Method, apparatus, communication device and storage medium for transmitting a credential

By receiving base station indication information from the terminal, the user plane security protection operation of DRB can be activated or rejected, which solves the security problem in SNPN credential transmission and realizes reliable credential transmission and security assurance.

CN115868188BActive Publication Date: 2026-03-27BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-19
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In existing technologies, when a terminal accesses a standalone non-public network (SNPN), the transmission of credentials lacks security and is vulnerable to attacks from fake base stations, leading to the theft of credentials. Furthermore, core network equipment cannot effectively implement user plane security policies.

Method used

The terminal receives the instruction information from the base station and decides whether to activate the user plane security protection operation of the Radio Data Bearer (DRB) to ensure the security of credential transmission, including integrity protection and encryption, reject illegal RRC connection reconfiguration messages, and ensure the execution of security policies through AMF entity authentication and PDU session establishment request messages.

Benefits of technology

It improves the reliability and security of credential transmission, prevents credentials from being illegally stolen, and ensures the secure transmission of credentials in user plane PDU sessions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115868188B_ABST
    Figure CN115868188B_ABST
Patent Text Reader

Abstract

The method for transmitting a credential provided by the embodiments of the present disclosure is executed by a terminal, and the method comprises: receiving first indication information sent by a base station; wherein the first indication information is used to indicate that a user plane security protection operation of a radio data bearer (DRB) of the terminal is requested to be activated or not activated; and the DRB is used to at least carry a credential required by the terminal to access an independent non-public network (SNPN).
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of wireless communication, and more particularly, to a method and apparatus for transmitting a credential, a communication device, and a storage medium. BACKGROUND

[0002] In order to enhance the support for terminal access to a non-public network (NPN), a stand-alone NPN (SNPN) credential needs to be provided to the terminal. The credential is used for primary authentication, so that the terminal can access the desired SNPN after the authentication is passed. Here, the terminal should be allowed to access the login network before the credential is provided to the terminal. The credential is different from the ordinary user service flow transmitted in the user plane, and the credential is highly sensitive data, which needs to be securely protected. Otherwise, the terminal will not be able to pass the identity verification to access the desired SNPN or may be tricked to access a malicious SNPN. In the related art, in order to ensure the security of the credential transmission, a protection mechanism needs to be introduced to ensure the security of the credential transmission. SUMMARY

[0003] Embodiments of the present disclosure disclose a method and apparatus for transmitting a credential, a communication device, and a storage medium.

[0004] According to a first aspect of embodiments of the present disclosure, a method for transmitting a credential is provided, wherein the method is performed by a terminal, and the method comprises:

[0005] receiving first indication information sent by a base station;

[0006] The first indication information is used to indicate that a user plane security protection operation of a radio data bearer (DRB) of the terminal is requested to be activated or not activated, and the DRB is used to at least carry a credential required by the terminal to access a stand-alone non-public network (SNPN).

[0007] According to a second aspect of embodiments of the present disclosure, a method for transmitting a credential is provided, wherein the method is performed by a base station, and the method comprises:

[0008] sending first indication information to a terminal;

[0009] The first indication information is used to indicate that a user plane security protection operation of a radio data bearer (DRB) of the terminal is requested to be activated or not activated, and the DRB is used to at least carry a credential required by the terminal to access a stand-alone non-public network (SNPN).

[0010] According to a third aspect of embodiments of the present disclosure, a method for transmitting a credential is provided, wherein the method is performed by a first core network device, and the method comprises:

[0011] receiving the registration request message sent by the base station;

[0012] The registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used for the terminal to log in to the ONN to obtain the credential required by the terminal to access the SNPN.

[0013] According to a fourth aspect of the embodiments of the present disclosure, a method for transmitting a credential is provided, wherein the method is performed by a second core network device, and the method comprises:

[0014] receiving a PDU session establishment request message sent by a first core network device;

[0015] The PDU session establishment request message comprises at least information of a DNN, wherein the information of the DNN is used to indicate a DNN for obtaining a credential required by a terminal to access an SNPN.

[0016] According to a fifth aspect of the embodiments of the present disclosure, an apparatus for transmitting a credential is provided, wherein the apparatus comprises:

[0017] The receiving module is configured to receive first indication information sent by a base station;

[0018] The first indication information is used to indicate that a user plane security protection operation of a radio data bearer DRB of the terminal is requested to be activated or not activated; and the DRB is used at least to carry a credential required by the terminal to access an SNPN.

[0019] According to a sixth aspect of the embodiments of the present disclosure, an apparatus for transmitting a credential is provided, wherein the apparatus comprises:

[0020] The sending module is configured to send first indication information to a terminal;

[0021] The first indication information is used to indicate that a user plane security protection operation of a radio data bearer DRB of the terminal is requested to be activated or not activated; and the DRB is used at least to carry a credential required by the terminal to access an SNPN.

[0022] According to a seventh aspect of the embodiments of the present disclosure, an apparatus for transmitting a credential is provided, wherein the apparatus comprises:

[0023] The receiving module is configured to receive a registration request message sent by a base station;

[0024] The registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used for the terminal to log in to the ONN to obtain the credential required by the terminal to access the SNPN.

[0025] According to an eighth aspect of embodiments of the present disclosure, a device for transmitting a credential is provided, and the device comprises:

[0026] a receiving module configured to receive a PDU session establishment request message sent by a first core network device;

[0027] The PDU session establishment request message comprises at least information of a DNN, wherein the information of the DNN is used to indicate a DNN of a credential required by a terminal to access an SNPN.

[0028] According to a ninth aspect of embodiments of the present disclosure, a communication device is provided, and the communication device comprises:

[0029] a processor;

[0030] a memory for storing executable instructions of the processor;

[0031] The processor is configured to implement the method of any of the embodiments of the present disclosure when the executable instructions are executed.

[0032] According to a tenth aspect of embodiments of the present disclosure, a computer storage medium is provided, and the computer storage medium stores a computer executable program, and the executable program is executed by a processor to implement the method of any of the embodiments of the present disclosure.

[0033] In the embodiments of the present disclosure, first indication information sent by a base station is received, wherein the first indication information is used to indicate that a user plane security protection operation of a data radio bearer (DRB) of the terminal is requested to be activated or not activated, and the DRB is used to at least carry a credential required by the terminal to access an SNPN. Here, after receiving the first indication information sent by the base station, the terminal can activate or not activate the user plane security protection operation of the DRB of the terminal based on the first indication information, so that the reliability of transmitting the credential of the SNPN by using the DRB can be improved, and the transmission safety of the credential can be ensured. BRIEF DESCRIPTION OF DRAWINGS

[0034] Figure 1 is a structural schematic diagram of a wireless communication system according to an exemplary embodiment.

[0035] Figure 2 is a schematic diagram of a network architecture according to an exemplary embodiment.

[0036] Figure 3 is a flowchart of a credential transmission method according to an exemplary embodiment.

[0037] Figure 4FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0038] Figure 5 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0039] Figure 6 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0040] Figure 7 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0041] Figure 8 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0042] Figure 9 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0043] Figure 10 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0044] Figure 11 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0045] Figure 12 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0046] Figure 13 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0047] Figure 14 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0048] Figure 15 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0049] Figure 16 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0050] Figure 17 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0051] Figure 18 FIG. 1 is a flow diagram illustrating a method of transmitting a credential according to an example embodiment.

[0052] Figure 19 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0053] Figure 20 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0054] Figure 21 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0055] Figure 22 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0056] Figure 23 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0057] Figure 24 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0058] Figure 25 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0059] Figure 26 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0060] Figure 27 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0061] Figure 28 is a flowchart of a method for transmitting a credential according to an example embodiment.

[0062] Figure 29 is a schematic diagram of a credential transmitting apparatus according to an example embodiment.

[0063] Figure 30 is a schematic diagram of a credential transmitting apparatus according to an example embodiment.

[0064] Figure 31 is a schematic diagram of a credential transmitting apparatus according to an example embodiment.

[0065] Figure 32 is a schematic diagram of a credential transmitting apparatus according to an example embodiment.

[0066] Figure 33 is a schematic diagram of a terminal according to an example embodiment.

[0067] Figure 34 is a block diagram of a base station according to an example embodiment. DETAILED DESCRIPTION

[0068] The example embodiments will be described in detail with reference to the accompanying drawings. In the following description, same numbers refer to same elements throughout the drawings. The following example embodiments are not representative of all possible embodiments consistent with the present disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0069] The terminology used in the present disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used in the present disclosure and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0070] It will be understood that, although the terms first, second, third, etc. can be used herein to describe various information, the information should not be limited to these terms. These terms are only used to distinguish one piece of information from another. For example, a first information can also be termed a second information, and, similarly, a second information can also be termed a first information, without departing from the scope of the present disclosure. The word "if" can be interpreted as meaning "when" or "upon" or "in response to determining," depending on the context.

[0071] For the purpose of brevity and clarity, the term "greater than" or "less than" is used herein when characterizing a size relationship. However, it will be understood by those skilled in the art that the term "greater than" also encompasses the meaning of "greater than or equal to," and the term "less than" also encompasses the meaning of "less than or equal to."

[0072] Reference is made to Figure 1 which shows a structure diagram of a wireless communication system provided by the present disclosure. As shown in Figure 1 , the wireless communication system is a communication system based on mobile communication technology, and the wireless communication system can include a plurality of user equipment 110 and a plurality of base stations 120.

[0073] The user equipment 110 can be a device that provides voice and / or data connectivity to a user. The user equipment 110 can communicate with one or more core networks via a Radio Access Network (RAN), and the user equipment 110 can be an Internet of Things user equipment, such as a sensor device, a mobile phone, and a computer with an Internet of Things user equipment, for example, which can be fixed, portable, pocket, hand-held, computer-embedded, or vehicle-mounted. For example, a Station (STA), a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal, an access terminal, a user terminal, a user agent, a user device, or a user equipment. Alternatively, the user equipment 110 can also be a device of an unmanned aerial vehicle. Alternatively, the user equipment 110 can also be a vehicle-mounted device, which can be a vehicle-mounted computer with wireless communication function or a wireless user equipment externally connected to the vehicle-mounted computer. Alternatively, the user equipment 110 can also be a roadside device, which can be a street lamp, a signal lamp, or other roadside devices with wireless communication function, etc.

[0074] The base station 120 can be a network-side device in a wireless communication system. The wireless communication system can be a 4th generation mobile communication (4G) system, also known as a Long Term Evolution (LTE) system, or the wireless communication system can also be a 5G system, also known as a New Radio system or a 5G NR system. Alternatively, the wireless communication system can also be a next generation of 5G system. In the 5G system, the access network can be referred to as an NG-RAN (New Generation-Radio Access Network).

[0075] The base station 120 can be an evolved NB (eNB) used in a 4G system. Alternatively, the base station 120 can also be a gNB (gNB) using a centralized-distributed architecture in a 5G system. When the base station 120 adopts a centralized-distributed architecture, it typically includes a central unit (CU) and at least two distributed units (DUs). The central unit is equipped with a protocol stack of the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, and the Media Access Control (MAC) layer; the distributed units are equipped with a physical (PHY) layer protocol stack. This disclosure does not limit the specific implementation of the base station 120.

[0076] Base station 120 and user equipment 110 can establish a wireless connection via a wireless air interface. In different implementations, the wireless air interface is a wireless air interface based on the fourth-generation mobile communication network technology (4G) standard; or, the wireless air interface is a wireless air interface based on the fifth-generation mobile communication network technology (5G) standard, such as a new air interface; or, the wireless air interface can also be a wireless air interface based on a next-generation mobile communication network technology standard based on 5G.

[0077] In some embodiments, user equipment 110 can also establish E2E (End to End) connections. Examples include V2V (vehicle to vehicle), V2I (vehicle to Infrastructure), and V2P (vehicle to pedestrian) communication scenarios in vehicle-to-everything (V2X) communication.

[0078] Here, the user equipment mentioned above can be considered as the terminal equipment in the following embodiments.

[0079] In some embodiments, the wireless communication system described above may further include a network management device 130.

[0080] A number of base stations 120 are connected to a network management device 130. The network management device 130 can be a core network device in a wireless communication system, for example, the network management device 130 can be a Mobility Management Entity (MME) in an Evolved Packet Core (EPC). Alternatively, the network management device can also be other core network devices, such as a Serving GateWay (SGW), a Public Data Network GateWay (PGW), a Policy and Charging Rules Function (PCRF), or a Home Subscriber Server (HSS), etc. The implementation form of the network management device 130 is not limited in the embodiments of the present disclosure.

[0081] For the convenience of those skilled in the art to understand, the embodiments of the present disclosure enumerate a plurality of embodiments to clearly explain the technical solutions of the embodiments of the present disclosure. Of course, those skilled in the art can understand that the plurality of embodiments provided by the embodiments of the present disclosure can be executed alone, or can be executed together after being combined with the method of other embodiments of the present disclosure, or can be executed alone or together after being combined with some methods in other related technologies; the embodiments of the present disclosure do not make any limitation in this regard.

[0082] In order to better understand the technical solutions disclosed by the embodiments of the present disclosure, the application scenarios of the provided credentials are described:

[0083] Please refer to Figure 2 In the embodiment, a network architecture is shown, based on which a terminal can first log in a network. A credential distribution server can pre-configure credentials to the terminal through a user plane connection.

[0084] In one embodiment, the terminal and the base station in the network (ONN, Onboarding Network) both support access layer security, and the Uu interface is protected after the terminal is successfully online. However, the user plane connection security protection is not compulsorily activated on the Uu interface, which leads to the risk of exposing the credentials to threats during the remote configuration of the credentials through the user plane connection.

[0085] In one embodiment, the user plane connection security of the Uu interface is activated based on the security policy information sent by the core network, which is set by the Unified Data Management (UDM) or the Session Management Function (SMF) according to the specific service requested by the terminal. The SMF determines the user plane security enforcement information of the PDU session based on the following information when establishing a Protocol Data Unit (PDU) session:

[0086] The signed user plane security policy information is part of the signed information received from the UDM;

[0087] When the UDM does not provide the user plane security policy information, the locally configured user plane security policy information in the SMF is used.

[0088] In one embodiment, the user plane security policy information indicates whether user plane security protection should be activated for all Data Radio Bearers (DRBs) belonging to the PDU session on the Uu interface. User plane encryption and / or user plane integrity protection are used for all DRBs belonging to the PDU session.

[0089] In one embodiment, according to the user plane security policy information provided by the SMF, if the security policy information indicates "required", the base station uses Radio Resource Control (RRC) signaling to activate user plane security protection for each DRB. If the policy indicates "not required", the establishment of the PDU session will be carried out without protection. If the policy indicates "recommended", the base station can autonomously decide whether to activate user plane security protection. However, when the policy indicates "required" or "not required", the base station cannot override the received user plane security policy information.

[0090] In one embodiment, user plane security protection is continuously implemented on the Uu interface by using the DRB addition procedure of the RRC connection reconfiguration procedure. When the base station determines to activate user plane security protection on the Uu based on the user plane security policy information, it includes an indication of user plane security protection activation in the RRC connection reconfiguration request. Then, the terminal implements the same user plane security protection based on the activation indication sent by the base station.

[0091] In order to protect the remote provisioning of SNPN credentials, there are two issues that need to be addressed:

[0092] 1、When the terminal selects an ONN to log in and obtain the required credential for accessing the SNPN, the selected ONN may not be the home network of the terminal. Therefore, the UDM in the ONN may not contain the user plane security policy information that the terminal has signed. Only the option of configuring the user plane security policy information locally by the SMF is left. However, how the SMF determines the security policy information for the user plane transmission of the SNPN credential has not been defined and is still under study.

[0093] 2、Since the SMF and the base station are network nodes in the ONN, they are different from the network nodes in the SNPN to which the terminal requests access. The SMF and the base station in the ONN may not be trusted by the SNPN and the terminal to correctly perform the security policy for protecting the SNPN credential. Especially in the case of a fake or faulty base station, the base station may ignore the security policy received from the SMF and disable user plane security protection on the Uu interface. In the related art, only the terminal is allowed to follow the activation indication sent by the base station to implement user plane security protection. The terminal cannot check whether the received security activation indication matches the security requirements of the requested PDU session.

[0094] In one scenario embodiment, when it is necessary to establish a user plane PDU session to transmit the credential, the base station sends an activation indication to the terminal for activating the user plane security protection operation (it should be noted that, in normal cases, in order to ensure the security of the transmission of the credential, if the base station is a trusted base station, the base station will definitely send an activation indication according to the security policy of the SMF to activate the terminal to perform the security protection operation. It will definitely not send an activation indication that does not conform to the security policy of the SMF). After receiving the activation indication, the terminal establishes a user plane PDU session and performs a user plane security protection operation, realizing the secure transmission of the credential.

[0095] However, in another scenario embodiment, due to the inevitable presence of unsafe factors in the network, for example, a fake base station or a faulty base station (here, collectively described as a pseudo base station) may send a non-activation indication (pseudo instruction) to the terminal that does not activate the user plane security protection operation. After receiving the non-activation indication, the terminal should follow the activation indication sent by the base station to activate the user plane security protection operation according to the existing mechanism, thereby establishing a user plane PDU session and not performing a user plane security protection operation (if it is according to the instruction of a trusted base station, it should originally be required to perform a user plane security protection operation, which is equivalent to being tampered with). At this time, there is no security guarantee for transmitting the credential using the user plane PDU session. This is also a problem in the related art.

[0096] In view of the above situation without security guarantee, the technical scheme of the embodiment of the present disclosure is proposed (here, it is to be noted that when the terminal needs to obtain the credential, the terminal determines that it has the need to perform the user plane security protection operation, and by default, it needs to activate the user plane security protection operation) :

[0097] The terminal will determine whether to establish the PDU session and whether to perform the user plane security protection operation according to the received indication, that is, if the received indication is the activation indication of activating the user plane security protection operation, the terminal will establish the PDU session and perform the user plane security protection operation; if the received indication is the activation indication of not activating the user plane security protection operation, the terminal will reject the RRC connection reconfiguration message, that is, the establishment of the PDU session fails (because the terminal receives the indication of not activating, it means that the base station has a fault, or it is attacked by a fake base station, or the network does not allow to build, at this time, not establishing the PDU session can effectively avoid the risk of credential theft).

[0098] Here, it is to be noted that if the terminal accepts the RRC connection reconfiguration message, the user plane PDU session for transmitting the credential will be established, and the credential will be transmitted by using the user plane PDU session. If the terminal rejects the RRC connection reconfiguration message, the user plane PDU session for transmitting the credential will not be established.

[0099] As shown in Figure 3 , the embodiment provides a method for transmitting a credential, wherein the method is performed by a terminal, and the method comprises the following steps:

[0100] Step 31, receiving first indication information sent by a base station;

[0101] The first indication information is used to indicate that the user plane security protection operation of a wireless data bearer (DRB) of the terminal is requested to be activated or not activated, and the DRB is at least used to carry a credential required by the terminal to access an independent non-public network (SNPN).

[0102] Here, the terminal can be, but is not limited to, a mobile phone, a tablet computer, a wearable device, a vehicle-mounted terminal, a roadside unit (RSU, Road Side Unit), a smart home terminal, an industrial sensor device, a medical device, and / or the like.

[0103] Here, the base station involved in the present disclosure can be various types of base stations, such as a base station of a third generation mobile communication (3G) network, a base station of a fourth generation mobile communication (4G) network, a base station of a fifth generation mobile communication (5G) network, or other evolved base stations. Here, the base station can be a base station logged into a network (ONN).

[0104] In one embodiment, user plane security protection operations include: integrity protection and / or encryption. The user plane security protection operations of the terminal's DRB may involve integrity protection and / or encryption of the credentials required for the terminal to access the SNPN carried by the DRB.

[0105] In one embodiment, the RRC connection reconfiguration message carrying first indication information may be received from the base station. Here, the base station may send the RRC connection reconfiguration message to the terminal after RRC security protection is activated. In one embodiment, the RRC connection reconfiguration message is sent to the terminal after RRC encryption and RRC integrity protection are activated.

[0106] In one embodiment, it may be an RRC connection reconfiguration message carrying first indication information sent by the receiving base station. Here, the first indication information may be sent for a specific DRB. The first indication information may include user plane integrity protection indication and / or user plane encryption indication.

[0107] In one embodiment, the terminal receives an RRC connection reconfiguration message from a base station carrying first indication information, wherein the first indication information indicates a request to activate user plane security protection operations for a DRB. Based on the first indication information, for each DRB, the terminal initiates uplink user plane integrity protection and downlink user plane authentication; and / or, based on the first indication information, for each DRB, the terminal initiates uplink user plane encryption and downlink user plane decryption.

[0108] In one embodiment, the terminal receives an RRC connection reconfiguration message from a base station carrying first indication information, wherein the first indication information indicates a request not to activate user plane security protection operations for the terminal's DRB. The terminal will reject the RRC connection reconfiguration message. Here, the terminal's rejection of the RRC connection reconfiguration message may be as follows: based on the first indication information, for each DRB, the terminal will not initiate uplink user plane integrity protection and downlink user plane authentication; and based on the first indication information, for each DRB, the terminal will not initiate uplink user plane encryption and downlink user plane decryption.

[0109] Here, user plane integrity protection can refer to the integrity protection of credentials carried on the DRB. User plane encryption can refer to the encryption of credentials carried on the DRB. This ensures that credentials are not illegally intercepted and that the transmission of credentials is secure. It should be noted that user plane integrity protection can also refer to the integrity protection of other types of data carried on the DRB besides credentials. Similarly, user plane encryption can also refer to the encryption of other types of data carried on the DRB besides credentials; this is not limited here.

[0110] In an embodiment, after receiving the RRC connection reconfiguration message, the terminal verifies the RRC connection reconfiguration message. In response to the verification being unsuccessful, the terminal ignores the RRC connection reconfiguration message. In response to the verification being successful, the terminal performs a corresponding operation based on the indication of the first indication information in the RRC connection reconfiguration message.

[0111] In an embodiment, a base station sends an RRC connection reconfiguration message carrying first indication information; a terminal verifies the RRC connection reconfiguration message, and obtains a verification result. If the verification result indicates that the verification is successful, the terminal determines whether to activate a user plane security protection operation of a DRB of the terminal according to the first indication information. Here, the terminal can reject the RRC connection reconfiguration message in response to the first indication information indicating that it is requested not to activate the user plane security protection operation of the DRB of the terminal; or the terminal can perform the user plane security protection operation in response to the first indication information indicating that it is requested to activate the user plane security protection operation of the DRB of the terminal. Here, after the terminal determines to perform the user plane security protection operation, the terminal can send an RRC connection reconfiguration complete message to the base station. Here, the RRC connection reconfiguration complete message is used to indicate that the activation of the user plane security protection operation of the DRB of the terminal has been completed.

[0112] In an embodiment, before the base station of the ONN sends the first indication information to the terminal, the terminal sends second indication information to the base station in an RRC connection establishment process, where the second indication information is used to indicate that the established RRC connection is used for the terminal to log in to the ONN; after receiving the second indication information, the base station selects an access and mobility management function (AMF) entity that supports the terminal to log in to the ONN, where it should be noted that the AMF entity is configured with AMF login configuration data; the AMF login configuration data includes DNN information used to obtain a credential and / or information limiting the terminal to only request to obtain a credential.

[0113] In an embodiment, after the base station selects the AMF entity, when the terminal needs to register to the ONN, the base station is sent a registration request message. Here, the registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain a credential. For example, the predetermined registration type is a registration type of "log in to SNPN". After the base station receives the registration request message, the base station sends the registration request message to the AMF. After the AMF receives the registration request message, the AMF initiates a procedure of authenticating the terminal to an authentication service function (AUSF) entity in the ONN. Here, the AMF login configuration data can be data that limits the terminal to request only the distribution of SNPN credentials in the user plane.

[0114] In an embodiment, after the terminal successfully logs in to the ONN, if the terminal needs to receive an SNPN credential from the ONN through the user plane, a PDU session establishment procedure is initiated. Here, initiating the PDU session establishment procedure can be sending a first PDU session establishment request message to a base station in the ONN, wherein the first PDU session establishment request message includes digital data network (DNN) information used to obtain an SNPN credential. It should be noted that in an embodiment, the terminal can be pre-configured with DNN information, wherein a provisioning server that provides an SNPN credential is located in a DNN indicated by the DNN information, or the DNN information is provided to the terminal by the ONN during the login process. In an embodiment, the trigger for the terminal to initiate the PDU session establishment procedure to retrieve an SNPN credential depends on the terminal, for example, the terminal initiates the PDU session establishment procedure according to user input. After the base station receives the first PDU session establishment request message sent by the terminal, the base station sends the first PDU session establishment request message to the AMF.

[0115] In an embodiment, after the AMF receives the first PDU session establishment request message sent by the base station, the AMF determines whether the terminal requests to establish a PDU session for obtaining a credential based on a DNN determined based on the DNN information in the first PDU session establishment request message and a DNN determined based on the DNN information in the AMF login configuration data. In an embodiment, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data not matching, the PDU session establishment request message is rejected. In another embodiment, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data matching, a session management function (SMF) entity connected to the DNN is selected.

[0116] In an embodiment, after selecting the SMF entity connected to the DNN, a second PDU session establishment request message is sent to the SMF entity, wherein the second PDU session establishment request message includes information of the DNN and creation indication information of creating a PDU session for obtaining a credential. After the SMF entity receives the second PDU session establishment request message, the security policy information of the PDU session to be created for obtaining the credential is configured to indicate a first target state according to the creation indication information, wherein the first target state is a state indicating that the user plane security protection is performed. Here, the first target state can be a “required” state indicating that the security protection needs to be performed on the DRB of the terminal.

[0117] In an embodiment, after connecting to the SMF entity of the DNN, a third PDU session establishment request message is sent to the SMF, wherein the third PDU session establishment request message includes information of the DNN and does not include creation indication information of creating a PDU session for obtaining a credential. After the SMF entity receives the third PDU session establishment request message, the security policy information of the PDU session is determined according to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF. In an embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the first target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF matching. Alternatively, in another embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the second target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF not matching, wherein the first target state is a state indicating that the user plane security protection is performed.

[0118] In the embodiment of the present disclosure, first indication information sent by a base station is received; wherein the first indication information is used to indicate: a user plane security protection operation of a radio data bearer (DRB) of a terminal is requested to be activated or not activated; and the DRB is used to at least carry a credential required by the terminal to access a standalone non-public network (SNPN). Here, after receiving the first indication information sent by the base station, the terminal can activate or not activate the user plane security protection operation of the DRB of the terminal based on the first indication information, so that the reliability of transmitting the credential of the SNPN through the DRB can be improved, and the transmission safety of the credential can be ensured.

[0119] It should be noted that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in the embodiments of the present disclosure or some methods in related technologies.

[0120] As shown in Figure 4 the method provided by the embodiments of the present disclosure, the method is executed by a terminal, and the method comprises the following steps.

[0121] Step 41, receiving an RRC connection reconfiguration message carrying first indication information sent by a base station.

[0122] In one embodiment, the RRC connection reconfiguration message carrying the first indication information sent by the base station can be received. Here, the base station can send the RRC connection reconfiguration message to the terminal after the RRC security protection is activated. In one embodiment, the base station sends the RRC connection reconfiguration message to the terminal after the RRC encryption and the RRC integrity protection are activated.

[0123] In one embodiment, the RRC connection reconfiguration message carrying the first indication information sent by the base station can be received. Here, the first indication information can be sent for a certain DRB. The first indication information can include the user plane integrity protection indication and / or the user plane encryption indication.

[0124] In one embodiment, the RRC connection reconfiguration message carrying the first indication information sent by the base station is received, wherein the first indication information indicates that the user plane security protection operation of the DRB of the terminal is requested to be activated. Based on the first indication information, the terminal starts the uplink user plane integrity protection and the downlink user plane verification for each DRB; and / or, based on the first indication information, the terminal starts the uplink user plane encryption and the downlink user plane decryption for each DRB.

[0125] It should be noted that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in the embodiments of the present disclosure or some methods in related technologies.

[0126] As shown in Figure 5 the method provided by the embodiments of the present disclosure, the method is executed by a terminal, and the method comprises the following steps.

[0127] Step 51, verifying the RRC connection reconfiguration message to obtain a verification result.

[0128] In one embodiment, in response to the RRC connection reconfiguration message verification being unsuccessful, the terminal ignores the RRC connection reconfiguration message. In response to the RRC connection reconfiguration message verification being successful, the terminal determines the related operation according to the first indication information in the RRC connection reconfiguration message. Here, it can be that if the verification result indicates that the verification is successful, the terminal determines whether to activate the user plane security protection operation of the DRB of the terminal according to the first indication information. In one embodiment, in response to the first indication information indicating that the user plane security protection operation of the DRB of the terminal is requested to be not activated, the RRC connection reconfiguration message is rejected. In another embodiment, in response to the first indication information indicating that the user plane security protection operation of the DRB of the terminal is requested to be activated, the user plane security protection operation is performed.

[0129] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0130] As shown in Figure 6 , the present embodiment provides a method for transmitting a credential, wherein the method is executed by a terminal, and the method comprises:

[0131] Step 61, in response to the first indication information indicating that the user plane security protection operation of the DRB of the terminal is requested to be not activated, the RRC connection reconfiguration message is rejected.

[0132] Or,

[0133] In response to the first indication information indicating that the user plane security protection operation of the DRB of the terminal is requested to be activated, the RRC connection reconfiguration message is accepted and the user plane security protection operation is performed.

[0134] Here, in response to the RRC connection reconfiguration message being rejected, the terminal will not establish a PDU session for credential transmission and will not perform the user plane security protection operation.

[0135] Here, performing the user plane security protection operation can be based on the generated user plane integrity protection key K UPint and the user plane encryption key K UPenc .

[0136] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0137] As shown in Figure 7 , the present embodiment provides a method for transmitting a credential, wherein the method is executed by a terminal, and the method comprises:

[0138] Step 71, sending an RRC connection reconfiguration complete message to the base station.

[0139] In one embodiment, the terminal receives the RRC connection reconfiguration message carrying the first indication information sent by the base station, verifies the RRC connection reconfiguration message, and obtains a verification result. If the verification result indicates that the verification is successful, the terminal determines whether to activate the user plane security protection operation of the DRB of the terminal according to the first indication information. Here, the terminal can reject the RRC connection reconfiguration message in response to the first indication information indicating that it is requested not to activate the user plane security protection operation of the DRB of the terminal, or perform the user plane security protection operation in response to the first indication information indicating that it is requested to activate the user plane security protection operation of the DRB of the terminal. Here, after the terminal determines to perform the user plane security protection operation, the terminal can send an RRC connection reconfiguration complete message to the base station. Here, the RRC connection reconfiguration complete message is used to indicate that the activation of the user plane security protection operation of the DRB of the terminal has been completed.

[0140] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0141] As shown in Figure 8 The present embodiment provides a method for transmitting a credential, wherein the method is executed by a terminal, and the method comprises:

[0142] Step 81, sending second indication information to the base station of the ONN in the RRC connection establishment process, wherein the second indication information is used to indicate that the established RRC connection is used for the terminal to log in to the ONN.

[0143] In one embodiment, before the base station of the ONN sends the first indication information to the terminal, the terminal will send the second indication information to the base station in the RRC connection establishment process, wherein the second indication information is used to indicate that the established RRC connection is used for the terminal to log in to the ONN; after receiving the second indication information, the base station will select an access and mobility management function (AMF, Access Control And Mobility Management Function) entity that supports the terminal to log in to the ONN, and here it should be noted that the AMF entity is configured with AMF login configuration data; the AMF login configuration data includes: digital data network (DNN, Digital Data Network) information used to obtain a credential and / or information limiting the terminal to only request to obtain a credential.

[0144] It should be noted that those skilled in the art can understand that the method provided by the embodiment of the disclosure can be executed alone or together with some methods in the embodiment of the disclosure or some methods in related technologies.

[0145] As shown in Figure 9 The embodiment provides a method for transmitting a credential, and the method is executed by a terminal and includes the following steps.

[0146] Step 91, in response to the terminal starting to register with the ONN, sending a registration request message to the base station.

[0147] The registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain a credential.

[0148] In one embodiment, after the base station selects the AMF entity, when the terminal needs to register with the ONN, the terminal sends a registration request message to the base station. Here, the registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain a credential. For example, the predetermined registration type is the registration type of "logging in to the SNPN". After the base station receives the registration request message, the base station sends the registration request message to the AMF. After the AMF receives the registration request message, the AMF starts a procedure of authenticating the terminal with an authentication service function (AUSF) entity in the ONN. Here, the AMF login configuration data can be data for limiting the terminal network to request only the distribution of the SNPN credential in the user plane.

[0149] It should be noted that those skilled in the art can understand that the method provided by the embodiment of the disclosure can be executed alone or together with some methods in the embodiment of the disclosure or some methods in related technologies.

[0150] As shown in Figure 10 The embodiment provides a method for transmitting a credential, and the method is executed by a terminal and includes the following steps.

[0151] Step 101, in response to the terminal successfully logging in to the ONN and needing to receive a credential through the ONN, starting a PDU session establishment procedure.

[0152] In one embodiment, after the terminal successfully logs in the ONN, if the terminal needs to receive the SNPN credential from the ONN user plane. Then the PDU session establishment procedure is started. Here, starting the PDU session establishment procedure can be sending a first PDU session establishment request message to the base station in the ONN, wherein the first PDU session establishment request message includes digital data network (DNN) information for obtaining the SNPN credential. Here, it needs to be explained that in one embodiment, the terminal can be pre-configured with the DNN information, wherein the provisioning server that provides the SNPN credential is located in the DNN indicated by the DNN information, or the DNN information is provided to the terminal by the ONN in the login process. In one embodiment, the trigger for the terminal to start the PDU session establishment procedure to retrieve the SNPN credential depends on the terminal, for example, starting the PDU session establishment procedure according to the information input by the user. After the base station receives the first PDU session establishment request message sent by the terminal, the first PDU session establishment request message is sent to the AMF.

[0153] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0154] As shown in Figure 11 , the present embodiment provides a method for transmitting a credential, wherein the method is executed by a terminal, and the method comprises:

[0155] Step 111, sending a first PDU session establishment request message to a base station in the ONN, wherein the first PDU session establishment request message includes digital data network (DNN) information for obtaining the credential.

[0156] In one embodiment, after the base station receives the first PDU session establishment request message sent by the terminal, the first PDU session establishment request message is sent to the AMF. After the AMF receives the first PDU session establishment request message sent by the base station, it is determined whether the terminal requests to establish a PDU session for obtaining the credential according to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data. In one embodiment, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data not matching, the PDU session establishment request message is rejected. In another embodiment, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data matching, a session management function entity connected to the DNN is selected.

[0157] It should be noted that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in the embodiments of the present disclosure or some methods in related technologies.

[0158] As shown in Figure 12 The method for transmitting a credential provided in the embodiments includes the following steps.

[0159] Step 121, receiving security policy information sent by a second core network device;

[0160] Step 122, sending first indication information determined based on the security policy information to a terminal;

[0161] The first indication information is used to indicate that a user plane security protection operation of a data radio bearer (DRB) of the terminal is requested to be activated or not activated, and the DRB is used to at least carry a credential required by the terminal to access a SNPN.

[0162] Here, the terminal can be, but is not limited to, a mobile phone, a tablet computer, a wearable device, a vehicle terminal, a road side unit (RSU), a smart home terminal, an industrial sensor device, and / or a medical device, etc.

[0163] Here, the base station involved in the present disclosure can be various types of base stations, such as a base station of a third generation mobile communication (3G) network, a base station of a fourth generation mobile communication (4G) network, a base station of a fifth generation mobile communication (5G) network, or other evolved base stations. Here, the base station can be an on-network (ONN) base station.

[0164] In one embodiment, the user plane security protection operation includes integrity protection and / or encryption. The user plane security protection operation of the DRB of the terminal can be integrity protection and / or encryption on the credential required by the terminal to access the SNPN carried by the DRB.

[0165] In one embodiment, the RRC connection reconfiguration message carrying the first indication information sent by the base station can be received. Here, the base station can send the RRC connection reconfiguration message to the terminal after RRC security protection is activated. In one embodiment, the RRC connection reconfiguration message is sent to the terminal after RRC encryption and RRC integrity protection are activated.

[0166] In one embodiment, the RRC connection reconfiguration message carrying the first indication information sent by the base station can be received. Here, the first indication information can be sent for a certain DRB. The first indication information can include a user plane integrity protection indication and / or a user plane encryption indication.

[0167] In one embodiment, the terminal receives an RRC connection reconfiguration message sent by the base station, the RRC connection reconfiguration message carrying first indication information, the first indication information indicating that the user plane security protection operation of the DRB of the terminal is requested to be activated. Based on the first indication information, the terminal starts the uplink user plane integrity protection and the downlink user plane authentication for each DRB; and / or, based on the first indication information, the terminal starts the uplink user plane encryption and the downlink user plane decryption for each DRB.

[0168] In one embodiment, the terminal receives an RRC connection reconfiguration message sent by the base station, the RRC connection reconfiguration message carrying first indication information, the first indication information indicating that the user plane security protection operation of the DRB of the terminal is requested not to be activated. The terminal rejects the RRC connection reconfiguration message. Here, the terminal rejecting the RRC connection reconfiguration message can be that, based on the first indication information, the terminal does not start the uplink user plane integrity protection and the downlink user plane authentication for each DRB; and, based on the first indication information, the terminal does not start the uplink user plane encryption and the downlink user plane decryption for each DRB.

[0169] Here, the integrity protection of the user plane can be the integrity protection of the credential carried on the DRB. The user plane encryption can be the encryption of the credential carried on the DRB. In this way, it can be ensured that the credential is not illegally stolen, and the transmission of the credential is safe. It should be noted that the integrity protection of the user plane can also be the integrity protection of other types of data carried on the DRB in addition to the credential. The user plane encryption can also be the encryption of other types of data carried on the DRB in addition to the credential, which is not limited here.

[0170] In one embodiment, after receiving the RRC connection reconfiguration message, the terminal verifies the RRC connection reconfiguration message. In response to the verification being unsuccessful, the terminal ignores the RRC connection reconfiguration message. In response to the verification being successful, the terminal performs the corresponding operation based on the indication of the first indication information in the RRC connection reconfiguration message.

[0171] In an embodiment, the terminal receives the RRC connection reconfiguration message carrying the first indication information sent by the base station, verifies the RRC connection reconfiguration message, and obtains a verification result. If the verification result indicates that the verification is successful, the terminal determines whether to activate the user plane security protection operation of the DRB of the terminal according to the first indication information. Here, the terminal can reject the RRC connection reconfiguration message in response to the first indication information indicating that the terminal is requested not to activate the user plane security protection operation of the DRB of the terminal, or perform the user plane security protection operation in response to the first indication information indicating that the terminal is requested to activate the user plane security protection operation of the DRB of the terminal. Here, after the terminal determines to perform the user plane security protection operation, the terminal can send an RRC connection reconfiguration complete message to the base station. Here, the RRC connection reconfiguration complete message is used to indicate that the activation of the user plane security protection operation of the DRB of the terminal has been completed.

[0172] In an embodiment, before the base station of the ONN sends the first indication information to the terminal, the terminal sends second indication information to the base station in an RRC connection establishment process, where the second indication information is used to indicate that the established RRC connection is used for the terminal to log in to the ONN. After receiving the second indication information, the base station selects an access and mobility management function (AMF) entity that supports the terminal to log in to the ONN. Here, it should be noted that the AMF entity is configured with AMF login configuration data. The AMF login configuration data includes DNN information used to obtain credentials and / or information limiting the terminal to only request to obtain credentials.

[0173] In an embodiment, after the base station selects the AMF entity, when the terminal needs to register to the ONN, the terminal sends a registration request message to the base station. Here, the registration type of the registration request message is set to a predetermined registration type, and the predetermined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain credentials. For example, the predetermined registration type is a registration type of “log in to SNPN”. After the base station receives the registration request message, the base station sends the registration request message to the AMF. After receiving the registration request message, the AMF starts a procedure of authenticating the identity of the terminal to an authentication service function (AUSF) entity in the ONN. Here, the AMF login configuration data can be to limit the terminal network to only request the distribution of SNPN credentials in the user plane.

[0174] In one embodiment, after the terminal successfully logs in the ONN, if the terminal needs to receive the SNPN credential from the ONN, the PDU session establishment procedure is started. Here, starting the PDU session establishment procedure can be sending a first PDU session establishment request message to a base station in the ONN, wherein the first PDU session establishment request message includes digital data network (DNN) information used to obtain the SNPN credential. Here, it needs to be noted that, in one embodiment, the terminal can be pre-configured with the DNN information, wherein a provisioning server providing the SNPN credential is located in a DNN indicated by the DNN information, or the DNN information is provided to the terminal by the ONN in the login process. In one embodiment, the trigger for the terminal to start the PDU session establishment procedure to retrieve the SNPN credential depends on the terminal, for example, starting the PDU session establishment procedure according to the information input by the user into the terminal. After the base station receives the first PDU session establishment request message sent by the terminal, the first PDU session establishment request message is sent to the AMF.

[0175] In one embodiment, after the AMF receives the first PDU session establishment request message sent by the base station, it determines whether the terminal requests to establish a PDU session for obtaining a credential according to a DNN determined based on the DNN information in the first PDU session establishment request message and a DNN determined based on the DNN information in the AMF login configuration data. In one embodiment, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data not matching, the PDU session establishment request message is rejected. In another embodiment, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data matching, a session management function (SMF) entity connected to the DNN is selected.

[0176] In one embodiment, after the SMF entity connected to the DNN is selected, a second PDU session establishment request message is sent to the SMF entity, wherein the second PDU session establishment request message includes information of the DNN and creation indication information of a PDU session to be created for obtaining a credential. After the SMF entity receives the second PDU session establishment request message, it configures the security policy information of the PDU session to be created for obtaining a credential to a first target state according to the creation indication information, wherein the first target state is a state indicating that the user plane security protection is performed. Here, the first target state can be a "required" state indicating that the security protection needs to be performed on the DRB of the terminal.

[0177] In one embodiment, after the SMF entity connected to the DNN, a third PDU session establishment request message is sent to the SMF, wherein the third PDU session establishment request message includes information of the DNN and does not include creation indication information of the PDU session for obtaining the credential. After the SMF entity receives the third PDU session establishment request message, the security policy information of the PDU session is determined according to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF. In one embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the first target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF matching. Alternatively, in another embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the second target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF not matching, wherein the first target state is a state indicating that the user plane security protection is performed.

[0178] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0179] As shown in FIG. 13, the present embodiment provides a method for transmitting a credential, wherein the method is executed by a base station, and the method comprises the following steps: Figure 13

[0180] In one embodiment, the RRC connection reconfiguration message carrying the first indication information can be sent to the terminal. Here, the base station can send the RRC connection reconfiguration message to the terminal after the RRC security protection is activated. In one embodiment, the base station can send the RRC connection reconfiguration message to the terminal after the RRC encryption and the RRC integrity protection are activated.

[0181] In one embodiment, the RRC connection reconfiguration message carrying the first indication information can be sent to the terminal. Here, the first indication information can be sent to a certain DRB. The first indication information can include the indication of the user plane integrity protection and / or the indication of the user plane encryption.

[0182] In one embodiment, the RRC connection reconfiguration message carrying the first indication information can be sent to the terminal. Here, the first indication information can be sent to a certain DRB. The first indication information can include the indication of the user plane integrity protection and / or the indication of the user plane encryption.

[0183] ​In an embodiment, the RRC connection reconfiguration message carrying the first indication information is sent to the terminal, where the first indication information indicates that a user plane security protection operation of activating the DRB of the terminal is requested. The terminal will start the uplink user plane integrity protection and the downlink user plane authentication based on the first indication information for each DRB; and / or the terminal will start the uplink user plane encryption and the downlink user plane decryption based on the first indication information for each DRB.

[0184] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in the embodiments of the present disclosure or some methods in related technologies.

[0185] As shown in Figure 14 , the present embodiment provides a method for transmitting a credential, where the method is executed by a base station, and the method comprises:

[0186] Step 141, in response to sending the RRC connection reconfiguration message to the terminal, starting the user plane security protection operation of the DRB of the base station.

[0187] In an embodiment, the integrity protection of the user plane can be the integrity protection of the credential carried on the DRB. The user plane encryption can be the encryption of the credential carried on the DRB. In this way, it can be ensured that the credential is not illegally stolen, and the transmission of the credential is safe. It should be noted that the integrity protection of the user plane can also be the integrity protection of other types of data carried on the DRB in addition to the credential. The user plane encryption can also be the encryption of other types of data carried on the DRB in addition to the credential, which is not limited here.

[0188] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in the embodiments of the present disclosure or some methods in related technologies.

[0189] As shown in Figure 15 , the present embodiment provides a method for transmitting a credential, where the method is executed by a base station, and the method comprises:

[0190] Step 151, receiving the second indication information sent by the terminal in the RRC connection establishment process, where the second indication information is used to indicate that the established RRC connection is used for the terminal to log in to the ONN.

[0191] In an embodiment, before the base station of the ONN sends the first indication information to the terminal, the terminal sends second indication information to the base station in an RRC connection establishment process, where the second indication information is used to indicate that the established RRC connection is used for the terminal to log in to the ONN; after receiving the second indication information, the base station selects an access and mobility management function (AMF) entity that supports the terminal to log in to the ONN, where it should be noted that the AMF entity is configured with AMF login configuration data; the AMF login configuration data includes DNN information used to obtain credentials and / or information limiting the terminal to only request to obtain credentials.

[0192] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0193] As shown in Figure 16 , the present embodiment provides a method for transmitting credentials, where the method is executed by a base station, and the method includes:

[0194] Step 161, in response to receiving the second indication information, determining a first core network device for supporting the terminal to log in to the ONN;

[0195] Wherein the first core network device is configured with AMF login configuration data; the AMF login configuration data includes DNN information used to obtain credentials and / or information limiting the terminal to only request to obtain credentials.

[0196] Here, the first core network device can be an AMF.

[0197] In an embodiment, after the base station receives the registration request message, the base station sends the registration request message to the AMF. After receiving the registration request message, the AMF starts a procedure of authenticating the terminal to the AUSF entity in the ONN. Here, the AMF login configuration data can be an indication that the terminal network is only used for the allocation or issuance of user plane SNPN credentials.

[0198] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0199] As shown in Figure 17 , the present embodiment provides a method for transmitting credentials, where the method is executed by a base station, and the method includes:

[0200] Step 171, receiving a registration request message sent by the terminal;

[0201] The registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain the credential.

[0202] In one embodiment, after the base station selects the AMF entity, when the terminal needs to register to the ONN, the base station sends a registration request message. Here, the registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain the credential. For example, the predetermined registration type is the registration type of "log in SNPN".

[0203] In one embodiment, the base station also sends the registration request message to the session management function AMF.

[0204] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0205] As shown in Figure 18 The embodiments provide a method for transmitting a credential, wherein the method is executed by a base station, and the method comprises:

[0206] Step 181, receiving a first PDU session establishment request message sent by the terminal, wherein the first PDU session establishment request message comprises DNN information used to obtain the credential.

[0207] In one embodiment, after the terminal successfully logs in to the ONN, if the terminal needs to receive the SNPN credential from the ONN, the PDU session establishment procedure is started. Here, starting the PDU session establishment procedure can be sending a first PDU session establishment request message to the base station in the ONN, wherein the first PDU session establishment request message comprises digital data network (DNN) information used to obtain the credential. It should be noted that in one embodiment, the terminal can be pre-configured with the DNN information, wherein the provision server providing the SNPN credential is located in the DNN indicated by the DNN information, or the DNN information is provided to the terminal by the ONN in the login process. In one embodiment, the trigger for the terminal to start the PDU session establishment procedure to retrieve the SNPN credential depends on the terminal, for example, starting the PDU session establishment procedure according to the information input by the user. After the base station receives the first PDU session establishment request message sent by the terminal, the base station sends the first PDU session establishment request message to the AMF.

[0208] Here, the base station also sends the first PDU session establishment request message to the AMF.

[0209] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the disclosure can be executed alone or together with some methods in the embodiments of the disclosure or some methods in related technologies.

[0210] As shown in Figure 19 The embodiment provides a method for transmitting a credential, and the method is executed by a first core network device, and the method comprises the following steps:

[0211] Step 191, receiving a registration request message sent by a base station;

[0212] The registration type of the registration request message is set as a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used for the terminal to log in an ONN to obtain a credential required for logging in an SNPN.

[0213] Here, the first core network device can be an AMF entity.

[0214] In one embodiment, after receiving the registration request message, the AMF starts a procedure of authenticating the identity of the terminal to an authentication service function entity in the ONN. Here, the AMF login configuration data can be data for limiting the terminal network to request only the distribution of the SNPN credential in the user plane.

[0215] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the disclosure can be executed alone or together with some methods in the embodiments of the disclosure or some methods in related technologies.

[0216] As shown in Figure 20 The embodiment provides a method for transmitting a credential, and the method is executed by a first core network device, and the method comprises the following steps:

[0217] Step 201, receiving a first PDU session establishment request message sent by a base station, wherein the first PDU session establishment request message comprises DNN information used for obtaining an SNPN credential.

[0218] Here, the first core network device can be an AMF entity.

[0219] In one embodiment, after the terminal successfully logs in the ONN, if the terminal needs to receive the SNPN credential from the ONN, the PDU session establishment procedure is started. Here, starting the PDU session establishment procedure can be sending a first PDU session establishment request message to a base station in the ONN, wherein the first PDU session establishment request message includes digital data network (DNN) information used to obtain the credential. Here, it needs to be noted that, in one embodiment, the terminal can be pre-configured with the DNN information, wherein a provisioning server that provides the SNPN credential is located in a DNN indicated by the DNN information, or the DNN information is provided to the terminal by the ONN in the login process. In one embodiment, the trigger for the terminal to start the PDU session establishment procedure to retrieve the SNPN credential depends on the terminal, for example, starting the PDU session establishment procedure according to user input information of the terminal. After the base station receives the first PDU session establishment request message sent by the terminal, the first PDU session establishment request message is sent to the AMF.

[0220] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0221] As shown in Figure 21 , the present embodiment provides a method for transmitting a credential, wherein the method is executed by a first core network device, and the method comprises:

[0222] Step 211, determining whether the terminal requests to establish a PDU session for obtaining the credential according to a DNN determined based on the DNN information in the first PDU session establishment request message and a DNN determined based on the DNN information in the AMF login configuration data.

[0223] Here, the first core network device can be an AMF entity.

[0224] In one embodiment, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data not matching, the PDU session establishment request message is rejected; or, in response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data matching, a session management function (SMF) entity connected to the DNN is determined.

[0225] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0226] As shown in Figure 22As shown, this embodiment provides a method for transmitting credentials, wherein the method is executed by a first core network device, and the method includes:

[0227] Step 221: In response to the mismatch between the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data, reject the PDU session establishment request message;

[0228] or,

[0229] In response to the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data, a second core network device connected to the DNN is identified.

[0230] Here, the first core network device can be an AMF entity; the second core network device can be an SMF entity.

[0231] In one embodiment, rejecting a PDU session establishment request message may mean not responding to the PDU session establishment request message and performing other operations.

[0232] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.

[0233] like Figure 23 As shown, this embodiment provides a method for transmitting credentials, wherein the method is executed by a first core network device, and the method includes:

[0234] Step 231: In response to determining the second core network device, send a second PDU session establishment request message to the second core network device, wherein the second PDU session establishment request message includes the information of the DNN and creation instruction information for creating a PDU session for obtaining credentials.

[0235] Here, the first core network device can be an AMF entity; the second core network device can be an SMF.

[0236] In an embodiment, after selecting the SMF entity connected to the DNN, a second PDU session establishment request message is sent to the SMF entity, wherein the second PDU session establishment request message includes information of the DNN and creation indication information of creating a PDU session for obtaining a credential. After the SMF entity receives the second PDU session establishment request message, the security policy information of the PDU session to be created for obtaining the credential is configured to indicate a first target state according to the creation indication information, wherein the first target state is a state indicating that the user plane security protection is performed. Here, the first target state can be a "required" state indicating that the security protection needs to be performed on the DRB of the terminal.

[0237] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0238] As shown in Figure 24 , the present embodiment provides a method for transmitting a credential, wherein the method is executed by a first core network device, and the method comprises:

[0239] Step 241, in response to determining the second core network device, a third PDU session establishment request message is sent to the second core network device, wherein the third PDU session establishment request message includes information of the DNN and does not include creation indication information of creating a PDU session for obtaining a credential.

[0240] Here, the first core network device can be an AMF entity; the second core network device can be an SMF,

[0241] In one embodiment, after the SMF entity connected to the DNN, a third PDU session establishment request message is sent to the SMF, wherein the third PDU session establishment request message includes information of the DNN and does not include creation indication information of the PDU session for obtaining the credential. After the SMF entity receives the third PDU session establishment request message, the security policy information of the PDU session is determined according to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF. In one embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the first target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF matching. Alternatively, in another embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the second target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF not matching, wherein the first target state is a state indicating that the user plane security protection is performed.

[0242] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0243] As shown in Figure 25 , the present embodiment provides a method for transmitting a credential, wherein the method is executed by a second core network device, and the method comprises:

[0244] Step 251, receiving a PDU session establishment request message sent by a first core network device, wherein the PDU session establishment request message at least includes information of a DNN, wherein the information of the DNN is used to indicate a DNN required for obtaining a credential for accessing an SNPN by a terminal;

[0245] Step 252, determining security policy information of the PDU session according to the session establishment request message;

[0246] Step 253, sending the security policy information to a base station.

[0247] Here, the second core network device can be an SMF entity; and the first core network device can be an AMF entity.

[0248] In an embodiment, the PDU session establishment request message can be the second PDU session establishment request message or the third PDU session establishment request message. The second PDU session establishment request message includes the information of the DNN and the creation indication information of the PDU session for obtaining the credential. The third PDU session establishment request message includes the information of the DNN and does not include the creation indication information of the PDU session for obtaining the credential.

[0249] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0250] As shown in Figure 26 The embodiments provide a method for transmitting a credential, and the method is executed by a second core network device, and the method comprises the following steps:

[0251] In step 261, according to the creation indication information, the security policy information of the PDU session to be created for obtaining the credential is configured to indicate a first target state, wherein the first target state is a state indicating that the user plane security protection is performed.

[0252] Here, the second core network device can be an SMF entity.

[0253] After the SMF entity receives the second PDU session establishment request message, according to the creation indication information, the security policy information of the PDU session to be created for obtaining the credential is configured to indicate a first target state, wherein the first target state is a state indicating that the user plane security protection is performed. Here, the first target state can be a "need" state in which the DRB of the terminal needs to be protected.

[0254] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0255] As shown in Figure 27 The embodiments provide a method for transmitting a credential, and the method is executed by a second core network device, and the method comprises the following steps:

[0256] In step 271, according to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the second core network device, the security policy information of the PDU session is determined.

[0257] Here, the second core network device can be an SMF entity.

[0258] After the SMF entity receives the third PDU session establishment request message, the security policy information of the PDU session is determined according to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the SMF. In one embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the first target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message matching the DNN determined based on the DNN information configured in the SMF. Alternatively, in another embodiment, the security policy information of the PDU session to be created for obtaining the credential can be configured to indicate the second target state in response to the DNN determined based on the DNN information in the third PDU session establishment request message not matching the DNN determined based on the DNN information configured in the SMF, wherein the first target state is a state indicating that the user plane security protection is performed.

[0259] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0260] As shown in Figure 28 The present embodiment provides a method for transmitting a credential, wherein the method is executed by a second core network device, and the method comprises the following steps:

[0261] Step 281, in response to the DNN determined based on the DNN information in the third PDU session establishment request message matching the DNN determined based on the DNN information configured in the second core network device, the security policy information of the PDU session to be created for obtaining the credential is configured to indicate the first target state.

[0262] Alternatively,

[0263] in response to the DNN determined based on the DNN information in the third PDU session establishment request message not matching the DNN determined based on the DNN information configured in the second core network device, the security policy information of the PDU session to be created for obtaining the credential is configured to indicate the second target state, wherein the first target state is a state indicating that the user plane security protection is performed.

[0264] Here, the second core network device can be an SMF entity.

[0265] In an embodiment, the DNN indicated by the DNN information in the third PDU session establishment request message is the same as the DNN indicated by the DNN information configured in the SMF, and it is determined that the DNNs match. Alternatively, the DNN indicated by the DNN information in the third PDU session establishment request message is different from the DNN indicated by the DNN information configured in the SMF, and it is determined that the DNNs do not match.

[0266] Here, the second target state is a state in which the user plane security policy information determined by the SMF according to the requested specific service is set to indicate a specific option, and can be a state in which user plane security protection needs to be performed or a state in which user plane security protection does not need to be performed.

[0267] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0268] As shown in Figure 29 , the present embodiment provides a device for transmitting a credential, wherein the device comprises:

[0269] The receiving module 291 is configured to receive first indication information sent by the base station.

[0270] The first indication information is used to indicate that a user plane security protection operation of a radio data bearer (DRB) of the terminal is requested to be activated or not activated, and the DRB is used to at least carry a credential required by the terminal to access the SNPN.

[0271] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the present disclosure can be executed alone or together with some methods in some methods or related technologies in the embodiments of the present disclosure.

[0272] As shown in Figure 30 , the present embodiment provides a device for transmitting a credential, wherein the device comprises:

[0273] The receiving module 301 is configured to receive security policy information sent by the second core network device.

[0274] The sending module 302 is configured to send first indication information determined based on the security policy information to the terminal.

[0275] The first indication information is used to indicate that a user plane security protection operation of a radio data bearer (DRB) of the terminal is requested to be activated or not activated, and the DRB is used to at least carry a credential required by the terminal to access the SNPN.

[0276] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the disclosure can be executed alone or together with some methods in the embodiments of the disclosure or some methods in related technologies.

[0277] As shown in Figure 31 , the embodiment provides a device for transmitting a credential, wherein the device comprises:

[0278] The receiving module 311 is configured to receive a registration request message sent by a base station.

[0279] The registration type of the registration request message is set to a predetermined registration type; the predetermined registration type is used to indicate that the registration request message is used for terminal login ONN to obtain a credential required by the terminal to access an SNPN.

[0280] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the disclosure can be executed alone or together with some methods in the embodiments of the disclosure or some methods in related technologies.

[0281] As shown in Figure 32 , the embodiment provides a device for transmitting a credential, wherein the device comprises:

[0282] The receiving module 321 is configured to receive a PDU session establishment request message sent by a first core network device, wherein the PDU session establishment request message at least includes information of a DNN, and the information of the DNN is used to indicate a DNN for obtaining a credential required by a terminal to access an SNPN.

[0283] The determining module 322 is configured to determine security policy information of the PDU session according to the session establishment request message.

[0284] The sending module 323 is configured to send the security policy information to a base station.

[0285] It should be noted that those skilled in the art can understand that the method provided by the embodiments of the disclosure can be executed alone or together with some methods in the embodiments of the disclosure or some methods in related technologies.

[0286] The embodiment of the disclosure provides a communication device, the communication device comprising:

[0287] A processor;

[0288] A memory for storing processor-executable instructions;

[0289] The processor is configured to implement the method applied to any embodiment of the disclosure when the executable instructions are executed.

[0290] The processor can include various types of storage media that are non-transitory computer storage media capable of continuing to store information even after the communication device is powered off.

[0291] The processor can be connected with the memory through a bus or the like for reading an executable program stored on the memory.

[0292] The present disclosure also provides a computer storage medium, where the computer storage medium stores a computer executable program, and the executable program is executed by the processor to implement the method of any of the embodiments of the present disclosure.

[0293] As to the apparatus in the above embodiments, the specific manners in which the various modules perform operations have been described in detail in the embodiments of the method, and thus will not be described in detail here.

[0294] As shown in Figure 33 , one embodiment of the present disclosure provides a structure of a terminal.

[0295] Referring to Figure 33 , the present embodiment provides a terminal 800, which can be specifically a mobile phone, a computer, a digital broadcast terminal, a messaging equipment, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0296] Referring to Figure 33 , the terminal 800 can include one or more of the following components: a processing component 802, a memory 804, a power supply component 806, a multimedia component 808, an audio component 810, an input / output (I / O) interface 812, a sensor component 814, and a communication component 816.

[0297] The processing component 802 usually controls overall operations of the terminal 800, such as operations associated with displaying, making phone calls, data communications, camera operations and recording operations. The processing component 802 can include one or more processors 820 to execute instructions to complete all or part of steps of the above method. Further, the processing component 802 can include one or more modules to facilitate the interaction between the processing component 802 and other components. For example, the processing component 802 can include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.

[0298] The memory 804 is configured to store various types of data to support the operation of the terminal 800. Examples of such data include instructions for any application or method operating on the terminal 800, contact data, phonebook data, messages, pictures, videos, and the like. The memory 804 can be implemented by any type of volatile or nonvolatile storage devices or a combination thereof such as static random access memory (SRAM), electrically erasable programmable read only memory (EEPROM), erasable programmable read only memory (EPROM), programmable read only memory (PROM), read only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0299] The power supply component 806 supplies electrical power for the various components of the terminal 800. The power supply component 806 can include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing electrical power for the terminal 800.

[0300] The multimedia component 808 includes a screen providing an output interface between the terminal 800 and a user. In some embodiments, the screen can include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touch, swiping, and gestures on the touch panel. The touch sensor can not only sense a boundary of a touching or swiping action, but also detect duration and pressure related to the touching or swiping action. In some embodiments, the multimedia component 808 includes a front camera and / or a back camera. The front and / or back camera can receive external multimedia data when the terminal 800 is in an operation mode such as a photographing mode or a video mode. Each of the front and back camera can be a fixed optical lens system or have a focal length and optical zoom capability.

[0301] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC) configured to receive external audio signals when the terminal 800 is in an operation mode such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 804 or transmitted via the communication component 816. In some embodiments, the audio component 810 also includes a speaker for outputting audio signals.

[0302] The I / O interface 812 provides an interface between the processing component 802 and peripheral interface modules such as a keypad, a click wheel, buttons, and the like. The buttons can include, but are not limited to, a home button, a volume button, a start button, and a lock button.

[0303] Sensor assembly 814 includes one or more sensors for providing state assessments of various aspects of terminal 800. For example, sensor assembly 814 can detect the on / off state of terminal 800, the relative positioning of components such as the display and keypad of terminal 800, changes in the position of terminal 800 or a component of terminal 800, the presence or absence of user contact with terminal 800, the orientation or acceleration / deceleration of terminal 800, and temperature changes of terminal 800. Sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 814 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 814 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.

[0304] Communication component 816 is configured to facilitate wired or wireless communication between terminal 800 and other devices. Terminal 800 can access wireless networks based on communication standards, such as Wi-Fi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, communication component 816 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 816 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0305] In an exemplary embodiment, terminal 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.

[0306] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, which can be executed by a processor 820 of a terminal 800 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0307] like Figure 34 As shown, one embodiment of this disclosure illustrates the structure of a base station. For example, base station 900 can be provided as a network-side device. (Refer to...) Figure 34The base station 900 includes a processing component 922 that is further comprised of one or more processors, and memory resources represented by memory 932 for storing instructions executable by the processing component 922, such as an application. The memory 932 stored application can include one or more modules each corresponding to a set of instructions. In addition, the processing component 922 is configured to execute the instructions to perform any of the methods described above for the base station.

[0308] The base station 900 can also include a power supply component 926 configured to supply power to the base station 900, a wired or wireless network interface 950 configured to connect the base station 900 to a network, and an input output (I / O) interface 958. The base station 900 can operate based on an operating system stored in the memory 932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or the like.

[0309] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the specification and examples be considered as exemplary only, with the true scope and spirit of the application being indicated by the following claims.

[0310] It is to be understood that the application is not limited to the specific structures that have been described and that shown in the drawings, and that since modifications and changes can be made in the embodiments of the application, in its operation procedures, and / or in its details, without departing from the spirit and scope of the application. The application is only limited by the claims that follow.

Claims

1. A method for transmitting credentials, wherein, The method is executed by a terminal, and the method includes: The base station receives a first indication message sent by the base station. The first indication message is determined by the base station based on security policy information from a second core network device. The security policy information is determined by the second core network device based on a second PDU session establishment request message sent by the first core network device. The second PDU session establishment request message includes at least DNN information, wherein the DNN information is used to indicate the DNN required to obtain the credentials for the terminal to access the Independent Non-Public Network (SNPN). The first indication information is used to indicate: requesting activation or deactivation of uplink and / or downlink user plane security protection operations of the terminal's Radio Data Bearer (DRB); the DRB is at least used to carry the credentials.

2. The method according to claim 1, wherein, The user plane security protection operations include: integrity protection and / or encryption.

3. The method according to claim 1, wherein, The first indication information sent by the receiving base station includes: Receive a Radio Resource Control (RRC) connection reconfiguration message sent by the base station, carrying the first indication information.

4. The method according to claim 2, wherein, The method further includes: Verify the RRC connection reconfiguration message and obtain the verification result.

5. The method according to claim 4, wherein, The method further includes: In response to the verification result indicating successful verification, determine whether to activate the user plane security protection operation of the terminal's DRB based on the first indication information.

6. The method according to claim 5, wherein, The method further includes: In response to the first indication information indicating a request not to activate the user plane security protection operation of the terminal's DRB, the RRC connection reconfiguration message is rejected; or, In response to the first indication information indicating a request to activate the user plane security protection operation of the terminal's DRB, the system accepts the RRC connection reconfiguration message and performs the user plane security protection operation.

7. The method according to claim 6, wherein, The method further includes: Send an RRC connection reconfiguration complete message to the base station.

8. The method according to claim 1, wherein, The method further includes: During the RRC connection establishment process, a second indication message is sent to the base station of the login network ONN, wherein the second indication message is used to indicate that the established RRC connection is used for the terminal to log in to the ONN.

9. The method according to claim 8, wherein, The method further includes: In response to the terminal initiating registration with the ONN, a registration request message is sent to the base station; The registration type of the registration request message is set to a pre-defined registration type; the pre-defined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain the credentials.

10. The method according to claim 9, wherein, The method further includes: In response to the terminal successfully logging into the ONN and needing to receive the credentials through the ONN, the PDU session establishment procedure is initiated.

11. The method according to claim 10, wherein, The process of initiating the PDU session establishment includes: A first PDU session establishment request message is sent to the base station in the ONN, wherein the first PDU session establishment request message includes digital data network (DNN) information for obtaining the credentials.

12. A method for transmitting credentials, wherein, The method is executed by a base station, and the method includes: The system receives security policy information sent by a second core network device. The security policy information is determined based on a second PDU session establishment request message sent by a first core network device. The second PDU session establishment request message includes at least DNN information, wherein the DNN information is used to indicate the DNN required to obtain the credentials for terminal access to SNPN. Send a first indication message determined based on the security policy information to the terminal; The first indication information is used to indicate: requesting activation or deactivation of uplink and / or downlink user plane security protection operations of the terminal's Radio Data Bearer (DRB); the DRB is at least used to carry the credentials.

13. The method according to claim 12, wherein, The user plane security protection operations include: integrity protection and / or encryption.

14. The method according to claim 12, wherein, Sending the first instruction information to the terminal includes: Send an RRC connection reconfiguration message carrying the first indication information to the terminal.

15. The method according to claim 12, wherein, The method further includes: In response to sending the RRC connection reconfiguration message to the terminal, the user plane security protection operation of the DRB of the base station is initiated.

16. The method according to claim 12, wherein, The method further includes: During the RRC connection establishment process, a second indication message is received from the terminal, wherein the second indication message indicates that the established RRC connection is used for the terminal to log in to the ONN.

17. The method according to claim 16, wherein, The method further includes: In response to receiving the second indication information, a first core network device for supporting terminal login to the ONN is determined; The first core network device is configured with AMF login configuration data; the AMF login configuration data includes: digital data network (DNN) information for obtaining the credentials and / or information that restricts the terminal to only requesting the credentials.

18. The method according to claim 17, wherein, The method further includes: Receive the registration request message sent by the terminal; The registration type of the registration request message is set to a pre-defined registration type; the pre-defined registration type is used to indicate that the registration request message is used to log in to the ONN to obtain the credentials.

19. The method according to claim 18, wherein, The method further includes: Send the registration request message to the first core network device.

20. The method according to claim 19, wherein, The method further includes: The receiving terminal sends a first PDU session establishment request message, wherein the first PDU session establishment request message includes DNN information for obtaining the credentials.

21. The method according to claim 20, wherein, The method further includes: Send the first PDU session establishment request message to the first core network device.

22. A method for transmitting credentials, wherein, The method is executed by a first core network device, and the method includes: The first PDU session establishment request message sent by the base station is received, wherein the first PDU session establishment request message includes a DNN for obtaining the credentials required for the terminal to access the Independent Non-Public Network (SNPN); A second PDU session establishment request message is sent to a second core network device connected to the DNN. The second PDU session establishment request message includes at least information about the DNN, which is used to indicate the DNN that obtains the credentials. The second PDU session establishment request message is used to determine security policy information, which is used to determine first indication information. The first indication information is used to indicate whether to activate or deactivate uplink and / or downlink user plane security protection operations of the terminal's Radio Data Bearer (DRB). The DRB is used to carry at least the credentials.

23. The method according to claim 22, wherein, The method further includes: Receive registration request messages sent by the base station; The registration type of the registration request message is set to a pre-defined registration type; the pre-defined registration type is used to indicate that the registration request message is used for the terminal to log in to the ONN to obtain the credentials required for the terminal to access the SNPN.

24. The method according to claim 22, wherein, The method further includes: In response to receiving the registration request message, a procedure is initiated to authenticate the terminal with the Authentication Service Function (AUSF) in the ONN.

25. The method according to claim 24, wherein, The method further includes: Based on the DNN determined from the DNN information in the first PDU session establishment request message and the DNN determined from the DNN information in the AMF login configuration data, it is determined whether the terminal requests to establish a PDU session for obtaining the credentials.

26. The method according to claim 25, wherein, The step of determining whether the terminal requests to establish a PDU session for obtaining the credentials based on the DNN information determined in the first PDU session establishment request message and the DNN information determined in the AMF login configuration data includes: In response to the mismatch between the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data, the PDU session establishment request message is rejected. or, In response to a match between the DNN determined based on the DNN information in the first PDU session establishment request message and the DNN determined based on the DNN information in the AMF login configuration data, a second core network device connected to the DNN is determined.

27. The method according to claim 22, wherein, The second PDU session establishment request message includes creation instruction information for creating a PDU session to obtain the credentials.

28. The method according to claim 26, wherein, The method further includes: In response to identifying the second core network device, a third PDU session establishment request message is sent to the second core network device, wherein the third PDU session establishment request message includes DNN information but does not include creation instruction information for creating a PDU session for obtaining credentials.

29. A method for transmitting credentials, wherein, The method is executed by the second core network device, and the method includes: Receive a second PDU session establishment request message sent by a first core network device, wherein the second PDU session establishment request message includes at least DNN information, wherein the DNN information is used to indicate the DNN for obtaining the credentials required for the terminal to access the Independent Non-Public Network (SNPN); Based on the second PDU session establishment request message, determine the security policy information of the PDU session; The security policy information is sent to the base station. The security policy information is used to determine the first indication information, which is used to indicate whether to activate or deactivate the uplink and / or downlink user plane security protection operation of the terminal's Radio Data Bearer (DRB); the DRB is at least used to carry the credentials.

30. The method according to claim 29, wherein, The PDU session establishment request message is a second PDU session establishment request message that also includes creation instruction information for creating a PDU session for obtaining credentials; determining the security policy information of the PDU session based on the session establishment request message includes: According to the creation instruction information, the security policy information of the PDU session to be created for obtaining credentials is configured to indicate a first target state, wherein the first target state is a state indicating user plane security protection.

31. The method according to claim 29, wherein, The PDU session establishment request message is a third PDU session establishment request message that does not include creation instruction information for creating a PDU session for obtaining credentials; The step of determining the security policy information of the PDU session based on the session establishment request message includes: The security policy information of the PDU session is determined based on the DNN information determined in the third PDU session establishment request message and the DNN information configured in the second core network device.

32. The method according to claim 31, wherein, The step of determining the security policy information of the PDU session based on the DNN information determined in the third PDU session establishment request message and the DNN information configured in the second core network device includes: In response to the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the second core network device, the security policy information of the PDU session to be created for obtaining credentials is configured to indicate the first target state. or, In response to a mismatch between the DNN determined based on the DNN information in the third PDU session establishment request message and the DNN determined based on the DNN information configured in the second core network device, the security policy information of the PDU session to be created for obtaining credentials is configured to indicate a second target state, wherein the first target state is a state indicating user plane security protection.

33. An apparatus for transmitting credentials, wherein, The device includes: The receiving module is configured to receive first indication information sent by the base station. The first indication information is determined by the base station based on security policy information from the second core network device. The security policy information is determined by the second core network device based on a second PDU session establishment request message sent by the first core network device. The second PDU session establishment request message includes at least DNN information, wherein the DNN information is used to indicate the DNN required to obtain the credentials for the terminal to access the Independent Non-Public Network (SNPN). The first indication information is used to indicate: requesting activation or deactivation of uplink and / or downlink user plane security protection operations of the terminal's Radio Data Bearer (DRB); the DRB is at least used to carry the credentials.

34. An apparatus for transmitting credentials, wherein, The device includes: The receiving module is used to receive security policy information sent by the second core network device. The security policy information is determined based on the PDU session establishment request message sent by the first core network device. The PDU session establishment request message includes at least DNN information, wherein the DNN information is used to indicate the DNN required to obtain the credentials for the terminal to access the Independent Non-Public Network (SNPN). The sending module is used to send first indication information determined based on the security policy information to the terminal; The first indication information is used to indicate: requesting activation or deactivation of uplink and / or downlink user plane security protection operations of the terminal's Radio Data Bearer (DRB); the DRB is at least used to carry the credentials.

35. An apparatus for transmitting credentials, wherein, The device includes: The receiving module is configured to receive a first PDU session establishment request message sent by the base station, wherein the first PDU session establishment request message includes a DNN for obtaining the credentials required for the terminal to access the Independent Non-Public Network (SNPN); The sending module is configured to send a second PDU session establishment request message to a second core network device connected to the DNN, wherein the second PDU session establishment request message includes at least information about the DNN, the DNN information being used to indicate the DNN that obtains the credentials; the second PDU session establishment request message is used to determine security policy information, the security policy being used to determine first indication information, the first indication information being used to indicate: requesting activation or deactivation of uplink and / or downlink user plane security protection operations of the terminal's Radio Data Bearer (DRB), the DRB being used at least to carry the credentials.

36. An apparatus for transmitting credentials, wherein, The device includes: The receiving module is configured to receive a second PDU session establishment request message sent by a first core network device, wherein the second PDU session establishment request message includes at least DNN information, wherein the DNN information is used to indicate the DNN for obtaining the credentials required for the terminal to access the Independent Non-Public Network (SNPN). The determining module is configured to: determine the security policy information of the PDU session based on the second PDU session establishment request message; The sending module is configured to send the security policy information to the base station. The security policy information is used to determine first indication information, which indicates whether to activate or deactivate uplink and / or downlink user plane security protection operations of the terminal's Radio Data Bearer (DRB). The DRB is used to carry at least the credentials.

37. A communication device, wherein, include: Memory; A processor, connected to the memory, is configured to execute computer-executable instructions stored in the memory and to implement the method according to any one of claims 1 to 11, 12 to 21, 22 to 28, or 29 to 32.

38. A computer storage medium storing computer-executable instructions, which, when executed by a processor, enable the implementation of the method according to any one of claims 1 to 11, 12 to 21, 22 to 28, or 29 to 32.

Citation Information

Patent Citations

  • Communication method and equipment

    CN111641944A

  • User equipment onboarding based on default manufacturer credentials unlicensed

    US20210058784A1