A method and apparatus for configuring security information
By configuring security information through network elements in the 5G system such as UDR, NEF, MSF-C, etc., the security information configuration problem of terminal equipment and network side under the 5G MBS architecture is solved, the encryption and integrity protection of user plane data is realized, and data security is improved.
Patent Information
- Application Number
- CN202080104217.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-07
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2040-08-07
AI Technical Summary
In the existing 5G LTE multimedia broadcast and multicast functions, the key distribution process is not fully applicable to the 5G MBS architecture, making it difficult to configure security information on the terminal device and the network side, and unable to effectively protect the user plane data security under the 5G MBS architecture.
Through network elements in the 5G system such as UDR, NEF, MSF-C, etc., security information, including encryption keys, integrity protection keys and algorithms, is determined and configured to ensure the security of user plane data.
It realizes the security information configuration of terminal equipment and network side under the 5G MBS architecture, ensures the encryption and integrity protection of user plane data, and improves data security.
Smart Images

Figure CN116134841B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and in particular to a method and apparatus for configuring security information. BACKGROUND
[0002] A fifth generation (5G) network introduces user plane security information for user plane protection. The security information can include two features of confidentiality protection and integrity protection. The implementation manner can be that a session management function (SMF) determines the security information and sends the security information to a radio access network (RAN). The RAN can determine the protection requirements of the confidentiality protection and the integrity protection according to the security information.
[0003] A third generation partnership project (3GPP) study item report proposes a fifth generation (5G) multicast-broadcast service (MBS) architecture. Although the RAN can transmit data under the 5G MBS in a multicast or unicast manner in the architecture, the multicast manner cannot perform data protection at a packet data convergence protocol (PDCP) layer like the unicast manner. The multicast manner needs higher layer user plane data protection, for example, end-to-end (E2E) protection between a terminal device and an application function (AF) network element or E2E protection between the terminal device and a 5G core network (5GC).
[0004] Although in the multimedia broadcast multicast service (MBMS) function of the existing long term evolution (LTE) network, after the UE establishes a connection with the multimedia broadcast multicast service center (BM-SC), the BM-SC can send the key for broadcast multicast data through the hypertext transfer protocol (http). However, the key distribution process in LTE is not fully applicable to the 5G MBS architecture. This is because in the 5G MBS architecture, the functions of the BM-SC have been split into multiple network entities of 5G, such as the session management function (SMF) and the policy control function (PCF). Therefore, how to reuse the configuration process of 5GC to complete the configuration of security information between the terminal device and the network side under the 5GMBS architecture is an urgent problem to be solved. Summary of the Invention
[0005] The embodiments of the present application provide a method and apparatus for configuring security information, which can implement the configuration of security information between terminal devices and the network side under the 5G MBS architecture, and ensure the security of user plane data under the 5G MBS architecture.
[0006] To achieve the above objectives, the embodiments of the present application adopt the following technical solutions.
[0007] In a first aspect, a method for configuring security information is provided, which is applied to a system including a multicast-broadcast service (MBS) architecture, the system including a first network function network element and a second network function network element. The method includes: the first network function network element receives an identifier of a multicast group, determines security information corresponding to the identifier of the multicast group, where the security information is used to perform encryption protection and / or integrity protection on user plane data of the multicast group, and the security information includes an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm; the first network function network element sends the security information to the second network function network element, where the second network function network element includes one or more of a user plane function (e.g., MSF-U) network element of a multicast service function, a control plane function (e.g., MSF-C) network element of a multicast service function, a network exposure function (e.g., NEF) network element, or a session management function (e.g., SMF) network element; the first network function network element may include one or more of a unified data repository (e.g., UDR) network element, a network exposure function (e.g., NEF), a session management function (e.g., SMF), or a control plane function (e.g., MSF-C) network element of a multicast service function.
[0008] Therefore, in the 5G MBS architecture, security information can be configured through network elements within the 5G system, ensuring the security of user-plane data within the 5G MBS architecture. For example, the UDR network element can determine the security information corresponding to the multicast group identifier based on the security policy. Therefore, when the UE requests security information from the network, it can obtain the security information from the UDR network element and use it to decrypt the MBS user-plane data.
[0009] In one possible design, the security information also includes a security policy and / or protection method for user-plane data. The security policy indicates protection requirements for user-plane data, including encryption protection requirements and / or integrity protection requirements. The protection method indicates whether encryption protection and / or integrity protection are performed on user-plane data. In this way, network-side network elements that receive the security information can protect user-plane data based on the security information, or can also protect user-plane data based on the security policy or protection method.
[0010] In one possible design, the security information also includes a protection method; receiving the identifier of the multicast group, and determining the security information corresponding to the identifier of the multicast group includes: receiving the identifier and security policy of the multicast group from the network open function network element or the control plane function network element of the multicast service function; determining the protection method according to the security policy; or receiving the identifier and protection method of the multicast group from the network open function network element or the control plane function network element of the multicast service function; generating security information according to the protection method.
[0011] In other words, network elements in the MBS can generate security information based on received security policies or protection methods, allowing network-side network elements to protect MBS user plane data based on the security information. For example, a UDR network element receives the multicast group identifier and security policy from an NEF network element or an MSF-C network element, determines the protection method based on the security policy, and then generates security information based on the protection method. Alternatively, the UDR network element receives the multicast group identifier and protection method from an NEF network element or an MSF-C network element, and generates security information based on the protection method.
[0012] In one possible design, sending security information to the second network function network element includes sending security information to a network open function network element or a control plane function network element of a multicast service function. That is, after a network-side network element generates security information, it can send the security information to other network elements for storage. For example, a UDR network element sends the security information to an NEF network element or an MSF-C network element for storage. In this way, when a UE requests security information, the network-side network element can obtain security information corresponding to the multicast group identifier from the NEF network element or the MSF-C network element.
[0013] In one possible design, the first network function network element includes a unified data repository (e.g., UDR) network element; after generating security information according to the protection method, the method further includes: the unified data repository network element determines the correspondence between the security information and the identifier of the multicast group; receiving the identifier of the multicast group, and determining the security information corresponding to the identifier of the multicast group also includes: the unified data repository network element receives a request message from the session management function network element, the request message includes the identifier of the multicast group; the unified data repository network element determines the security information corresponding to the identifier of the multicast group according to the correspondence; sending security information to the second network function network element includes: the unified data repository network element sends security information to the session management function network element.
[0014] It can be understood that the unified database network element stores the correspondence between the multicast group identifier and security information. If a request message is subsequently received from the UE requesting the security information corresponding to the multicast group identifier, the unified database network element can respond to the UE with the security information based on the correspondence through the second network function network element. For example, the UDR network element stores the correspondence. When the UDR network element receives the request message sent by the SMF network element, the UDR network element sends the security information to the SMF network element, so that the SMF network element can send the security information to the UE.
[0015] The corresponding relationships stored in the unified database network element may be generated and saved by itself, or may be corresponding relationships received from other network elements such as network open function network elements or control plane function network elements of multicast service functions.
[0016] In one possible design, the first network function network element includes a network open function network element or a control plane function network element of a multicast service function, and the security information also includes a protection method; receiving the identifier of the multicast group and determining the security information corresponding to the identifier of the multicast group includes: the network open function network element or the control plane function network element of the multicast service function receives the identifier and security policy of the multicast group from the application function network element; the network open function network element or the control plane function network element of the multicast service function determines the protection method according to the security policy; the network open function network element or the control plane function network element of the multicast service function generates security information according to the protection method; sending security information to the second network function network element includes: the network open function network element or the control plane function network element of the multicast service function sends security information to the unified data storage network element.
[0017] That is, the security information configured by the network side can be generated by a network exposure function network element or a control plane function network element of a multicast service function, and the generated security information and the identifier of the multicast group are sent to a unified data repository network element for storage. For example, the NEF network element or the MSF-C network element receives the identifier of the multicast group and the security policy sent by the AF network element, the NEF network element or the MSF-C network element determines the security information according to the security policy, and the NEF network element or the MSF-C network element sends the security information to the UDR network element for storage. In this way, when the UE requests the security information, the network side network element can obtain the security information corresponding to the identifier of the multicast group from the UDR network element and send it to the UE.
[0018] In a possible design, the security information is generated according to the protection mode, including: if the protection mode indicates that encryption protection is performed on the user plane data, an encryption key and an encryption algorithm are generated; if the protection mode indicates that integrity protection is performed on the user plane data, an integrity protection key and an integrity protection algorithm are generated. If the protection mode indicates that no encryption protection is performed on the user plane data, and no integrity protection is performed on the user plane data, the network side network element can also generate the encryption key, the encryption algorithm, the integrity protection key and the integrity protection algorithm, but the encryption algorithm and the integrity protection algorithm are both empty algorithms.
[0019] In a possible design, the first network function network element includes a network exposure function network element or a control plane function network element of a multicast service function; the identifier of the multicast group is received, and the security information corresponding to the identifier of the multicast group is determined, including: the network exposure function network element or the control plane function network element of the multicast service function receives the identifier of the multicast group and the security policy from the application function network element; the network exposure function network element or the control plane function network element of the multicast service function sends the security policy and the identifier of the multicast group to the unified data repository network element, and the unified data repository network element can generate the security information according to the received security policy, and the unified data repository network element sends the security information and the identifier of the multicast group to the network exposure function network element or the control plane function network element of the multicast service function; or, the network exposure function network element or the control plane function network element of the multicast service function determines the protection mode according to the security policy, and sends the protection mode and the identifier of the multicast group to the unified data repository network element; the unified data repository network element can generate the security information according to the received protection mode, and the unified data repository network element sends the security information and the identifier of the multicast group to the network exposure function network element or the control plane function network element of the multicast service function, that is, the network exposure function network element or the control plane function network element of the multicast service function receives the security information from the unified data repository network element.
[0020] That is, upon receiving a security policy, the network open function network element or the control plane function network element of the multicast service function may send the security policy to the unified data storage network element, so that the unified data storage network element generates security information based on the security policy and then feeds it back to the network open function network element or the control plane function network element of the multicast service function. Alternatively, the network open function network element or the control plane function network element of the multicast service function may first generate a protection method based on the security policy, and then send the protection method to the unified data storage network element, so that the unified data storage network element generates security information based on the protection method and then feeds it back to the network open function network element or the control plane function network element of the multicast service function.
[0021] For example, upon receiving the multicast group identifier and security policy, the NEF or MSF-C network element can send the multicast group identifier and security policy to the UDR network element. The UDR network element generates security information based on the security policy and then feeds it back to the NEF or MSF-C network element. Alternatively, the NEF or MSF-C network element can first generate a protection mode based on the security policy and send it to the UDR network element. The UDR network element then generates security information based on the protection mode and then feeds it back to the NEF or MSF-C network element.
[0022] In one possible design, sending security information to the second network function network element includes: sending security information to a user plane function network element or a session management function network element of a multicast service function.
[0023] It can be understood that when the NEF network element or MSF-C network element receives the identification and security information of the multicast group from the UDR network element, the NEF network element can also send the identification and security information of the multicast group to the SMF network element. When the UE obtains the security information, it can obtain the security information from the SMF network element; or, the MSF-C network element can also send security information to the MSF-U network element. When the UE obtains the security information, it can obtain the security information from the MSF-U network element.
[0024] In a second aspect, a method for configuring security information is provided, which is applied to a terminal device, and the network where the terminal device is located includes a session management function network element. The method includes: sending a multicast group identifier to the session management function network element to request to join the multicast group; receiving security information from the session management function network element, the security information is used to encrypt and / or integrity protect user plane data of the multicast group, the security information includes an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm, the security information also includes a security policy and / or protection method for user plane data; the security policy indicates the protection requirements of the user plane data, the protection requirements include encryption protection requirements, and / or integrity protection requirements; the protection method indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data; and decrypting the received user plane data according to the security information.
[0025] The terminal device may be a UE. When security information is configured in the 5G MBS, if the UE wishes to join the multicast group and requests security information, the UE may request the security information from a session management function (e.g., SMF) network element. If the session management function network element stores the security information corresponding to the multicast group identifier, the security information may be directly delivered to the UE. If the session management function network element does not store the security information corresponding to the multicast group identifier, the session management function network element may request the security information from another network element, such as a unified data storage network element, and then deliver the security information to the UE. In this way, while the network-side network elements in the MBS architecture can protect the multicast group data based on the security information, the UE can also decrypt the data based on the requested security information, thereby ensuring the security of user-plane data in the MBS architecture.
[0026] On the third aspect, a method for configuring security information is provided, which is applied to a system including a multicast-broadcast service MBS architecture, the system including a unified data storage network element, a network open function network element, a control plane function network element for multicast service functions, a session management function network element and a terminal device.
[0027] In one possible design, the unified data repository network element receives a multicast group identifier and a security policy from a network open function network element or a control plane function network element of a multicast service function; the unified data repository network element determines a protection mode according to the security policy; and the unified data repository network element generates security information according to the protection mode.
[0028] Alternatively, the network exposure function network element or the control plane function network element of the multicast service function receives the identifier of the multicast group and the security policy, determines the protection mode according to the security policy, and sends the identifier of the multicast group and the protection mode to the unified data repository network element, which generates the security information according to the protection mode.
[0029] Further, the unified data repository network element can send the security information and the identifier of the multicast group to the network exposure function network element or the control plane function network element of the multicast service function. The security information can further include the protection mode.
[0030] The unified data repository network element can determine the correspondence between the security information and the identifier of the multicast group. When the unified data repository network element receives a request message from the session management function network element, the request message including the identifier of the multicast group, the unified data repository network element can determine the security information corresponding to the identifier of the multicast group according to the correspondence, and send the security information to the session management function network element.
[0031] In another possible design, the network exposure function network element or the control plane function network element of the multicast service function receives the identifier of the multicast group and the security policy from the application function network element, determines the protection mode according to the security policy, generates the security information according to the protection mode, and sends the security information to the unified data repository network element;
[0032] Alternatively, the network exposure function network element or the control plane function network element of the multicast service function receives the identifier of the multicast group and the security policy from the application function network element, sends the security policy and the identifier of the multicast group to the unified data repository network element, which generates the security information according to the received security policy, and sends the security information and the identifier of the multicast group to the network exposure function network element or the control plane function network element of the multicast service function. The network exposure function network element can further send the security information to the session management function network element, and the control plane function network element of the multicast service function can further send the security information to the user plane function network element of the multicast service function.
[0033] Alternatively, the network open function network element or the control plane function network element of the multicast service function receives the multicast group identifier and security policy from the application function network element. The network open function network element or the control plane function network element of the multicast service function may also first generate a protection mode based on the security policy and send the protection mode to the unified data storage network element. The unified data storage network element then generates security information based on the protection mode and feeds it back to the network open function network element or the control plane function network element of the multicast service function. The network open function network element may also send security information to the session management function network element, and the control plane function network element of the multicast service function may also send security information to the user plane function network element of the multicast service function.
[0034] When a terminal device decides to join a multicast group, it can send the multicast group identifier to the session management function network element to request to join the multicast group. If the session management function network element stores security information corresponding to the multicast group identifier, it can directly send the security information to the terminal device. If the session management function network element does not store security information corresponding to the multicast group identifier, it can request the security information from another network element, such as a unified data storage network element, and then send it to the terminal device.
[0035] The security policy indicates the protection requirements for user plane data, including encryption protection requirements and / or integrity protection requirements. The protection mode indicates whether encryption protection and / or integrity protection are performed on user plane data. Network-side network elements that receive security information can protect user plane data based on the security information, or they can protect user plane data based on the security policy or protection mode.
[0036] In a fourth aspect, a method for configuring security information is provided, which is applied to a system including a multicast-broadcast service MBS architecture, the system including a unified data storage network element, a network open function network element, and a session management function network element.
[0037] The unified data repository network element can receive the multicast group identifier and security policy from the network open function network element, determine a protection method based on the security policy, and generate security information based on the protection method. The unified data repository network element sends the security information to the network open function network element. The unified data repository network element can also determine a correspondence between the security information and the multicast group identifier. When the unified data repository network element receives a request message from the session management function network element, the request message including the multicast group identifier, the unified data repository network element can determine the security information corresponding to the multicast group identifier based on the correspondence, and send the security information to the session management function network element.
[0038] Alternatively, the network exposure function network element receives the identification of the multicast group and the security policy from the application function network element, the network exposure function network element determines the protection manner according to the security policy, and the network exposure function network element generates the security information according to the protection manner. The network exposure function network element can also send the security information to the unified data repository network element. The network exposure function network element can also send the security information to the session management function network element.
[0039] Alternatively, the network exposure function network element receives the identification of the multicast group and the security policy from the application function network element, the network exposure function network element determines the protection manner according to the security policy, and the network exposure function network element sends the protection manner and the identification of the multicast group to the unified data repository network element, the unified data repository network element can generate the security information according to the received protection manner, and the unified data repository network element sends the security information and the identification of the multicast group to the network exposure function network element. The network exposure function network element can also send the security information to the session management function network element.
[0040] In a possible design, the security information further includes a security policy and / or a protection manner of the user plane data; the security policy indicates a protection requirement of the user plane data, and the protection requirement includes an encryption protection requirement and / or an integrity protection requirement; and the protection manner indicates whether to perform encryption protection on the user plane data and / or whether to perform integrity protection on the user plane data.
[0041] In a fifth aspect, a method for configuring security information is provided, which is applied to a system including a multicast-broadcast service (MBS) architecture, and the system includes a control plane function network element of a multicast service function and a user plane function network element of the multicast service function.
[0042] The control plane function network element of the multicast service function receives the identification of the multicast group and the security policy from the application function network element, and the control plane function network element of the multicast service function can send the identification of the multicast group and the security policy to the unified data repository network element, so that the unified data repository network element determines the security information according to the security policy; or the control plane function network element of the multicast service function can send the identification of the multicast group and the protection manner to the unified data repository network element, so that the unified data repository network element determines the security information according to the protection manner.
[0043] Alternatively, the control plane function network element of the multicast service function can also determine the protection manner according to the security policy, generate the security information according to the protection manner, and send the identification of the multicast group and the security information to the user plane function network element of the multicast service function, so that the user plane function network element of the multicast service function protects the data according to the security information.
[0044] Alternatively, the control plane function network element of the multicast service function may also receive the multicast group identifier and security information. The control plane function network element of the multicast service function may also send the multicast group identifier and security information to the user plane function network element of the multicast service function, so that the user plane function network element of the multicast service function can protect the data according to the security information.
[0045] In one possible design, the security information also includes a security policy and / or protection method for user plane data; the security policy indicates the protection requirements of the user plane data, the protection requirements include encryption protection requirements, and / or integrity protection requirements; the protection method indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data.
[0046] In a sixth aspect, a method for configuring security information is provided, which is applied to a system including a multicast-broadcast service MBS architecture, the system including a unified data storage network element and a session management function network element.
[0047] When receiving the identifier and security policy of the multicast group, the unified data storage network element may determine security information according to the identifier and security policy of the multicast group and then send the security information to the session management function network element.
[0048] Alternatively, when the unified data storage network element receives the identifier and protection mode of the multicast group, it may determine the security information according to the identifier and protection mode of the multicast group and send it to the session management function network element.
[0049] The unified data repository network element may determine a correspondence between security information and a multicast group identifier. When the unified data repository network element receives a request message from a session management function network element, the request message including the multicast group identifier, the unified data repository network element may determine, based on the correspondence, the security information corresponding to the multicast group identifier and send the security information to the session management function network element.
[0050] In one possible design, the security information also includes a security policy and / or protection method for user plane data; the security policy indicates the protection requirements of the user plane data, the protection requirements include encryption protection requirements, and / or integrity protection requirements; the protection method indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data.
[0051] In the seventh aspect, a network function network element is provided, which is a first network function network element. The first network function network element is applied to a system of a multicast-broadcast service architecture. The system includes the first network function network element and the second network function network element. The first network function network element includes: a transceiver for receiving an identifier of a multicast group; a processor for determining security information corresponding to the identifier of the multicast group, the security information being used to encrypt and / or integrity protect the user plane data of the multicast group, the security information including an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm; the transceiver is also used to send security information to the second network function network element, the second network function network element including one or more of a user plane function network element of a multicast service function, a control plane function network element of a multicast service function, a network open function network element or a session management function network element.
[0052] In one possible design, the security information also includes a security policy and / or protection method for user plane data; the security policy indicates the protection requirements of the user plane data, the protection requirements include encryption protection requirements, and / or integrity protection requirements; the protection method indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data.
[0053] In one possible design, the security information also includes a protection method; a transceiver is used to receive the identifier and security policy of the multicast group from the network open function network element or the control plane function network element of the multicast service function, and a processor is used to determine the protection method based on the security policy; or, a transceiver is used for the identifier and protection method of the multicast group from the network open function network element or the control plane function network element of the multicast service function; and a processor is used to generate security information based on the protection method.
[0054] In one possible design, the transceiver is configured to send security information to a network open function network element or a control plane function network element of a multicast service function.
[0055] In one possible design, the first network function network element includes a unified data storage network element; the processor is further used to determine the correspondence between security information and the identifier of the multicast group; the transceiver is further used to receive a request message from the session management function network element, the request message including the identifier of the multicast group; the processor is further used to determine the security information corresponding to the identifier of the multicast group based on the correspondence; the transceiver is further used to send the security information to the session management function network element.
[0056] In one possible design, the first network function network element includes a network open function network element or a control plane function network element of a multicast service function, and the security information also includes a protection method; a transceiver is used to receive the identifier and security policy of the multicast group from the application function network element; a processor is used to determine the protection method according to the security policy; the processor is used to generate security information according to the protection method; and the transceiver is used to send security information to a unified data storage repository network element.
[0057] In one possible design, the processor is configured to: generate an encryption key and an encryption algorithm if the protection mode indicates that encryption protection is performed on user plane data; and generate an integrity protection key and an integrity protection algorithm if the protection mode indicates that integrity protection is performed on user plane data.
[0058] In one possible design, the first network function network element includes a network open function network element or a control plane function network element of a multicast service function; a transceiver for receiving the identifier and security policy of the multicast group from the application function network element; a transceiver for sending the security policy and the identifier of the multicast group to the unified data repository network element; or, a processor for determining the protection method according to the security policy, and a transceiver for sending the protection method and the identifier of the multicast group to the unified data repository network element; a transceiver for receiving security information from the unified data repository network element.
[0059] In one possible design, the transceiver is configured to send security information to a user plane function network element or a session management function network element of a multicast service function.
[0060] In an eighth aspect, a terminal device is provided, wherein the network where the terminal device is located includes a session management function network element, and the terminal device includes: a transceiver, used to send an identifier of a multicast group to the session management function network element to request to join the multicast group; the transceiver is also used to receive security information from the session management function network element, the security information is used to encrypt and / or integrity protect the user plane data of the multicast group, the security information includes an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm, the security information also includes a security policy and / or protection method for the user plane data; the security policy indicates the protection requirements of the user plane data, the protection requirements include encryption protection requirements, and / or integrity protection requirements; the protection method indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data; a processor, used to decrypt the received user plane data according to the security information.
[0061] In the ninth aspect, an embodiment of the present application provides a computer-readable storage medium, including computer instructions. When the computer instructions are run on an electronic device, the electronic device executes the method for configuring security information in the above-mentioned first aspect and any possible implementation of the first aspect.
[0062] In the tenth aspect, an embodiment of the present application provides a computer-readable storage medium, including computer instructions. When the computer instructions are executed on an electronic device, the electronic device executes the security information configuration method in the above-mentioned second possible implementation method.
[0063] In the eleventh aspect, an embodiment of the present application provides a computer program product, which, when running on a computer, enables an electronic device to execute the security information configuration method in the above-mentioned first aspect and any possible implementation of the first aspect.
[0064] In a twelfth aspect, an embodiment of the present application provides a computer program product, which, when running on a computer, enables an electronic device to execute the security information configuration method in a possible implementation of the above-mentioned second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] Figure 1 A schematic diagram of the basic architecture of a 5G MBS provided in an embodiment of the present application;
[0066] Figure 2 A schematic diagram of the basic architecture of a 5G MBS provided in an embodiment of the present application;
[0067] Figure 3 A schematic diagram of the basic architecture of a 5G MBS provided in an embodiment of the present application;
[0068] Figure 4 A schematic diagram of the main process of configuring a user plane security policy provided in an embodiment of the present application;
[0069] Figure 5 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0070] Figure 6 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0071] Figure 7 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0072] Figure 8 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0073] Figure 9 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0074] Figure 10A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0075] Figure 11 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0076] Figure 12 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0077] Figure 13 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0078] Figure 14 A flowchart of a method for configuring security information provided in an embodiment of the present application;
[0079] Figure 15 A schematic diagram of the structure of a network function network element provided in an embodiment of the present application;
[0080] Figure 16 A schematic diagram of the structure of a network function network element provided in an embodiment of the present application. DETAILED DESCRIPTION
[0081] The embodiments of the present application can be applied to the 5G MBS architecture. The network-side device configures security information so that the terminal device participating in the multicast broadcast service can decrypt the user plane data based on the security information, thereby improving the security of the user plane data under the 5G MBS architecture.
[0082] First, let’s introduce the basic architecture of 5G MBS proposed by 3GPP.
[0083] One architecture of 5G MBS can be as follows Figure 1 As shown, it is based on the existing 5G network architecture and enhances the functions of some network function (NF) network elements in the 5G network architecture. The architecture 1 may include: AF network element, network exposure function (NEF) network element, policy control function (PCF) network element, session management function (SMF) network element, user plane function (UPF) network element, next generation radio access network (NG-RAN) network element and terminal equipment (for example, user equipment (UE)), etc. Among them:
[0084] The AF network element can be the source of multicast and / or broadcast data, call the MBS provided by the 5G system, and send multicast and / or groupcast data to multiple UEs through 5G.
[0085] NEF network elements implement 5G open functions and communicate with AF network elements. AF network elements can access some functional network elements in the 5G network through NEF network elements. In addition, NEF network elements can negotiate 5G MBS with AF network elements, including quality of service (QoS) and 5G MBS service domain.
[0086] The PCF network element can support 5G MBS; provide MBS session-related policy messages to the SMF network element; receive MBS service information from the AF network element directly or indirectly (through the NEF);
[0087] The SMF network element can control MBS transmission based on the MBS policy received from the PCF network element; configure MBS flows and point-to-point or point-to-multipoint transmission on the UPF network element; configure MBS flows and QoS information on the RAN network element; and configure session management of MBS flows on the UE.
[0088] The UPF network element supports packet filtering of MBS flows and can transmit MBS flows to the RAN network element in a point-to-point or point-to-multipoint manner; receives MBS configuration from the SMF network element; checks the Internet Group Management Protocol (IGMP) packet and notifies the SMF network element of the IGMP packet; receives unicast or multicast flows from the AF, etc.
[0089] The NG-RAN network element can receive the MBS stream sent by the UPF network element, switch the transmission of the MBS stream between multicast and unicast, etc.
[0090] UE can support MBS policy configuration; support MBS flow session management; support joining MBS flow; support MBS at the access layer, etc.
[0091] Corresponding to architecture 1, Figure 2As shown, there is also a 5G MBS architecture 2 that adds a multicast service function (MSF) network element on the basis of architecture 1. In this architecture 2, the AF network element can use the MBS provided by the 5G system through the MSF network element. The MSF network element can request MBS through the NEF network element or the PCF network element. Among them, the MSF network element can serve as the entry point for control plane signaling and user plane data. The MSF network element may include an MSF control plane function (MSFcontrol plane, MSF-C) network element and an MSF network element user plane function (MSFuser plane, MSF-U) network element. The MSF-C network element is used for signaling processing and receiving signaling, such as signaling for multicast service configuration and MBS bearer activation. The MSF-U network element is used for user plane data transmission and user plane data encoding.
[0092] Another 5G MBS architecture 3 can be as follows Figure 3 This architecture 3 introduces new NFs to the existing 5G system architecture and enhances the functions of existing UE and NG-RAN network elements to support 5G MBS. This architecture 3 may include:
[0093] The AMF network element that enhances the UE, NG-RAN and access and mobility management function (AMF) can be called an M-AMF network element;
[0094] Multicast / broadcast session management function (MB-SMF) network element and multicast / broadcast user plane function (MB-UPF) network element. The MB-SMF can be used for MBS session management, and the MB-UPF can be used to transmit multicast and broadcast data. The MB-SMF network element here is equivalent to the MSF-C network element mentioned in this application.
[0095] Multicast / broadcast service function (MBSF) network element, which is used to process signaling and provide an interface to the AF;
[0096] The multicast / broadcast service user plane function (MBSU) network element can be used to transmit multicast and broadcast data, etc.; the MBSU network element is equivalent to the MSF-U network element mentioned in this application.
[0097] Currently, although the 5G network has introduced a user plane security policy configuration process for user plane protection, this process does not support the negotiation mechanism of security information in 5G MBS for the above architectures 1, 2, and 3.
[0098] The main process of current user plane security policy configuration is as follows: Figure 4 Shown, including:
[0099] 41. In the protocol data unit (PDU) session establishment process, the UE sends a non-access stratum (NAS) message to the AMF network element. The message may include parameters such as the network slice identifier (single network slice selection assistance information, S-NSSAI) and the data network name (DNN).
[0100] 42. The AMF network element sends a create SMF context request (create SMF context request) or an update SMF context request (update SMF context request) to the SMF network element. The request may carry a subscription permanent identifier (SUPI), S-NSSAI and DNN, etc.
[0101] 43. The SMF network element determines the user plane security policy. The specific method may include: the SMF network element sends a request to the unified data management function (UDM) network element, and the request carries SUPI, DNN and / or S-NSSAI, so that the UDM network element determines the contracted user plane security policy based on DNN and / or S-NSSAI, and sends the contracted user plane security policy to the SMF network element. Whether the SMF network element here can obtain the contracted user plane security policy from the UDM network element is optional. This is because the SMF network element may also store the configured user plane security policy locally. If the SMF network element obtains the contracted user plane security policy from the UDM network element, the contracted user plane security policy will be used as the final user plane security policy; otherwise, the SMF network element will use the user plane security policy corresponding to the locally configured DNN and / or S-NSSAI as the final user plane security policy.
[0102] The user plane security policy here includes the requirements for confidentiality protection and integrity protection.
[0103] Confidentiality protection requirements may include:
[0104] A.required, confidentiality protection is required.
[0105] B.preferred, hope to use confidentiality protection.
[0106] C. not needed, confidentiality protection is not required.
[0107] Integrity protection requirements may include:
[0108] A.required, integrity protection is required.
[0109] B.preferred, you want to use integrity protection.
[0110] C. not needed, integrity protection is not required.
[0111] 44. The SMF network element sends the user plane security policy to the base station through the AMF network element.
[0112] 45. The base station determines the protection method for the end user plane based on local capabilities (such as whether integrity protection rate is supported, etc.).
[0113] If the protection requirement is required, the base station must perform protection. If it cannot be performed, a rejection indication is sent to the SMF network element.
[0114] If the protection requirement is preferred, the protection mode is optional and the base station decides whether to perform protection.
[0115] If the protection requirement is not needed, the base station does not perform protection.
[0116] The protection here includes confidentiality protection and integrity protection.
[0117] 46. The base station sends a confidentiality protection indication and / or an integrity protection indication, where the confidentiality protection indication is used to indicate whether confidentiality protection is required, and the integrity protection indication is used to indicate whether integrity protection is required.
[0118] 47. The UE performs subsequent user plane data protection according to the confidentiality protection indication and / or integrity protection indication.
[0119] It can be seen that the user plane security policy configuration process introduced by the existing 5G network for user plane protection is not targeted at 5G MBS. Therefore, how to introduce user plane security policy configuration in 5G MBS is a technical problem to be solved by this application.
[0120] To this end, an embodiment of the present application provides a method for configuring security information, which can be applied to the above-mentioned architecture 1 or architecture 2 or architecture 3. For example, in architecture 1, the process of sending user plane data can be: after the UPF receives the user plane data that needs to be sent from the AF network element, the UPF network element sends the user plane data to the corresponding RAN node (base station); then the RAN node sends the user plane data to the UE. For example, in architecture 2 or architecture 3, a service layer is introduced. The service layer includes the MSF-C network element and the MSF-U network element. The MSF-C network element mainly processes the control plane data; the MSF-U network element mainly processes the user plane data. The process of sending user plane data can be: after the MSF-U network element receives the user plane data from the AF network element, it first sends it to the UPF network element, and then the UPF network element sends the user plane data to the corresponding base station; then the base station broadcasts the user plane data to the corresponding UE.
[0121] In order to ensure the security of the user plane data sent down by 5G MBS under Architecture 1, Architecture 2 and Architecture 3, the present application provides a variety of security information configuration methods. For example, one method may include: as a network element that can be used to store data in Architecture 1 and Architecture 2: a unified data repository (UDR) network element, which can save data of multiple network elements, such as data of network elements such as NEF network elements, PCF network elements, SMF network elements and AMF network elements. Therefore, in the present application, the UDR network element can obtain the identifier of the multicast group, determine the security information corresponding to the identifier of the multicast group, and save the security information. The security information is used to encrypt and / or integrity protect the user plane data of the multicast group. The security information includes an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm. The UDR network element can determine the corresponding security information based on the identifier of the multicast group, or it can receive security information determined by other network elements, such as the NEF network element or the MSF-C network element based on the identifier of the multicast group and save it.
[0122] For another example, another method for configuring security information may include: the NEF network element or MSF-C network element receives the multicast group identifier and security policy sent by the AF network element, the NEF network element or MSF-C network element determines security information based on the security policy, and then sends the security information to the UDR network element. Alternatively, the NEF network element or MSF-C network element receives the multicast group identifier and security policy sent by the AF network element and sends the multicast group identifier and security policy to the UDR, or sends the protection mode and multicast group identifier determined by the NEF network element or MSF-C network element based on the security policy to the UDR network element. After the UDR network element determines the security information, the NEF network element or MSF-C network element receives the security information sent by the UDR network element.
[0123] When a UE joins the multicast group, it can request security information from a core network element, such as an SMF network element. The SMF network element can obtain the security information from the UDR network element and send it to the UE. When the UE receives downlink user plane data, it can decrypt the user plane data based on the security information.
[0124] The configuration process of the security information of this application is not limited to the above two methods, and specific implementation methods will be described in the following embodiments.
[0125] An embodiment of the present application provides a method for configuring security information. The method can be applied to a system including an MBS. The system includes a first network function element and a second network function element. The method may include:
[0126] The first network function network element receives a multicast group identifier and determines security information corresponding to the multicast group identifier. The security information is used to encrypt and / or integrity protect user plane data of the multicast group. The security information includes an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm. The multicast group identifier may also be replaced with a broadcast group identifier. This means that the present application can be applied to protecting user plane data of both multicast services and broadcast services.
[0127] The first network function network element sends security information to the second network function network element, where the second network function network element includes one or more of a user plane function network element of a multicast service function, a control plane function network element of a multicast service function, a network open function network element, or a session management function network element. The first network function network element may include one or more of a unified data repository network element, a network open function network element, and a control plane function network element of a multicast service function.
[0128] These first network function network elements and second network function network elements are both network elements under the 5G MBS architecture. Therefore, the security information configuration method provided in the embodiment of the present application can be applied to the protection of user plane data under the 5G MBS architecture.
[0129] In some embodiments, the security information may also include security policies and / or protection methods for user plane data;
[0130] The security policy indicates the protection requirements of user plane data, which include encryption protection requirements and / or integrity protection requirements;
[0131] The protection mode indicates whether encryption protection is performed on the user plane data and / or whether integrity protection is performed on the user plane data.
[0132] In some embodiments, the security information further includes a protection mode. The receiving the multicast group identifier and determining the security information corresponding to the multicast group identifier may include: receiving the multicast group identifier and a security policy from a network open function network element or a control plane function network element of a multicast service function, and determining the protection mode based on the security policy; or receiving the multicast group identifier and the protection mode from a network open function network element or a control plane function network element of a multicast service function, and generating the security information based on the protection mode.
[0133] Exemplarily, the unified data repository network element may receive the multicast group identifier and security policy from the network open function network element or the control plane function network element of the multicast service function, and determine the protection mode based on the security policy; or the unified data repository network element may directly receive the multicast group identifier and protection mode from the network open function network element or the control plane function network element of the multicast service function. Furthermore, the unified data repository network element generates security information based on the protection mode.
[0134] In some embodiments, sending security information to the second network function network element includes: sending security information to a network open function network element or a control plane function network element of a multicast service function.
[0135] For example, after obtaining security information, the unified data storage network element may send the security information to the network open function network element or the control plane function network element of the multicast service function, and the network open function network element or the control plane function network element of the multicast service function may store the security information. If a terminal device subsequently requests security information, the security information may be obtained from the network open function network element or the control plane function network element of the multicast service function.
[0136] In some embodiments, the first network function network element includes a unified data repository network element; after generating the security information according to the protection method, the method further includes: the unified data repository network element determining a correspondence between the security information and an identifier of the multicast group. In other words, the unified data repository network element stores the correspondence.
[0137] Based on this, the above-mentioned receiving the multicast group identifier and determining the security information corresponding to the multicast group identifier may also include:
[0138] The unified data repository network element receives a request message from the session management function network element, the request message including the multicast group identifier; the unified data repository network element determines the security information corresponding to the multicast group identifier based on the corresponding relationship. Thus, the sending of the security information to the second network function network element may include: the unified data repository network element sending the security information to the session management function network element.
[0139] In this way, when the terminal device requests the security information from the session management function network element, the session management function network element can obtain the security information from the unified data repository network element and then send the security information to the terminal device.
[0140] It should be noted that the correspondence stored in the unified data repository network element can also be obtained in other manners, such as the implementation manner described in the following embodiments.
[0141] In some embodiments, the first network function network element includes a network exposure function network element or a control plane function network element of a multicast service function, and the security information further includes a protection manner. The receiving of the identifier of the multicast group and the determining of the security information corresponding to the identifier of the multicast group can include: the network exposure function network element or the control plane function network element of the multicast service function receiving the identifier of the multicast group and a security policy from an application function network element; the network exposure function network element or the control plane function network element of the multicast service function determining the protection manner according to the security policy; and the network exposure function network element or the control plane function network element of the multicast service function generating the security information according to the protection manner. Thus, the sending of the security information to the second network function network element can include: the network exposure function network element or the control plane function network element of the multicast service function sending the security information to the unified data repository network element.
[0142] In some embodiments, the generating of the security information according to the protection manner can include: if the protection manner indicates that encryption protection is performed on user plane data, generating an encryption key and an encryption algorithm; and if the protection manner indicates that integrity protection is performed on the user plane data, generating an integrity protection key and an integrity protection algorithm.
[0143] In some embodiments, the first network function network element includes a network exposure function network element or a control plane function network element of a multicast service function. The receiving of the identifier of the multicast group and the determining of the security information corresponding to the identifier of the multicast group can include: the network exposure function network element or the control plane function network element of the multicast service function receiving the identifier of the multicast group and a security policy from an application function network element. The network exposure function network element or the control plane function network element of the multicast service function sends the security policy and the identifier of the multicast group to the unified data repository network element, and the unified data repository network element generates the security information according to the security policy; or the network exposure function network element or the control plane function network element of the multicast service function determines a protection manner according to the security policy, sends the protection manner and the identifier of the multicast group to the unified data repository network element, and the unified data repository network element generates the security policy according to the protection manner.
[0144] In this way, the network exposure function network element or the control plane function network element of the multicast service function can receive the security information from the unified data repository network element.
[0145] In some embodiments, sending the security information to the second network function network element includes sending the security information to a user plane function network element of a multicast service function or a session management function network element.
[0146] Exemplarily, the network openness function network element may send security information to the session management function network element, which may store the correspondence between the security information and the multicast group identifier. Alternatively, the control plane function network element of the multicast service function may send security information to the user plane function network element of the multicast service function, which may store the correspondence between the security information and the multicast group identifier.
[0147] After completing the configuration process of the complete security information of the MBS architecture, when the terminal device joins the multicast service corresponding to the multicast group identifier, it can obtain security information from the network function network element on the network side, so as to decrypt the user plane data received from the network side according to the security information.
[0148] Therefore, an embodiment of the present application also provides a method for configuring security information, which is applied to a terminal device, and the network where the terminal device is located includes a session management function network element. The method may include: sending a multicast group identifier to the session management function network element to request to join the multicast group; receiving security information from the session management function network element, the security information is used to encrypt and / or integrity protect the user plane data of the multicast group, the security information includes an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm, the security information also includes a security policy and / or protection method for the user plane data; the security policy indicates the protection requirements of the user plane data, the protection requirements include encryption protection requirements, and / or integrity protection requirements; the protection method indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data; and decrypting the received user plane data according to the security information.
[0149] In this way, after the network function element in the MBS protects the user plane data according to the security information, the terminal device can decrypt the ciphertext sent by the network side according to the requested security information to obtain the decrypted user plane data.
[0150] The following embodiments will be described using the unified data storage network element as the UDR network element, the network open function network element as the NEF network element, the user plane function network element of the multicast service function as the MSF-U network element, the control plane function network element of the multicast service function as the MSF-C network element, and the session management function network element as the SMF network element as an example.
[0151] Example 1
[0152] like Figure 5 As shown, an embodiment of the present application provides a method for configuring security information, the method comprising:
[0153] 501. The AF network element sends the multicast group identifier to the NEF network element.
[0154] Among them, the identifier of the multicast group can be a multicast group ID (identity), or the identifier of the multicast group can also be replaced by a multicast context identifier (multicast context ID). Among them, the identifier of the multicast group can be used to identify the multicast service, and can also be called a multicast identifier or a multicast service identifier, etc. The following embodiments are all described using the identifier of the multicast group as an example. In addition, the broadcast service is similar to the multicast service, for example, the identifier of the multicast group here can also be replaced by the identifier of the broadcast group. That is, the following operations on the identifier of the multicast group are also applicable to the identifier of the broadcast group, that is, the protection and negotiation process for the multicast service is also applicable to the broadcast service. The identifier of the multicast group here may include an IP multicast address, and the identifier of the multicast group may also include information used to identify the application or service, such as the identifier of the application or service, or the identifier of the network where the application or service is located, or the access point identifier, or the access network identifier, or the identifier of the data network where the AF is located, etc. In the embodiment of the present application, the multicast group identifier may include a temporary mobile group identity (TMGI).
[0155] In some embodiments, the AF network element may also send a security policy to the NEF network element. The security policy indicates the protection requirements for the user plane data of the multicast group. In other words, the security policy is used to identify the protection requirements corresponding to the multicast group identifier. The protection requirements may include encryption protection requirements and / or integrity protection requirements. Encryption protection requirements may include, for example, the aforementioned required, preferred, or not needed. Integrity protection requirements may also include, for example, the aforementioned required, preferred, or not needed.
[0156] Encryption protection can be understood as encrypting data using an encryption algorithm and encryption key to produce ciphertext. The device receiving the data can decrypt the ciphertext using the decryption key and decryption algorithm to obtain the data. Integrity protection can be understood as protecting the integrity of the data using an integrity protection algorithm and integrity protection key, and outputting integrity protection verification parameters. The device that receives the data and integrity protection verification parameters can verify the integrity of the data and integrity protection verification parameters using the integrity protection verification key and integrity protection algorithm. For example, if the data has been deleted or added, the data will fail verification.
[0157] In some embodiments, the AF network element may send the identifier and security policy of the multicast group to the NEF network element via a multicast session request message.
[0158] 502. The NEF network element determines security information according to the identifier of the multicast group.
[0159] In some embodiments, the NEF network element determines the protection mode according to the identifier of the multicast group and the security policy.
[0160] In some embodiments, after receiving the identifier of the multicast group and the security policy, the NEF network element may first determine whether it is authorized to provide services for the identifier of the multicast group.
[0161] For example, 1) the NEF network element may determine whether to provide services for the identifier of the multicast group based on the local policy of the NEF network element;
[0162] 2) The NEF network element can send the multicast group identifier to other network elements (such as UDM network elements, UDR network elements, PCF network elements, or MSF-C network elements) to obtain the subscription data corresponding to the multicast group identifier from the other network elements. The NEF network element then determines whether to authorize the provision of services for the multicast group identifier based on the subscription data. Optionally, the subscription data may also include the security policy corresponding to the multicast group identifier.
[0163] 3) The NEF network element can send the multicast group identifier to other network elements (such as UDM network elements, UDR network elements, PCF network elements or MSF-C network elements, etc.). After other network elements determine whether to provide services for the multicast group identifier based on the multicast group identifier and local policies, they send an indication to the NEF network element to indicate whether to authorize the service for the multicast group identifier.
[0164] If the NEF determines to provide services for the multicast group identifier, the NEF may continue to determine a protection mode based on the security policy corresponding to the multicast group identifier. The protection mode indicates whether to perform encryption protection on the user plane data and / or whether to perform integrity protection on the user plane data.
[0165] Optionally, the security policy may be obtained from the AF network element, or may be obtained by requesting from other network elements, or the security policy may be determined based on the identifier of the multicast group and a local policy.
[0166] For example, if the encryption protection requirement of the security policy is required, the NEF network element determines the protection mode to indicate that encryption protection is to be performed on the user plane data. However, if the capability of the NEF network element does not support the execution of encryption protection, the NEF network element sends a notification to the AF network element to inform the AF network element that the encryption protection cannot be performed and rejects the multicast session establishment request of the AF network element.
[0167] If the security policy's encryption protection requirement is "preferred," the NEF network element can determine, based on the local policy, whether to enable or disable encryption protection for user plane data. If the NEF network element determines to enable encryption protection for user plane data, it determines a protection mode indicating that encryption protection is to be performed on the user plane data. If the NEF network element determines to disable encryption protection for user plane data, it determines a protection mode indicating that encryption protection is not to be performed on the user plane data. Optionally, the NEF network element also sends a notification to the AF network element, notifying the AF whether encryption protection is enabled.
[0168] If the encryption protection requirement of the security policy is not needed, the NEF network element determines the protection mode to indicate that encryption protection is not performed on the user plane data.
[0169] In addition, the processing of integrity protection requirements and encryption protection requirements for security policies is similar and will not be repeated here.
[0170] Furthermore, the NEF network element may continue to generate security information according to the protection mode.
[0171] In some embodiments, security information is used to perform encryption protection and / or integrity protection on user plane data of a multicast group. The security information includes an encryption key k1 and an encryption algorithm a1, and / or an integrity protection key k2 and an integrity protection algorithm a2.
[0172] Exemplarily, if the protection mode indicates that encryption protection is performed on the user plane data, the NEF network element determines k1 and a1; if the protection mode indicates that encryption protection is not performed on the user plane data, the NEF network element does not need to determine k1 and a1;
[0173] If the protection mode indicates that integrity protection is performed on the user plane data, the NEF network element determines k2 and a2; if the protection mode indicates that integrity protection is not performed on the user plane data, the NEF network element does not need to determine k2 and a2.
[0174] In some embodiments, the NEF network element may generate k1 and k2 in various ways according to the protection mode. For example, the NEF network element may directly generate k1 and k2 according to the protection mode, or the NEF network element may request other network elements to generate k1 and k2 according to the protection mode and then return them to the NEF network element. This application does not limit this.
[0175] In some embodiments, the NEF network element may generate a1 and a2 in various ways based on the protection mode. For example, the NEF network element may directly generate a1 and a2 based on the protection mode, or the NEF network element may request other network elements to generate a1 and a2 based on the protection mode and then return them to the NEF network element. This application is not limiting. In some embodiments, if the protection mode indicates that encryption protection is not performed on user plane data, then a1 can be a null algorithm. If the protection mode indicates that integrity protection is not performed on user plane data, then a2 can be a null algorithm.
[0176] In some embodiments, if the protection mode indicates that encryption protection and integrity protection are not performed on user plane data, the NEF network element may also generate a1, a2, k1 and k2, but a1 and a2 are both null algorithms.
[0177] In some embodiments, the NEF network element may also select an SMF, and the selection method of the SMF is not limited. Optionally, the SMF here may be an SMF functional network element specifically for multicast or broadcast services.
[0178] 503. The NEF network element sends the multicast group identifier and security information to the UDR network element.
[0179] In some embodiments, if the protection mode determined in step 502 indicates that encryption protection and integrity protection are performed on the user plane data, then the security information sent in step 503 includes the above-mentioned a1, a2, k1 and k2;
[0180] If the protection mode determined in step 502 indicates that encryption protection is performed on the user plane data and that integrity protection is not performed on the user plane data, then the security information sent in step 503 may include k1 and a1, but not k2 and / or a2. Even if k2 or a2 is included, k2 and a2 are empty.
[0181] If the protection mode determined in step 502 indicates that the user plane data is not to be encrypted and that the user plane data is to be integrity protected, then the security information sent in step 503 may include the above-mentioned k2 and a2, but does not include k1 and / or a1. Even if k1 or a2 is included, k1 and a1 are empty.
[0182] In some embodiments, the security information may further include a protection method.
[0183] In some embodiments, the security information may also include a security policy.
[0184] In some embodiments, the security information may further include an SMF ID, where the SMF ID is the ID of the SMF selected by the NEF network element.
[0185] In some embodiments, the NEF network element can send the multicast group identifier and security information to the UDR network element or other NF network elements via a multicast session request message. The following steps are described using the example of the UDR network element receiving the multicast session request message.
[0186] 504. The UDR network element determines and saves the correspondence between the security information and the identifier of the multicast group.
[0187] In some embodiments, when the security information received by the UDR network element also includes the ID of the SMF, the UDR network element may also save the ID of the SMF. The UDR network element may also send a multicast session response message to the NEF network element to indicate that the security information and the multicast group identifier have been received.
[0188] 505. The NEF network element sends the multicast group identifier and security information to the SMF network element.
[0189] In some embodiments, the NEF network element may send the multicast group identifier and security information via a multicast distribution request message.
[0190] In some embodiments, the NEF network element may further send a policy authorization request to the PCF network element, and the PCF network element may send a policy authorization response to the NEF network element.
[0191] 506. The SMF network element determines and saves the correspondence between the security information and the identifier of the multicast group.
[0192] In some embodiments, when the SMF network element receives the corresponding relationship, it can send a multicast distribution session response message to the NEF network element, and the message can also carry the ingress address of the UPF network element.
[0193] In some embodiments, the NEF network element may further send a multicast session response message to the AF network element. The message may carry the ingress address of the NEF network element and may also carry a protection mode.
[0194] The AF network element can save the protection mode. If the AF network element determines that the protection mode needs to be updated, it can also adjust the security policy according to the protection mode and re-initiate the method flow of this embodiment according to the adjusted security policy.
[0195] In some embodiments, the SMF network element may further send an MBS policy association request message to the PCF network element, and the PCF network element may then send an MBS policy association response message to the SMF network element.
[0196] 507. The SMF network element sends the correspondence between the security information and the identifier of the multicast group to the UPF network element.
[0197] In some embodiments, the SMF network element may send the corresponding relationship to the UPF network element via a session request message, and accordingly, the UPF network element may feedback a session response message to the SMF network element to indicate receipt of the corresponding relationship. The session response here may include the entry address of the UPF network element.
[0198] 508. The UPF network element performs protection on the user plane data corresponding to the multicast group identifier according to the security information.
[0199] When the AF network element subsequently sends downlink user plane data, it sends the user plane data directly to the UPF network element. Therefore, when the UPF network element stores the security information, it can determine how to encrypt and integrity protect the user plane data based on the security information. The UPF network element can then send the encrypted and integrity-protected user plane data to the UE via the RAN network element.
[0200] In some embodiments, if the security information includes k1 and a1, or the protection mode indicates that encryption protection is required for the user plane data; the UPF network element performs encryption protection on the received user plane data according to k1 and a1;
[0201] If the security information includes k2 and a2, or the protection mode indicates that integrity protection of the user plane data is required, the UPF network element performs integrity protection on the received user plane data according to k2 and a2;
[0202] If the security information does not include k1 and a1, or the protection mode indicates that encryption protection of the user plane data is not required, the UPF network element does not perform encryption protection on the received user plane data;
[0203] If the security information does not include the k2 and a2 methods, or the protection mode indicates that integrity protection of the user plane data is not required, the UPF network element does not perform integrity protection on the user plane data;
[0204] In other words, if the security information includes k1, and k1 is not a null algorithm, then the UPF network element performs encryption protection on the user plane data according to k1; if the security information includes k2, and k2 is not a null algorithm, then the UPF network element performs integrity protection on the user plane data according to k2;
[0205] If the security information includes k1 and k1 is a null algorithm, the UPF network element does not perform encryption protection on the user plane data; if the security information includes k2 and k2 is a null algorithm, the UPF network element does not perform integrity protection on the user plane data.
[0206] In some embodiments, if the protection mode indicates that encryption protection or integrity protection is required, and the UPF network element does not currently support encryption protection, the UPF network element sends a rejection message to the SMF network element. In some embodiments, the SMF network element may reject the establishment of the multicast session by sending a rejection message to the NEF network element, which in turn may send a rejection message to the AF network element, indicating that the establishment of the multicast session is rejected. Alternatively, the SMF network element may reselect a UPF network element and start again from step 507.
[0207] In some embodiments, if a UE newly added to the multicast group subsequently wants to obtain security information, the UE can request the security information from the SMF network element through the RAN network element and the AMF network element, or the UE can request the security information from the SMF network element through the RAN network element and the UPF network element. If the SMF network element saves the above-mentioned correspondence, it can send the security information to the UE. If the SMF network element does not save the above-mentioned correspondence, the SMF network element can request the security information from the UDR network element or the PCF network element and then send it to the UE, so that the UE can decrypt the received user plane data according to the security information.
[0208] It should be noted that step 502 above also includes other possibilities: the NEF network element does not determine the protection mode, but instead determines the algorithm and key from other network elements and sends the algorithm and key to the UDR network element. The NEF network element can then send a security policy to the SMF network element, which then determines the protection mode based on the security policy. Alternatively, the SMF network element can send a security policy to the UPF network element, which then determines the protection mode and sends it to the SMF network element. The SMF network element can also send the protection mode to the NEF network element, which then stores the mode in the UDR network element. The advantage of this approach is that the UPF network element, which ultimately performs encryption and integrity protection, determines whether to enable encryption or integrity protection.
[0209] In some embodiments, the configuration process of the security information described above does not require processing actions of security policy and protection mode, and only includes the saving and delivery actions of the encryption key and encryption algorithm, the integrity protection key and integrity protection algorithm, and the subsequent encryption key and encryption algorithm determined by the NEF network element.
[0210] Therefore, the method flow provided by the embodiments of the present application can be applied to the configuration process of security information under the 5G MBS service. The above embodiments mainly illustrate that the security information determined by the NEF network element is stored in the UDR network element.
[0211] Embodiment two
[0212] As shown in Figure 6 The embodiments of the present application also provide a configuration method of security information, which comprises:
[0213] 601. The AF network element sends the identifier of the multicast group to the NEF network element.
[0214] In some embodiments, the AF network element can also send the security policy corresponding to the identifier of the multicast group to the NEF network element.
[0215] The implementation of step 601 can refer to the implementation of step 501 described above.
[0216] 602. The NEF network element sends the identifier of the multicast group to the UDR network element.
[0217] In some embodiments, the NEF network element can also send the security policy to the UDR network element.
[0218] 603. The UDR network element determines the protection mode corresponding to the identifier of the multicast group according to the security policy, and generates the security information corresponding to the identifier of the multicast group according to the protection mode.
[0219] The security policy in step 603 can be received by the UDR network element from other network elements (such as the NEF network element), or can be determined locally by the UDR network element according to the identifier of the multicast group.
[0220] In some embodiments, the UDR network element can also send the security policy to other network elements, and after other network elements generate the security information according to the security policy, the security information is sent to the UDR network element.
[0221] The implementation of the UDR determining the protection mode according to the identifier of the multicast group and the security policy can refer to the implementation of the NEF network element in step 602 described above.
[0222] 604. The UDR network element sends the identifier of the multicast group and the security information to the NEF network element.
[0223] 605. The NEF network element sends the multicast group identifier and security information to the SMF network element.
[0224] 606. The SMF network element sends the multicast group identifier and security information to the UPF network element.
[0225] 607. The UPF network element performs protection on the user plane data corresponding to the multicast group identifier according to the security information.
[0226] The UPF network element can perform encryption protection and / or integrity protection on the user plane data of the multicast group according to the security information. For details, please refer to the implementation of step 508.
[0227] Similar to Example 1, the UE newly joining the multicast group can request security information from the SMF network element. If the SMF network element saves the above-mentioned corresponding relationship, it can send security information to the UE. If the SMF network element does not save the above-mentioned corresponding relationship, the SMF network element can request security information from the UDR network element or the PCF network element and then send it to the UE, so that the UE can decrypt the received user plane data according to the security information.
[0228] Example 3
[0229] like Figure 7 As shown, the embodiment of the present application also provides a method for configuring security information, the method comprising:
[0230] 701. The AF network element sends a multicast group identifier to the NEF network element.
[0231] In some embodiments, the AF network element may further send a security policy corresponding to the identifier of the multicast group to the NEF network element.
[0232] The implementation of step 701 may refer to the implementation of step 501 above.
[0233] 702. The NEF network element determines a protection mode corresponding to the multicast group identifier according to the multicast group identifier.
[0234] The security policy in step 702 may be received by the NEF network element from other network elements (eg, AF network element), or may be determined locally by the NEF network element according to the identifier of the multicast group.
[0235] The implementation of step 702 may refer to the implementation of step 502 described above.
[0236] 703. The NEF network element sends the multicast group identifier and protection mode to the UDR network element.
[0237] 704. The UDR network element generates security information corresponding to the multicast group identifier according to the protection mode.
[0238] The implementation method of the UDR determining the protection mode according to the multicast group identifier and security policy can refer to the implementation method of the NEF network element in the above step 602.
[0239] 705. The UDR network element sends the multicast group identifier and security information to the NEF network element.
[0240] 706. The NEF network element sends the multicast group identifier and security information to the SMF network element.
[0241] 707. The SMF network element sends the multicast group identifier and security information to the UPF network element.
[0242] 708. The UPF network element performs protection on the user plane data corresponding to the multicast group identifier according to the security information.
[0243] The implementation of step 708 may refer to the implementation of step 508 above.
[0244] It can be understood that in this embodiment, the NEF network element determines the protection mode, and the UDR network element generates security information according to the protection mode and sends it to other NF network elements to perform protection of the user plane data of the MBS to ensure the security of the user plane data of the 5G MBS.
[0245] Example 4
[0246] like Figure 8 As shown, the embodiment of the present application also provides a method for configuring security information, the method comprising:
[0247] 801. The AF network element sends a multicast group identifier to the NEF network element.
[0248] In some embodiments, the AF network element may further send a security policy corresponding to the identifier of the multicast group to the NEF network element.
[0249] The implementation of step 801 may refer to the implementation of step 501 described above.
[0250] 802. The NEF network element sends the multicast group identifier to the SMF network element.
[0251] In some embodiments, the NEF network element may also send a security policy corresponding to the identifier of the multicast group to the SMF network element.
[0252] 803. The SMF network element determines the security information corresponding to the multicast group identifier according to the security policy.
[0253] The security policy in step 803 may be received by the SMF network element from the NEF network element, or generated locally by the SMF network element based on the identifier of the multicast group.
[0254] The implementation manner of the SMF network element determining the security information according to the security policy may refer to the implementation manner of the NEF network element in the above step 502.
[0255] Alternatively, the SMF network element can generate a protection method based on the security policy, and send the protection method and the identifier of the multicast group to the NEF network element. The NEF network element generates security information based on the protection method and then feeds it back to the SMF network element.
[0256] 804. The SMF network element sends the multicast group identifier and security information to the UDR network element.
[0257] In some embodiments, the SMF network element may also send the identification and security information of the multicast group to the PCF network element.
[0258] 805. The SMF network element sends the multicast group identifier and security information to the UPF network element.
[0259] 806. The UPF network element performs protection on the user plane data corresponding to the multicast group identifier according to the security information.
[0260] The implementation of step 806 may refer to the implementation of step 508 above.
[0261] It can be understood that in this embodiment, the SMF network element can generate security information and send it to other NF network elements to perform protection of the user plane data of the MBS to ensure the security of the user plane data of the 5G MBS.
[0262] Example 5
[0263] like Figure 9 As shown, the embodiment of the present application also provides a method for configuring security information, the method comprising:
[0264] 901. The AF network element sends a multicast group identifier to the NEF network element.
[0265] In some embodiments, the AF network element may further send a security policy corresponding to the identifier of the multicast group to the NEF network element.
[0266] The implementation of step 801 may refer to the implementation of step 501 described above.
[0267] 902. The NEF network element determines a protection mode corresponding to the multicast group identifier according to the security policy.
[0268] The security policy in step 902 may be received by the NEF network element from the AF network element, or generated locally by the NEF network element according to the identifier of the multicast group.
[0269] The implementation manner of the NEF network element determining the protection mode according to the security policy can refer to the implementation manner of the NEF network element in the above step 502.
[0270] 903. The NEF network element sends the multicast group identifier and protection mode to the SMF network element.
[0271] 904. The SMF network element generates security information corresponding to the multicast group identifier according to the protection method.
[0272] The implementation method of the SMF network element generating security information according to the protection method can refer to the implementation method of the NEF network element in the above step 502.
[0273] 905. The SMF network element sends the multicast group identifier and security information to the UDR network element.
[0274] In some embodiments, the SMF network element may also send the identification and security information of the multicast group to the PCF network element.
[0275] 906. The SMF network element sends the multicast group identifier and security information to the UPF network element.
[0276] 907. The UPF network element performs protection on the user plane data corresponding to the multicast group identifier according to the security information.
[0277] The implementation of step 907 may refer to the implementation of step 508 above.
[0278] It can be understood that in this embodiment, the protection method can be determined by the NEF network element, and the SMF network element generates security information according to the protection method and sends it to other NF network elements to perform protection of the user plane data of the MBS to ensure the security of the user plane data of the 5G MBS.
[0279] The implementation methods of Embodiments 1 to 5 can be applied to the above-mentioned Architecture 1.
[0280] Example 6
[0281] like Figure 10 As shown, the embodiment of the present application also provides a method for configuring security information, the method comprising:
[0282] 101. The AF network element sends the multicast group identifier to the MSF-C network element.
[0283] In some embodiments, the AF network element may further send a security policy corresponding to the identifier of the multicast group to the MSF-C network element.
[0284] The implementation of step 101 may refer to the implementation of step 501 in which the AF network element sends the multicast group identifier and security policy to the NEF network element.
[0285] 102. The MSF-C network element sends the multicast group identifier to the UDR network element.
[0286] In some embodiments, the MSF-C network element may also send a security policy corresponding to the identifier of the multicast group to the UDR network element.
[0287] 103. The UDR network element determines the security information corresponding to the multicast group identifier according to the security policy.
[0288] In some embodiments, the security policy in step 103 may be received by the UDR network element from the MSF-C network element, or generated locally by the UDR network element according to the identifier of the multicast group.
[0289] The implementation of step 103 may refer to the implementation of the NEF determining the security information in step 502 above.
[0290] 104. The UDR network element sends the multicast group identifier and security information to the MSF-C network element.
[0291] 105. The MSF-C network element sends the multicast group identifier and security information to the MSF-U network element.
[0292] 106. The MSF-U network element performs protection on the user plane data corresponding to the multicast group identifier according to the security information.
[0293] The implementation of step 106 may refer to the implementation of the UPF network element in step 508. For example, when the MSF-U network element receives the user plane data of the multicast group sent by the AF network element, it may protect the user plane data and then send it to the UPF2 network element. The UPF2 network element sends the user plane data to the UE through the RAN network element. The UE may decrypt the user plane data based on the security information requested from the UDR network element.
[0294] In some embodiments, the MSF-C network element may also send a protection mode to the AF network element.
[0295] It can be understood that in this embodiment, the UDR network element can generate security information based on the security policy received from the MSF-C network element, and send it to other NF network elements to perform protection of the user plane data of the MBS to ensure the security of the user plane data of the 5G MBS.
[0296] Example 7
[0297] like Figure 11 As shown, the embodiment of the present application also provides a method for configuring security information, the method comprising:
[0298] 111. The AF network element sends the multicast group identifier to the MSF-C network element.
[0299] In some embodiments, the AF network element may further send a security policy corresponding to the identifier of the multicast group to the MSF-C network element.
[0300] The implementation of step 101 can refer to the implementation of the step 501 described above that the AF network element sends the identification of the multicast group and the security policy to the NEF network element.
[0301] 112. The MSF-C network element determines the protection mode corresponding to the identification of the multicast group.
[0302] In some embodiments, the security policy in step 112 can be received by the MSF-C network element from the AF network element, or generated locally by the MSF-C network element according to the identification of the multicast group.
[0303] The implementation of step 112 can refer to the implementation of the step 502 described above that the NEF network element determines the protection mode.
[0304] 113. The MSF-C network element sends the identification of the multicast group and the protection mode to the UDR network element.
[0305] 114. The UDR network element determines the security information corresponding to the identification of the multicast group according to the protection mode.
[0306] The implementation of step 114 can refer to the implementation of the step 502 described above that the NEF network element determines the security information.
[0307] 115. The UDR network element sends the identification of the multicast group and the security information to the MSF-C network element.
[0308] 116. The MSF-C network element sends the identification of the multicast group and the security information to the MSF-U network element.
[0309] 117. The MSF-U network element performs protection on the user plane data corresponding to the identification of the multicast group according to the security information.
[0310] It can be understood that in the present embodiment, the MSF-C network element can determine the protection mode corresponding to the identification of the multicast group, the UDR network element can generate the security information according to the protection mode received from the MSF-C network element, and send it to other NF network elements to perform protection on the user plane data of the MBS, so as to ensure the security of the user plane data of the 5G MBS.
[0311] Embodiment eight
[0312] As shown in the following, the present embodiment further provides a security information configuration method, which comprises: Figure 12
[0313] 121. The AF network element sends the identification of the multicast group to the MSF-C network element.
[0314] In some embodiments, the AF network element can also send the security policy corresponding to the identification of the multicast group to the MSF-C network element.
[0315] The implementation of step 101 can refer to the implementation of the step 501 described above that the AF network element sends the identification of the multicast group and the security policy to the NEF network element.
[0316] 122. The MSF-C network element determines the security information corresponding to the identification of the multicast group according to the security policy.
[0317] In some embodiments, the security policy in step 122 can be received by the MSF-C network element from the AF network element, or generated locally by the MSF-C network element according to the identification of the multicast group.
[0318] The implementation of step 122 can refer to the implementation of the step 502 described above that the NEF network element determines the security information.
[0319] 123. The MSF-C network element sends the identification of the multicast group and the security information to the UDR network element.
[0320] 124. The MSF-C network element sends the identification of the multicast group and the security information to the MSF-U network element.
[0321] 125. The MSF-U network element performs protection on the user plane data corresponding to the identification of the multicast group according to the security information.
[0322] It should be noted that the MSF-U network element described above is optional, and if the MSF-C network element determines not to perform protection, the MSF-C network element can also not select the MSF-U.
[0323] It can be understood that in the present embodiment, the MSF-C network element can determine the security information corresponding to the identification of the multicast group, and send it to other NF network elements to perform protection on the user plane data of the MBS, so as to ensure the security of the user plane data of the 5G MBS.
[0324] In the embodiments six to eight, the MSF-C network element can also send the identification of the multicast group and the security information to the SMF network element or the PCF network element, and the SMF network element or the PCF network element stores the security information. Subsequently, when the UE requests the security information, the UE can request the security information from the SMF network element or the PCF network element. Of course, the UE can also request the security information from the UDR network element.
[0325] Embodiment nine
[0326] Embodiment nine will describe the implementation of the security information when the UE joins the identification of the multicast group corresponding to the service flow.
[0327] As shown in Figure 13 The present application also provides a security information configuration method, which comprises:
[0328] 131. The AF network element executes the security configuration process of the multicast group.
[0329] The security configuration process may refer to the configuration process of any one of the above-mentioned embodiments 1 to 8, for example.
[0330] In some embodiments, step 131 is optional, that is, the network side has completed the security configuration process, for example, the correspondence between the multicast group identifier and security information is saved in the UDR network element; or, the network has not completed the security configuration process, that is, the configuration process of the above embodiment has not been executed.
[0331] The AF network element may also be replaced by a context provider (content provider, CP) network element.
[0332] 132. The UE completes the registration process with the network.
[0333] In some embodiments, the UE may complete a session establishment procedure with the network.
[0334] 133. The network side completes the multicast service announcement so that the UE can perceive the multicast service.
[0335] Step 133 is optional.
[0336] 134. The UE accesses the service corresponding to the identifier of the multicast group through a user plane or a control plane.
[0337] The purpose of step 134 is that the SMF1 network element will determine the identifier of the multicast group that the UE wants to access, which can be determined based on the multicast group information sent by the UE in the user plane, such as the Internet Group Management Protocol (IGMP) message, or the multicast address, or the network identifier where the multicast service or application is located, or the multicast service / application identifier, or the multicast group identifier, etc., or based on the multicast group information sent by the UE in the control plane, such as the multicast address, or the network identifier where the multicast service or application is located, or the multicast service / application identifier, or the multicast group identifier, etc.
[0338] Here, the manner in which SMF1 determines the multicast group information, such as the multicast group identifier, is not limited. Assuming that the SMF1 network element determines the identifier of the multicast group that the UE wishes to access, the method further includes:
[0339] 135. The SMF1 network element requests to obtain the security information corresponding to the identifier of the multicast group.
[0340] In some embodiments, the SMF1 can send a multicast request message to the UDR network element, carrying the identifier of the multicast group, to request the security information corresponding to the identifier of the multicast group. When the UDR network element stores the security information, it can send the security information to the SMF1 network element through a multicast response message.
[0341] In some embodiments, if the security information is stored in the PCF network element, the SMF1 network element can also request the PCF network element to obtain the security information.
[0342] In some embodiments, here the SMF network element can determine the address information of the multicast group and send the address information of the multicast group to the UDR network element, and the UDR network element determines whether there is corresponding security information according to the address information.
[0343] Optionally, the multicast group information sent by the UE here can be the identifier or address of the multicast group, and the multicast group information determined by the SMF can be the identifier or address of the multicast group, which can be different from the identifier of the multicast group sent by the AF in Embodiment 1, but they have relevance. For example, the address or network identifier of the multicast group in the multicast group information can be consistent with the multicast group identifier or the network identifier in the multicast group identifier sent by the AF. The manner of association is not limited here. The UDR can determine whether the multicast group identifier received from the NEF previously matches according to the multicast group information sent by the SMF.
[0344] 136、The SMF1 network element sends the identifier and security information of the multicast group to the AMF network element.
[0345] Exemplarily, the SMF1 network element can send the identifier and security information of the multicast group to the AMF network element through a Namf_Communication_N1N2Message Transfer message.
[0346] In some embodiments, the SMF1 can only send the security information to the AMF.
[0347] 137、The AMF network element sends the identifier and security information of the multicast group to the RAN network element.
[0348] Exemplarily, the AMF network element can send the identifier and security information of the multicast group to the RAN network element through an N2 session request message.
[0349] In some embodiments, the AMF network element can only send the security information to the RAN network element.
[0350] 138、The RAN network element sends the identifier and security information of the multicast group to the UE.
[0351] In some embodiments, the RAN network element may send the multicast group identifier and security information to the UE via a PDU session modification / accept message.
[0352] In some embodiments, the RAN network element may only send security information to the UE.
[0353] In some embodiments, the PDU session modification / accept message may also be a message sent by the SMF1 network element to the UE via the AMF network element and the RAN network element. The message is encapsulated in the Namf_Communication_N1N2Message Transfer_N2 session request and the RRC message and sent to the UE.
[0354] In some embodiments, the RAN network element may further modify access network resources according to the multicast group identifier and security information.
[0355] Therefore, the UE may, based on the multicast group identifier and the security information, decrypt the received user plane data according to the security information when receiving user plane data of a service corresponding to the multicast group identifier.
[0356] Next, choose to execute step 139 or step 143.
[0357] 139. The RAN network element sends an N2 session response message to the AMF network element, indicating that user plane data is sent to the UE in multicast mode. Then, step 140 or step 142 may be continued.
[0358] 140. The AMF network element sends an N11 session response message to the SMF1 network element. The message is used to indicate that user plane data is sent in multicast mode.
[0359] In some embodiments, if the RAN network element selects a multicast mode to send user plane data to the UE, then when the SMF 1 network element receives the N11 session response message, the method further includes:
[0360] 141. The SMF1 network element sends the multicast group identifier and security information to the SMF2 network element, and the SMF2 network element sends the multicast group identifier and security information to the UPF2 network element, and the UPF2 network element performs protection of the user plane data of the multicast group; or, the SMF1 network element sends the multicast group identifier and security information to the SMF2 network element, and the SMF2 network element sends the multicast group identifier and security information to the MSF-U network element, and the MSF-U network element performs protection of the user plane data of the multicast group. Figure 13 not shown).
[0361] 142. The AMF network element sends the multicast group identifier and security information to the SMF2 network element, and the SMF2 network element sends the multicast group identifier and security information to the UPF2 or MSF-U network element, and the UPF2 network element or the MSF-U network element performs the protection of the user plane data of the multicast group; or, the AMF network element sends the multicast group identifier and security information to the MSF-C network element, and the MSF-C network element sends the multicast group identifier and security information to the MSF-U network element, and the MSF-U network element performs the protection of the user plane data of the multicast group ( Figure 13 not shown).
[0362] 143. The RAN network element sends an N2 session response message to the AMF network element, which is used to indicate that user plane data is sent to the UE in unicast mode.
[0363] 144. The AMF network element sends an N11 session response message to the SMF1 network element, which is used to indicate that user plane data is sent in unicast mode.
[0364] 145. The SMF1 network element sends the multicast group identifier and security information to the SMF2 network element, and the SMF2 network element sends the multicast group identifier and security information to the UPF2 network element or the MSF-U network element, and the UPF2 network element or the MSF-U network element performs protection of the user plane data of the unicast; or, the SMF1 network element sends the multicast group identifier and security information to the MSF-C network element, and the MSF-C network element sends the multicast group identifier and security information to the MSF-U network element, and the MSF-U network element performs protection of the user plane data of the unicast.
[0365] It should be noted that the above step 135 can be when the UDR network element stores security information and the SMF1 network element requests the UDR network element to obtain the security information. That is, step 135 is performed after the network side security configuration process is executed in step 131. However, if step 131 is not executed, that is, the security configuration process is not completed, the implementation method of step 135 can be replaced by (the replacement step of step 135 is in Figure 13 Not shown):
[0366] 135a. The SMF1 network element determines the security information corresponding to the multicast group identifier and sends the security information to the UDR network element. The UDR saves the correspondence between the multicast group identifier and the security information.
[0367] If the UE subsequently accesses the multicast group through the SMF1 network element, the SMF1 network element can still obtain security information from the UDR network element and send it to the UE.
[0368] Or replace it with:
[0369] 135b. The SMF1 network element sends the multicast group identifier to the UDR network element to request security information. After the UDR network element determines the security information, it sends the security information to the SMF1 network element.
[0370] It is also possible that when the UDR network element does not store the security information corresponding to the multicast group identifier, the UDR network element feeds back an indication that the security information is not stored to the SMF1 network element. In this case, the SMF1 network element needs to determine the security information corresponding to the multicast group identifier by itself.
[0371] Or replace it with:
[0372] 135c. The SMF1 network element sends the multicast group identifier to the SMF2 network element to request security information. After determining the security information, the SMF2 network element sends it to the UPF2 network element, which then performs user plane data protection. Furthermore, the SMF2 network element sends the security information to the SMF1 network element.
[0373] Or replace it with:
[0374] 135d. The SMF1 network element sends the multicast group identifier to the MSF-C network element to request security information. After confirming the security information, the MSF-C network element sends it to the MSF-U network element, which then protects the user plane data. The MSF-C network element also sends the security information to the SMF1 network element.
[0375] Therefore, this application can ensure the security of user plane data delivery in 5G MBS by adding a configuration process of security information in the process of UE registering to the network including 5G MBS.
[0376] Example 10
[0377] Example 10 will describe an implementation method of obtaining only the security policy of the multicast group from the network side when the UE joins the business process corresponding to the identifier of the multicast group. This can enable a UE that has not signed a contract with the network side to obtain the security policy of the signed UE, thereby ensuring the data security of the unsigned UE.
[0378] like Figure 14As shown, an embodiment of the present application provides a method for configuring a security policy, the method comprising:
[0379] 151. The AF network element sends a multicast session request to the NEF network element. The request carries the multicast group identifier and security policy.
[0380] In some embodiments, the multicast session request is a multicast session request, and the multicast session request carries an identifier of the multicast group, a quality of service (QoS) request, and a security policy.
[0381] 152. When the NEF network element determines that it is authorized to provide services for the identifier of the multicast group, it selects the SMF2 network element.
[0382] 153. The NEF network element sends a multicast session request message to the UDR network element. The request message carries the multicast group identifier, SMF2ID, and security policy.
[0383] 154. The UDR network element determines and saves the correspondence between the multicast group identifier and the security policy.
[0384] 155. The UDR network element sends a multicast session response message to the NEF network element.
[0385] 156. The NEF network element sends a multicast distribution session request message to the SMF2 network element, where the message carries the identifier of the multicast group.
[0386] 157. The SMF2 network element sends an MBS policy negotiation request (policy association request) message to the PCF network element, where the message carries the identifier of the multicast group.
[0387] 158. The PCF network element sends an MBS policy negotiation response (policy association response) message to the SMF2 network element.
[0388] 159. The SMF2 network element sends a session request message to the UPF2 network element.
[0389] 160. The UPF2 network element sends a session response message to the SMF2 network element, and the message carries the ingressaddress of UPF2.
[0390] 161. The SMF2 network element sends a multicast configuration session response message to the NEF network element, and the message carries the ingressaddress of SMF2.
[0391] 162. The NEF network element sends a multicast session response message to the AF network element. The message carries the ingressaddress of the NEF network element.
[0392] The focus of this embodiment is step 151, step 152, step 154, and step 155. Other steps may be optional.
[0393] Later, if the UE requests to join a multicast group from the SMF1 network element, the SMF2 network element can send the multicast group identifier to the UDR network element based on the determined multicast group identifier, requesting the security policy. The UDR network element determines the saved security policy based on the multicast group identifier and sends it to the SMF2 network element. The SMF2 network element can then send the security policy to the RAN network element, which then determines the air interface protection method between it and the UE based on the security policy and sends the air interface protection method to the UE. In this way, the RAN network element customizes the UE's multicast data protection based on the security policy sent by the AF network element to the network, ensuring UE data security.
[0394] It should be noted that, for the embodiments of the present application, actions such as negotiation and sending of security policies and protection methods may also be removed. In this case, the solution of the present application may only include actions for determining the keys (encryption keys and integrity protection keys) and protection algorithms (encryption algorithms and integrity protection algorithms) in the security information. After removing actions such as security policies and protection methods, the embodiments of the present application may focus on implementing the sharing of keys and protection algorithms. In addition, the solution of the present application may also support a mechanism for performing only encryption protection, or only integrity protection, or both encryption protection and integrity protection according to the default policy.
[0395] For the embodiments of the present application, the generation of keys and / or protection algorithms can be completed independently by NEF network elements / UDR network elements / SMF network elements, etc., or by calling other NF network elements. This application does not impose any restrictions. For example, the NEF network element sends a protection method to a key management network element, requesting the key management network element to generate corresponding encryption keys and / or integrity protection keys based on the protection method. Afterwards, the key management network element returns the encryption key and / or integrity protection key to the NEF network element. In addition, the selection of the protection algorithm is similar to that of the key, and can also be completed by other NF network elements. In addition, both the key and the algorithm can be completed by other entities and then fed back to the NEF network element. This type of processing method can better determine the security information based on the call completion, and simplify the functions of entities such as the NEF network element / UDR network element / SMF network element.
[0396] For the embodiments of the present application, the actions of the UDR network element can also be performed by the UDM network element, etc., and the embodiments of the present application do not limit this.
[0397] It is understandable that in order to implement the above functions, the network function network element provided by this application includes hardware and / or software modules corresponding to the execution of each function. In combination with the algorithm steps of each example described in the embodiments disclosed herein, this application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in a hardware or computer software driven hardware manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in combination with the embodiments, but such implementation should not be considered to be beyond the scope of this application.
[0398] In this embodiment, the network function network element can be divided into functional modules according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The network function network element can be a unified data storage (such as UDR) network element, a network open function (such as NEF) network element, a session management function (such as SMF) network element, and a multicast service function control plane function (MSF-C) network element. The above-mentioned integrated modules can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is schematic and is only a logical function division. There may be other division methods in actual implementation.
[0399] In the case of dividing each functional module into corresponding functional modules, Figure 15 A possible composition diagram of the network function element 150 involved in the above embodiment is shown. Figure 15 As shown, the network function network element 150 may include: a receiving unit 1501, a determining unit 1502 and a sending unit 1503.
[0400] The following description uses the UDR network element as an example.
[0401] Among them, the receiving unit 1501 can be used to support the network function network element 150 to execute the above steps 503, step 602, step 703, step 804, step 905, step 113, step 123, step 135a, step 135b, step 153, etc., and / or other processes for the technology described in this article.
[0402] The determining unit 1502 may be configured to support the network function element 150 in executing the above steps 504 , 603 , 704 , 103 , 114 , 154 , etc., and / or other processes for the technology described herein.
[0403] The sending unit 1503 can be used to support the network function network element 150 to perform the above-mentioned steps 604, 705, 104, 115, 155, etc., and / or other processes for the technology described in this document.
[0404] It should be noted that all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module and will not be repeated here.
[0405] The network function network element 150 provided in this embodiment is used to execute the above-mentioned security information configuration method, and thus can achieve the same effect as the above-mentioned implementation method.
[0406] When integrated, the network function element 150 may include a processing module, a storage module, and a communication module. The processing module may be used to control and manage the actions of the network function element 150. For example, it may be used to support the network function element 150 in executing the steps performed by the determining unit 1502. The storage module may be used to support the network function element 150 in storing program code and data. The communication module may be used to support communication between the network function element 150 and other devices, such as other network function elements, and may support the network function element 150 in executing the steps performed by the receiving unit 1501 and the sending unit 1503.
[0407] The processing module may be a processor or controller. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a digital signal processing (DSP) and a microprocessor, and so on. The storage module may be a memory. The communication module may specifically be a device that interacts with other network function elements, such as a radio frequency circuit, a Bluetooth chip, or a Wi-Fi chip.
[0408] In one embodiment, when the processing module is a processor, the storage module is a memory, and the communication module is a transceiver, the network function element involved in this embodiment may be a network element having Figure 16 The network function network element 160 of the structure shown.
[0409] The present application also provides a network function element, comprising one or more processors and one or more memories. The one or more memories are coupled to the one or more processors and are configured to store computer program code, the computer program code comprising computer instructions. When the one or more processors execute the computer instructions, the electronic device executes the above-mentioned related method steps to implement the security information configuration method in the above-mentioned embodiment.
[0410] An embodiment of the present application also provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed on a network function network element, the network function network element executes the above-mentioned related method steps to implement the security information configuration method in the above-mentioned embodiment.
[0411] An embodiment of the present application also provides a computer program product. When the computer program product runs on a computer, it enables the computer to execute the above-mentioned related steps to implement the configuration method of security information executed by the network function network element in the above-mentioned embodiment.
[0412] In addition, an embodiment of the present application also provides a device, which can specifically be a chip, component or module, and the device may include a connected processor and memory; wherein the memory is used to store computer execution instructions, and when the device is running, the processor can execute the computer execution instructions stored in the memory to enable the chip to execute the security information configuration method executed by the network function network element in the above-mentioned method embodiments.
[0413] Among them, the network function network element, computer storage medium, computer program product or chip provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0414] Another embodiment of the present application provides a system, which may include at least one network element among a unified data repository (e.g., UDR) network element, a network open function (e.g., NEF) network element, a session management function (e.g., SMF) network element, and a multicast service function control plane function (MSF-C) network element, which can be used to implement the above-mentioned security information configuration method.
[0415] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0416] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. For example, the apparatus embodiments described above are merely illustrative, for example, the division of the modules or units is merely a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, apparatuses or units, and can be electrical, mechanical or other forms.
[0417] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, that is, can be located in one place or distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0418] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0419] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the parts that make contributions to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes a plurality of instructions for causing an apparatus (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various storage medium that can store program codes.
[0420] The above is merely a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for configuring security information, characterized in that: The method is applied to a system including a multicast-broadcast service architecture, the system including a first network function network element and a second network function network element, and the method includes: The first network function network element receives a multicast group identifier, determines security information corresponding to the multicast group identifier, the security information being used to perform encryption protection and / or integrity protection on user plane data of the multicast group, the security information including an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm; the first network function network element includes a unified data storage network element; The first network function network element sends the security information to the second network function network element, where the second network function network element includes one or more of a user plane function network element of a multicast service function, a control plane function network element of a multicast service function, a network open function network element, or a session management function network element.
2. The method according to claim 1, characterized in that The security information also includes a security policy and / or protection method for the user plane data; The security policy indicates protection requirements for the user plane data, where the protection requirements include encryption protection requirements and / or integrity protection requirements; The protection mode indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data.
3. The method according to claim 2, characterized in that The security information also includes the protection method; The receiving a multicast group identifier and determining security information corresponding to the multicast group identifier includes: Receiving the identifier of the multicast group and the security policy from a network open function network element or a control plane function network element of a multicast service function; determining the protection mode according to the security policy; or receiving the identifier of the multicast group and the protection mode from a network open function network element or a control plane function network element of a multicast service function; The security information is generated according to the protection mode.
4. The method according to claim 3, characterized in that The sending the security information to the second network function network element includes: The security information is sent to the network open function network element or the control plane function network element of the multicast service function.
5. The method according to claim 3 or 4, characterized in that The first network function network element includes a unified data storage network element; After generating the security information according to the protection mode, the method further comprises: the unified data repository network element determining a correspondence between the security information and the identifier of the multicast group; The receiving a multicast group identifier and determining security information corresponding to the multicast group identifier further includes: The unified data storage network element receives a request message from a session management function network element, where the request message includes an identifier of the multicast group; The unified data storage network element determines the security information corresponding to the identifier of the multicast group according to the corresponding relationship; The sending the security information to the second network function network element includes: The unified data storage network element sends the security information to the session management function network element.
6. A network function element, characterized in that: The network function network element is a first network function network element, and the first network function network element includes a unified data storage network element; the first network function network element is applied to a system of a multicast-broadcast service architecture, and the system includes the first network function network element and a second network function network element, and the first network function network element includes: a transceiver for receiving an identifier of a multicast group; a processor, configured to determine security information corresponding to the identifier of the multicast group, the security information being used to perform encryption protection and / or integrity protection on user plane data of the multicast group, the security information including an encryption key and an encryption algorithm, and / or an integrity protection key and an integrity protection algorithm; The transceiver is also used to send the security information to the second network function network element, where the second network function network element includes one or more of a user plane function network element of a multicast service function, a control plane function network element of a multicast service function, a network open function network element or a session management function network element.
7. The network function element according to claim 6, characterized in that: The security information also includes a security policy and / or protection method for the user plane data; The security policy indicates protection requirements for the user plane data, where the protection requirements include encryption protection requirements and / or integrity protection requirements; The protection mode indicates whether encryption protection is performed on the user plane data, and / or whether integrity protection is performed on the user plane data.
8. The network function element according to claim 7, characterized in that: The security information also includes the protection method; The transceiver is configured to receive the identifier of the multicast group and the security policy from a network open function network element or a control plane function network element of a multicast service function, and the processor is configured to determine the protection mode according to the security policy; or the transceiver is configured to receive the identifier of the multicast group and the protection mode from a network open function network element or a control plane function network element of a multicast service function; The processor is configured to generate the security information according to the protection method.
9. The network function network element according to claim 8, characterized in that: The transceiver is used for: The security information is sent to the network open function network element or the control plane function network element of the multicast service function.
10. The network function network element according to claim 8 or 9, characterized in that: The first network function network element includes a unified data storage network element; The processor is further configured to determine a correspondence between the security information and an identifier of the multicast group; The transceiver is further configured to receive a request message from a session management function network element, wherein the request message includes an identifier of the multicast group; The processor is further configured to determine security information corresponding to the identifier of the multicast group according to the corresponding relationship; The transceiver is further configured to send the security information to the session management function network element.
11. A computer-readable storage medium, characterized in that The method comprises computer instructions, which, when executed on an electronic device, cause the electronic device to execute the method according to any one of claims 1 to 5.
12. A chip, characterized in that: The chip stores computer-executable instructions, and when the computer-executable instructions are executed, the method according to any one of claims 1 to 5 is executed.
Citation Information
Patent Citations
Network architecture having multicast and broadcast multimedia subsystem capabilities
CN110169104A