] In one possible implementation, the first response and the first key response may also include the GPSI or first identifier of the second terminal device.
[0283] In one possible implementation, the first request is a secure communication parameter acquisition request, and the first response is a secure communication parameter acquisition response.
[0284] In one possible implementation, after the processing unit 902 fails to pass the authorization check of the second terminal device based on the second identifier, the sending unit 903 may notify the unified data management network element to delete the correspondence between the first identifier and the SUPI of the second terminal device.
[0285] In one possible implementation, the sending unit 903 may also send a first instruction to the unified data management network element, the first instruction being used to indicate the correspondence between the stored first identifier and the SUPI of the second terminal device.
[0286] Based on the same inventive concept as the method embodiments, this application also provides a communication device for executing the method executed by the unified data management network element or UDM network element in the above method embodiments. Related features can be found in the above method embodiments, and will not be repeated here. Figure 10 As shown, the device includes a receiving unit 1001, a processing unit 1002, and a transmitting unit 1003;
[0287] The receiving unit 1001 is configured to receive a first request from the key management network element, the first request including a first identifier, the first identifier being an anonymized identifier or a temporary identifier of the second terminal device;
[0288] Processing unit 1002 is configured to determine that the first request includes a first identifier; and after determining that the first request includes a first identifier, to obtain the SUPI of the second terminal device based on the first identifier;
[0289] The sending unit 1003 is used to send a first response to the key management network element, the first response including the SUPI of the second terminal device.
[0290] In one possible implementation, when the processing unit 1002 determines the SUPI of the second terminal device based on the anonymization identifier of the second terminal device, it can obtain the SUPI of the second terminal device from the user identifier hidden network element based on the anonymization identifier of the second terminal device.
[0291] In one possible implementation, when the processing unit 1002 determines the SUPI of the second terminal device based on the temporary identifier of the second terminal device, it may determine the SUPI of the second terminal device based on the stored correspondence between the SUPI of the terminal device and the temporary identifier.
[0292] In one possible implementation, the processing unit 1002 may also assign a temporary identifier to the second terminal device and save the correspondence between the SUPI of the second terminal device and the temporary identifier; then, the sending unit 1003 may send the temporary identifier to the second terminal device through the neighboring service network element.
[0293] In one possible implementation, the processing unit 1002 may also obtain the temporary identifier assigned to the second terminal device by the neighboring service network element from the neighboring service network element, and save the correspondence between the SUPI of the second terminal device and the temporary identifier.
[0294] In one possible implementation, after obtaining the SUPI of the second terminal device according to the first identifier, the processing unit 1002 may store the correspondence between the first identifier and the SUPI of the second terminal device.
[0295] In one possible implementation, before the processing unit 1002 stores the correspondence between the first identifier and the SUPI of the second terminal device, the receiving unit 1001 may receive a first instruction from the key management network element. The first instruction is used to indicate the storage of the correspondence between the first identifier and the SUPI of the second terminal device.
[0296] In one possible implementation, before storing the correspondence between the first identifier and the SUPI of the second terminal device, the processing unit 1002 may also determine, based on the attributes of the second terminal device, the correspondence between the first identifier and the SUPI of the second terminal device that needs to be stored.
[0297] In one possible implementation, the processing unit 1002 may delete the correspondence between the first identifier and the SUPI of the second terminal device upon notification from the key management network element.
[0298] In one possible implementation, the processing unit 1002 can determine the GPSI of the second terminal device based on the SUPI of the second terminal device, and then carry the GPSI of the second terminal device in the first response.
[0299] In one possible implementation, the receiving unit 1001 may also receive a user identity resolution request from the session management network element. The user identity resolution request includes a second identifier, which is one of the following: the anonymization identifier of the second terminal device, the temporary identifier of the second terminal device, or the GPSI of the second terminal device. Then, the processing unit 1002 determines the SUPI of the second terminal device based on the second identifier. Then, the sending unit 1003 sends a user identity resolution response to the session management network element, which includes the SUPI of the second terminal device.
[0300] In one possible implementation, the receiving unit 1001 may also receive an identifier resolution request from the mobile access management network element. The identifier resolution request includes a second identifier, which is one of the following: the anonymized identifier of the second terminal device, the temporary identifier of the second terminal device, or the GPSI of the second terminal device. Then, the processing unit 1002 can determine the SUPI of the second terminal device based on the second identifier. Then, the sending unit 1003 sends an identifier resolution response to the mobile access management network element, which includes the SUPI of the second terminal device.
[0301] In one possible implementation, the first request is a secure communication parameter acquisition request, and the first response is a secure communication parameter acquisition response.
[0302] In one possible implementation, the first response may include a first identifier.
[0303] Based on the same inventive concept as the method embodiments, this application also provides a communication device for executing the method executed by the session management network element or SMF network element in the above method embodiments. Related features can be found in the above method embodiments, and will not be repeated here. Figure 11 As shown, the device includes a receiving unit 1101, a processing unit 1102, and a transmitting unit 1103;
[0304] The receiving unit 1101 is used to receive terminal-reported messages from the first terminal device. The terminal-reported messages include a second identifier and IP information assigned by the first terminal device to the second terminal device. The second identifier is one of the following: the anonymized identifier of the second terminal device, the temporary identifier of the second terminal device, or the GPSI of the second terminal device.
[0305] Processing unit 1102 is used to determine that the message reported by the terminal includes a second identifier.
[0306] The sending unit 1103 is used to send a user identity resolution request to the unified data management network element after the processing unit 1102 determines that the terminal-reported message includes the second identifier. The user identity resolution request includes the second identifier.
[0307] The receiving unit 1101 is also configured to receive a user identity resolution response from a unified data management network element, wherein the user identity resolution response includes the SUPI of the second terminal device.
[0308] The processing unit 1102 also performs service control on the second terminal device based on the SUPI and IP information of the second terminal device.
[0309] Based on the same inventive concept as the method embodiments, this application also provides a communication device for executing the method executed by the mobile access management network element or AMF network element in the above method embodiments. Related features can be found in the above method embodiments, and will not be repeated here. Figure 12 As shown, the device includes a receiving unit 1201, a processing unit 1202, and a transmitting unit 1203;
[0310] The receiving unit 1201 is used to receive terminal-reported messages from the first terminal device. The terminal-reported messages include a second identifier and IP information assigned by the first terminal device to the second terminal device. The second identifier is one of the following: the anonymized identifier of the second terminal device, the temporary identifier of the second terminal device, or the GPSI of the second terminal device.
[0311] Processing unit 1202 is used to determine that the message reported by the terminal includes a second identifier.
[0312] The sending unit 1203 is used to send an identifier resolution request to the unified data management network element after the processing unit 1202 determines that the terminal-reported message includes the second identifier. The identifier resolution request includes the user permanent identifier (SUPI) of the second terminal device.
[0313] The receiving unit 1201 is also configured to receive an identifier resolution response from a unified data management network element, wherein the identifier resolution request includes the SUPI of the second terminal device.
[0314] The sending unit 1203 is also used to send the SUPI and IP information of the second terminal device to the session management network element.
[0315] Based on the same inventive concept as the method embodiments, this application also provides a communication device for executing the method executed by the first terminal device or relay UE in the above method embodiments. Related features can be found in the above method embodiments, and will not be repeated here. Figure 13 As shown, the device includes a receiving unit 1301, a processing unit 1302, and a transmitting unit 1303;
[0316] Processing unit 1302 is used to determine whether direct communication with the second terminal device needs to be established.
[0317] The sending unit 1303 is used to send a first key request to the key management network element after the processing unit 1302 determines that it is necessary to establish direct communication with the second terminal device. The first key request includes a first identifier, which is the anonymization identifier or temporary identifier of the second terminal device.
[0318] The receiving unit 1301 is used to receive a first key response from the key management network element, wherein the first key response includes secure communication parameters;
[0319] The processing unit 1302 is also used to establish secure communication with the second terminal device based on secure communication parameters.
[0320] In one possible implementation, the first key response may also include the GPSI or first identifier of the second terminal device.
[0321] The unit division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into a single processor, exist as separate physical units, or two or more units can be integrated into a single module. The integrated units described above can be implemented in hardware or as software functional modules.
[0322] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a terminal device (which may be a personal computer, mobile phone, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0323] In this embodiment, the key management network element, unified data management network element, session management network element, mobile access management network element, and first terminal device can all be presented in an integrated manner, divided into various functional modules. Here, "module" can refer to a specific ASIC, circuit, processor and memory executing one or more software or firmware programs, integrated logic circuits, and / or other devices that can provide the aforementioned functions.
[0324] In a simple embodiment, those skilled in the art will realize that the key management network element, unified data management network element, session management network element, and mobile access management network element can all be employed. Figure 14 As shown in the figure.
[0325] like Figure 14 The communication device 1400 shown includes at least one processor 1401 and a memory 1402, and optionally, may also include a communication interface 1403.
[0326] Memory 1402 may be volatile memory, such as random access memory; memory may also be non-volatile memory, such as read-only memory, flash memory, hard disk drive (HDD), or solid-state drive (SSD); or memory 1402 may be any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 1402 may be a combination of the above-described memories.
[0327] This application embodiment does not limit the specific connection medium between the processor 1401 and the memory 1402. In this embodiment, the memory 1402 and the processor 1401 are connected via a bus 1404, which is represented by a thick line. The connection methods between other components are only illustrative and not intended to be limiting. This bus 1404 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 14 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0328] Processor 1401 can have data transmission and reception capabilities, enabling it to communicate with other devices, such as... Figure 14 The device can also be equipped with a separate data transceiver module, such as communication interface 1403, for sending and receiving data; when the processor 1401 communicates with other devices, it can transmit data through communication interface 1403.
[0329] When the key management network element adopts Figure 14 When in the form shown, Figure 14 The processor 1401 can call computer execution instructions stored in the memory 1402, so that the key management network element can execute the method executed by the key management network element or PKMF network element in any of the above method embodiments.
[0330] Specifically, Figure 9 The functions / implementation processes of the transmitting unit, receiving unit, and processing unit can all be accessed through... Figure 14 The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Or, Figure 9 The function / implementation process of the processing unit in the middle can be obtained through Figure 14 The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Figure 9 The functions / implementation process of the transmitting and receiving units in the middle can be obtained through Figure 14 It is implemented using the communication interface 1403.
[0331] When the unified data management network element adopts Figure 14 When in the form shown, Figure 14 The processor 1401 can call computer execution instructions stored in the memory 1402, so that the unified data management network element can execute the method executed by the unified data management network element or UDM network element in any of the above method embodiments.
[0332] Specifically, Figure 10 The functions / implementation processes of the transmitting unit, receiving unit, and processing unit can all be accessed through... Figure 14The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Or, Figure 10 The function / implementation process of the processing unit in the middle can be obtained through Figure 14 The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Figure 10 The functions / implementation process of the transmitting and receiving units in the middle can be obtained through Figure 14 It is implemented using the communication interface 1403.
[0333] When the session management network element adopts Figure 14 When in the form shown, Figure 14 The processor 1401 can call computer execution instructions stored in the memory 1402, enabling the session management network element to execute the methods executed by the session management network element or SMF network element in any of the above method embodiments.
[0334] Specifically, Figure 11 The functions / implementation processes of the receiving unit, transmitting unit, and processing unit can all be accessed through... Figure 14 The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Or, Figure 11 The function / implementation process of the processing unit in the middle can be obtained through Figure 14 The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Figure 11 The functions / implementation process of the receiving unit and the transmitting unit can be obtained through Figure 14 It is implemented using the communication interface 1403.
[0335] When the mobile access management network element adopts Figure 14 When in the form shown, Figure 14 The processor 1401 can call computer execution instructions stored in the memory 1402, so that the mobile access management network element can execute the method executed by the mobile access management network element or AMF network element in any of the above method embodiments.
[0336] Specifically, Figure 12 The functions / implementation processes of the receiving unit, transmitting unit, and processing unit can all be accessed through... Figure 14 The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Or, Figure 12 The function / implementation process of the processing unit in the middle can be obtained through Figure 14 The processor 1401 in the memory calls computer execution instructions stored in memory 1402 to implement this. Figure 12 The functions / implementation process of the receiving unit and the transmitting unit can be obtained through Figure 14 It is implemented using the communication interface 1403.
[0337] In a simple embodiment, those skilled in the art will realize that the key management network element, unified data management network element, session management network element, and mobile access management network element can all be employed. Figure 15 As shown in the figure.
[0338] like Figure 15 The communication device 1500 shown includes at least one processor 1501 and a memory 1502, and optionally, may also include a transceiver 1503.
[0339] The processor 1501 and memory 1502 are similar to the processor 1401 and memory 1402, as detailed above, and will not be repeated here.
[0340] This application embodiment does not limit the specific connection medium between the processor 1501 and the memory 1502. In this embodiment, the memory 1502 and the processor 1501 are connected via a bus 1504, which is represented by a thick line. The connection methods between other components are only illustrative and not intended to be limiting. This bus 1504 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 15 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0341] Processor 1501 can have data transmission and reception capabilities, enabling it to communicate with other devices, such as... Figure 15 The device can also be equipped with a separate data transceiver module, such as transceiver 1503, for sending and receiving data; when the processor 1501 communicates with other devices, it can transmit data through transceiver 1503.
[0342] When the first terminal device adopts Figure 15 When in the form shown, Figure 15 The processor 1501 can call computer execution instructions stored in the memory 1502, enabling the first terminal device to execute the method executed by the first terminal device or the relay UE in any of the above method embodiments.
[0343] Specifically, Figure 13 The functions / implementation processes of the transmitting unit, receiving unit, and processing unit can all be accessed through... Figure 15 The processor 1501 in the memory calls computer execution instructions stored in memory 1502 to implement the function. Alternatively, Figure 13 The function / implementation process of the processing unit in the middle can be obtained through Figure 15 The processor 1501 in the memory calls computer execution instructions stored in memory 1502 to implement this. Figure 13The functions / implementation process of the transmitting and receiving units in the middle can be obtained through Figure 15 It is implemented using the transceiver 1503.
[0344] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0345] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0346] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0347] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0348] Obviously, those skilled in the art can make various modifications and variations to the embodiments of this application without departing from the scope of the embodiments of this application. Therefore, if these modifications and variations to the embodiments of this application fall within the scope of the claims of this application and their equivalents, this application also intends to include these modifications and variations.
Claims
1. A communication system, characterized by The communication system comprises a key management network element and a unified data management network element: The key management network element is configured to receive a first key request from a relay device, the first key request comprising a subscriber concealed identity (SUCI) of a remote device; and send a first request to the unified data management network element after determining that the first key request comprises the SUCI of the remote device, the first request comprising the SUCI of the remote device; The unified data management network element is configured to receive the first request; decrypt the SUCI of the remote device to obtain a subscriber permanent identity of the remote device, and send a first response to the key management network element, the first response comprising the subscriber permanent identity of the remote device; The key management network element is further configured to receive the first response, perform authorization checking on the remote device according to the subscriber permanent identity of the remote device, and send a first key response to the relay device after the authorization checking on the remote device passes, the first key response comprising a security communication parameter.
2. The system of claim 1, wherein, The first response and the first key response further comprise a generic public user identity of the remote device, and the unified data management network element is further configured to: determine the generic public user identity of the remote device according to the subscriber permanent identity of the remote device.
3. The system of claim 1, wherein, The first response and the first key response further comprise the SUCI of the remote device, and the unified data management network element is further configured to: store a correspondence between the SUCI of the remote device and the subscriber permanent identity of the remote device.
4. The system of claim 3, wherein before the unified data management network element stores the correspondence between the SUCI of the remote device and the subscriber permanent identity of the remote device, the unified data management network element is further configured to: receive a first indication from the key management network element, the first indication being used to instruct to store the correspondence between the SUCI of the remote device and the subscriber permanent identity of the remote device; The key management network element is further configured to: send the first indication to the unified data management network element.
5. The system of claim 3 or 4, wherein after the authorization checking on the remote device fails, the key management network element is further configured to instruct the unified data management network element to delete the correspondence between the SUCI of the remote device and the subscriber permanent identity of the remote device; after the instruction of the key management network element, the unified data management network element is further configured to delete the correspondence between the SUCI of the remote device and the subscriber permanent identity of the remote device.
6. The system of any one of claims 1 to 4, wherein, The unified data management network element decrypts the SUCI of the remote device to obtain the subscriber permanent identity of the remote device, and is specifically configured to: obtain the subscriber permanent identity of the remote device from a user identity de-concealing network element according to the SUCI of the remote device.
7. The system of claim 6, wherein, The system further comprises the user identity de-concealing network element; The user identity de-concealing network element is configured to decrypt the SUCI of the remote device to obtain the subscriber permanent identity of the remote device.
8. The system of any of claims 1-4, 7, wherein, The system further comprises a session management network element, The session management network element is configured to receive a terminal reporting message from the relay device, the terminal reporting message comprising a second identifier and IP information allocated by the relay device for the remote device, the second identifier being one of an anonymized identifier of the remote device, a temporary identifier of the remote device, or a universal public user identifier of the remote device; and send a user identity resolution request to the unified data management network element after determining that the terminal reporting message comprises the second identifier, the user identity resolution request comprising the second identifier. The unified data management network element is further configured to receive the user identity resolution request, determine a user permanent identifier of the remote device according to the second identifier, and send a user identity resolution response to the session management network element, the user identity resolution response comprising the user permanent identifier of the remote device. The session management network element is further configured to receive the user identity resolution response, and perform service control on the remote device according to the user permanent identifier of the remote device and the IP information.
9. The system of any of claims 1-4, 7, wherein, The system further comprises a mobile access management network element, The mobile access management network element is configured to receive a terminal reporting message from the relay device, the terminal reporting message comprising a second identifier and IP information allocated by the relay device for the remote device, the second identifier being one of an anonymized identifier of the remote device, a temporary identifier of the remote device, or a universal public user identifier of the remote device; and send an identifier resolution request to the unified data management network element, the identifier resolution request comprising the second identifier. The unified data management network element is further configured to receive the identifier resolution request, determine a user permanent identifier of the remote device according to the second identifier, and send an identifier resolution response to the mobile access management network element, the identifier resolution response comprising the user permanent identifier of the remote device. The mobile access management network element is further configured to receive the identifier resolution response, and send the user permanent identifier of the remote device and the IP information to a session management network element.
10. The system of any of claims 1-4, 7, wherein, The system further comprises the relay device. The relay device is configured to send the first key request to the key management network element, and receive the first key response from the key management network element.
11. The system of claim 10, wherein, The relay device is further configured to: After establishing secure communication with the remote device based on the secure communication parameter, send a terminal reporting message to a session management network element through a mobile access management network element, the terminal reporting message comprising a second identifier and IP information allocated by the relay device for the remote device, the second identifier being one of an anonymized identifier of the remote device, a temporary identifier of the remote device, or a universal public user identifier of the remote device.
12. The system of any of claims 1-4, 7, 11, wherein, The system further comprises a proximity service network element. The proximity service network element is configured to allocate a temporary identifier for the remote device, and send the temporary identifier to the unified data management network element and the remote device.
13. The system of any of claims 1-4, 7, 11, wherein: The key management network element is further configured to receive a second key request from the relay device, the second key request being used to request the security communication parameter from the key management network element, the second key request comprising an international mobile subscriber identity of the remote device; perform an authorization check on the remote device according to the international mobile subscriber identity of the remote device, and send a second key response to the relay device after the authorization check on the remote device is passed, the second key response comprising the security communication parameter.
14. The system of any of claims 1-4, 7, 11, wherein, The first request is a security communication parameter acquisition request, and the first response is a security communication parameter acquisition response.
15. An identification acquisition method of a terminal device, characterized by, The method comprises the following steps: The key management network element receives a first key request from a relay device, the first key request comprising a subscriber concealed identity (SUCI) of a remote device, the SUCI of the remote device being used to decrypt to acquire a user permanent identity of the remote device; The key management network element sends a first request to a unified data management network element after determining that the first key request comprises the SUCI of the remote device, the first request comprising the SUCI of the remote device; The key management network element receives a first response from the unified data management network element, the first response comprising the user permanent identity of the remote device; The key management network element performs an authorization check on the remote device according to the user permanent identity of the remote device, and sends a first key response to the relay device after the authorization check on the remote device is passed, the first key response comprising a security communication parameter.
16. The method of claim 15, wherein, The first response and the first key response further comprise a generic public user identity of the remote device or the SUCI of the remote device.
17. The method of claim 15 or 16, wherein, The first request is a security communication parameter acquisition request, and the first response is a security communication parameter acquisition response.
18. The method of any one of claims 15-16, wherein, The method further comprises the following steps: The key management network element notifies the unified data management network element to delete a correspondence between the SUCI of the remote device and the user permanent identity of the remote device after the authorization check on the remote device according to the user permanent identity of the remote device is failed.
19. The method of any one of claims 15-16, wherein, The method further comprises the following steps: The key management network element sends a first indication to the unified data management network element, the first indication being used to indicate to store the correspondence between the SUCI of the remote device and the user permanent identity of the remote device.
20. A method for acquiring an identity of a terminal device, the method comprising: The method comprises the following steps: The key management network element receives a first key request from a relay device, the first key request comprising a subscriber concealed identity (SUCI) of a remote device; The key management network element sends a first request to a unified data management network element after determining that the first key request comprises the SUCI of the remote device, the first request comprising the SUCI of the remote device; The unified data management network element receives a first request from a key management network element, the first request comprising a SUCI of a remote device; The unified data management network element decrypts the SUCI of the remote device to acquire a user permanent identity of the remote device; The unified data management network element sends a first response to the key management network element, the first response including a user permanent identifier of the remote device.
21. The method of claim 20, wherein, The unified data management network element decrypts the SUCI of the remote device to obtain the user permanent identifier of the remote device. The unified data management network element obtains the user permanent identifier of the remote device from a user identifier de-concealing network element according to the SUCI of the remote device.
22. The method of claim 21, wherein, The method further includes: The user identifier de-concealing network element decrypts the SUCI of the remote device to obtain the user permanent identifier of the remote device.
23. The method of any one of claims 20-22, wherein, After the unified data management network element decrypts the SUCI of the remote device to obtain the user permanent identifier of the remote device, the method further includes: The unified data management network element stores a correspondence between the SUCI of the remote device and the user permanent identifier of the remote device.
24. The method of claim 23, wherein, Before the unified data management network element stores the correspondence between the SUCI of the remote device and the user permanent identifier of the remote device, the method further includes: The unified data management network element receives a first indication from the key management network element, the first indication indicating that the correspondence between the SUCI of the remote device and the user permanent identifier of the remote device is to be stored.
25. The method of claim 24, wherein, Before the unified data management network element stores the correspondence between the SUCI of the remote device and the user permanent identifier of the remote device, the method further includes: The unified data management network element determines, according to attributes of the remote device, that the correspondence between the SUCI of the remote device and the user permanent identifier of the remote device needs to be stored.
26. The method of claim 23, wherein, The method further includes: The unified data management network element deletes the correspondence between the SUCI of the remote device and the user permanent identifier of the remote device under notification of the key management network element.
27. The method of any one of claims 20-22, 24-26, wherein, The first response further includes a generic public user identifier of the remote device, and the method further includes: The unified data management network element determines the generic public user identifier of the remote device according to the user permanent identifier of the remote device.
28. The method of any one of claims 20-22, 24-26, wherein, The first response further includes the SUCI of the remote device.
29. The method of any one of claims 20-22, 24-26, wherein, The method further includes: The unified data management network element receives a user identity resolution request from a session management network element, the user resolution identity request including a second identifier, the second identifier being one of a user concealed identifier SUCI of the remote device or a generic public user identifier of the remote device; The unified data management network element determines the user permanent identifier of the remote device according to the second identifier; The unified data management network element sends a user identity resolution response to the session management network element, the user identity resolution response including the user permanent identifier of the remote device.
30. The method of any one of claims 20-22, 24-26, wherein, The method further includes: The unified data management network element receives an identity resolution request from a mobile access management network element, the identity resolution request including a second identifier, the second identifier being one of an anonymized identifier of the remote device, a temporary identifier of the remote device, or a generic public user identifier of the remote device; The unified data management network element determines the user permanent identifier of the remote device according to the second identifier; The unified data management network element sends an identifier resolution response to the mobile access management network element, and the identifier resolution response includes the user permanent identifier of the remote device.
31. The method of any one of claims 20-30, wherein, The first request is a security communication parameter acquisition request, and the first response is a security communication parameter acquisition response.
32. A communications device, characterized by Comprise: The receiving unit is configured to receive a first key request from a relay device, wherein the first key request includes a subscriber concealed identifier (SUCI) of a remote device, and the SUCI of the remote device is used to decrypt to obtain a user permanent identifier of the remote device. The processing unit is configured to determine that the SUCI of the remote device is included in the first key request. The sending unit is configured to send a first request to a unified data management network element after the processing unit determines that the SUCI of the remote device is included in the first key request, wherein the first request includes the SUCI of the remote device. The receiving unit is further configured to receive a first response from the unified data management network element, wherein the first response includes the user permanent identifier of the remote device. The processing unit is further configured to perform authorization checking on the remote device according to the user permanent identifier of the remote device. The sending unit is further configured to send a first key response to the relay device after the processing unit passes the authorization checking on the remote device, wherein the first key response includes a security communication parameter.
33. The apparatus of claim 32, wherein, The first response and the first key response further include a generic public user identifier of the remote device or the SUCI of the remote device.
34. The apparatus of claim 32 or 33, wherein, The first request is a security communication parameter acquisition request, and the first response is a security communication parameter acquisition response.
35. The apparatus of any one of claims 32-33, wherein, The sending unit is further configured to: After the processing unit fails to pass the authorization checking on the remote device according to the user permanent identifier of the remote device, the sending unit is further configured to notify the unified data management network element to delete a correspondence between the SUCI of the remote device and the user permanent identifier of the remote device.
36. The apparatus of any one of claims 32-33, wherein, The sending unit is further configured to send a first indication to the unified data management network element, wherein the first indication is used to indicate to store the correspondence between the SUCI of the remote device and the user permanent identifier of the remote device.
37. A communications device, characterized by The apparatus comprises a processor and a memory, and the memory stores instructions, and the processor executes the instructions to enable the apparatus to perform the method in any one of claims 15 to 19.
38. A computer-readable storage medium, characterized in that, The computer readable storage medium stores instructions, and when the instructions stored in the computer readable storage medium are executed on a computer, the computer is enabled to perform the method in any one of claims 15 to 31.
39. A computer program product, characterised in that, The computer program product comprises instructions, and when the instructions comprised in the computer program product are executed on a computer, the computer is enabled to perform the method in any one of claims 15 to 31.
Citation Information
Patent Citations
Communication method and device
CN110830989A
Method and device for protecting privacy
WO2019023825A1