A secure communication method and apparatus

By introducing the mechanism of key generation parameters and message complete code between terminal devices, the problem that the terminal device does not verify the identity of the other party before establishing direct communication is solved, which significantly improves communication security.

CN116235524BActive Publication Date: 2025-06-10HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080104555.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-06
Publication Date
2025-06-10
Estimated Expiration
2040-08-06

AI Technical Summary

Technical Problem

The identity of the other party is not verified before establishing direct communication between terminal devices, resulting in poor communication security.

Method used

By introducing key generation parameters between the first terminal device and the second terminal device, a discovery key and a message complete code are generated to ensure identity authentication during communication.

Benefits of technology

It effectively improves the security of direct communication between terminal devices and ensures the legitimacy and trust of both parties to the communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116235524B_ABST
    Figure CN116235524B_ABST
Patent Text Reader

Abstract

A secure communication method and apparatus for ensuring the security of direct communication between terminal devices. In this application, a first terminal device can receive key generation parameters from a first network element, where the key generation parameters include a proximity service temporary identifier of the first terminal device; then, the first terminal device can generate a first discovery key according to the key generation parameters; the first terminal device sends a proximity service request message, where the proximity service request message includes a proximity service temporary identifier and a message integrity code, and the message integrity code is generated based on the discovery key. A second terminal device receives the proximity service request message and verifies the first terminal device according to the message integrity code to ensure the security of direct communication between the first terminal device and the second terminal device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a secure communication method and apparatus. Background Art

[0002] Currently, in proximity service scenarios, direct communication can be carried out between terminal devices. One terminal device can provide proximity services to another terminal device for data interaction.

[0003] Taking the first terminal device (user equipment, UE) as the terminal device requesting proximity services and the second terminal device as the terminal device providing proximity services as an example, the method for establishing direct communication between terminal devices will be described below.

[0004] First, the first terminal device and the second terminal device respectively interact with the 5G direct communication discovery name management function network element to obtain their respective proximity service parameters, such as ProSe application code and discovery filter.

[0005] After that, the first terminal device sends a proximity service request message to the surrounding terminal devices. The proximity service request message includes the proximity service parameters of the first terminal device. After receiving the proximity service request, the second terminal device determines whether it can provide proximity services according to the proximity service parameters of the first terminal device carried in the proximity service request, such as determining whether the proximity service parameters of the first terminal device match the proximity service parameters of the second terminal device. If the second terminal device determines that it can provide proximity services, it can establish direct communication with the first terminal device for data interaction.

[0006] From the above process, it can be seen that the identities of each other are not verified before the terminal devices establish direct communication. The first terminal device cannot determine whether the second terminal device is a terminal device that can truly provide proximity services, and the second terminal device cannot determine whether the first terminal device is a terminal device that truly needs proximity services, resulting in poor security for direct communication between terminal devices. Summary of the Invention

[0007] This application provides a secure communication method and apparatus to ensure the security of direct communication between terminal devices.

[0008] In a first aspect, an embodiment of the present application provides a secure communication method. In this method, a first terminal device may receive key generation parameters, such as receiving key generation parameters from a first network element. The key generation parameters include a proximity service temporary identifier of the first terminal device. After that, the first terminal device may generate a first discovery key of the first terminal device according to a root key and the key generation parameters. The first discovery key may be a discovery key at the proximity service granularity of the first terminal device. When the first terminal device determines that proximity services need to be performed, such as when the first terminal device starts an application corresponding to proximity services, the first terminal device may send a proximity service request message, which includes a proximity service temporary identifier and a message integrity code, and the message integrity code is generated based on the first discovery key.

[0009] Through the above method, when the first terminal device needs to establish direct communication with other terminal devices, it may send a proximity service request message carrying the message integrity code, so that the second terminal device can verify the first terminal device according to the message integrity code to ensure the security of direct communication between the first terminal device and the second terminal device.

[0010] In a possible implementation, there are many ways for the first terminal device to obtain key generation parameters. The first terminal device may send a parameter acquisition request to the first network element. The parameter acquisition request may be used to request proximity service parameters of the first terminal device, and the parameter acquisition request includes an identity identifier of the first terminal device. After that, the first terminal device may receive a parameter acquisition response from the first network element. The parameter acquisition response may include proximity service parameters of the first terminal device. The proximity service parameters of the first terminal device include a proximity service temporary identifier of the first terminal device, the current time, the maximum offset, etc. Some or all of the proximity service parameters may be used as key generation parameters, that is, the parameter acquisition response includes the key generation parameters.

[0011] Through the above method, when the first terminal device requests proximity service parameters from the first network element, optionally, it may also obtain key generation parameters in addition to obtaining proximity service parameters.

[0012] In a possible implementation, when the first terminal device generates a message integrity code based on the first discovery key, it may directly generate the message integrity code according to the first discovery key, or generate a sub-key according to the first discovery key. Then, generate the message integrity code according to the sub-key.

[0013] Through the above method, the first terminal device can generate the message integrity code more flexibly, which is suitable for different scenarios.

[0014] In a possible implementation, the parameter acquisition response further includes the validity period of the proximity service temporary identifier. For example, the parameter acquisition response includes current time, MAX offset, and validity timer. Current time, MAX offset, and validity timer can be used to indicate the validity period of the proximity service temporary identifier.

[0015] Through the above method, since the proximity service temporary identifier has a validity period, the security of the proximity service temporary identifier can be ensured.

[0016] In a possible implementation, the validity period of the proximity service temporary identifier can be used as the validity period of the first discovery key. After the first terminal device determines that the validity period of the proximity service temporary identifier has expired, the first terminal device deletes the first discovery key.

[0017] Through the above method, it can be ensured that the first discovery key is deleted when the proximity service temporary identifier is invalid, thus ensuring the security and effectiveness of the first discovery key.

[0018] In a possible implementation, the key generation parameters further include some or all of the proximity service parameters assigned by the first network element to the first terminal device except the proximity service temporary identifier, such as some or all of the current time and the maximum offset. The key generation parameters can also include other parameters, such as the counter value, etc.

[0019] Through the above method, the key generation parameters can include different types of parameters, making the generation method of the discovery key more flexible.

[0020] In a possible implementation, the root key can be any one of the following: Kausf, Kamf, Kakma, or a pre-configured key.

[0021] Through the above method, different keys can be selected as the root key, which is applicable to different scenarios.

[0022] In a second aspect, an embodiment of the present application provides a secure communication method. In this method, the first network element can send down adjacent key generation parameters. For example, the first network can send key generation parameters to the first terminal device. The key generation parameters include the proximity service temporary identifier of the first terminal device. The key generation parameters are the parameters required when generating the first discovery key (i.e., the discovery key at the proximity service granularity) of the first terminal device. These parameters may be parameters that the first terminal device has not saved or cannot know. The first network element can also receive a verification request from the second terminal device. The verification request includes the proximity service temporary identifier and the message integrity code. The first network element obtains the first discovery key of the first terminal device according to the proximity service temporary identifier, and generates an expected message integrity code according to the first sending key.

[0023] After verifying the first terminal device based on the message integrity code and the expected message integrity code, the first network element sends a verification response to the second terminal device. The verification response is used to indicate the verification result of the first terminal device, and the verification result indicates that the verification of the first terminal device is successful or failed.

[0024] Through the above method, the first network element can send the key generation parameters to the first terminal device, so that the first terminal device can generate the first discovery key, and then generate the message integrity code. The first network element can also verify the first terminal device based on the message integrity code and timely inform the second terminal device of the verification result, ensuring that the first terminal device and the second terminal device can perform secure direct communication.

[0025] In a possible implementation manner, there are many ways for the first network element to send the key generation parameters to the first terminal device. For example, the first network element receives a parameter acquisition request from the first terminal device. The parameter acquisition request can be used to request the proximity service parameters of the first terminal device. The proximity service parameters are the parameters required for the first terminal device to perform proximity services. The parameter acquisition request includes the identity identifier of the first terminal device. After passing the authorization check of the first terminal device according to the identity identifier of the first terminal device, the first network element allocates the proximity service parameters of the first terminal device to the first terminal device, such as allocating a proximity service temporary identifier. The first network element obtains the first discovery key according to the proximity service temporary identifier. The first network element sends a parameter acquisition response to the first terminal device. The parameter acquisition response may include the proximity service parameters of the first terminal device. The proximity service parameters of the first terminal device include the proximity service temporary identifier, the current time, the maximum offset, etc. Some or all of the proximity service parameters can be used as the key generation parameters, that is, the parameter acquisition response includes the key generation parameters.

[0026] Through the above method, when the first network element allocates the proximity service parameters to the first terminal device, optionally, it can also send the key generation parameters to the first terminal device.

[0027] In a possible implementation manner, the first network element can also save the correspondence between the proximity service temporary identifier and the first discovery key.

[0028] Through the above method, the first network element can conveniently and quickly determine the first discovery key according to the proximity service temporary identifier.

[0029] In a possible implementation, the parameter acquisition request further includes the proximity service information of the first terminal device, and the proximity service information can indicate the proximity services that the first terminal device needs to perform. When the first network element passes the authorization check on the first terminal device according to the identity identifier of the first terminal device, it can perform the authorization check on the first terminal device by itself. Exemplarily, the first network element obtains the subscription information of the proximity services of the first terminal device from the unified data management network element according to the identity identifier of the first terminal device and the proximity service information of the first terminal device; the first network element authenticates the first terminal device by comparing the proximity service information of the first terminal device with the proximity service subscription information of the first terminal device, and after determining that the proximity service information of the first terminal device is consistent with the proximity service subscription information of the first terminal device, the first network element passes the authorization check on the first terminal device.

[0030] Through the above method, the first network element can perform the authorization check on the first terminal device by itself, which is relatively fast and can ensure the legitimacy of the first terminal device.

[0031] In a possible implementation, the parameter acquisition request further includes the proximity service information of the first terminal device. When the first network element passes the authorization check on the first terminal device according to the identity identifier of the first terminal device, it can also perform the authorization check on the first terminal device through other network elements, such as the unified data management network element, the proximity service application server, or other network elements storing the subscription information of the proximity services of the first terminal device. Taking the other network element as the unified data management network element as an example, the first network element can send a check request to the unified data management network element for requesting to perform the authorization check on the first terminal device, and the check request includes the identity identifier of the first terminal device. The first network element can receive a check response from the unified data management network element, and the check response is used to indicate that the authorization check on the first terminal device passes.

[0032] Through the above method, the first network element can conveniently perform the authorization check on the first terminal device through other network elements to ensure the legitimacy of the first terminal device.

[0033] In a possible implementation, there are many ways for the first network element to obtain the first discovery key according to the proximity service temporary identifier. Three of them are listed below:

[0034] 1. The first network element generates the first discovery key according to the proximity service temporary identifier and the root key. The root key is a key allocated or pre-configured for the first terminal device, that is, the root key can be the key allocated by the network side for the first terminal device and stored on the network side when the first terminal device registers to the network side, and this key is the same as the key generated and stored by the first terminal device itself. The root key can also be a key pre-configured on the network side and corresponding to the first terminal device, and this key is also pre-configured on the first terminal device side.

[0035] 2. The first network element obtains a first discovery key from the key generation network element according to the proximity service temporary identifier.

[0036] 3. The first network element obtains a second discovery key from the key generation network element according to the identity identifier. The second discovery key may be a discovery key at the terminal device granularity of the first terminal device. After that, the first network element may generate a first discovery key according to the second discovery key and the proximity service temporary identifier.

[0037] Through the above method, the first network element obtains the first discovery key in different ways, which is applicable to different scenarios and expands the applicable scope.

[0038] In a possible implementation manner, the key generation parameter further includes part or all of the proximity service parameters other than the proximity service temporary identifier assigned by the first network element to the first terminal device, such as part or all of the current time and the maximum offset, and may further include other parameters, such as the counter value, etc.

[0039] Through the above method, different types of parameters can be included in the key generation parameter, making the generation method of the discovery key more flexible.

[0040] In a possible implementation manner, when the first network element obtains the first discovery key from the key generation network element according to the proximity service temporary identifier, the first network element may send a first key acquisition request to the key generation network element. The first key acquisition request includes the identity identifier of the first terminal device and the proximity service temporary identifier. The first key acquisition request may further carry other information, such as part or all of the current time, the maximum offset, and the proximity service information of the first terminal device, etc.; the first network element receives a first key acquisition response from the key generation network element, and the first key acquisition response includes the first discovery key.

[0041] Through the above method, the first network element can obtain the first discovery key from the key generation network element more conveniently and quickly.

[0042] In a possible implementation manner, when the first network element obtains the second discovery key from the key generation network element according to the identity identifier, the first network element may send a second key acquisition request to the key generation network element. The second key acquisition request includes the identity identifier of the first terminal device. The first key acquisition request may further carry other information, such as part or all of the proximity service information of the first terminal device, etc.; after that, the first network element receives a second key acquisition response from the key generation network element, and the second key acquisition response includes the second discovery key.

[0043] Through the above method, the first network element can obtain the second discovery key from the key generation network element, and then generate the first discovery key by itself. The first network element and the key generation network element do not need to interact with the proximity service temporary identifier, which can ensure the security of the proximity service temporary identifier.

[0044] In a possible implementation manner, when the first network element generates an expected message integrity code based on the first discovery key, the first network element can generate a sub-key based on the first discovery key; then, generate the expected integrity code based on the sub-key. It is also possible to directly generate the expected integrity code based on the first discovery key.

[0045] Through the above method, the first network element can generate the message integrity code more flexibly, which is applicable to different scenarios.

[0046] In a possible implementation manner, the key generation network element is any of the following network elements: authentication service function network element, access and mobility management function network element, authentication and key management anchor function network element of the application, boot service function network element, 5G direct communication discovery name management function network element, or key management network element, where the key management network element is the network element that stores the key pre-configured for the first terminal device. To be applicable to different scenarios.

[0047] In a possible implementation manner, the first network element can determine the validity period of the proximity service temporary identifier and save the corresponding relationship between the validity period and the first discovery key.

[0048] Through the above method, the validity period of the first discovery key is the same as the validity period of the proximity service temporary identifier.

[0049] In a possible implementation manner, after the validity period of the proximity service temporary identifier expires, the first network element deletes the first discovery key.

[0050] Through the above method, it can be ensured that the first discovery key is deleted when the proximity service temporary identifier is invalid, ensuring the security and effectiveness of the first discovery key.

[0051] In a third aspect, an embodiment of the present application provides a secure communication method, and the method includes: the key generation network element can receive a key acquisition request from the first network element and feedback the discovery key of the first terminal device to the first network element. The following are two ways:

[0052] In Method 1, the key generation network element can receive a first key acquisition request from the first network element. The first key acquisition request includes the identity identifier of the first terminal device and the proximity service temporary identifier. The key generation network element determines the root key according to the identity identifier of the first terminal device. The root key is a key allocated or pre-configured for the first terminal device. This root key can be stored locally by the key generation network element or obtained from the network element storing this root key. The key generation network element generates a first discovery key according to the root key and the proximity service temporary identifier. The key generation network element sends a first key acquisition response to the first network element. The first key acquisition response includes the first discovery key.

[0053] In Method 2, the key generation network element receives a second key acquisition request from the first network element. The second key acquisition request includes the identity identifier of the first terminal device. The key generation network element determines the root key according to the identity identifier of the first terminal device. The key generation network element generates a second discovery key according to the root key. The key generation network element sends a second key acquisition response to the first network element. The second key acquisition response includes the second discovery key.

[0054] Through the above method, the key generation network element can feedback different types of discovery keys to the first network element for different scenarios.

[0055] In a possible implementation, the key generation network element is any of the following network elements: the authentication service function network element, the access and mobility management function network element, the authentication and key management anchor function network element of the application, the bootstrapping service function network element, the 5G direct communication discovery name management function network element, or the key management network element. Among them, the key management network element is the network element storing the key pre-configured for the first terminal device, so as to be applicable to different scenarios.

[0056] In a fourth aspect, an embodiment of the present application provides a secure communication method. In the method, the second terminal device receives a proximity service request message sent by the first terminal device. The proximity service request message includes the proximity service temporary identifier of the first terminal device and the message integrity code. After the second terminal device determines that it can support the proximity service according to the proximity service temporary identifier, it sends a verification request to the first network element. The verification request includes the proximity service temporary identifier and the message integrity code. The second terminal device receives a verification response from the first network element. The verification response is used to indicate the verification result of the first terminal device. The second terminal device determines whether to establish direct communication with the first terminal device according to the verification result.

[0057] Through the above method, when the second terminal device receives the proximity service request message carrying the message integrity code sent by the first terminal device, it can verify the first terminal device according to the message integrity code to ensure the security of direct communication between the first terminal device and the second terminal device.

[0058] Fifth aspect, embodiments of the present application further provide a communication device, which is applied to a first terminal device. The beneficial effects can be referred to the description in the first aspect and will not be elaborated here. This device has the functions to implement the behaviors in the method examples of the above first aspect. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the structure of the device includes a receiving unit, a processing unit, and a transmitting unit, and these units can execute the corresponding functions in the method examples of the above first aspect. For specific details, refer to the detailed description in the method examples and will not be elaborated here.

[0059] Sixth aspect, embodiments of the present application further provide a communication device, which is applied to a first network element. The beneficial effects can be referred to the description in the second aspect and will not be elaborated here. This device has the functions to implement the behaviors in the method examples of the above second aspect. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the structure of the device includes a receiving unit, a processing unit, and a transmitting unit, and these units can execute the corresponding functions in the method examples of the above second aspect. For specific details, refer to the detailed description in the method examples and will not be elaborated here.

[0060] Seventh aspect, embodiments of the present application further provide a communication device, which is applied to a key generation network element. The beneficial effects can be referred to the description in the third aspect and will not be elaborated here. This device has the functions to implement the behaviors in the method examples of the above third aspect. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the structure of the device includes a receiving unit, a processing unit, and a transmitting unit, and these units can execute the corresponding functions in the method examples of the above third aspect. For specific details, refer to the detailed description in the method examples and will not be elaborated here.

[0061] Eighth aspect, embodiments of the present application further provide a communication device, which is applied to a second terminal device. The beneficial effects can be referred to the description in the fourth aspect and will not be elaborated here. This device has the functions to implement the behaviors in the method examples of the above fourth aspect. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. In a possible design, the structure of the device includes a receiving unit, a processing unit, and a transmitting unit, and these units can execute the corresponding functions in the method examples of the above fourth aspect. For specific details, refer to the detailed description in the method examples and will not be elaborated here.

[0062] In a ninth aspect, an embodiment of the present application further provides a communication device, which is applied to a first terminal device. The beneficial effects can be referred to the description in the first aspect and will not be elaborated here. The structure of the communication device includes a processor and a memory. The processor is configured to support the session management network element to execute the corresponding functions in the method of the first aspect. The memory is coupled to the processor and stores the necessary program instructions and data of the communication device. The structure of the communication device further includes a transceiver for communicating with other devices.

[0063] In a tenth aspect, an embodiment of the present application further provides a communication device, which is applied to a first network element. The beneficial effects can be referred to the description in the second aspect and will not be elaborated here. The structure of the communication device includes a processor and a memory. The processor is configured to support the first terminal device to execute the corresponding functions in the method of the second aspect. The memory is coupled to the processor and stores the necessary program instructions and data of the communication device. The structure of the communication device further includes a communication interface for communicating with other devices.

[0064] In an eleventh aspect, an embodiment of the present application further provides a communication device, which is applied to a key generation network element. The beneficial effects can be referred to the description in the third aspect and will not be elaborated here. The structure of the communication device includes a processor and a memory. The processor is configured to support the access and mobility management function network element to execute the corresponding functions in the method of the third aspect. The memory is coupled to the processor and stores the necessary program instructions and data of the communication device. The structure of the communication device further includes a communication interface for communicating with other devices.

[0065] In a twelfth aspect, an embodiment of the present application further provides a communication device, which is applied to a second terminal device. The beneficial effects can be referred to the description in the fourth aspect and will not be elaborated here. The structure of the communication device includes a processor and a memory. The processor is configured to support the unified data management network element to execute the corresponding functions in the method of the fourth aspect. The memory is coupled to the processor and stores the necessary program instructions and data of the communication device. The structure of the communication device further includes a transceiver for communicating with other devices.

[0066] In a thirteenth aspect, the present application further provides a computer-readable storage medium, in which instructions are stored. When the instructions are run on a computer, the computer is enabled to execute the methods described in the above aspects.

[0067] In a fourteenth aspect, the present application further provides a computer program product containing instructions. When the computer program product is run on a computer, the computer is enabled to execute the methods described in the above aspects.

[0068] In a fifteenth aspect, the present application further provides a computer chip, which is connected to a memory. The chip is configured to read and execute a software program stored in the memory and execute the methods described in the above aspects. Description of the Drawings

[0069] Figure 1A It is an architecture diagram of a system provided by an embodiment of the present application;

[0070] Figure 1B It is a schematic diagram of a method for direct communication between an A-UE and an M-UE;

[0071] Figure 2 It is a schematic diagram of a method for a first terminal device to obtain key generation parameters provided by the present application;

[0072] Figure 3 It is a schematic diagram of a method for a first terminal device to perform authentication with a second terminal device provided by the present application;

[0073] Figure 4 It is a schematic diagram of a secure communication method provided by the present application;

[0074] Figure 5 It is a schematic diagram of a secure communication method provided by the present application;

[0075] Figure 6 It is a schematic diagram of a secure communication method provided by the present application;

[0076] Figure 7 It is a schematic diagram of a secure communication method provided by the present application;

[0077] Figures 8 to 13 It is a schematic structural diagram of a communication device provided by an embodiment of the present application. Detailed Embodiments

[0078] Refer to Figure 1A As shown, it is a specific system architecture schematic diagram applicable to the present application. The network elements in this system architecture include a user equipment (UE), Figure 1AFour UEs, namely UE A, UE B, UE C, and UE D, are exemplarily drawn. The system architecture also includes a radio access network (RAN), an access and mobility management function (AMF) network element, a session management function (SMF) network element, a user plane function (UPF) network element, a unified data management (UDM) network element, a unified data repository (UDR) network element, an application function (AF) network element, a data network (DN), a network exposure function (NEF) network element, a 5G direct discovery name management function (5GDDNMF) network element, a policy control function (PCF) network element, a ProSe application server, etc. Among them, network elements such as the AMF network element, the SMF network element, the UDM network element, the NEF network element, and the PCF network element belong to the core network elements in the 5th generation mobile networks (5G) network architecture. Only some core network elements are exemplarily shown here, and other core network elements may also be included in this system architecture.

[0079] A terminal device is a device with wireless transceiver functions. It can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as ships, etc.); it can also be deployed in the air (such as airplanes, balloons, satellites, etc.). The terminal device can be a mobile phone, a tablet computer (pad), a computer with wireless transceiver functions, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The terminal device in the embodiment of the present application can be a terminal device capable of communicating in a proximity service (ProSe) scenario. This terminal device has a proximity service application (ProSe application) function. Terminal devices with ProSe application functions can communicate through the PC5 interface.

[0080] In the embodiment of the present application, there are two types of terminal devices, namely the first terminal device and the second terminal device. The first terminal device can request other terminal devices (including the second terminal device) to provide proximity services for the first terminal device. When the second terminal device determines that it can provide proximity services for the first terminal device, it can provide proximity services for the first terminal device, and the second terminal device and the first terminal device can communicate directly.

[0081] In different discovery scenarios, the names of the second terminal device providing proximity services and the first terminal device in need of proximity services are different. Here, two discovery scenarios are introduced, namely the open ProSe discovery scenario and the restricted ProSe discovery scenario. The relevant descriptions of the open ProSe discovery scenario and the restricted ProSe discovery scenario can refer to the prior art and will not be elaborated here.

[0082] For example, if user A uses terminal device A to play games, user A does not have a clear game partner, and can just "randomly" find a game partner. This scenario is an open proximity service scenario. If user A uses terminal device A to play games with a clear partner, user A can "specify" a partner through terminal device A. Only the partner he specifies can access the game, and others cannot. This scenario is a restricted proximity service discovery scenario.

[0083] Optionally, in an embodiment of the present application, the discovery mode in the discovery scenario includes model A or model B. The difference between model A and model B is that the terminal device initiates discovery in a different manner in the discovery scenario.

[0084] Model A means "I am here". The terminal devices involved in model A are divided into announcing UE and monitoring UE. The announcing UE broadcasts "I am here". After receiving the message broadcast by the announcing UE, the monitoring UE determines whether to establish a connection with the announcing UE based on whether it meets its own business needs.

[0085] Model B means "Who is there? / Where are you?". The terminal devices involved in model B are divided into discoveree UE and discoverer UE. The discoverer UE initiates a request, which includes specific information, such as "Who is there? / Where are you?". After receiving the request initiated by the discoverer UE, the discoveree UE determines whether to reply to the request based on whether it can provide business services. If it replies, it means "I am here". In the embodiment of the present application, the open proximity service discovery scenario is only applicable to the model A discovery mode, while the restricted proximity service discovery scenario is applicable to both model A and model B discovery modes.

[0086] In the embodiments of the present application, the network side (such as a core network element or a 5G DDNMF network element) may determine the type of the first terminal device or the second terminal device according to the proximity service information reported by the first terminal device or the second terminal device to the network side. For example, the discovery command included in the proximity service information reported by the first terminal device or the second terminal device to the network side can indicate whether the first terminal device or the second terminal device is an announcing UE or a monitoring UE; whether it is a response terminal device (response UE) or a query terminal device (query UE). Among them, the announcing UE and the monitoring UE are the two terminal devices in the above model A, and the Response UE and the Query UE correspond to the discoveree UE and the discoverer UE in the above model B respectively.

[0087] In the embodiments of the application, before the second terminal device provides proximity services to the first terminal device, it needs to first verify the identity of the first terminal device to determine whether the second terminal device is a terminal device that truly needs proximity services. Specifically, the second terminal device may report the message integrity code obtained from the first terminal device to the core network element or the 5G DDNMF network element. Among them, the message integrity code is generated based on the discovery key of the first terminal device, and the discovery key of the first terminal device is generated using the key generation parameter obtained from the core network element or the 5G DDNMF network element. The core network element or the 5G DDNMF network element verifies based on the message integrity code reported by the second terminal device and the expected message integrity code calculated by the 5G DDNMF network element according to the discovery key of the first terminal device. The second terminal device may also obtain the discovery key of the first terminal device from the core network element or the 5G DDNMF network element, and calculate the expected message integrity code for verification.

[0088] Similarly, before the first terminal device accepts the proximity services provided by the second terminal device, it may also first verify the identity of the second terminal device to determine whether the second terminal device is a terminal device that can truly provide proximity services. The specific method is similar to the method by which the second terminal device verifies the identity of the first terminal device.

[0089] The main function of the RAN is to control users to wirelessly access the mobile communication network. The RAN is a part of the mobile communication system. It implements a wireless access technology. Conceptually, it resides between certain devices (such as a mobile phone, a computer, or any remote control machine) and provides a connection to its core network.

[0090] The AMF network element is responsible for the access management and mobility management of the terminal. In practical applications, it includes the mobility management function in the MME of the LTE network framework and adds the access management function.

[0091] Optionally, the AMF network element can also use Kamf to generate the discovery key of the terminal device and send the discovery key of the terminal device to the 5G DDNMF network element or other network elements (such as the ProSe application server).

[0092] Among them, Kamf is a root key of the terminal device, which is allocated by the network side (such as the AMF network element) to the terminal device when the terminal device registers to the network, and the keys are respectively stored in the terminal device and the AMF side.

[0093] The SMF network element is responsible for session management, such as the establishment of user sessions, etc.

[0094] The PCF network element is a control plane function provided by the operator and is used to provide session policies to the SMF network element. The policies can include charging-related policies, QoS-related policies, authorization-related policies, etc.

[0095] The UPF network element is a user plane functional network element, mainly responsible for connecting to the external network, and it includes the related functions of the serving gateway (SGW) and the public data network gateway (PDN-GW) in LTE.

[0096] The DN is the network that provides services for the terminal. For example, some DNs provide Internet access functions for the terminal, and some other DNs provide SMS functions for the terminal, etc.

[0097] The UDM network element can store the subscription information of the user and implement a function similar to the HSS in 4G. In the embodiments of the present application, the UDM can determine the subscription permanent identifier (SUPI) of the UE according to the anonymized identifier or the temporary identifier of the UE.

[0098] The UDR network element is mainly used to store the subscription information of the user, policy data, structured data for opening, and application data.

[0099] The AF network element can be a third-party application control platform or the operator's own device. The AF network element can provide services for multiple application servers.

[0100] The NEF network element opens the capabilities and events of other network elements to third-party partners or AF network elements. It provides a way for the AF network element to securely provide information to the 3rd generation partnership project (3GPP) network. The NEF network element can verify, authorize, and assist in restricting the AF network element. In addition, the NEF network element can also transform the information exchanged by the AF network element and the information exchanged by the core network functional network element.

[0101] The ProSe application server stores the user identifiers of proximity services and can also authenticate the terminal devices in the discovery scenario. It can also store the pre-configured keys for the terminal devices, which are keys related to proximity services.

[0102] In practical applications, the ProSe application Server can be an AF network element, that is, an AF network element with the functions of the ProseApplication server. In this way, the Prose application server and the UE can perform user-plane communication through the path of UE-RAN-UPF-AF. The Prose application server can also communicate with other core network elements through the NEF network element. For example, communicate with the PCF network element through the NEF network element.

[0103] In the open proximity service discovery scenario, the 5G DDNMF network element can allocate a proximity service application identifier (ProSe application ID) and a proximity service application code (ProSe application code), and handle the mapping between the proximity service application identifier (ProSe application ID) and the proximity service application code (ProSe application code). In the restricted proximity service discovery scenario, the 5G DDNMF network element can communicate with the ProSe application server through the PC2 interface to handle the authorization of discovery requests, allocate a restricted proximity service application identifier (ProSe discovery UE ID) and a restricted proximity service code (ProSe restricted code), and handle the mapping between the proximity service application identifier (ProSe discovery UE ID) and the restricted proximity service code (ProSe restricted code). Among them, both the proximity service application code (ProSe application code) and the restricted proximity service code (ProSe restricted code) can be used as the proximity service temporary identifier mentioned in the embodiments of this application.

[0104] In the embodiments of this application, the 5G DDNMF network element has an enhanced security function that can verify the identities of terminal devices (such as the first terminal device and the second terminal device). For example, after receiving the message integrity code from the first terminal device reported by the second terminal device, the 5G DDNMF network element can generate an expected message integrity code using the discovery key of the first terminal device. After determining that the message integrity code is consistent with the expected message integrity code, it notifies the second terminal device that the verification of the first terminal device is successful.

[0105] It should be noted that only the example of the 5G DDNMF network element having an enhanced security function is used here for illustration. This security function can also be added to other network elements, such as core network elements or ProSe application Servers, and other network elements can interact with terminal devices to verify the identities of other terminal devices.

[0106] Although not shown, the core network element further includes an authentication server function (AUSF) network element, an authentication and key management for applications (AKMA) anchor function (AAnF) network element, a bootstrapping server function (BSF), etc. The AUSF network element has an authentication service function. In the embodiments of the present application, the AUSF network element can generate a discovery key of the terminal device by using Kausf of the terminal device and send the discovery key of the terminal device to the 5G DDNMF network element. Similarly, the AAnF network element can generate a discovery key of the terminal device by using Kakma and send the discovery key of the terminal device to the 5G DDNMF network element. The bootstrapping server function (BSF) network element can generate a discovery key of the terminal device by using Ks and send the discovery key of the terminal device to the 5G DDNMF network element.

[0107] Among them, Kausf, Kakma, or Ks is also used as the root key for generating the discovery key of the terminal device. These keys are assigned by the network side to the terminal device when the terminal device registers to the network and are stored on the network side. And this key is the same as the key generated by the terminal device itself and stored on the terminal device side.

[0108] Next, based on the system architecture as Figure 1B shown, taking the authentication method between an A-UE (i.e., announcing UE) and an M-UE (i.e., monitoring UE) in the open Prose discovery scenario as an example, the authentication method between UEs in the discovery scenario in the prior art will be described. Here, the AMF interacting with the A-UE is denoted as A-AMF, and the AMF interacting with the M-UE is denoted as M-AMF. As Figure 2 shown, the method includes:

[0109] Step 101: The A-UE sends a parameter acquisition request to the A-AMF. The parameter acquisition request is used to request the neighboring service parameters of the A-UE. The parameter acquisition request includes the identity identifier of the A-UE and the neighboring service information of the A-UE. The identity identifier of the A-UE is used to indicate the A-UE. The neighboring service information of the A-UE is used to indicate the neighboring services required by the A-UE.

[0110] The proximity service information of the A-UE includes one or more of, but is not limited to, user identity, discovery mode, discovery command, discovery type, and application ID.

[0111] In the open proximity service discovery scenario, the user identity can be the ProSe application ID. Here, only the open proximity service discovery scenario is taken as an example. In the restricted proximity service discovery scenario, the user identity can be the restricted ProSe application user ID (RPAUID).

[0112] Step 102: The A-AMF forwards a parameter acquisition request to the 5GDDNMF.

[0113] Step 103: After receiving the parameter acquisition request, the 5GDDNMF allocates proximity service parameters for the A-UE. The proximity service parameters include, but are not limited to, ProSe application code, validity time, and discovery filter.

[0114] It should be noted that in the open proximity service discovery scenario, the ProSe application code is an instruction allocated in the open discovery scenario. In the restricted proximity service discovery scenario, the ProSe application code is replaced by the ProSe restricted code.

[0115] Step 104: The 5GDDNMF sends the allocated proximity service parameters for the A-UE to the A-UE through the A-AMF.

[0116] Step 105: The M-UE requests proximity service parameters from the 5GDDNMF through the M-AMF and obtains the proximity service parameters allocated by the 5GDDNMF for the M-UE through the M-AMF. The way the M-UE requests proximity service parameters from the 5GDDNMF through the M-AMF and obtains the proximity service parameters allocated by the 5GDDNMF for the M-UE is similar to the way the A-UE requests proximity service parameters from the 5GDDNMF through the A-AMF and obtains the proximity service parameters allocated by the 5GDDNMF for the A-UE. For details, please refer to Steps 101 to 104 and will not be elaborated here.

[0117] It should be noted that the 5G DDNMF interacting with the M-UE and the 5G DDNMF interacting with the A-UE may be the same or different.

[0118] Step 106: The A-UE sends a broadcast message over the air interface. The broadcast message includes the Prose application Code. The M-UE receives the broadcast message and establishes a PC5 unicast connection with the A-UE.

[0119] From the above process, it can be seen that in the discovery scenario, the authentication process is not performed between the two terminal devices. Taking the open proximity service discovery scenario as an example, the A-UE cannot know whether the M-UE really has the ability to provide proximity services for it. The M-UE may be an illegal UE, stealing the information of the A-UE and reselling it for profit. And the M-UE also cannot determine whether the A-UE is a UE that really needs proximity services. The A-UE may be an attacker, establishing a connection with the M-UE by broadcasting the Prose application Code, resulting in the M-UE being unable to establish a connection with other A-UEs. Therefore, the security of establishing a connection and conducting direct communication between the current A-UE and the M-UE is relatively poor.

[0120] To ensure the security of the two terminal devices conducting direct communication, in the embodiments of the present application, before the first terminal device and the second terminal device establish direct communication, the first terminal device and the second terminal device can perform verification. The process is as follows: The first terminal device can obtain key generation parameters from the first network element, generate a discovery key using the key generation parameters, and then generate a message integrity code using the discovery key. When the second terminal device needs to verify the identity of the first terminal device, the second terminal device sends the message integrity code received from the first terminal device to the first network element, requesting the first network element to verify the first terminal device. After receiving the message integrity code, the first network element generates an expected message integrity code using the stored discovery key of the first terminal device. After determining that the message integrity code and the expected message integrity code are consistent, the verification of the first terminal device is successful, and the second terminal device is notified that the verification of the first terminal device is successful. After determining that the first network element has successfully verified the first terminal device, the second terminal device can establish a connection with the first terminal device and conduct direct communication. Similarly, the first terminal device can also verify the second terminal device in a similar manner. Thus, it can be ensured that before the second terminal device and the first terminal device conduct direct communication, the identity of the other party can be determined, thereby ensuring the security of direct communication.

[0121] The following describes a secure communication method provided by an embodiment of the present application in conjunction with the accompanying drawings. The secure communication method provided by the embodiment of the present application includes two parts. One part is that the first terminal device obtains key generation parameters from the first network element, and the other part is the verification between the first terminal device and the second terminal device. The following will be described separately:

[0122] (1). The first terminal device obtains key generation parameters from the first network element.

[0123] See Figure 2 , which is a method for obtaining key generation parameters in an embodiment of the present application. The method includes:

[0124] Step 201: The first terminal device sends a parameter acquisition request to the first network element. The parameter acquisition request includes the identity identifier of the first terminal device. The first network element can be a 5G direct communication discovery name management function network element, or a proximity service application server, or other core network network elements. The identity identifier of the first terminal device can be the user permanent identifier of the first terminal device, such as SUPI, generic public subscription identifier (GPSI), permanent equipment identifier (PEI), or the anonymized identifier of the first terminal device, such as subscription concealed identifier (SUCI), or a temporary identifier of the first terminal device. The temporary identifier can be pre-allocated by the network side for the first terminal device, or can be allocated by the network side for the first terminal device after the first terminal device registers to the network, such as globally unique temporary UE identity (GUTI).

[0125] The parameter acquisition request can be used to request the first network element to allocate proximity service parameters. The proximity service parameters are the parameters required by the first terminal device for proximity services. The proximity service parameters are allocated by the network side (such as a 5G DDNMF network element or a core network network element) for the first terminal device. The proximity service parameters include a proximity service temporary identifier. The proximity service temporary identifier is a temporary identifier allocated by the first network element for the first terminal device for proximity services, and is used for terminal devices to discover each other through the proximity service temporary identifier in the discovery scenario, so as to find each other.

[0126] In different discovery scenarios, the ProSe temporary identifier also varies. For example, in the open ProSe discovery scenario, the ProSe temporary identifier can be referred to as the ProSe application code, and in the restricted ProSe discovery scenario, the ProSe temporary identifier can be referred to as the restricted ProSe code.

[0127] The parameter acquisition request may further include the ProSe information of the first terminal device, where the ProSe information of the first terminal device is used to indicate the ProSe services required by the first terminal device. The ProSe information of the first terminal device includes some or all of the following:

[0128] The user identity of the first terminal device, discovery command, discovery model, discovery type, and application ID.

[0129] The user identity of the first terminal device can also be referred to as the ProSe identity. The user identity of a first terminal device is the application layer user identity of the first terminal device in a ProSe scenario (i.e., discovery scenario). For an application corresponding to a ProSe service in the first terminal device, a user identity can be configured. Multiple different user identities can be configured for applications corresponding to the same ProSe service, and different user identities can be configured for applications corresponding to different ProSe services. There is no limit to the number of user identities in the ProSe information of the first terminal device, which can be one or multiple.

[0130] The discovery command is used to identify the type of the first terminal device, and can indicate that the first terminal device is an announcing UE or a monitoring UE; it can also indicate that the first terminal device is a Response UE or a Query UE.

[0131] The discovery type is used to indicate the type of discovery scenario to which the first terminal device belongs, such as indicating open ProSe discovery or restricted ProSe discovery.

[0132] The discovery model is used to indicate the discovery model of the first terminal device, such as indicating model A or model B.

[0133] The application ID is used to indicate the application corresponding to the ProSe service. The application ID can be pre-configured in the first terminal device.

[0134] The embodiments of the present application do not limit the manner in which the first terminal device sends a parameter acquisition request to the first network element. The first terminal device may send a parameter acquisition request to the first network element through the control plane or through the user plane. The following describes these two methods:

[0135] 1. The first terminal device sends a parameter acquisition request to the first network element through the control plane.

[0136] The first terminal device may send the parameter acquisition request to the access and mobility management function network element. After receiving the parameter acquisition request, the access and mobility management function network element may directly forward the parameter acquisition request to the first network element, or may parse the parameter acquisition request. After parsing the parameter acquisition request, the parsed parameter acquisition request is sent to the first network element.

[0137] Here, the specific type of the parsing operation of the parameter acquisition request by the access and mobility management function network element is not limited. For example, the access and mobility management function network element may verify the first terminal device according to the identity identifier of the first terminal device; for another example, if the identity identifier of the first terminal device is not the user's permanent identifier, the access and mobility management function network element may determine the user's permanent identifier of the first terminal device according to the identity identifier of the first terminal device.

[0138] Exemplarily, the access and mobility management function network element may locally store the correspondence between the user's permanent identifier of the first terminal device and the identity identifier of the first terminal device. The access and mobility management function network element may determine the permanent identifier of the first terminal device according to the identity identifier of the first terminal device, replace the identity identifier of the first terminal device in the parameter acquisition request with the permanent identifier of the first terminal device, and then send the parameter acquisition request with the replaced permanent identifier of the first terminal device to the first network element.

[0139] Exemplarily, the access and mobility management function network element may also request the user's permanent identifier of the first terminal device from other network elements (such as the unified data management network element). The access and mobility management function network element may request the user's permanent identifier of the first terminal device from the unified data management network element according to the identity identifier of the first terminal device. After obtaining the permanent identifier of the first terminal device from the unified data management network element, the identity identifier of the first terminal device in the parameter acquisition request is replaced with the permanent identifier of the first terminal device, and then the parameter acquisition request with the replaced permanent identifier of the first terminal device is sent to the first network element.

[0140] Optionally, if the mobile access network element can also store information of the key generation network element, such as the address or identity (ID) of the key generation network element. The key generation network element stores a root key and can generate a discovery key for the first terminal device based on the root key. The access and mobility management function network element can also carry the information of the key generation network element in the parameter acquisition request.

[0141] 2. The first terminal device sends a parameter acquisition request to the first network element through the user plane.

[0142] The first terminal device can send the parameter acquisition request to the first network element through the user plane network element.

[0143] Step 202: After receiving the parameter acquisition request, the first network element can allocate adjacent service parameters for the first terminal device, such as an adjacent service temporary identifier.

[0144] Before allocating adjacent service parameters for the first terminal device after receiving the parameter acquisition request, the first network element can first perform an authorization check on the first terminal device.

[0145] The embodiments of the present application do not limit the manner in which the first network element performs an authorization check on the first terminal device. The following lists two of the manners:

[0146] Manner 1: The first network element requests another network element to perform an authorization check. Among them, the other network element can be a network element that stores the subscription information of the adjacent services of the first terminal device, such as a unified data management network element or an adjacent service application server.

[0147] The first network element can send the adjacent service information of the first terminal device to the other network element, and can also send the identification information of the first terminal device (such as at least one of the identity identification and user identification of the first terminal device) to the other network element to request the other network element to perform an authorization check on the first terminal device. For example, the first network element can send a check request to the other network element to request an authorization check on the first terminal device, and the check request includes the adjacent service information of the first terminal device and the identification information of the first terminal device.

[0148] It should be noted that the identity identification of the first terminal device here can be the identity identification carried in the parameter acquisition request sent by the first terminal device, or when the first terminal device sends the parameter acquisition request through the control plane, after the access and mobility management function network element parses the parameter acquisition request, the user permanent identification of the first terminal device obtained.

[0149] After receiving the identification information of the first terminal device, other network elements may determine the subscription information related to the proximity service of the first terminal device (which may also be referred to as the subscription information of the proximity service) based on the identification information of the first terminal device. For example, when the other network element is a unified data management network element, the unified data management network element may determine the subscription information of the first terminal device based on the identity identification of the first terminal device, and then determine the subscription information related to the proximity service (which may also be referred to as the subscription information of the proximity service) from the subscription information of the first terminal device according to the user identification. When the other network element is a proximity service application server, after receiving the user identification of the first terminal device, the proximity service application server may also directly determine the subscription information of the proximity service from the subscription information of the first terminal device according to the user identification.

[0150] After determining the subscription information of the proximity service, the other network element will compare the subscription information of the proximity service with the proximity service information of the first terminal device. For example, it will check whether the discovery command and discovery type in the proximity service information of the first terminal device are the same as those in the subscription information of the proximity service.

[0151] After determining that the subscription information of the proximity service is consistent with the proximity service information of the first terminal device, the other network element determines that the authorization check for the first terminal device passes. If they are inconsistent, the authorization check for the first terminal device fails. The other network element may send the result of the authorization check (such as passing or failing the authorization check) to the first network element. For example, the other network element may feedback a check response to the first network element, and this check response indicates whether the authorization check for the first terminal device passes or fails.

[0152] If the authorization check passes, the first network element may allocate proximity service parameters for the first terminal device. If the authorization check fails, the first network element does not allocate proximity service parameters for the first terminal device and may reject the parameter acquisition request of the first terminal device.

[0153] Method 2: The first network element performs the authorization check by itself.

[0154] The first network element may send at least one of the identity identification and user identification of the first terminal device to other network elements, and request all subscription information related to the proximity service of the first terminal device (which may also be referred to as all subscription information of the proximity service) or the subscription information of the proximity service of the first terminal device.

[0155] After receiving at least one of the identity identifier and the user identifier of the first terminal device, other network elements may determine the subscription information of all neighboring services of the first terminal device or the subscription information of the neighboring services of the first terminal device according to the identity identifier of the first terminal device and / or, and the other network elements send the subscription information of all neighboring services of the first terminal device or the subscription information of the neighboring services of the first terminal device to the first network element. Exemplarily, the first network element sends at least one of the identity identifier and the user identifier of the first terminal device to other network elements, and the other network elements determine the subscription information of all neighboring services of the first terminal device or the subscription information of the neighboring services of the first terminal device according to at least one of the identity identifier and the user identifier of the first terminal device, and send the subscription information of all neighboring services of the first terminal device or the subscription information of the neighboring services of the first terminal device to the first network element. After obtaining the subscription information of all neighboring services of the first terminal device or the subscription information of the neighboring services of the first terminal device, the first network element may save the subscription information of all neighboring services of the first terminal device or the subscription information of the neighboring services of the first terminal device. To save the process of re-requesting and avoid causing additional signaling overhead.

[0156] The first network element compares the subscription information of all neighboring services of the first terminal device (or the subscription information of the neighboring services of the first terminal device) with the neighboring service information of the first terminal device. For example, it checks whether the discovery command and discovery type in the neighboring service information of the first terminal device are consistent with the discovery command and discovery type in the subscription information of all neighboring services (or the subscription information of the neighboring services of the first terminal device).

[0157] If they are consistent, the first network element determines that the authorization check for the first terminal device passes. If they are inconsistent, the authorization check for the first terminal device fails, and the first network element does not allocate neighboring service parameters to the first terminal device.

[0158] If the parameter acquisition request includes multiple user identifiers, for each user identifier, the first network element may perform the authorization check in Method 1 or Method 2.

[0159] After the authorization check for the first terminal device by the first network element passes, the first network element may allocate neighboring service parameters to the first terminal device. The neighboring service parameters include a neighboring service temporary identifier. The first network element may allocate a neighboring service temporary identifier to the first terminal device for each user identifier. That is to say, each user identifier corresponds to a neighboring service temporary identifier. The neighboring service temporary identifiers corresponding to different user identifiers may be the same or different.

[0160] In addition to the proximity service temporary identifier, the proximity service parameters may further include the validity period of the proximity service temporary identifier. There are many parameters characterizing the validity period of the proximity service temporary identifier, including but not limited to: current time, MAX offset, and validity timer.

[0161] The current time is time information representing the current time based on the coordinated universal time of the first network element. The MAX offset can indicate the time length of the validity period of the proximity service temporary identifier, that is, the difference between the expiration moment of the proximity service temporary identifier and the current time.

[0162] The validity timer is a timer for the validity period of the proximity service temporary identifier. Each proximity service temporary identifier corresponds to a validity timer, and the validity timers corresponding to different proximity service temporary identifiers may be the same or different.

[0163] Step 203: The first network element obtains the discovery key of the first terminal device.

[0164] In the embodiments of the present application, there are two different types of discovery keys for the first terminal device. One is the discovery key at the terminal device granularity, that is, one terminal device corresponds to one discovery key. The other is the discovery key at the proximity service granularity, and the discovery keys corresponding to different proximity services are different.

[0165] The first network element may obtain the discovery key at the proximity service granularity according to the proximity service temporary identifier, or obtain the discovery key at the terminal device granularity according to the identity identifier of the first terminal device.

[0166] Optionally, after obtaining the discovery key at the terminal device granularity, the first network element may further generate the discovery key at the proximity service granularity according to the discovery key at the terminal device granularity.

[0167] Step 204: The first network element sends a parameter acquisition response to the first terminal device, and the parameter acquisition response includes key generation parameters. The key generation parameters are the parameters that need to be sent to the first terminal device among the parameters required to generate the discovery key of the first terminal device. For different types of discovery keys, the key generation parameters may also be different.

[0168] The parameter acquisition response may also include some or all of the following: current time, MAX offset, validity timer. That is, the first terminal device can determine the validity period of the proximity service temporary identifier from the parameter acquisition response.

[0169] There are multiple ways for the first network element to obtain the discovery key of the first terminal device. The first network element can generate the discovery key of the first terminal device by itself, or request the discovery key from the key generation network element.

[0170] The following describes these two different methods separately:

[0171] 1. The first network element requests the discovery key from the key generation network element. The key generation network element can be an authentication service function network element (such as an AUSF network element), an access and mobility management function network element (such as an AMF network element), an authentication and key management anchor function network element for applications (such as an AAnF network element), a bootstrapping service function network element (such as a BSF network element), a 5G direct communication discovery name management function network element (such as a 5G DDNMF network element), or a key management network element. Among them, the key management network element is a network element that stores pre-configured keys for terminal devices (such as the first terminal device or the second terminal device), and the pre-configured keys can correspond to the user identifiers of the terminal devices.

[0172] The embodiments of the present application do not limit the specific type of the key generation network element. Any network element that can generate a discovery key is applicable to the embodiments of the present application.

[0173] Since the types of discovery keys are different, the generation methods of discovery keys are also different. The following describes them separately:

[0174] 1). Discovery key at the terminal device granularity.

[0175] The first network element sends a first key acquisition request to the key generation network element. The first key acquisition request may include the identity identifier of the first terminal device. Optionally, it may also include some or all of the proximity service information of the first terminal device.

[0176] After receiving the first key acquisition request, the key generation network element can determine the root key according to the identity identifier of the first terminal device.

[0177] The root key is a key allocated or pre-configured for the first terminal device. For example, when the first terminal device registers to the network, the network side (such as the unified data management network element, the key generation network element) allocates and stores the key for the first terminal device, and the first terminal device can generate the same key as the network side locally and store the key. Another example is that the root key can also be a key pre-configured on the network side, which corresponds to the first terminal device, and the same key is also pre-configured on the first terminal device side. The embodiments of this application do not limit the type of the pre-configured key, that is, the pre-configured key can be a symmetric key or an asymmetric key.

[0178] The types of key generation network elements are different, and the stored root keys are also different. For example, when the key generation network element is the authentication service function network element, the root key is Kausf, and Kausf is the Kausf in 2.1-1 of TS33.501 v16.3.0 standard. The generation and storage of Kausf can both refer to the generation and storage process of Kausf in 2.1-1 of the standard S33.501 v16.3.0 standard. When the key generation network element is the access and mobility management function network element, the root key is Kamf, and Kamf is the Kamf in 2.1-1 of TS33.501 v16.3.0 standard. The generation and storage of Kamf can both refer to the generation and storage process of Kamf in 2.1-1 of the standard S33.501 v16.3.0 standard. When the key generation network element is the AAnF network element, the root key is Kakma, and Kakma is the Kakma in 1-1 of TS33.535 v16.0.0 standard. The generation and storage of Kakma can both refer to the generation and storage process of Kakma in 1-1 of the standard S33.535 v16.1.0 standard. When the key generation network element is the BSF network element, the root key is Ks, and Ks is the Ks in 3 of TS33.220 v16.0.0 standard. The generation and storage of Ks can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 6 .2.1-1 of the Kausf, and its generation and storage can both refer to the generation and storage process of Kausf in 2.1-1 of the standard S33.501 v16.3.0 standard. When the key generation network element is the access and mobility management function network element, the root key is Kamf, and Kamf is the Kamf in 2.1-1 of TS33.501 v16.3.0 standard. The generation and storage of Kamf can both refer to the generation and storage process of Kamf in 2.1-1 of the standard S33.501 v16.3.0 standard. When the key generation network element is the AAnF network element, the root key is Kakma, and Kakma is the Kakma in 1-1 of TS33.535 v16.0.0 standard. The generation and storage of Kakma can both refer to the generation and storage process of Kakma in 1-1 of the standard S33.535 v16.1.0 standard. When the key generation network element is the BSF network element, the root key is Ks, and Ks is the Ks in 3 of TS33.220 v16.0.0 standard. The generation and storage of Ks can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 6 .2.1-1 of the Kamf, and its generation and storage can both refer to the generation and storage process of Kamf in 2.1-1 of the standard S33.501 v16.3.0 standard. When the key generation network element is the AAnF network element, the root key is Kakma, and Kakma is the Kakma in 1-1 of TS33.535 v16.0.0 standard. The generation and storage of Kakma can both refer to the generation and storage process of Kakma in 1-1 of the standard S33.535 v16.1.0 standard. When the key generation network element is the BSF network element, the root key is Ks, and Ks is the Ks in 3 of TS33.220 v16.0.0 standard. The generation and storage of Ks can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 6 .2.1-1 of the Kamf, and its generation and storage can both refer to the generation and storage process of Kamf in 2.1-1 of the standard S33.501 v16.3.0 standard. When the key generation network element is the AAnF network element, the root key is Kakma, and Kakma is the Kakma in 1-1 of TS33.535 v16.0.0 standard. The generation and storage of Kakma can both refer to the generation and storage process of Kakma in 1-1 of the standard S33.535 v16.1.0 standard. When the key generation network element is the BSF network element, the root key is Ks, and Ks is the Ks in 3 of TS33.220 v16.0.0 standard. The generation and storage of Ks can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 6 .2.1-1 of the Kakma, and its generation and storage can both refer to the generation and storage process of Kakma in 1-1 of the standard S33.535 v16.1.0 standard. When the key generation network element is the BSF network element, the root key is Ks, and Ks is the Ks in 3 of TS33.220 v16.0.0 standard. The generation and storage of Ks can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 5 .1-1 of the Kakma, and its generation and storage can both refer to the generation and storage process of Kakma in 1-1 of the standard S33.535 v16.1.0 standard. When the key generation network element is the BSF network element, the root key is Ks, and Ks is the Ks in 3 of TS33.220 v16.0.0 standard. The generation and storage of Ks can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 5 .1-1 of the Ks, and its generation and storage can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 4 .3 of the Ks, and its generation and storage can both refer to the generation and storage process of Ks in 3 of the standard S33.220 v16.0.0 standard. Figure 4. The generation and storage process of Ks in 0.3. When the key generation network element is the key management network element, the root key is the key stored in the key management network element and pre-configured for the first terminal device. Among them, "allocation" means that when there is a key derivation process, the key generation network element can allocate the root key to the first terminal device by itself or obtain the key from other network elements participating in key allocation. For Kausf, the AUSF network element can generate Kausf by itself, or the UDM network element generates Kausf and then sends Kausf to the AUSF network element. For Kakma, after the AUSF network element generates Kakma, it can pass Kakma to the AAnF network element. The keys allocated for the first terminal device (such as Kausf, Kamf, Kakma, Ks) can correspond to the identity identifier of the first terminal device. That is, the allocated key can be determined through the identity identifier of the first terminal device. The pre-configured key (such as the key stored in the key management network element) can correspond to the user identifier of the first terminal device, that is, the pre-configured key can be determined through the user identifier.

[0179] It should be noted that if the key generation network element is the key management network element, the first key acquisition request may not carry the identity identifier of the first terminal device, but carry the user identifier of the first terminal device. After receiving the first key acquisition request, the key management network element can determine the key pre-configured for the first terminal device according to the user identifier of the first terminal device, and this pre-configured key can be used as the root key to obtain the discovery key at the terminal device granularity.

[0180] After determining the root key, the key generation network element can generate the discovery key at the terminal device granularity based on the root key.

[0181] The discovery key at the terminal device granularity = KDF(root key, other input parameters), where KDF is the key derivation function, and the root key in the parameters used to generate the discovery key at the terminal device granularity is a mandatory parameter.

[0182] When generating the discovery key at the terminal device granularity, the key generation network element can also add other input parameters. The embodiments of the present application do not limit the type of other input parameters. The other input parameters can be a string, such as "5G ProSe", or a counter value. The present invention does not limit the number of other parameters, which can be 0, 1, or multiple. For example, the discovery key at the terminal device granularity = KDF(root key, SUPI, "5G Prose"). For another example, the discovery key at the terminal device granularity = KDF(root key, "5G Prose", counter value). For another example, the discovery key at the terminal device granularity = KDF(root key, counter value).

[0183] After generating the discovery key at the terminal device granularity, the key generation network element may carry the discovery key at the terminal device granularity in the first key acquisition response and send it to the first network element. After receiving the discovery key at the terminal device granularity, the first network element may save the discovery key at the terminal device granularity.

[0184] Optionally, the key generation network element may also send the first parameter required to generate the discovery key at the terminal granularity to the first network element. Here, the first parameter is part or all of the other input parameters except the root key when the key generation network element generates the discovery key at the terminal granularity. The first parameter may be a parameter that is not saved or cannot be known on the first network element side. For example, in the case of using a counter value to generate the discovery key at the terminal granularity, the counter value is a parameter that the first network element cannot know, and the key generation network element may send the counter value to the first network element.

[0185] It should be noted that if the input parameters when generating the discovery key at the terminal granularity include some or all of the following: the identity identifier of the first terminal device, the root key, and the string, which are parameters that the first network element can know or pre-save, the key generation network element may not need to send these input parameters to the first network element.

[0186] After obtaining the discovery key at the terminal device granularity, the first network element may directly execute step 204, that is, send the key generation parameters required to generate the discovery key at the terminal granularity to the first terminal device. The key generation parameters are part or all of the other input parameters except the root key when the key generation network element generates the discovery key at the terminal granularity. The key generation parameters may be parameters that the first terminal device does not save or cannot know. For example, in the case of using a counter value to generate the discovery key at the terminal granularity, the counter value is a parameter that the first terminal device cannot know, and the first network element may send the counter value as the key generation parameter to the first terminal device. Also, for example, if the input parameters when generating the discovery key at the terminal granularity include some or all of the following: the identity identifier of the first terminal device, the root key, and the string, which are parameters that the first terminal device can know or pre-save, the first network element may not need to send these input parameters to the first terminal device.

[0187] The first network element may also, after obtaining the discovery key at the terminal granularity, generate the discovery key at the adjacent service granularity based on the discovery key at the terminal granularity, and then execute step 204.

[0188] The first network element may generate the discovery key at the adjacent service granularity in the following manner:

[0189] The discovery key at the neighboring service granularity = KDF(discovery key at the terminal device granularity, other input parameters). When generating the discovery key at the neighboring service granularity, the first network element may also include other input parameters. The embodiments of the present application do not limit the type of other input parameters. The other input parameters may be a neighboring service temporary identifier. In addition to the neighboring service temporary identifier, part or all of the neighboring service information of the first terminal device may also be used as input parameters, or other parameters in the neighboring service parameters of the first terminal device, such as the current time, maximum offset, etc. The present application does not limit the number and type of other input parameters.

[0190] After the first network element generates the discovery key at the neighboring service granularity, it may perform step 204, where it feeds back to the first terminal device the key generation parameters required to generate the discovery key at the neighboring service granularity. The key generation parameters here include other input parameters (i.e., parameters that the first network element does not save or cannot know, such as the counter value) except the root key when the key generation network element generates the discovery key at the terminal granularity, and other input parameters except the neighboring service information of the first terminal device and the discovery key at the terminal granularity when the first network element generates the discovery key at the neighboring service granularity, such as the current time, maximum offset, etc.

[0191] The first network element may also save the discovery key at the neighboring service granularity. When saving the discovery key at the neighboring service granularity, the first network element may also save the correspondence between the validity period of the neighboring service temporary identifier and the discovery key at the neighboring service granularity, such as saving the validity period timer of the neighboring service temporary identifier. The validity period indicated by the validity period timer corresponding to the neighboring service temporary identifier may also be used as the validity period of the discovery key at the neighboring service granularity.

[0192] 2) The discovery key at the neighboring service granularity.

[0193] The first network element sends a second key acquisition request to the key generation network element. The second key acquisition request may include at least one of the identification information of the first terminal device (such as at least one of the identity identification and user identification of the first terminal device) and the neighboring service temporary identifier. Optionally, it may also include part or all of the neighboring service information of the first terminal device and other parameters of the neighboring service parameters of the first terminal device, such as part or all of the current time, maximum offset, and validity period timer.

[0194] After receiving the second key acquisition request, the key generation network element may determine the root key according to the identification information of the first terminal device. For the description of the root key, reference may be made to the foregoing description and will not be elaborated here.

[0195] After determining the root key, the key generation network element may generate the discovery key at the neighboring service granularity based on the root key.

[0196] Discovery key for adjacent service granularity = KDF(Root key, other input parameters).

[0197] When generating the discovery key for adjacent service granularity, the key generation network element may also add other input parameters. The embodiments of the present application do not limit the type of other input parameters. The other input parameters may be the adjacent service temporary identifier. In addition to the adjacent service temporary identifier, part or all of the adjacent service information of the first terminal device may also be used as other input parameters. Part or all of other parameters (such as the current time, maximum offset, and part or all of the validity period timer) in the adjacent service parameters of the first terminal device may also be used as other input parameters. The other input parameters may also be the input parameters introduced for generating the discovery key of the terminal device granularity. The embodiments of the present application do not limit the number and type of other input parameters.

[0198] The key generation network element may also save the discovery key for adjacent service granularity. When saving the discovery key for adjacent service granularity, the key generation network element may also save the correspondence between the validity period of the adjacent service temporary identifier and the discovery key for adjacent service granularity, such as saving the validity period timer of the adjacent service temporary identifier. The validity period indicated by the validity period timer corresponding to the adjacent service temporary identifier may also be used as the validity period of the discovery key for adjacent service granularity. The key generation network element may delete the discovery key for adjacent service granularity after the validity period expires.

[0199] After generating the discovery key for adjacent service granularity, the key generation network element may send a second key acquisition response to the first network element, and the second key acquisition response carries the discovery key for adjacent service granularity.

[0200] Optionally, the key generation network element may also send the second parameter required for generating the discovery key for adjacent service granularity to the first network element. The second parameter may be part or all of the other input parameters. The second parameter may be a parameter that the first network element has not saved or cannot obtain, such as an input parameter other than the adjacent service information of the first terminal device, the adjacent service parameters of the first terminal device, and the root key.

[0201] After obtaining the discovery key for adjacent service granularity from the second key acquisition response, the first network element may perform step 204, where the key generation parameters required for generating the discovery key for adjacent service granularity are fed back to the first terminal device.

[0202] The first network element may also save the discovery key for the neighboring service granularity. When the first network element saves the discovery key for the neighboring service granularity, it may also save the correspondence between the validity period of the neighboring service temporary identifier and the discovery key for the neighboring service granularity. For example, it saves a validity period timer for the neighboring service temporary identifier, and the validity period indicated by the validity period timer corresponding to the neighboring service temporary identifier may also be used as the validity period of the discovery key for the neighboring service granularity.

[0203] Second, the first network element generates the discovery key for the first terminal device by itself.

[0204] The method by which the first network element generates the discovery key for the terminal device granularity or the discovery key for the neighboring service granularity is the same as the method by which the key generation network element generates the discovery key for the terminal device granularity or the discovery key for the neighboring service granularity. The difference lies in the execution entity, and the specific details can be referred to the foregoing description.

[0205] It should be noted that before the first network element generates the discovery key for the first terminal device by itself, it may first determine a root key. The root key may be saved locally by the first network element, or may be obtained by the first network element from other network elements (such as the key generation network element in the foregoing description) according to the identity identifier and / or user identifier of the first terminal device.

[0206] It should be noted that after the first network element obtains the discovery key of the first terminal device (the discovery key can be a key at the neighboring service granularity or a key at the terminal device granularity), it can also generate a sub-key according to the discovery key of the first terminal device. The sub-key includes at least one of an integrity protection sub-key and a confidentiality protection sub-key. The first network element can also generate other sub-keys according to the discovery key of the first terminal device, such as a scramble sub-key. The integrity protection sub-key can be used to generate a message integrity code on the first terminal device side, and the integrity protection sub-key can also perform integrity protection on some parameters (such as some or all of the neighboring service parameters) on the first terminal device side. The confidentiality protection sub-key is used to provide confidentiality protection for all or part of the messages of the first terminal device (such as neighboring service request messages). Integrity protection means protecting the integrity of data during transmission. Integrity means being consistent with the original data and not being modified. Confidentiality protection is to make the attacker "unreadable". The scramble sub-key is used to disrupt the original order of the message to achieve an interference function, so that the bit order of the data transmitted over the air interface is disordered each time, which is different from the bit order of the original data, thus increasing the difficulty for the attacker to crack the data. The embodiments of the present application do not limit the manner of generating the sub-key by the first network element according to the discovery key of the first terminal device and the types of the generated sub-keys. For example, the sub-key can be generated by using a key generation function and the discovery key of the first terminal device. The input parameters used when generating the discovery key at the terminal granularity and the discovery key at the neighboring service granularity can both be used as parameters for generating the sub-key.

[0207] For example, sub-key = KDF(discovery key of the first terminal device, other input parameters). The types of the generated sub-keys are different, and the other input parameters can also be different. Taking the use of a string as an input parameter as an example, integrity protection sub-key = KDF(discovery key of the first terminal device, "IK"), confidentiality protection sub-key = KDF(discovery key of the first terminal device, "CK"), scramble sub-key = KDF(discovery key of the first terminal device, "SK"). Another example is represented by a sub-key type discriminator, that is, integrity protection sub-key = KDF(discovery key of the first terminal, 0x01), confidentiality protection sub-key = KDF(discovery key of the first terminal device, 0x02), scramble sub-key = KDF(discovery key of the first terminal device, 0x03).

[0208] For another example, the first network element may also intercept a portion of the discovery key of the first terminal device as the subkey. For example, after the length of the discovery key of the first terminal device is 256 bits (the discovery key can be a key at the neighboring service granularity or a key at the terminal device granularity), the upper 128 bits can be used as an integrity protection subkey, and the lower 128 bits can be used as a confidentiality protection subkey. For another example, after the length of the discovery key of the first terminal device is 512 bits (the discovery key can be a key at the neighboring service granularity or a key at the terminal device granularity), the highest 128 bits can be used as an integrity protection subkey, the next 128 bits can be used as a confidentiality protection subkey, and the next 128 bits can be used as a scrambling subkey. The roles of the integrity protection subkey, confidentiality protection subkey and scrambling subkey are reflected in the process of verification between the first terminal device and the second terminal device, and please refer to the subsequent content for details.

[0209] When the first network element executes step 204, the first network element can send key generation parameters required to generate a discovery key for the first terminal device to the first terminal device. The key generation parameters are parameters that are not saved or cannot be known by the first terminal device, such as proximity service parameters (such as proximity service temporary identifier) ​​and counter values ​​used to generate the discovery key for the first terminal device.

[0210] It should be noted that the parameter acquisition response includes the proximity service parameters, and the proximity service parameters used to generate the discovery key of the first terminal device, such as the proximity service temporary identifier, the current time, the maximum offset, etc., can be used as key generation parameters. Taking the proximity service temporary identifier used to generate the discovery key of the first terminal device as an example, the proximity service temporary identifier included in the parameter acquisition response has two identities, one is the parameter in the proximity service parameters, and the other is the parameter in the key generation parameters. In order to reduce signaling overhead, the proximity service temporary identifier only needs to be carried once in the parameter acquisition response to send the proximity service temporary identifier as the proximity service parameter and the key generation parameter to the first terminal device.

[0211] At this point, the first terminal device obtains the key generation parameters required to generate the discovery key from the first network element. In the case where the discovery key of the neighboring service granularity has a validity period, when the first network element determines that the discovery key of the neighboring service granularity stored locally has expired, the discovery key of the neighboring service granularity can be deleted, or the discovery key of the neighboring service granularity can be updated, and the first terminal device can be notified to update the discovery key of the neighboring service granularity, and the key generation parameters used to generate the updated discovery key of the neighboring service granularity can also be sent to the first terminal device.

[0212] Here, only the discovery key at the neighboring service granularity is taken as an example. For the discovery key at the terminal device granularity, the first network element can also use one or more validity timers corresponding to the neighboring service temporary identifiers as the validity timer of the discovery key at the terminal device granularity. After the discovery key at the terminal device granularity expires, the discovery key at the terminal device granularity can be deleted, or the discovery key at the terminal device granularity can be updated and the first terminal device can be notified to inform the first terminal device to update the discovery key at the terminal device granularity. The key generation parameters used to generate the updated discovery key at the terminal device granularity can also be sent to the first terminal device.

[0213] If the parameter acquisition response includes some or all of the following: current time, MAX offset, validity timer. That is, the parameter acquisition response can indicate the validity period of the neighboring service temporary identifier. The first terminal device can use the validity period of the neighboring service temporary identifier as the existence validity period of the discovery key at the neighboring service granularity. When the first terminal device determines that the discovery key at the neighboring service granularity locally saved has expired, the discovery key at the neighboring service granularity can be deleted.

[0214] In the first part of the description, the method for the first terminal device to obtain the key generation parameters is described by taking the first terminal device as an example. The method for the second terminal device to obtain the key generation parameters is similar to that of the first terminal device to obtain the key generation parameters, and will not be elaborated here.

[0215] In one embodiment, after the first network element obtains the discovery key at the terminal device granularity or the discovery key at the proximity service granularity or the sub - key of the first terminal device, it can directly send the discovery key at the terminal device granularity or the discovery key at the proximity service granularity or the sub - key to the first terminal device. The first network element can also save the discovery key at the terminal device granularity or the discovery key at the proximity service granularity or the sub - key. Further, the embodiments of the present application do not limit whether the first terminal device directly uses the discovery key received from the first network element or further generates other keys after receiving the discovery key at the terminal device granularity or the discovery key at the proximity service granularity from the first network element. For example, after the first terminal device receives the discovery key at the terminal device granularity sent by the first network element, the first terminal device can further generate the discovery key at the proximity service granularity. For another example, after the first terminal device receives the discovery key at the terminal device granularity sent by the first network element, the first terminal device can further generate the sub - key. For example, the first terminal device can first generate the discovery key at the proximity service granularity, then use the discovery key at the proximity granularity to generate the sub - key, or directly use the discovery key at the terminal device granularity to generate the sub - key. Correspondingly, the first network element device will also obtain the sub - key in a manner similar to that of the first terminal device. It should be noted that the first network element also needs to send the parameters required to generate the sub - key to the first terminal device.

[0216] (2) Verification is performed between the first terminal device and the second terminal device. Here, the verification method of the first terminal device by the second terminal device as the provider of the proximity service is described. In practical applications, the first terminal device can also verify the second terminal device in a similar manner.

[0217] See Figure 3 , for the verification method between terminal devices provided by the embodiments of the present application. The method includes:

[0218] Step 301: The first terminal device sends a proximity service request message, which includes the proximity service temporary identifier and the message integrity code of the first terminal device.

[0219] After the first terminal device obtains the key generation parameters from the first network element, it can generate the discovery key of the first terminal device according to the key generation parameters.

[0220] The embodiments of the present application do not limit the manner in which the first terminal device generates the message integrity code based on the discovery key of the first terminal device. For example, the first terminal device may directly generate the message integrity code based on the discovery key of the first terminal device, such as message integrity code = KDF(discovery key of the first terminal device, other parameters). The other parameters here may be part or all of the proximity service temporary identifier, current time, MAX_offset, or other types of parameters. The present application does not limit the number and type of the other parameters. Again, for example, the first terminal device may generate a sub-key based on the discovery key of the first terminal device, and then generate the message integrity code based on the sub-key, such as message integrity code = KDF(sub-key, other parameters). The other parameters here may be part or all of the proximity service temporary identifier, current time, MAX_offset, or other types of parameters. The present application does not limit the number and type of the other parameters.

[0221] Optionally, after generating the discovery key of the first terminal device, the first terminal device may also generate a sub-key based on the discovery key of the first terminal device. The manner in which the first terminal device generates the sub-key based on the discovery key of the first terminal device is similar to the manner in which the first network element generates the sub-key based on the discovery key of the first terminal device. For specific details, please refer to the foregoing content. After generating the sub-key, the first terminal device may use the sub-key to perform integrity protection on the message integrity code. For example, message integrity code = KDF(integrity protection sub-key, other parameters), and integrity protection is performed on the message integrity code. Optionally, the first terminal device may also use the confidentiality protection sub-key to encrypt all or part of the information carried in the proximity service request message to achieve confidentiality protection of the message integrity code.

[0222] Optionally, the first terminal device may also use the interference sub-key to interfere with all or part of the information carried in the proximity service request message to achieve interference protection.

[0223] The embodiments of the present application do not limit the use and the number of uses of integrity protection, confidentiality protection, and interference protection. That is to say, only one of the protections may be used. For example, only integrity protection may be performed, or only confidentiality protection may be performed, or only interference protection may be performed. Or at least two of them may be used, or all of them may be used. At the same time, the embodiments of the present application do not limit their order of use. That is, integrity protection may be performed first, and then confidentiality protection may be performed on part or all of the information with integrity protection, and then interference protection may be performed on the information with confidentiality protection. Or confidentiality protection may be performed first on all or part of the information carried in the proximity service request message, then integrity protection may be performed on the information with confidentiality protection, and then interference protection may be performed on the information with integrity protection.

[0224] Step 302: The second terminal device receives the proximity service request message, and determines that it can provide proximity services for the first terminal device according to the proximity service temporary identifier included in the proximity service request message. The second terminal device can determine that it can communicate with the first terminal for proximity services based on the proximity service temporary identifier, that is, it can support proximity services.

[0225] Step 303: After determining that it can provide proximity services for the first terminal device, the second terminal device can verify the first terminal device based on the message integrity code.

[0226] The second terminal device can request the first network element to verify the first terminal device, or it can verify the first terminal device by itself. The following will explain these two methods separately:

[0227] First, the second terminal device requests the first network element to verify the first terminal device.

[0228] The second terminal device can send a verification request to the first network element, and the verification request includes the temporary service temporary identifier of the first terminal device and the message integrity code.

[0229] After receiving the verification request, the first network element can determine the discovery key of the first terminal device saved according to the temporary service temporary identifier of the first terminal device.

[0230] The first network element generates an expected message integrity code based on the discovery key of the first terminal device saved locally in the same way as the first terminal device generates the message integrity code.

[0231] The first network element can compare the message integrity code with the expected message integrity code. If the message integrity code is consistent with the expected message integrity code, the verification of the first terminal device is successful; otherwise, the verification of the first terminal device fails.

[0232] Optionally, if the first terminal device performs integrity protection on the message integrity code, after receiving the integrity-protected message integrity code, the first network element first performs integrity verification on the integrity-protected message integrity code by using the integrity protection sub-key generated according to the discovery key of the first terminal device. After the verification passes, it then compares the message integrity code with the expected message integrity code.

[0233] In a possible implementation, if the first terminal device performs confidentiality protection on all or part of the information carried in the proximity service request message, that is, encrypts all or part of the information, after receiving the encrypted all or part of the information, the first network element first decrypts the encrypted all or part of the information by using the confidentiality protection sub-key generated according to the discovery key of the first terminal device. After decryption, it then compares the message integrity code with the expected message integrity code.

[0234] In another possible implementation, if the first terminal device performs confidentiality protection on all or part of the information, after receiving the encrypted all or part of the information, the first network element first performs integrity protection verification on the message integrity code using integrity protection. After successfully comparing the message integrity code with the expected message integrity code, it then decrypts all or part of the encrypted information.

[0235] The first network element sends a verification response to the second terminal device, and the verification response carries the verification result of the first network element on the first terminal device. The verification result indicates that the verification of the first terminal device is successful or failed.

[0236] Second, the second terminal device independently verifies the first terminal device.

[0237] The second terminal device can obtain the discovery key of the first terminal device from the first network element. The second terminal device can, after or before receiving the neighboring service request message of the first terminal device, request the neighboring service parameters of the second terminal device from the second network element in a manner similar to the embodiment shown in Figure 2 as follows.

[0238] The difference is that after receiving a request message from the second terminal device for requesting adjacent service parameters, the second network element can first determine whether it needs to interact with the first network element. For example, the request message may carry relevant information of the first terminal device, such as the application identifier or identity identifier of the first terminal device, etc. Among them, the relevant information of the first terminal device can be pre-obtained by the second terminal device or obtained from the adjacent service request message sent by the first terminal device. The second network element can determine that it needs to interact with the first network element based on the relevant information of the first terminal device carried in the request message. After determining that it needs to interact with the first network element, the second network element can send a parameter request carrying the relevant information of the first terminal device to the first network element, for requesting the discovery key or sub-key of the first terminal device. The first network element associates with the first terminal device based on the information carried in the request message, and determines the discovery key or sub-key of the first terminal device, and sends the discovery key of the first terminal device to the second network element. In addition to allocating adjacent service parameters for the second terminal device and sending the allocated adjacent service parameters to the second terminal device, the second network element can also send the discovery key or sub-key of the first terminal device to the second terminal device. After the second terminal receives the adjacent service request message sent by the first terminal device, the second terminal device generates an expected message integrity code based on the discovery key or sub-key of the first terminal device obtained from the second network element in the same way as the first terminal device generates the message integrity code. The second terminal device can compare the message integrity code with the expected message integrity code. If the message integrity code is consistent with the expected message integrity code, the verification of the first terminal device is successful; otherwise, the verification of the first terminal device fails. Among them, the first network element and the second network element can be the same or different.

[0239] It should be noted that the discovery key or sub-key of the first terminal device can be generated by other network elements (such as a key generation network element), and the second network element obtains the discovery key of the first terminal device from other network elements.

[0240] Step 304: The second terminal device determines whether to provide adjacent services for the first terminal device according to the verification result, that is, determines whether to establish direct communication with the first terminal device. The verification result indicates that the verification of the first terminal device by the second terminal device is successful or failed.

[0241] If the verification of the first terminal device by the second terminal device is successful, the second terminal device can provide adjacent services for the first terminal device and establish direct communication with the first terminal device; if the verification of the first terminal device by the second terminal device fails, the second terminal device can refuse to provide adjacent services for the first terminal device.

[0242] When the first terminal device verifies the second terminal device, the second terminal device generates a message integrity code 1 in a similar manner to the first terminal device according to the discovery key of the second terminal device, and carries the message integrity code 1 in the message replied to the first terminal device.

[0243] The first terminal device can verify the second terminal device in a similar manner to step 303. If the verification is successful, it receives the proximity service provided by the second terminal device and establishes direct communication; otherwise, it rejects the proximity service provided by the second terminal device and rejects establishing direct communication. Among them, the generation method of the expected integrity code 1 by the first terminal device is the same as the method of generating the message integrity code 1 by the second terminal device. For specific details, refer to the foregoing content and will not be elaborated here.

[0244] The following is based on the Figure 1A shown system architecture, combined with the attached Figure 4 , to further illustrate a secure communication method provided by an embodiment of the present application. Refer to Figure 2 , Figure 2 In the open ProSe discovery scenario, the first network element is a 5G DDNMF network element, the first terminal device is an A-UE, the second terminal device is an M-UE, the A-UE interacts with the A-5G DDNMF network element through the A-AMF network element, and the M-UE interacts with the A-5G DDNMF network element through the M-AMF network element. The A-UE and the M-UE can interact with the A-5G DDNMF network element through different AMF network elements, which are distinguished by the A-AMF network element and the M-AMF network element here. The method for the A-UE to obtain key generation parameters from the A-5G DDNMF network element is shown in steps 401 to 409, and the method for the M-UE to verify the A-UE is shown in steps 410 to 414. The method includes:

[0245] Step 400: The A-UE registers to the network and performs authentication with the network side. The main authentication process can refer to section 6.1 in the standard TS33.501.

[0246] During the main authentication process, the AUSF network element obtains the Kausf corresponding to the A-UE from the UDM network element or generates the Kausf corresponding to the A-UE by itself. The AUSF network element obtains the Kausf during the main authentication process and stores the Kausf. The UE generates the Kausf during the main authentication process and stores the Kausf.

[0247] Step 401: The A-UE sends a parameter acquisition request to the A-AMF network element. This parameter acquisition request is used to request the neighboring service parameters of the A-UE. The identity identifier of the A-UE and the neighboring service information of the A-UE are carried in the parameter acquisition request. The identity identifier of the A-UE is used to indicate the A-UE. The neighboring service information of the A-UE is used to indicate the neighboring services required by the A-UE. The A-UE is the announcing UE in the openProSe discovery scenario.

[0248] The embodiments of the present application do not limit the specific type of the identity identifier of the A-UE. The identity identifier of the A-UE can be the anonymized identifier of the A-UE, such as SUCI, or the temporary identifier of the A-UE, such as 5G-GUTI, or the user permanent identifier of the A-UE, such as SUPI or GPSI or PEI.

[0249] The neighboring service information of the A-UE may include user identity, discovery command, discovery model, and discovery type. The descriptions of User Identity, discovery command, discovery model, and discovery type can be referred to the foregoing content and will not be elaborated here.

[0250] The number of user identities is not limited here. It can be one or multiple. When there are multiple user identities, each user identity is the identity information of the A-UE in a neighboring service scenario, and different user identities correspond to different neighboring services.

[0251] Step 402: After receiving the parameter acquisition request, the A-AMF network element may send the parameter acquisition request to the A-5GDDNMF network element.

[0252] Optionally, the A-AMF network element may also parse the parameter acquisition request to obtain the information carried in the parameter acquisition request. For example, if it is determined that the temporary identifier or anonymized identifier of the A-UE is carried in the parameter acquisition request, the A-AMF network element may determine the user permanent identifier of the A-UE according to the temporary identifier or anonymized identifier of the A-UE, update the temporary identifier or anonymized identifier of the A-UE in the parameter acquisition request to the user permanent identifier of the A-UE, and then send the parameter acquisition request to the A-5GDDNMF network element.

[0253] The embodiments of the present application do not limit the manner in which the A-AMF network element determines the user permanent identifier of the A-UE based on the temporary identifier or anonymized identifier of the A-UE. For example, the A-AMF network element may store the correspondence between the temporary identifier or anonymized identifier of the A-UE and the user permanent identifier of the A-UE, and the A-AMF network element may determine the user permanent identifier of the A-UE according to this correspondence; for another example, the A-AMF network element may request the network element (such as the UDM network element) that stores the correspondence between the temporary identifier or anonymized identifier of the A-UE and the user permanent identifier of the A-UE to obtain the user permanent identifier of the A-UE.

[0254] If the A-AMF network element stores the information of the AUSF network element that stores the Kausf of the A-UE, such as the identifier or address of the AUSF network element. The A-AMF network element may also carry the information of the AUSF network element in the parameter acquisition request and send it to the A-5G DDNMF network element.

[0255] Step 403: After receiving the parameter acquisition request, the A-5G DDNMF network element may perform an authorization check on the A-UE according to the parameter acquisition request.

[0256] The embodiments of the present application do not limit the manner in which the A-5G DDNMF network element performs an authorization check on the A-UE according to the parameter acquisition request. Two methods are introduced below:

[0257] Method 1: The A-5G DDNMF network element requests the UDM network element or the adjacent service application server to perform an authorization check.

[0258] The manner in which the A-5G DDNMF network element requests the UDM network element or the adjacent service application server to perform an authorization check may refer to the manner in which the first network element requests other network elements to perform an authorization check in the foregoing content, and will not be elaborated here.

[0259] Method 2: The A-5G DDNMF network element performs an authorization check by itself.

[0260] The manner in which the A-5G DDNMF network element performs an authorization check by itself may refer to the manner in which the first network element performs an authorization check by itself in the foregoing content, and will not be elaborated here.

[0261] The A-5G DDNMF network element may send the identity identifier of the A-UE to the UDM network element and request the subscription information of all adjacent services of the A-UE.

[0262] After receiving the identity identifier and user identifier of A-UE, the UDM network element can determine all the subscription information related to proximity services in the subscription information of A-UE according to the A-UE identity identifier (which can also be called all the subscription information of proximity services), and the UDM network element sends all the subscription information of proximity services to the A-5G DDNMF network element.

[0263] The A-5G DDNMF network element compares all the subscription information of proximity services with the proximity service information of A-UE. For example, it checks whether there are discovery commands and discovery types in all the subscription information of proximity services of A-UE that are consistent with the discovery command and discovery type in the proximity service information.

[0264] If there are, the A-5G DDNMF network element determines that the authorization check for A-UE passes. If not, the A-5G DDNMF network element fails the authorization check for A-UE, and the A-5G DDNMF network element does not allocate proximity service parameters for A-UE.

[0265] If the parameter acquisition request includes multiple user identifiers, for each user identifier, the A-5G DDNMF network element can perform the authorization check in Method 1 or Method 2.

[0266] Step 404: After the 5G DDNMF passes the authorization check for A-UE, the 5G DDNMF allocates proximity service parameters for A-UE. The proximity service parameters include ProSe application code, and also include some or all of the following: current time, MAX offset, validity timer.

[0267] Step 405: The A-5G DDNMF network element can send a key acquisition request to the AUSF network element. The key acquisition request includes the identity identifier of A-UE. Optionally, it can also include some or all of the information of the proximity service parameters, or some or all of the information of the proximity service information of A-UE.

[0268] Before the A-5G DDNMF network element executes Step 405, the A-5G DDNMF network element can first determine whether it needs to request a key from the AUSF network element. If it is determined that it is needed, then execute Step 405. The A-5G DDNMF network element can determine whether it needs to request a key from the AUSF network element by determining the proximity service information.

[0269] For example, the A-5G DDNMF network element determines the type of the UE through the discovery command in the proximity service information. If it is determined that the A-UE is an Announce UE, a Response UE, or a Query UE, then step 405 needs to be executed.

[0270] For another example, it is determined to be a monitor UE through the discovery command of the proximity service information, and then it is determined to be model B according to the discovery mode, and then it is determined to execute step 405.

[0271] Before the A-5G DDNMF network element executes step 405, it can also first determine whether the discovery key of the A-UE is stored locally. If it is determined that the discovery key of the A-UE is not stored, the A-5G DDNMF network element then executes step 405. If the discovery key of the A-UE is stored, the A-5G DDNMF network element can obtain the discovery key of the A-UE stored locally.

[0272] It should be noted that the embodiments of the present application do not limit the order of the two operations of the A-5G DDNMF network element allocating proximity service parameters to the A-UE and the A-5G DDNMF network element sending a key acquisition request to the AUSF network element. For example, the A-5G DDNMF network element can first allocate proximity service parameters to the A-UE, and then send a key acquisition request to the AUSF network element. In this case, the key acquisition request can include some or all of the information of the proximity service parameters. For another example, the A-5G DDNMF network element can first send a key acquisition request to the AUSF network element, and then allocate proximity service parameters to the A-UE. In this case, the key acquisition request does not include some or all of the information of the proximity service parameters.

[0273] Step 406: After receiving the key acquisition request, the AUSF network element determines the Kausf of the A-UE according to the identity identifier of the A-UE, and calculates the discovery key of the A-UE according to the Kausf.

[0274] The following separately describes the method for the AUSF network element to calculate the UE granularity discovery key or the proximity service granularity discovery key of the A-UE according to the Kausf:

[0275] (1). The AUSF network element calculates the discovery key of the A-UE at the proximity service granularity according to the Kausf.

[0276] The AUSF network element can generate the discovery key of the A-UE at the proximity service granularity in the following two ways:

[0277] 1). The AUSF network element directly generates the discovery key of the A-UE at the proximity service granularity based on the Kausf.

[0278] The method by which the AUSF network element directly generates the discovery key for the A-UE proximity service granularity based on Kausf can refer to the method by which the key generation network element generates the discovery key for the first terminal device proximity service granularity based on the root key in the foregoing description, which will not be elaborated here.

[0279] 2), The AUSF network element first generates the discovery key for the UE granularity based on Kausf, and then generates the discovery key for the A-UE proximity service granularity based on the key for the UE granularity.

[0280] The method by which the AUSF network element directly generates the discovery key for the A-UE UE granularity based on Kausf can refer to the method by which the key generation network element generates the discovery key for the terminal device granularity based on the root key in the foregoing description, which will not be elaborated here.

[0281] The method by which the AUSF network element generates the discovery key for the A-UE proximity service granularity based on the key for the UE granularity can refer to the method by which the first network element generates the discovery key for the first terminal device proximity service granularity based on the discovery key for the terminal device granularity in the foregoing description, which will not be elaborated here.

[0282] Optionally, the AUSF network element can set a lifecycle for the discovery key of the A-UE. For example, save the Validitytimer, and use the Validity timer as the generation period of the discovery key of the UE. After the Validity timer expires, the AUSF network element can delete the discovery key generated for the A-UE.

[0283] (2), The AUSF network element calculates the discovery key for the UE granularity of the A-UE according to Kausf.

[0284] The method by which the AUSF network element calculates the discovery key for the A-UE UE granularity according to Kausf can refer to the foregoing description, which will not be elaborated here.

[0285] Step 407: The AUSF network element sends a key acquisition response to the A-5G DDNMF network element, and the key acquisition response includes the discovery key of the A-UE. The discovery key of the A-UE is the discovery key for the UE granularity of the A-UE or the discovery key for the A-UE proximity service granularity.

[0286] The AUSF network element can also send the first parameter required to generate the discovery key of the A-UE to the A-5G DDNMF network element, and the first parameter is a parameter that the A-5G DDNMF network element has not saved or cannot obtain.

[0287] If the discovery key of the A-UE is the discovery key for the UE granularity of the A-UE, the A-5G DDNMF network element can further generate the discovery key for the A-UE proximity service granularity according to the discovery key for the UE granularity of the A-UE.

[0288] The method by which the A-5G DDNMF network element generates the discovery key for the proximity service granularity of the A-UE based on the discovery key of the UE granularity of the A-UE is similar to the method by which the AUSF network element generates the discovery key for the proximity service granularity of the A-UE based on the discovery key of the UE granularity of the A-UE. For specific details, please refer to the foregoing content and will not be elaborated here.

[0289] Optionally, the A-5G DDNMF network element saves the discovery key of the UE granularity of the A-UE or the discovery key of the proximity service granularity of the A-UE together with the validity timer and the Prose application code as the 5G Prose security context of the A-UE. After the validity timer expires, the A-5G DDNMF network element deletes the discovery key of the UE granularity of the A-UE or the discovery key of the proximity service granularity of the A-UE; if the A-5G DDNMF network element saves both the discovery key of the UE granularity of the A-UE and the discovery key of the proximity service granularity of the A-UE, after the validity timer expires, the A-5G DDNMF network element deletes the discovery key of the proximity service granularity of the A-UE and continues to save the discovery key of the UE granularity of the A-UE.

[0290] Optionally, the A-5G DDNMF network element can also determine one or more sub-keys based on the discovery key of the A-UE. For example, the 5G DDNMF network element can also generate a key CK for confidentiality protection and a key IK for integrity protection based on the discovery key of the A-UE. The embodiments of the present application do not limit whether to generate sub-keys through the discovery key of the UE granularity or through the discovery key of the proximity service granularity.

[0291] The embodiments of the present application do not limit the method by which the A-5G DDNMF network element determines one or more sub-keys based on the discovery key. For example, the A-5G DDNMF network element can generate them using KDF, or split the discovery key into one or more sub-keys. The A-5G DDNMF network element uses a part of the discovery key as CK and a part for IK. For example, if the length of the discovery key of the A-UE is 512 bits (bit), the A-5G DDNMF network element can use the first 128-bit field as CK and the middle 128-bit field as IK. In the case of generating sub-keys, the A-UE can use the sub-keys to generate a message integrity code.

[0292] As shown in Table 1, it is the storage method of the discovery key of the proximity service granularity of the A-UE after the A-5G DDNMF network element receives the discovery key of the proximity service granularity of the A-UE.

[0293] Table 1

[0294]

[0295] In Table 1, SUPI represents a terminal device (i.e., A-UE). ProSe application code-1 and ProSe application code-2 represent proximity service temporary identifiers corresponding to two different applications. These two different applications have different user identities and different discovery keys. Therefore, discovery key-1 and discovery key-2 are discovery keys at the proximity service granularity for different proximity services. In the manner of Table 1, when A-UE uses ProSe application code-1, A-UE generates a message integrity code based on discovery key-1. In Table 1, the A-5G DDNMF network element can further generate sub-keys based on discovery key-1 and discovery key-2. This embodiment does not make any limitations.

[0296] As shown in Chart 2, it is the storage method of the discovery key at the UE granularity of A-UE and the discovery key at the proximity service granularity of A-UE after the A-5G DDNMF network element receives the discovery key at the UE granularity of A-UE.

[0297] Table 2

[0298]

[0299] In Table 2, SUPI represents a terminal device (i.e., A-UE), and the discovery key is the discovery key shared by all applications of A-UE. The discovery key is the discovery key at the UE granularity of A-UE, and user identity-1 discovery key and user identity-2 discovery key are discovery keys at the proximity service granularity for different proximity services. In the manner of Table 2, when A-UE uses ProSe application code-1, A-UE generates a message integrity code based on discovery key-1. The discovery key-1 and discovery key-2 in Table 2 can further generate sub-keys. This embodiment does not make any limitations.

[0300] In another implementation, if Table 2 has only one discovery key and no user identity-1 discovery key and user identity-2 discovery key, it means that the discovery key is shared by all applications.

[0301] Step 408: The A-5G DDNMF network element sends a parameter acquisition response through the A-AMF network element. The reference acquisition response includes key generation parameters required for the A-UE to generate the discovery key of the A-UE. These key generation parameters are parameters that the A-UE does not maintain or cannot obtain. For example, the key generation parameters can be proximity service parameters used to generate the discovery key, such as ProSe application code.

[0302] Step 409. After receiving the parameter acquisition response, the A-UE generates the discovery key of the A-UE using the same method as the AUSF network element or the A-5G DDNMF network element.

[0303] So far, the A-UE has obtained the key generation parameters for generating the discovery key of the A-UE from the A-5G DDNMF network element.

[0304] Step 410: When the A-UE determines that it needs to use proximity services, that is, when it needs to establish direct communication with other UEs, it can send a proximity service request message, which includes ProSe application code and a message integrity code (MIC).

[0305] The A-UE can generate the MIC based on the discovery key of the A-UE. The embodiments of the present application do not limit the manner in which the A-UE generates the MIC based on the discovery key of the A-UE. The discovery key of the A-UE can be the UE granularity discovery key of the A-UE or the proximity service granularity discovery key.

[0306] For example, MIC = KDF(discovery key of the A-UE, other parameters). The other parameters can be at least one of ProSe application code, Current time, and MAX_OFFset, and can also be the proximity service request message.

[0307] Optionally, the A-UE may determine a sub-key based on the discovery key of the A-UE and generate a MIC using the sub-key. For example, the A-UE generates a MIC based on the integrity protection sub-key IK, and uses the confidentiality protection sub-key CK to perform confidentiality protection on some or all of the information in the proximity service request message. The A-UE may also use the confidentiality protection sub-key CK to perform confidentiality protection on all or some bits of the MIC.

[0308] It should be noted here that in the case of having CK and IK, there is no need to generate a MIC separately. Because in the case of integrity protection, a parameter with the same function as the MIC will be generated. For example, this parameter can be a message authentication code (MAC). The MAC can replace the position of the MIC and has the same function as the MIC.

[0309] Before sending the proximity service request message, if the A-UE generates CK (that is), it can encrypt all or some of the information in the proximity service request message, that is, perform confidentiality protection.

[0310] Exemplarily, the A-UE may perform confidentiality protection only on the sensitive data in the proximity service request message in a pre-determined manner. Which sensitive data to perform confidentiality protection on can be specified in the standard.

[0311] For example, the standard stipulates that confidentiality protection is only performed on data such as current time. The A-UE may perform confidentiality protection only on current time.

[0312] Another example is that the standard indicates to perform confidentiality protection on some information in the proximity service request message in the manner sent by the network side. In this case, the network side (A-5G DDNMF network element) may generate a template and send it to the A-UE together with the proximity service parameters. The confidentiality protection template is used to indicate the bit information that needs to be protected confidentially. The content of the confidentiality protection template can be random or fixed. Random means that the bit information that needs to be protected confidentially indicated by each template is not necessarily the same. Fixed means that the bit information that needs to be protected confidentially indicated by each template is the same. Of course, the fixed confidentiality protection template is not immutable, and the operator can change the corresponding content at any time. Different fixed templates can also be used for different terminals. At this time, it can be understood that there is a corresponding relationship between the confidentiality protection template and the identity identifier or service identifier of the A-UE. The content of the confidentiality protection template is, for example: perform confidentiality protection on some random bits in the message, and other bits do not need to be protected. The A-UE encrypts the proximity service request message according to the template.

[0313] For another example, the A-UE can generate a confidentiality protection template by itself and perform confidentiality protection on some content of the message according to the content of the confidentiality protection template. When the A-UE can generate a confidentiality protection template by itself, the proximity service request message in step 410 may carry the confidentiality template.

[0314] IK is used to perform integrity protection on all or some of the information in the proximity service request message. The present invention does not limit the usage order of IK and CK. That is, CK can be used first to encrypt all or some of the information in the proximity service request message to achieve confidentiality protection, and then integrity protection is performed on all or some of the encrypted information; or IK can be used first to perform integrity protection on all or some of the information in the proximity service request message. The IK can be used to encrypt some or all of the information after integrity protection to achieve confidentiality protection, or the IK can be used to encrypt some or all of the information that is not completely included to achieve confidentiality protection.

[0315] Step 411: The M-UE receives the proximity service request message. After determining that it can provide proximity services for the A-UE according to the ProSe application code included in the proximity service request message, the M-UE sends a verification request to the A-5G DDNMF network element. The verification request includes the ProSe application code and MIC of the A-UE.

[0316] In an actual application scenario, different UEs can interact with different 5G DDNMF network elements. Here, the 5G DDNMF network element that interacts with the A-UE in steps 401 to 109 is the A-5G DDNMF network element, and the 5G DDNMF network element that interacts with the M-UE is the M-5G DDNMF network element. The M-UE sends the verification request to the M-5G DDNMF network element through the M-AMF network element, and the M-5G DDNMF network element then sends the verification request to the A-5G DDNMF network element.

[0317] Step 412: After receiving the verification request, the A-5G DDNMF verifies the A-UE according to the verification request. The A-5G DDNMF can determine the discovery key of the A-UE according to the ProSe application code, generate an expected message integrity code (expected MIC, XMIC) according to the discovery key of the A-UE. The way the A-5G DDNMF generates the XMIC according to the discovery key of the A-UE is the same as the way the A-UE generates the MIC according to the discovery key of the A-UE. After generating the XMIC, the A-5G DDNMF determines whether the XMIC and the MIC are consistent.

[0318] If the XMIC is the same as the MIC, it indicates that the identity of the A-UE is legal and the verification of the A-UE is successful. Otherwise, the identity of the A-UE is illegal and the verification of the A-UE fails.

[0319] If integrity protection and confidentiality protection are performed on the A-UE side, correspondingly, the A-5G DDNMF network element needs to perform integrity protection verification and decryption operations. The operation sequence of the A-5G DDNMF network element is opposite to that of the A-UE. For example, if the A-UE first performs confidentiality protection and then integrity protection, then the A-5G DDNMF network element needs to first verify the integrity protection and, after successful verification, decrypt the message to obtain the original information. When the A-5G DDNMF network element performs the decryption operation, correspondingly, it can perform the decryption operation in a pre-agreed manner, or in the manner of the confidentiality template generated by the A-5G DDNMF network element, or in the manner of the confidentiality template received from the A-UE.

[0320] Step 413: After successfully verifying the A-UE, the A-5G DDNMF sends a verification success response to the M-UE through the M-AMF network element.

[0321] Step 414: After receiving the verification success response, the M-UE can provide proximity services to the A-UE, that is, establish direct communication with the A-UE.

[0322] In Steps 410 to 414, the verification of the A-UE's identity by the M-UE is taken as an example for illustration. In actual applications, the A-UE can also verify the identity of the M-UE. For example, the M-UE can obtain the key generation parameters and the ProSe application code of the M-UE from the 5G DDNMF in a manner similar to Steps 401 to 409. Then, the M-UE generates the discovery key of the M-UE based on the key generation parameters, and then generates the corresponding MIC, and sends the MIC to the A-UE. The A-UE can obtain the MIC from the M-UE in a manner similar to Steps 411 to 414 and send a verification request carrying the MIC to the 5G DDNMF.

[0323] In the above description, the key generation network element is taken as the AUSF network element as an example for illustration. As a possible implementation manner, the key generation network element can also be the AMF network element, and the corresponding root key is Kamf. The situation where the key generation network element is the AMF network element is similar to the situation where the key generation network element is the AUSF network element, except that the execution entity is different and the root key is different. For details, please refer to Figure 4The related descriptions of the embodiments shown are not elaborated here. The key generation network element can also be other network elements, and the corresponding root key is the key related to the A-UE stored in other network elements. The situation where the key generation network element is other network elements is similar to the situation where the key generation network element is the AUSF network element, except that the execution entity is different and the root key is different. For details, please refer to Figure 4 The related descriptions of the embodiments shown are not elaborated here.

[0324] In the embodiment as Figure 4 shown, the A-5GDDNMF can send key generation parameters to the A-UE so that the A-UE can generate the discovery key of the A-UE according to the key generation parameters. After that, when the M-UE verifies the A-UE, it can be verified through the A-5GDDNMF. As a possible implementation, the A-5GDDNMF can send the UE granular discovery key of the A-UE to the A-UE so that the A-UE can generate the discovery key of the adjacent service granularity of the A-UE according to the discovery key of the A-UE, and then generate the MIC. After that, when the M-UE verifies the A-UE, it can be verified through the A-5GDDNMF. The following describes this method. Please refer to Figure 5 , to further illustrate a secure communication method provided by an embodiment of the present application. Please refer to Figure 5 , Figure 5 In [reference], in the openProSe discovery scenario, the first network element is the 5G DDNMF network element, the first terminal device is the A-UE, the second terminal device is the M-UE, the A-UE interacts with the A-5G DDNMF network element through the A-AMF network element, and the M-UE interacts with the A-5G DDNMF network element through the M-AMF network element. An example is used to illustrate the secure communication method provided by an embodiment of the present application. The A-UE and the M-UE can interact with the A-5G DDNMF network element through different AMF network elements, which are distinguished by the A-AMF network element and the M-AMF network element here. The method for the A-UE to obtain the key generation parameters from the A-5GDDNMF network element is shown in steps 501 to 509, and the method for the M-UE to verify the A-UE is shown in steps 510 to 514. The method includes:

[0325] Step 500: The same as step 400. For details, please refer to the related descriptions of step 400, which are not elaborated here.

[0326] Step 501: The same as step 401. For details, please refer to the related descriptions of step 401, which are not elaborated here.

[0327] Step 502: The same as step 402. For details, please refer to the related descriptions of step 402, which are not elaborated here.

[0328] Step 503: The same as step 403. For specific details, please refer to the relevant description of step 403, which will not be elaborated here.

[0329] Step 504: The same as step 404. For specific details, please refer to the relevant description of step 404, which will not be elaborated here.

[0330] Step 505: The same as step 405. For specific details, please refer to the relevant description of step 405, which will not be elaborated here.

[0331] Step 506: After the AUSF network element receives the key acquisition request, it determines the Kausf of the A-UE according to the identity identifier of the A-UE, and calculates the UE-granularity discovery key of the A-UE based on the Kausf.

[0332] Optionally, the AUSF network element may generate the discovery key for adjacent services of the A-UE based on the UE-granularity discovery key of the A-UE. The AUSF network element calculates the UE-granularity discovery key of the A-UE according to the Kausf. After that, the method of generating the discovery key for adjacent services of the A-UE based on the UE-granularity discovery key of the A-UE can refer to the relevant description in step 406, which will not be elaborated here.

[0333] Step 507: The AUSF network element sends a key acquisition response to the A-5G DDNMF network element. The key acquisition response includes the UE-granularity discovery key of the A-UE. Optionally, it also includes the discovery key for adjacent services of the A-UE.

[0334] If the key acquisition response only includes the UE-granularity discovery key of the A-UE, the A-5G DDNMF network element may further generate the discovery key for adjacent services of the A-UE according to the UE-granularity discovery key of the A-UE.

[0335] The method by which the A-5G DDNMF network element generates the discovery key for adjacent services of the A-UE according to the UE-granularity discovery key of the A-UE is similar to the method by which the AUSF network element generates the discovery key for adjacent services of the A-UE according to the UE-granularity discovery key of the A-UE. For specific details, please refer to the foregoing content, which will not be elaborated here.

[0336] If the key acquisition response only includes the UE-granularity discovery key of the A-UE, the A-5G DDNMF network element may further generate the discovery key for adjacent services of the A-UE according to the UE-granularity discovery key of the A-UE. The A-5G DDNMF network element may further generate the sub-key of the A-UE according to the discovery key for adjacent services of the A-UE.

[0337] The method by which the A-5G DDNMF network element generates the sub-key of the A-UE based on the discovery key at the proximity service granularity of the A-UE is similar to the method by which the AUSF network element generates the discovery key at the proximity service granularity of the A-UE based on the discovery key at the UE granularity of the A-UE. For specific details, please refer to the foregoing content and will not be elaborated here.

[0338] If the key acquisition response only includes the discovery key at the UE granularity of the A-UE, the A-5G DDNMF network element may not generate the discovery key at the proximity service granularity of the A-UE. Instead, it directly generates the sub-key of the A-UE based on the discovery key at the UE granularity.

[0339] The method by which the A-5G DDNMF network element generates the sub-key of the A-UE based on the discovery key at the proximity service granularity of the A-UE is similar to the method by which the AUSF network element generates the discovery key at the proximity service granularity of the A-UE based on the discovery key at the UE granularity of the A-UE. For specific details, please refer to the foregoing content and will not be elaborated here.

[0340] Optionally, the method by which the A-5G DDNMF network element stores the discovery key at the UE granularity of the A-UE and / or the discovery key at the proximity service granularity of the A-UE can be referred to the relevant description in step 407 and will not be elaborated here.

[0341] Step 508: The A-5G DDNMF network element sends a parameter acquisition response through the A-AMF network element. The reference acquisition response includes the discovery key at the UE granularity of the A-UE and proximity service parameters, such as ProSe application code.

[0342] Step 509. After receiving the parameter acquisition response, the A-UE generates the discovery key at the proximity service granularity of the A-UE using the same method as the AUSF network element or the A-5G DDNMF network element. Optionally, the A-UE further generates the sub-key of the A-UE using the same method as the AUSF network element or the A-5G DDNMF network element.

[0343] Optionally, in another implementation method, after receiving the parameter acquisition response, the A-UE generates the sub-key of the A-UE using the same method as the AUSF network element or the A-5G DDNMF network element.

[0344] It should be noted that in step 508, taking the parameter acquisition response including the discovery key at the UE granularity of the A-UE as an example, as a possible implementation, the parameter acquisition response may not include the discovery key at the UE granularity of the A-UE, but carry the discovery key at the proximity service granularity of the A-UE or the sub-key. The sub-key can be generated based on the discovery key at the UE granularity of the A-UE or the discovery key at the proximity service granularity of the A-UE.

[0345] If the parameter acquisition response carries the discovery key for the proximity service granularity of A-UE, in step 509, when A-UE receives this parameter acquisition response, A-UE can generate a sub-key based on the discovery key for the proximity service granularity of A-UE.

[0346] Thus, A-UE has obtained from the A-5G DDNMF network element the discovery key and / or sub-key for generating the proximity service granularity of A-UE, as well as proximity service parameters.

[0347] Step 510: When A-UE determines that it needs to use proximity services, that is, when it needs to establish direct communication with other UEs, it can send a proximity service request message, which includes ProSe application code and MIC.

[0348] Among them, MIC is generated based on the discovery key of A-UE. For example, when A-UE receives the discovery key for the UE granularity of A-UE carried in the parameter acquisition response, A-UE can directly generate MIC based on the discovery key for the UE granularity, or first generate a sub-key based on the discovery key for the UE granularity, and then generate MIC based on the sub-key.

[0349] Another example is that A-UE obtains the discovery key for the proximity service granularity of this A-UE (the discovery key for the proximity service granularity of this A-UE can be carried in the parameter acquisition response, or can be generated by A-UE based on the discovery key for the UE granularity carried in the parameter acquisition response). A-UE can directly generate MIC based on the discovery key for the proximity service granularity, or first generate a sub-key based on the discovery key for the proximity service granularity, and then generate MIC based on this sub-key.

[0350] Another example is that A-UE receives the sub-key carried in the parameter acquisition response, and A-UE can generate MIC based on this sub-key.

[0351] Step 511: It is the same as step 411. For specific details, please refer to the relevant description in step 411 and will not be elaborated here.

[0352] Step 512: After receiving the verification request, A-5GDDNMF can determine the discovery key of A-UE (such as UE granularity discovery key or proximity service granularity discovery) or sub-key according to the Prose application code, generate the expected message integrity code (expected MIC, XMIC) based on the discovery key of A-UE. The way A-5GDDNMF generates XMIC based on the discovery key of A-UE is the same as the way A-UE generates MIC based on the discovery key of A-UE. After generating the XMIC, A-5GDDNMF determines whether the XMIC and MIC are consistent.

[0353] If the XMIC and MIC are consistent, it indicates that the identity of A-UE is legal and the verification of A-UE is successful. Otherwise, the identity of A-UE is illegal and the verification of A-UE fails.

[0354] Step 513: It is the same as step 413. For specific details, please refer to the relevant description of step 413 and will not be elaborated here.

[0355] Step 514: It is the same as step 414. For specific details, please refer to the relevant description of step 414 and will not be elaborated here.

[0356] In steps 510 to 514, the verification of A-UE by M-UE is taken as an example for illustration. In practical applications, A-UE can also verify the identity of M-UE. For example, M-UE can obtain the UE granularity discovery key of M-UE and the Prose application code of M-UE from 5GDDNMF in a similar way to steps 501 to 514. Then, M-UE generates the proximity service granularity discovery key of M-UE based on the UE granularity discovery key of M-UE, and further generates the corresponding MIC, and sends the MIC to A-UE. A-UE can obtain the MIC from M-UE in a similar way to steps 511 to 514 and send a verification request carrying the MIC to 5GDDNMF.

[0357] In Figure 4 and Figure 5 In the illustrated embodiments, when M-UE verifies A-UE, it is verified through A-5GDDNMF. In practical applications, M-UE can also verify A-UE by itself.

[0358] Next, based on the system architecture as Figure 1A shown, in combination with the attached Figure 5 , a secure communication method provided by an embodiment of the present application will be further described. Refer to Figure 6 , Figure 6In the open ProSe discovery scenario, the first network element is a 5G DDNMF network element, the first terminal device is an A-UE, the second terminal device is an M-UE. Taking the interaction between the A-UE and the A-5G DDNMF network element through the A-AMF network element, and the interaction between the M-UE and the A-5G DDNMF network element through the M-AMF network element as an example, the security communication method provided by the embodiments of the present application is described. The A-UE and the M-UE can interact with the A-5G DDNMF network element through different AMF network elements, and here the A-AMF network element and the M-AMF network element are used for distinction. The method for the A-UE to obtain key generation parameters from the A-5G DDNMF network element can be seen in steps 601 to 609, and the method for the M-UE to verify the A-UE can be seen in steps 610 to 614. The method includes:

[0359] Step 600: The same as step 400. For specific details, refer to the relevant description of step 400, which will not be elaborated here.

[0360] Step 601: The same as step 401. For specific details, refer to the relevant description of step 401, which will not be elaborated here.

[0361] Step 602: The same as step 402. For specific details, refer to the relevant description of step 402, which will not be elaborated here.

[0362] Step 603: The same as step 403. For specific details, refer to the relevant description of step 403, which will not be elaborated here.

[0363] Step 604: The same as step 404. For specific details, refer to the relevant description of step 404, which will not be elaborated here.

[0364] Step 605: The same as step 405. For specific details, refer to the relevant description of step 405, which will not be elaborated here.

[0365] Step 606: The same as step 406. For specific details, refer to the relevant description of step 406, which will not be elaborated here.

[0366] Step 607: The same as step 407. For specific details, refer to the relevant description of step 407, which will not be elaborated here.

[0367] Step 608: The same as step 408. For specific details, refer to the relevant description of step 408, which will not be elaborated here.

[0368] Step 609: The same as step 409. For specific details, refer to the relevant description of step 409, which will not be elaborated here.

[0369] Step 610: The same as step 410. For specific details, refer to the relevant description of step 410, which will not be elaborated here.

[0370] Step 611: The M-UE sends a request message for requesting proximity service parameters to the M-5G DDNMF network element via the M-AMF network element. The relevant information of the A-UE, such as the identity identifier of the A-UE or the ProSe application code, is carried in the request message.

[0371] Step 612: The M-5G DDNMF network element allocates proximity service parameters for the M-UE and sends a parameter request to the A-5G DDNMF network element. The relevant information of the A-UE is included in the parameter request, and the parameter request is used to request the discovery key of the A-UE.

[0372] Step 613: After receiving the parameter request, the A-5G DDNMF network element determines the discovery key of the A-UE according to the relevant information of the A-UE and feeds back the discovery key of the A-UE to the M-5G DDNMF network element.

[0373] Step 614: The M-5G DDNMF network element sends a response message to the M-UE, which includes the proximity service parameters of the M-UE and the discovery key of the A-UE.

[0374] Step 615: The M-UE receives the proximity service request message and determines that it can provide proximity service for the A-UE according to the ProSe application code and the proximity service parameters of the M-UE included in the proximity service request message.

[0375] Step 616: The M-UE verifies the A-UE. The M-UE can generate the XMIC according to the discovery key of the A-UE. The way the M-UE generates the XMIC according to the discovery key of the A-UE is the same as the way the A-UE generates the MIC according to the discovery key of the A-UE. After generating the XMIC, the M-UE determines whether the XMIC and the MIC are consistent.

[0376] If the XMIC and the MIC are consistent, it indicates that the identity of the A-UE is legal and the verification of the A-UE is successful. Otherwise, the identity of the A-UE is illegal and the verification of the A-UE fails.

[0377] Step 617: After the M-UE successfully verifies the A-UE, it can provide proximity service for the A-UE, that is, establish direct communication with the A-UE.

[0378] It should be noted that Step 610 can also be executed after Step 614, that is, the M-UE can first request proximity service parameters from the M-5G DDNMF network element and request the discovery key of the A-UE from the A-5G DDNMF network element. In this case, the relevant information of the A-UE carried in the request message sent by the M-UE can be pre-obtained by the M-UE, such as the application identifier and / or identity identifier of the A-UE, etc.

[0379] Taking the verification of the identity of A-UE by M-UE in steps 610 to 617 as an example, in actual applications, A-UE can also verify the identity of M-UE. For example, M-UE can obtain key generation parameters from 5G DDNMF in a manner similar to steps 601 to 614. After that, M-UE generates a discovery key for the proximity service granularity of M-UE based on the key generation parameters, and then generates a corresponding MIC, and sends the MIC to A-UE. A-UE can obtain the MIC from M-UE in a manner similar to steps 611 to 617, obtain the discovery key of M-UE from 5G DDNMF, generate XMIC, and verify M-UE.

[0380] To ensure the security of the discovery key of A-UE, the 5G DDNMF or the AUSF network element (i.e., the key generation network element) can set a lifecycle for the discovery key of A-UE. This lifecycle can be sent to A-UE or not sent to A-UE. The following is combined with Figure 7 for illustration. See Figure 7 , the method includes:

[0381] Step 701: The same as steps 400 to 409. For specific details, refer to the relevant descriptions in steps 400 to 407, which will not be elaborated here.

[0382] Step 702: The same as step 408. For specific details, refer to the relevant description in step 408, which will not be elaborated here. The reference acquisition response can also include a validity timer for indicating the validity period of the discovery key of A-UE.

[0383] Step 703: The same as step 409. For specific details, refer to the relevant description in step 409, which will not be elaborated here.

[0384] Step 704: After the validity timer expires, the A-5G DDNMF network element deletes the discovery key of A-UE.

[0385] If the A-5G DDNMF network element saves the discovery key at the UE granularity of the A-UE or the discovery key at the proximity service granularity of the A-UE together with the validity timer and the Prose application Code as the 5G Prose security context of the A-UE. After the validity timer expires, the A-5G DDNMF network element may delete the discovery key at the UE granularity of the A-UE or the discovery key at the proximity service granularity of the A-UE; if the A-5G DDNMF network element saves both the discovery key at the UE granularity of the A-UE and the discovery key at the proximity service granularity of the A-UE, after the validity timer expires, the A-5G DDNMF network element deletes the discovery key at the proximity service granularity of the A-UE and continues to save the discovery key at the UE granularity of the A-UE.

[0386] Step 705: The A-5G DDNMF network element obtains the discovery key of the new A-UE. The A-5G DDNMF network element may request the discovery key of the new A-UE from the AUSF network element or generate the discovery key of the A-UE by itself.

[0387] Step 706: The A-5G DDNMF network element sends indication information to the A-UE, and this indication information indicates to update the discovery key of the A-UE. The embodiments of the present application do not limit the manner in which this indication information indicates to update the discovery key of the A-UE. An explicit indication manner may be adopted. For example, the update of the discovery key of the A-UE may be indicated by a pre-agreed identifier or character, or an implicit indication manner may be adopted. For example, the update may be indicated by carrying key generation parameters for generating the discovery key of the new A-UE.

[0388] If an explicit indication manner is adopted, the indication message may also carry the key generation parameters for generating the discovery key of the new A-UE.

[0389] Step 707: After receiving this indication information, the A-UE updates the discovery key of the A-UE according to this indication information.

[0390] If the indication information includes the key generation parameters for generating the discovery key of the new A-UE, the A-UE generates the discovery key of the new A-UE according to these key generation parameters. If the indication information does not include the key generation parameters for generating the discovery key of the new A-UE, the A-UE may send a parameter acquisition request to the A-5G DDNMF network element again.

[0391] It should be noted that if the A-UE obtains the validity timer, before the validity timer expires, the A-UE can initiate multiple proximity service parameter request processes, but there is no need to update the discovery key. When the validity timer expires, the A-UE can delete the discovery key or send a parameter acquisition request to the A-5G DDNMF network element again.

[0392] Based on the same inventive concept as the method embodiment, an embodiment of the present application further provides a communication device for executing the method performed by the first terminal device or the A-UE in the above method embodiment. For related features, reference can be made to the above method embodiment and will not be elaborated here. As Figure 8 shown, the device includes a receiving unit 801, a processing unit 802, and a transmitting unit 803:

[0393] The receiving unit 801 is configured to obtain key generation parameters, where the key generation parameters include the proximity service temporary identifier of the first terminal device.

[0394] The processing unit 802 is configured to generate a first discovery key according to the root key and the key generation parameters; and generate a message integrity code based on the first discovery key.

[0395] The transmitting unit 803 is configured to send a proximity service request message, where the proximity service request message includes a proximity service temporary identifier and a message integrity code.

[0396] In a possible implementation manner, the transmitting unit 803 may further send a parameter acquisition request to the first network element, where the parameter acquisition request includes the identity identifier of the first terminal device, and the receiving unit 801 receives a parameter acquisition response from the first network element, where the parameter acquisition response includes key generation parameters.

[0397] In a possible implementation manner, when the processing unit 802 generates a message integrity code based on the discovery key, it may first generate a sub-key according to the discovery key; and then generate a message integrity code according to the sub-key. It may also directly generate a message integrity code according to the discovery key.

[0398] In a possible implementation manner, the key generation parameters further include part or all of the proximity service parameters assigned by the first network element to the first terminal device except the proximity service temporary identifier, such as part or all of the current time and the MAX offset. Optionally, the key generation parameters may further include other parameters, such as a counter value.

[0399] In a possible implementation manner, the parameter acquisition response further includes the validity period of the proximity service temporary identifier.

[0400] In a possible implementation, the processing unit 802 may also save the first discovery key and the validity period.

[0401] In a possible implementation, after the expiration of the validity period, the processing unit 802 may also delete the first discovery key.

[0402] In a possible implementation, the root key may be any one of the following: Kausf, Kamf, Kakma, or a pre-configured key.

[0403] Based on the same inventive concept as the method embodiment, an embodiment of the present application also provides a communication device for executing the method performed by the first network element or the A-5G DDNMF network element in the above method embodiment. For related features, reference may be made to the above method embodiment and will not be elaborated here. As Figure 9 shown, the device includes a sending unit 901, a processing unit 902, and a receiving unit 903.

[0404] The sending unit 901 is configured to send key generation parameters, where the key generation parameters include the proximity service temporary identifier of the first terminal device;

[0405] The receiving unit 903 is configured to receive a verification request from the second terminal device, where the verification request includes the proximity service temporary identifier and the message integrity code;

[0406] The processing unit 902 is configured to determine the first discovery key of the first terminal device according to the proximity service temporary identifier, generate an expected message integrity code according to the first discovery key; and verify the first terminal device according to the message integrity code and the expected message integrity code;

[0407] The sending unit 901 is further configured to send a verification response to the second terminal device after the processing unit 902 verifies the first terminal device according to the message integrity code and the expected message integrity code, where the verification response is used to indicate the verification result of the first terminal device.

[0408] In a possible implementation, the receiving unit 903 may receive a parameter acquisition request from the first terminal device, where the parameter acquisition request includes the identity identifier of the first terminal device; the processing unit 902 may authorize and check the first terminal device according to the identity identifier of the first terminal device. After the authorization check passes, the processing unit 902 may allocate a proximity service temporary identifier for the first terminal device; may also obtain the first discovery key according to the proximity service temporary identifier; the sending unit 901 may send a parameter acquisition response to the first terminal device, where the parameter acquisition response includes the key generation parameters; the processing unit 902 may also save the correspondence between the proximity service temporary identifier and the first discovery key.

[0409] In a possible implementation, the parameter acquisition request further includes the proximity service information of the first terminal device. When the processing unit 902 passes the authentication of the first terminal device according to the identity identifier of the first terminal device, the receiving unit 903 may obtain the subscription information of the proximity service of the first terminal device from the unified data management network element according to the identity identifier of the first terminal device and the proximity service information of the first terminal device; thereafter, after the processing unit 902 determines that the proximity service information of the first terminal device is consistent with the proximity service subscription information of the first terminal device, the authorization check for the first terminal device passes.

[0410] In a possible implementation, the parameter acquisition request further includes the proximity service information of the first terminal device. When the processing unit 902 passes the authorization check of the first terminal device according to the identity identifier of the first terminal device, the sending unit 901 may send a check request to the unified data management network element for requesting an authorization check for the first terminal device, and the check request includes the identity identifier of the first terminal device; thereafter, the receiving unit 903 may receive a check response from the unified data management network element, and the detection response is used to indicate that the authorization check for the first terminal device passes.

[0411] In a possible implementation, there are three methods for the processing unit 902 to obtain the first discovery key according to the proximity service temporary identifier:

[0412] First, the processing unit 902 generates the first discovery key according to the proximity service temporary identifier and the root key, and the root key is a key assigned or pre-configured for the first terminal device.

[0413] Second, the processing unit 902 obtains the first discovery key from the key generation network element through the receiving unit 903 according to the proximity service temporary identifier.

[0414] Third, the processing unit 902 obtains the second discovery key from the key generation network element through the receiving unit 903 according to the identity identifier, and generates the first discovery key according to the second discovery key and the proximity service temporary identifier.

[0415] In a possible implementation, the key generation parameters further include some or all of the proximity service parameters other than the proximity service temporary identifier assigned by the first network element for the first terminal device, such as the current time, some or all of the maximum offset. Optionally, the key generation parameters may further include other parameters, such as the counter value.

[0416] In a possible implementation, when the processing unit 902 obtains the first discovery key from the key generation network element through the receiving unit 903 according to the proximity service temporary identifier, the sending unit 901 may send a first key acquisition request to the key generation network element. The first key acquisition request includes the identity identifier of the first terminal device and the proximity service temporary identifier. After that, the receiving unit 903 may receive a first key acquisition response from the key generation network element. The first key acquisition response includes the first discovery key.

[0417] In a possible implementation, when the processing unit 902 obtains the second discovery key from the key generation network element through the receiving unit 903 according to the identity identifier, the sending unit 901 may send a second key acquisition request to the key generation network element. The second key acquisition request includes the identity identifier of the first terminal device. The receiving unit 903 may receive a second key acquisition response from the key generation network element. The second key acquisition response includes the second discovery key.

[0418] In a possible implementation, when the processing unit 902 generates an expected message integrity code based on the sending key, it may first generate a sub - key according to the first discovery key, and then generate the expected integrity code according to the sub - key. The processing unit 902 may also directly generate the expected message integrity code according to the sending key.

[0419] In a possible implementation, the key generation network element is any of the following network elements:

[0420] The authentication service function network element, the access and mobility management function network element, the authentication and key management anchor function network element of the application, the bootstrapping service function network element, the 5G direct communication discovery name management function network element, or the key management network element, where the key management network element is the network element that stores the pre - configured key for the first terminal device.

[0421] In a possible implementation, the processing unit 902 may also determine the validity period of the proximity service temporary identifier and save the corresponding relationship between the validity period and the first discovery key.

[0422] In a possible implementation, after the validity period expires, the processing unit 902 deletes the first discovery key.

[0423] Based on the same inventive concept as the method embodiment, the embodiment of the present application also provides a communication device for executing the method executed by the key generation network element or the AUSF network element in the above - mentioned method embodiment. The related features can be referred to the above - mentioned method embodiment and will not be elaborated here. As Figure 10 shown, the communication device may interact with the first network element in any of the following two ways. The device includes a receiving unit 1001, a processing unit 1002, and a sending unit 1003:

[0424] Method 1:

[0425] A receiving unit 1001, configured to receive a first key acquisition request from a first network element, where the first key acquisition request includes an identity identifier of a terminal device and key generation parameters.

[0426] A processing unit 1002, configured to determine a root key according to the identity identifier of the first terminal device; and generate a discovery key for the proximity service granularity of the first terminal device according to the root key and the key generation parameters.

[0427] A sending unit 1003, configured to send a first key acquisition response to the first network element, where the first key acquisition response includes the discovery key for the proximity service granularity of the first terminal device.

[0428] Method 2:

[0429] A receiving unit 1001, configured to receive a second key acquisition request from a first network element, where the first key acquisition request includes an identity identifier of a terminal device.

[0430] A processing unit 1002, configured to determine a root key according to the identity identifier of the first terminal device; and generate a discovery key for the terminal device granularity of the first terminal device according to the root key and the key generation parameters.

[0431] A sending unit 1003, configured to send a second key acquisition response to the first network element, where the first key acquisition response includes the discovery key for the terminal device granularity of the first terminal device.

[0432] In a possible implementation manner, the key generation network element is any one of the following network elements:

[0433] An authentication service function network element, an access and mobility management function network element, an authentication and key management anchor function network element of an application, a boot service function network element, a 5G direct communication discovery name management function network element, or a key management network element, where the key management network element is a network element that stores a key pre-configured for the first terminal device.

[0434] Based on the same inventive concept as the method embodiment, an embodiment of the present application further provides a communication device, configured to execute the method executed by the second terminal device or the M-UE in the above method embodiment. Related features can be referred to the above method embodiment and will not be elaborated here. As Figure 11 shown, the device includes a receiving unit 1101, a processing unit 1102, and a sending unit 1103.

[0435] A receiving unit 1101, configured to receive a proximity service request message broadcast by a first terminal device, where the proximity service request message includes a proximity service temporary identifier of the first terminal device and a message integrity code;

[0436] A processing unit 1102, configured to determine whether the proximity service can be supported according to the temporary identifier of the proximity service;

[0437] A sending unit 1103, configured to send a verification request to a first network element after the processing unit 1102 determines that the proximity service can be supported according to the temporary identifier of the proximity service, where the verification request includes the temporary identifier of the proximity service and a message integrity code;

[0438] A receiving unit 1101 is further configured to receive a verification response from the first network element, where the verification response is used to indicate a verification result of the first terminal device;

[0439] The processing unit 1102 is further configured to determine whether to establish direct communication with the first terminal device according to the verification result.

[0440] In the embodiments of the present application, the division of units is illustrative. It is only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present application, each functional unit may be integrated in a processor, or may exist physically alone, or two or more units may be integrated in a module. The above integrated units may be implemented in the form of hardware or in the form of software function modules.

[0441] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a terminal device (which may be a personal computer, a mobile phone, or a network device, etc.) or a processor to execute all or part of the steps of the method in each embodiment of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc that can store program codes.

[0442] In the embodiments of the present application, the first network element, the key generation network element, the first terminal device, and the second terminal device may all be presented in the form of dividing each functional module in an integrated manner. Here, the "module" may refer to a specific ASIC, a circuit, a processor and a memory that execute one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions.

[0443] In a simple embodiment, those skilled in the art can think that the first network element and the key generation network element can both adoptFigure 12 The form shown.

[0444] like Figure 12 The communication device 1200 shown includes at least one processor 1201 , a memory 1202 , and optionally, a communication interface 1203 .

[0445] The memory 1202 may be a volatile memory, such as a random access memory; the memory may also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the memory 1202 may be any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1202 may be a combination of the above memories.

[0446] The specific connection medium between the processor 1201 and the memory 1202 is not limited in the embodiment of the present application. In the figure, the memory 1202 and the processor 1201 are connected via a bus 1204, which is represented by a thick line in the figure. The connection between other components is only for schematic illustration and is not limited. The bus 1204 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 12 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0447] The processor 1201 may have a data transceiver function and may communicate with other devices. Figure 12 An independent data transceiver module, such as a communication interface 1203, may also be provided in the device for transmitting and receiving data; when the processor 1201 communicates with other devices, data may be transmitted through the communication interface 1203.

[0448] When the first network element adopts Figure 12 When the form shown is Figure 12 The processor 1201 in the embodiment can call the computer execution instructions stored in the memory 1202, so that the session management network element can execute the method executed by the first network element or the A-5G DDNMF network element in any of the above method embodiments.

[0449] Specifically, Figure 9 The functions / implementation processes of the sending unit, receiving unit and processing unit in the Figure 12 The processor 1201 in the embodiment calls the computer execution instruction stored in the memory 1202 to implement. Or, Figure 9 The function / implementation process of the processing unit in can beFigure 12 The processor 1201 in the embodiment calls the computer execution instruction stored in the memory 1202 to implement, Figure 9 The functions / implementation process of the sending unit and the receiving unit in can be achieved through Figure 12 It is implemented by the communication interface 1203 in.

[0450] When the key generation network element adopts Figure 12 When the form shown is Figure 12 The processor 1201 in the embodiment can call the computer execution instructions stored in the memory 1202, so that the key generation network element can execute the method executed by the key generation network element or the AUSF network element in any of the above method embodiments.

[0451] Specifically, Figure 10 The functions / implementation processes of the receiving unit, sending unit and processing unit in the Figure 12 The processor 1201 in the embodiment calls the computer execution instruction stored in the memory 1202 to implement. Or, Figure 10 The function / implementation process of the processing unit in can be Figure 12 The processor 1201 in the embodiment calls the computer execution instruction stored in the memory 1202 to implement, Figure 10 The functions / implementation process of the receiving unit and the sending unit in the Figure 12 It is implemented by the communication interface 1203 in.

[0452] In a simple embodiment, those skilled in the art can imagine that both the first terminal device and the second terminal device can use Figure 13 The form shown.

[0453] like Figure 13 The communication device 1300 shown includes at least one processor 1301 , a memory 1302 , and optionally, a transceiver 1303 .

[0454] The processor 1301 and the memory 1302 are similar to the processor 1201 and the memory 1202 . For details, please refer to the above content and will not be repeated here.

[0455] The specific connection medium between the processor 1301 and the memory 1302 is not limited in the embodiment of the present application. In the figure, the memory 1302 and the processor 1301 are connected via a bus 1304, which is represented by a thick line in the figure. The connection between other components is only for schematic illustration and is not limited. The bus 1304 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 13 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0456] The processor 1301 may have a data transceiver function and be capable of communicating with other devices. In a device such as Figure 13 , an independent data transceiver module may also be provided, such as the transceiver 1303, for data transceiver; when the processor 1301 communicates with other devices, data transmission may be performed through the transceiver 1303.

[0457] When the first terminal device adopts the Figure 13 form shown, Figure 13 the processor 1301 in

[0458] Specifically, Figure 8 the functions / implementation processes of the sending unit, receiving unit, and processing unit in Figure 13 can all be implemented by the processor 1301 in Figure 8 calling the computer-executable instructions stored in the memory 1302. Or, Figure 13 the function / implementation process of the processing unit in Figure 8 can be implemented by the processor 1301 in Figure 13 calling the computer-executable instructions stored in the memory 1302, and

[0459] the functions / implementation processes of the sending unit and receiving unit in Figure 13 can be implemented by the transceiver 1303 in Figure 13 When the second terminal device adopts the

[0460] Specifically, Figure 11 the functions / implementation processes of the sending unit, receiving unit, and processing unit in Figure 13 can all be implemented by the processor 1301 in Figure 11 calling the computer-executable instructions stored in the memory 1302. Or, Figure 13 the function / implementation process of the processing unit in Figure 11 can be implemented by the processor 1301 in Figure 13 calling the computer-executable instructions stored in the memory 1302, and

[0461] In this method, those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0462] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices produce a device for implementing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.

[0463] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device that implements the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.

[0464] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.

[0465] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A secure communication method, characterized in that, the method includes: The first terminal device sends a parameter acquisition request to the first network element, and the parameter acquisition request includes the identity identifier of the first terminal device; The first terminal device receives a parameter acquisition response from the first network element, the parameter acquisition response includes key generation parameters, and the key generation parameters include the proximity service temporary identifier of the first terminal device; The first terminal device generates a first discovery key according to the root key and the key generation parameters; The first terminal device generates a message integrity code based on the first discovery key; The first terminal device sends a proximity service request message, and the proximity service request message includes the proximity service temporary identifier and the message integrity code.

2. The method according to claim 1, characterized in that, the first terminal device generating the message integrity code based on the first discovery key includes: The first terminal device generates a sub-key according to the first discovery key; The first terminal device generates the message integrity code according to the sub-key.

3. The method according to claim 1, characterized in that, the parameter acquisition response further includes the validity period of the proximity service temporary identifier.

4. The method according to claim 2, characterized in that, the parameter acquisition response further includes the validity period of the proximity service temporary identifier.

5. The method according to claim 3, characterized in that, the method further includes: The first terminal device saves the first discovery key and the validity period.

6. The method according to claim 4, characterized in that, the method further includes: The first terminal device saves the first discovery key and the validity period.

7. The method according to claim 5, characterized in that, the method further includes: After the validity period expires, the first terminal device deletes the first discovery key.

8. The method according to claim 6, characterized in that, the method further includes: After the validity period expires, the first terminal device deletes the first discovery key.

9. The method according to any one of claims 1 to 8, characterized in that, the key generation parameters further include any one or a combination of the following information: Current time, MAX offset.

10. The method according to any one of claims 1 to 8, characterized in that, the root key is Kausf.

11. The method according to claim 9, characterized in that, the root key is Kausf.

12. The method according to any one of claims 1 to 8, characterized in that, the root key is Kamf.

13. The method according to claim 9, characterized in that, the root key is Kamf.

14. The method according to any one of claims 1 to 8, characterized in that, the root key is Kakma.

15. The method according to claim 9, characterized in that, the root key is Kakma.

16. The method according to any one of claims 1 to 8, characterized in that, the root key is a pre-configured key.

17. The method according to claim 9, wherein, the root key is a pre-configured key.

18. A secure communication method, wherein, the method includes: a first network element sending key generation parameters, the key generation parameters including a proximity service temporary identifier of a first terminal device; the first network element receiving a verification request from a second terminal device, the verification request including the proximity service temporary identifier and a message integrity code; the first network element determining a first discovery key of the first terminal device according to the proximity service temporary identifier; the first network element generating an expected message integrity code according to the first discovery key; after verifying the first terminal device according to the message integrity code and the expected message integrity code, the first network element sending a verification response to the second terminal device, the verification response being used to indicate the verification result of the first terminal device.

19. The method according to claim 18, wherein, the first network element sending the key generation parameters includes: the first network element receiving a parameter acquisition request from the first terminal device, the parameter acquisition request including an identity identifier of the first terminal device; after passing an authorization check on the first terminal device according to the identity identifier of the first terminal device, the first network element allocating the proximity service temporary identifier to the first terminal device; the first network element acquiring the first discovery key according to the proximity service temporary identifier; the first network element sending a parameter acquisition response to the first terminal device, the parameter acquisition response including the key generation parameters.

20. The method according to claim 19, wherein, the method further includes: the first network element saving the correspondence between the proximity service temporary identifier and the first discovery key.

21. The method according to claim 18, wherein, the method further includes: the first network element saving the correspondence between the proximity service temporary identifier and the first discovery key.

22. The method according to claim 19, wherein, the first network element acquiring the first discovery key according to the proximity service temporary identifier includes: the first network element generating the first discovery key according to the proximity service temporary identifier and a root key, the root key being a key allocated or pre-configured for the first terminal device; or the first network element acquiring the first discovery key from a key generation network element according to the proximity service temporary identifier; or the first network element acquiring a second discovery key from the key generation network element according to the identity identifier, and generating the first discovery key according to the second discovery key and the proximity service temporary identifier.

23. The method according to claim 20, wherein, the first network element acquiring the first discovery key according to the proximity service temporary identifier includes: the first network element generating the first discovery key according to the proximity service temporary identifier and a root key, the root key being a key allocated or pre-configured for the first terminal device; or The first network element obtains the first discovery key from a key generation network element according to the adjacent service temporary identifier; or The first network element obtains a second discovery key from the key generation network element according to the identity identifier, and generates the first discovery key according to the second discovery key and the adjacent service temporary identifier.

24. The method according to claim 22,[[]] wherein,[[]] The first network element obtaining the first discovery key from a key generation network element according to the adjacent service temporary identifier specifically includes:[[]] The first network element sends a first key acquisition request to the key generation network element, and the first key acquisition request includes the adjacent service temporary identifier and the identity identifier; The first network element receives a first key acquisition response from the key generation network element, and the first key acquisition response includes the first discovery key.

25. The method according to claim 22,[[]] wherein,[[]] The first network element obtaining a second discovery key from the key generation network element according to the identity identifier includes:[[]] The first network element sends a second key acquisition request to the key generation network element, and the second key acquisition request includes the identity identifier; The first network element receives a second key acquisition response from the key generation network element, and the second key acquisition response includes the second discovery key.

26. The method according to claim 20,[[]] wherein,[[]] The key generation network element is any one of the following network elements:[[]] Authentication service function network element, access and mobility management function network element, authentication and key management anchor function network element of an application, boot service function network element, 5G direct communication discovery name management function network element, or key management network element, where the key management network element is a network element storing a key pre-configured for a first terminal device.

27. The method according to any one of claims 22-25,[[]] wherein,[[]] The key generation network element is any one of the following network elements:[[]] Authentication service function network element, access and mobility management function network element, authentication and key management anchor function network element of an application, boot service function network element, 5G direct communication discovery name management function network element, or key management network element, where the key management network element is a network element storing a key pre-configured for a first terminal device.

28. The method according to any one of claims 18 to 26,[[]] wherein,[[]] The first network element generating an expected message integrity code according to the first discovery key includes:[[]] The first network element generates a sub-key according to the first discovery key; The first network element generates an expected integrity code according to the sub-key.

29. The method according to claim 27,[[]] wherein,[[]] The first network element generating an expected message integrity code according to the first discovery key includes:[[]] The first network element generates a sub-key according to the first discovery key; The first network element generates an expected integrity code according to the sub-key.

30. The method according to any one of claims 18 to 26,[[]] wherein,[[]] The key generation parameters further include any one or a combination of the following information:[[]] Current time, MAX offset.

31. The method according to claim 27, wherein, the key generation parameter further includes any one or a combination of the following information: current time, MAX offset.

32. The method according to any one of claims 18 to 26, wherein, the method further includes: the first network element determines the validity period of the proximity service temporary identifier, and stores the correspondence between the validity period and the first discovery key.

33. The method according to claim 27, wherein, the method further includes: the first network element determines the validity period of the proximity service temporary identifier, and stores the correspondence between the validity period and the first discovery key.

34. The method according to claim 32, wherein, the method further includes: after the validity period expires, the first network element deletes the first discovery key.

35. The method according to claim 33, wherein, the method further includes: after the validity period expires, the first network element deletes the first discovery key.

36. A secure communication method, wherein, the method includes: a second terminal device receives a proximity service request message sent by a first terminal device, the proximity service request message includes the proximity service temporary identifier of the first terminal device and a message integrity code; after determining that the proximity service can be supported according to the proximity service temporary identifier, the second terminal device sends a verification request to a first network element, the verification request includes the proximity service temporary identifier and the message integrity code; the second terminal device receives a verification response from the first network element, the verification response is used to indicate the verification result of the first terminal device; the second terminal device determines whether to establish direct communication with the first terminal device according to the verification result.

37. A communication device, wherein, the device includes: a sending unit, configured to send a parameter acquisition request to a first network element, the parameter acquisition request includes the identity identifier of the communication device; a receiving unit, configured to receive a parameter acquisition response from the first network element, the parameter acquisition response includes a key generation parameter, and the key generation parameter includes the proximity service temporary identifier of the communication device; a processing unit, configured to generate a first discovery key according to a root key and the key generation parameter; generate a message integrity code based on the first discovery key; the sending unit, configured to send a proximity service request message, the proximity service request message includes the proximity service temporary identifier and the message integrity code.

38. The device according to claim 37, wherein, the processing unit is configured to: generate a sub-key according to the first discovery key; generate the message integrity code according to the sub-key.

39. The device according to claim 37, wherein, the parameter acquisition response further includes the validity period of the proximity service temporary identifier.

40. The device according to claim 38, wherein, the parameter acquisition response further includes the validity period of the proximity service temporary identifier.

41. The device according to claim 39, wherein, the processing unit is further configured to: save the first discovery key and the validity period.

42. The device according to claim 40, wherein, the processing unit is further configured to: save the first discovery key and the validity period.

43. The device according to claim 41, wherein, the processing unit is further configured to: delete the first discovery key after the validity period expires.

44. The device according to claim 42, wherein, the processing unit is further configured to: delete the first discovery key after the validity period expires.

45. The device according to any one of claims 37 to 44, wherein, the key generation parameter further includes a combination of any one or more of the following information: current time, MAX offset.

46. The device according to any one of claims 37 to 44, wherein, the root key is Kausf.

47. The device according to claim 45, wherein, the root key is Kausf.

48. The device according to any one of claims 37 to 44, wherein, the root key is Kamf.

49. The device according to claim 45, wherein, the root key is Kamf.

50. The device according to any one of claims 37 to 44, wherein, the root key is Kakma.

51. The device according to claim 45, wherein, the root key is Kakma.

52. The device according to any one of claims 37 to 44, wherein, the root key is a pre-configured key.

53. The device according to claim 45, wherein, the root key is a pre-configured key.

54. A communication device, wherein, the device includes: a sending unit, configured to send a key generation parameter, where the key generation parameter includes a proximity service temporary identifier of a first terminal device; a receiving unit, configured to receive a verification request from a second terminal device, where the verification request includes the proximity service temporary identifier and a message integrity code; a processing unit, configured to determine a first discovery key of the first terminal device according to the proximity service temporary identifier; generate an expected message integrity code according to the first discovery key; verify the first terminal device according to the message integrity code and the expected message integrity code; the sending unit is further configured to send a verification response to the second terminal device, where the verification response is used to indicate a verification result of the first terminal device.

55. The device according to claim 54, wherein, the receiving unit is further configured to: receive a parameter acquisition request from the first terminal device, where the parameter acquisition request includes an identity identifier of the first terminal device; The processing unit is configured to, after authorizing and passing the check on the first terminal device according to the identity identifier of the first terminal device, allocate the proximity service temporary identifier to the first terminal device; and obtain the first discovery key according to the proximity service temporary identifier. The sending unit is configured to send a parameter acquisition response to the first terminal device, where the parameter acquisition response includes the key generation parameter.

56. The apparatus according to claim 55, wherein, the processing unit is further configured to: save the correspondence between the proximity service temporary identifier and the first discovery key.

57. The apparatus according to claim 54, wherein, the processing unit is further configured to: save the correspondence between the proximity service temporary identifier and the first discovery key.

58. The apparatus according to claim 55, wherein, the processing unit is configured to: generate the first discovery key according to the proximity service temporary identifier and the root key, where the root key is a key allocated or pre-configured for the first terminal device; or obtain the first discovery key from a key generation network element according to the proximity service temporary identifier; or obtain a second discovery key from the key generation network element according to the identity identifier of the first terminal device, and generate the first discovery key according to the second discovery key and the proximity service temporary identifier.

59. The apparatus according to claim 56, wherein, the processing unit is configured to: generate the first discovery key according to the proximity service temporary identifier and the root key, where the root key is a key allocated or pre-configured for the first terminal device; or obtain the first discovery key from a key generation network element according to the proximity service temporary identifier; or obtain a second discovery key from the key generation network element according to the identity identifier, and generate the first discovery key according to the second discovery key and the proximity service temporary identifier.

60. The apparatus according to claim 58, wherein, the sending unit is further configured to: send a first key acquisition request to the key generation network element, where the first key acquisition request includes the proximity service temporary identifier and the identity identifier; the receiving unit is further configured to: receive a first key acquisition response from the key generation network element, where the first key acquisition response includes the first discovery key.

61. The apparatus according to claim 58, wherein, the sending unit is further configured to: send a second key acquisition request to the key generation network element, where the second key acquisition request includes the identity identifier; the receiving unit is further configured to: receive a second key acquisition response from the key generation network element, where the second key acquisition response includes the second discovery key.

62. The apparatus according to claim 56, wherein, the key generation network element is any one of the following network elements: An authentication service function network element, an access and mobility management function network element, an authentication and key management anchor function network element for an application, a bootstrapping service function network element, a 5G direct communication discovery name management function network element, or a key management network element, wherein the key management network element is a network element that stores a key pre-configured for a first terminal device.

63. The apparatus according to any one of claims 58 - 61, characterized in that the key generation network element is any one of the following network elements: An authentication service function network element, an access and mobility management function network element, an authentication and key management anchor function network element for an application, a bootstrapping service function network element, a 5G direct communication discovery name management function network element, or a key management network element, wherein the key management network element is a network element that stores a key pre-configured for a first terminal device.

64. The apparatus according to any one of claims 54 - 62, characterized in that the processing unit is configured to: generate a sub-key according to the first discovery key; generate an expected complete code according to the sub-key.

65. The apparatus according to claim 63, characterized in that the processing unit is configured to: generate a sub-key according to the first discovery key; generate an expected complete code according to the sub-key.

66. The apparatus according to any one of claims 54 - 62, characterized in that the key generation parameters further include any one or a combination of the following information: current time, MAX offset.

67. The apparatus according to claim 63, characterized in that the key generation parameters further include any one or a combination of the following information: current time, MAX offset.

68. The apparatus according to any one of claims 54 - 62, characterized in that the processing unit is further configured to: determine the validity period of the proximity service temporary identifier, and save the corresponding relationship between the validity period and the first discovery key.

69. The apparatus according to claim 63, characterized in that the processing unit is further configured to: determine the validity period of the proximity service temporary identifier, and save the corresponding relationship between the validity period and the first discovery key.

70. The apparatus according to claim 68, characterized in that the processing unit is further configured to: delete the first discovery key after the validity period expires.

71. The apparatus according to claim 69, characterized in that the processing unit is further configured to: delete the first discovery key after the validity period expires.

72. A communication apparatus, characterized in that the apparatus includes: a receiving unit, configured to: receive a proximity service request message sent by a first terminal device, where the proximity service request message includes a proximity service temporary identifier of the first terminal device and a message complete code; a processing unit, configured to: determine that the proximity service can be supported according to the proximity service temporary identifier; a sending unit, configured to: send a verification request to a first network element, where the verification request includes the proximity service temporary identifier and the message complete code; The receiving unit is further configured to: receive a verification response from the first network element, where the verification response is used to indicate a verification result of the first terminal device; The processing unit is further configured to: determine whether to establish direct communication with the first terminal device according to the verification result.

73. A communication device, characterized in that it includes a processor and a memory, instructions are stored in the memory, and when the processor executes the instructions, the device executes the method according to any one of claims 1 to 36.

Citation Information

Patent Citations

  • Peer-to-peer relaying of discovery information

    CN106464726A