Information transmission method and device
By unifying the security context to a native security context and performing authentication when user equipment switches from a 5G network to a 4G network, the problem of inconsistent security contexts during MME handover is solved, ensuring the service continuity and communication performance of user equipment.
Patent Information
- Application Number
- CN202080105755.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-26
- Publication Date
- 2026-01-13
- Estimated Expiration
- 2040-10-26
AI Technical Summary
When a user equipment switches from a 5G network to a 4G network, during the handover process between MMEs, the user equipment's access may be denied due to inconsistencies in security context types, affecting service continuity.
After receiving the TAU request message through the first mobility management network element, the security context is unified to the native security context, and authentication of the user equipment is triggered to ensure the synchronization of the security context during network handover.
This avoids situations where user equipment access is denied due to a lack of security context synchronization, thereby improving the service continuity and communication performance of user equipment.
Smart Images

Figure CN116250263B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and in particular to an information transmission method and device. BACKGROUND
[0002] With the rapid development of wireless communication technology, the fifth generation (5G) mobile communication network (5G network for short) emerges as the times require, and the 5G network can coexist with the existing fourth generation (4G) network, and interworking between the two can be achieved. When a user equipment (UE) is switched from a 5G network to a 4G network, if the user equipment moves again, it can trigger the switching between mobility management nodes (MMEs), for example, the user equipment (UE) is switched from MME1 to MME2, and then MME2 judges that the security context type corresponding to the UE is inconsistent with the local security context type saved by MME2 according to the key set identifier (eKSI) included in the tracking area update (TAU) request sent by the UE subsequently, and then MME2 rejects the TAU request of the UE, thereby causing the UE to be unable to access the network again for a period of time, and affecting the service continuity of the user equipment. The eKSI is used to identify the security context corresponding to the 4G network.
[0003] The security context includes a mapped type and a native type. The native type refers to a security context generated in a certain communication system and used only in the communication system, for example, a local security context used in a 4G network or a local security context negotiated after authentication in a 5G network. The mapped type refers to a context generated in a certain communication system and used in other communication systems after derivation or processing.
[0004] For example, if the UE moves from the 5G network to the 4G network, the core access and mobility management function (AMF) in the 5G network can derive the mapped security context from the native security context used in the 5G network, and send the mapped security context to the MME1. Therefore, the eKSI stored by the UE and the MME1 is the mapped security context, and when the UE moves and triggers a handover from the MME1 to the MME2, the MME2 determines the security context received from the MME1 as the native security context, and the MME2 determines that the UE uses the mapped security context according to the eKSI carried in the TAU request message sent by the UE. The MME2 cannot find the mapped security context locally, and therefore the MME2 fails to verify the TAU message of the UE, and sends a rejection message to the UE. The rejection message can also carry a rejection indication, indicating that the UE can access after a period of time. Obviously, this will seriously affect the continuity of the UE service. SUMMARY
[0005] Embodiments of the present application provide an information transmission method and device to solve the problem of security context synchronization when MME switching occurs.
[0006] To achieve the above object, the embodiments of the present application adopt the following technical solutions:
[0007] In a first aspect, the embodiments of the present application provide an information transmission method applied to a first mobile management network element, the method comprising: receiving a tracking area update (TAU) request message from a user equipment, the user equipment switching from a second network to a first network, and the first mobile management network element belonging to the first network; and setting a security context used between the first mobile management network element and the user equipment as a native security context according to the TAU request message.
[0008] In the above technical solution, when the user equipment switches from the second network to the first mobile management network element of the first network, the first mobile management network element can set the security context used between the first mobile management network element and the user equipment as the native security context according to the TAU request message. The native security context is a context used in the first network, so that when the user equipment needs to switch from the first mobile management network element to another mobile management network element in the first network due to movement or other reasons, the access of the user equipment can be avoided from being rejected by the other mobile management network element due to asynchronous security context, the service continuity of the user equipment is guaranteed, and the communication performance is improved.
[0009] Furthermore, the user equipment in each embodiment of this application is merely an example and may be other types of terminal equipment.
[0010] In one possible implementation, the security context used between the first mobility management network element and the user equipment is set as a native security context, including: the first mobility management network element authenticating the user equipment.
[0011] In the above possible implementations, the first mobility management network element unifies the security context used with the user equipment into a native security context. Specifically, the first mobility management network element can trigger user authentication. After authentication, the security context can be unified to the native type used within the first network. Thus, the security contexts between the first mobility management network element and other mobility management network elements within the first network and the user equipment can be synchronized. This ensures that when the user equipment needs to switch from the first mobility management network element to another mobility management network element within the first network due to mobility or other reasons, the user equipment is not rejected when accessing other mobility management network elements, thus guaranteeing the service continuity of the user equipment.
[0012] In one possible implementation, the TAU request message includes the user equipment's status information. The first mobility management network element authenticates the user equipment, specifically including: if the status information indicates that the user equipment is switching from the second network to the first network, or if the status information indicates the user equipment's mobility management registration information of the second network, or if the status information indicates that the user equipment has the network security capabilities of the second network, or if the status information indicates that the user equipment has the N1 interface capabilities of the second network, then the first mobility management network element authenticates the user equipment.
[0013] In the aforementioned possible implementations, the first mobility management network element can trigger authentication of the user equipment (MAU) based on the aforementioned status information confirming that the MAU is switching from the second network to the first network. This unifies the security context used between the first MAU and the MAU to the native type. Consequently, when the MAU needs to switch from the first MAU to another MAU within the first network due to mobility or other reasons, it can avoid the situation where the MAU's access is rejected by other MAUs due to security context inconsistencies, thus improving the service continuity of the MAU. Furthermore, the conditions for triggering authentication of the MAU are highly flexible and relatively easy to implement.
[0014] In one possible implementation, the security context used between the first mobility management network element and the user equipment is set to a native security context according to the TAU request message. Specifically, this includes: the first mobility management network element determining the identifier of the user equipment according to the TAU request message; the first mobility management network element determining that the location of the user equipment has changed according to the identifier of the user equipment; and the first mobility management network element authenticating the user equipment.
[0015] In the above possible implementations, the first mobility management network element can determine that the user equipment will undergo a handover between mobility management network elements based on the change in the user equipment's location, thereby triggering authentication of the user equipment. The security context used between the first mobility management network element and the user equipment is of the native type. This way, when the user equipment needs to switch from the first mobility management network element to other mobility management network elements in the first network due to mobility or other reasons, the user equipment's access can be rejected by other mobility management network elements due to security context asynchrony, thus improving the service continuity of the user equipment.
[0016] In one possible implementation, the first mobility management network element determines that the location information of the user equipment has changed based on the identifier of the user equipment. Specifically, the first mobility management network element determines that the user equipment needs to switch to the second mobility management network element based on the identifier of the user equipment.
[0017] In one possible implementation, setting the security context used between the first mobility management network element and the user equipment to a native security context according to the TAU request message includes: determining the identifier of the user equipment according to the TAU request message, the TAU request message including the identifier; determining first indication information corresponding to the identifier according to the identifier, the indication information coming from the AMF; and determining to authenticate the user equipment according to the first indication information.
[0018] In the above possible implementations, the first mobility management network element can trigger authentication of the user equipment based on the first instruction information, thereby improving the flexibility of security context synchronization and enhancing the service continuity of the user equipment.
[0019] In one possible implementation, the first indication information is at least one of authentication indication information, 5G access type, or tunnel identifier.
[0020] In the above possible implementations, the first mobility management network element can determine that the user equipment is switching from the 5G network to the first network based on at least one of the authentication indication information, the 5G access type, or the tunnel identifier, thereby triggering authentication of the user equipment. When the user equipment needs to switch from the first mobility management network element to other mobility management network elements within the first network due to mobility or other reasons, it can avoid the situation where the user equipment's access is rejected by other mobility management network elements due to security context asynchrony, thereby improving the flexibility of security context synchronization and enhancing the service continuity of the user equipment.
[0021] In one possible implementation, the first network is a 4G network and the second network is a 5G network.
[0022] In a second aspect, an information transmission method is provided, applied to a first mobility management network element, the method comprising: the first mobility management network element determining that a user equipment switches from a second network to a first network, the first network including the first mobility management network element and a second mobility management network element; the first mobility management network element sending second indication information to the second mobility management network element, the second indication information indicating the mapped security context of the user equipment, or instructing the second mobility management network element to authenticate the user equipment.
[0023] In the above possible implementations, in the scenario where a user equipment switches from the second network to the first network and then switches from the first mobility management network element to the second mobility management network element, the first mobility management network element can send a second instruction information to the second mobility management network element so that the second mobility management network element can synchronize the security context used by the second mobility management network element and the user equipment according to the instruction, thereby avoiding the user equipment's access being denied and improving the service continuity of the user equipment.
[0024] In one possible implementation, the second indication information includes at least one of the following: 5G security algorithm, 5G radio access type, 5G or next-generation radio security capability, or tunnel identification.
[0025] In the above possible implementations, the first mobility management network element can send 5G network-related indication information to the second mobility management network element to indicate that the user equipment is switching from the 5G network to the first network. In this way, the second mobility management network element can synchronize the security context with the user equipment through the above indication information.
[0026] In one possible implementation, the first network is a 4G network and the second network is a 5G network.
[0027] Thirdly, an information transmission method is provided, applied to a second mobility management network element, the second mobility management network element belonging to a first network, the first network further including the first mobility management network element, and a user equipment (UE) switching from the second network to the first network. The method includes: determining that the UE is switching from the first mobility management network element to the second mobility management network element; receiving second indication information from the first mobility management network element, the second indication information indicating that the security context of the UE is a mapped security context, or indicating that the second mobility management network element authenticates the UE; and determining the security context used between the second mobility management network element and the UE based on the second indication information.
[0028] In the above possible implementations, in the scenario where a user equipment switches from the second network to the first network and then switches from the first mobility management element to the second mobility management element, the second mobility management element can receive second indication information from the first mobility management element to determine the synchronization of the security context with the user equipment, thereby preventing the second mobility management element from refusing access to the user equipment, improving the service continuity of the user equipment, and enhancing communication performance.
[0029] In one possible implementation, the second indication information indicates that the security context of the user equipment is a mapped security context. Determining the security context used between the second mobility management network element and the user equipment based on the second indication information includes: determining that the security context used between the second mobility management network element and the user equipment is a mapped security context.
[0030] In the above possible implementations, the second mobility management network element can determine the security context used with the user equipment as the mapped security context based on the security context of the user equipment indicated by the second indication information, ignoring the locally stored security context type, thereby avoiding the second mobility management network element from rejecting the user equipment's access and improving the service continuity of the user equipment.
[0031] In one possible implementation, the second indication information includes at least one of the following: 5G security algorithm, 5G radio access type, 5G or next-generation network security capabilities, or tunnel identifier. Determining the security context used between the second mobility management network element and the user equipment based on the second indication information includes: determining that the security context used between the second mobility management network element and the user equipment is a mapped security context.
[0032] In the above possible implementations, the second mobility management network element can determine whether the user equipment is switching from the 5G network to the first network based on the above indication information, thereby improving the flexibility of the second indication information configuration, making it easier to synchronize the security context, and improving the service continuity of the user equipment.
[0033] In one possible implementation, the second instruction information instructs the second mobility management network element to authenticate the user equipment. Determining the security context used between the second mobility management network element and the user equipment based on the second instruction information includes: the second mobility management network element authenticating the user equipment and setting the security context used between the second mobility management network element and the user equipment as a local security context.
[0034] In the above possible implementations, the second mobility management network element can also authenticate the user equipment according to the second instruction information. After authentication, the security context used between the second mobility management network element and the user equipment can be unified as the local security context, avoiding the rejection of the user equipment's access request and ensuring the continuity of the user's services.
[0035] In one possible implementation, the first network is a 4G network and the second network is a 5G network.
[0036] Fourthly, an information transmission device is provided, the device including a receiving module for receiving a Tracking Area Update (TAU) request message from a user equipment, wherein the user equipment switches from a second network to a first network and the device belongs to the first network; and a processing module for setting the security context used between the device and the user equipment to a native security context according to the TAU request message.
[0037] In one possible implementation, the processing module is specifically used to authenticate the user equipment.
[0038] In one possible implementation, the TAU request message includes the user equipment's status information. The processing module is specifically used to: authenticate the user equipment if the status information indicates that the user equipment is switching from the second network to the first network, or if the status information indicates the user equipment's mobility management registration information of the second network, or if the status information indicates that the user equipment has the network security capabilities of the second network, or if the status information indicates that the user equipment has the N1 interface capabilities of the second network.
[0039] In one possible implementation, based on the TAU request message, the processing module is specifically used to: determine the identifier of the user equipment based on the TAU request message; determine that the location of the user equipment has changed based on the identifier of the user equipment; and authenticate the user equipment.
[0040] In one possible implementation, the processing module is specifically used to: determine whether the user equipment needs to switch to the second mobility management network element based on the user equipment's identifier.
[0041] In one possible implementation, the processing module is specifically used to: determine the identifier of the user equipment based on the TAU request message, the TAU request message including the identifier; determine the first indication information corresponding to the identifier based on the identifier, the first indication information coming from the core access and mobility management function (AMF) network element; and determine to authenticate the user equipment based on the first indication information.
[0042] In one possible implementation, the first indication information is at least one of authentication indication information, 5G access type, or tunnel identifier.
[0043] In one possible implementation, the first network is a 4G network and the second network is a 5G network.
[0044] Fifthly, an information transmission apparatus is provided, comprising: a processing module, configured to determine that a user equipment switches from a second network to a first network, and to determine that the user equipment switches from a first mobility management network element to a second mobility management network element, wherein the first network includes the apparatus and the second mobility management network element; and a sending module, configured to send second indication information to the second mobility management network element, wherein the second indication information indicates the mapped security context of the user equipment, or instructs the second mobility management network element to authenticate the user equipment.
[0045] In one possible implementation, the second indication information includes at least one of the following: 5G security algorithm, 5G radio access type, 5G or next-generation radio security capability, or tunnel identification.
[0046] In one possible implementation, the first network is a 4G network and the second network is a 5G network.
[0047] Sixthly, an information transmission apparatus is provided, the apparatus belonging to a first network, the first network further including a first mobility management network element, and a user equipment (UE) switching from a second network to the first network, characterized in that the apparatus includes: a processing module, configured to determine that the UE switches from the first mobility management network element to the apparatus; a receiving module, configured to receive second indication information from the first mobility management network element, the second indication information indicating that the security context of the UE is a mapped security context, or indicating that the apparatus authenticates the UE; the processing module is further configured to determine the security context used between the apparatus and the UE based on the second indication information.
[0048] In one possible implementation, the processing module is specifically used to: determine that the security context used between the device and the user equipment is a mapped security context when the second indication information indicates that the security context of the user equipment is a mapped security context.
[0049] In one possible implementation, the processing module is specifically used to: determine the security context used between the device and the user equipment as a mapped security context when the second indication information includes at least one of the following: a 5G security algorithm, a 5G wireless access type, a 5G or next-generation network security capability, or a tunnel identifier.
[0050] In one possible implementation, the processing module is specifically used to: when the second indication information indicates that the device authenticates the user equipment, authenticate the user equipment and set the security context used between the device and the user equipment to a local security context.
[0051] In one possible implementation, the first network is a 4G network and the second network is a 5G network.
[0052] A seventh aspect provides a communication device including a processor and a transmission interface; wherein the processor is configured to execute instructions stored in a memory to cause the device to perform the method as described in any one of the first aspects above.
[0053] Eighthly, a computer-readable storage medium is provided, including a program or instructions that, when executed by a processor, perform the method described in any one of the first aspects above.
[0054] Ninth aspect, a computer program product is provided that, when the computer program product is run on a computer or processor, causes the computer or processor to perform the method as described in any one of the first aspects above.
[0055] A tenth aspect provides a communication device, characterized in that the communication device includes a processor and a transmission interface; wherein the processor is configured to execute instructions stored in a memory to cause the device to perform the method as described in any one of the second aspects above.
[0056] Eleventh aspect: A computer-readable storage medium is provided, characterized in that it includes a program or instructions that, when the program or instructions are run by a processor, execute the method described in any one of the second aspects above.
[0057] In a twelfth aspect, a computer program product is provided that, when run on a computer or processor, causes the computer or processor to perform the method as described in any one of the second aspects above.
[0058] In a thirteenth aspect, a communication device is provided, characterized in that the communication device includes a processor and a transmission interface; wherein the processor is configured to execute instructions stored in a memory to cause the device to perform the method as described in any one of the third aspects above.
[0059] In a fourteenth aspect, a computer-readable storage medium is provided, characterized in that it includes a program or instructions that, when run by a processor, execute the method described in any one of the third aspects above.
[0060] In a fifteenth aspect, a computer program product is provided that, when the computer program product is run on a computer or processor, causes the computer or processor to perform the method as described in any one of the third aspects above.
[0061] In a sixteenth aspect, a communication system is provided, characterized in that it includes the apparatus as described in any one of the second aspects and the apparatus as described in any one of the third aspects.
[0062] It is understood that any of the information transmission methods, communication devices, communication systems, computer-readable storage media or computer program products provided above can be implemented by the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding methods provided above, and will not be repeated here. Attached Figure Description
[0063] Figure 1 A schematic diagram of the communication system provided in the embodiments of this application;
[0064] Figure 2 A flowchart illustrating an information transmission method provided in an embodiment of this application;
[0065] Figure 3 Implementation process of an information transmission method provided in this application embodiment Figure 1 ;
[0066] Figure 4 A flowchart illustrating another information transmission method provided in an embodiment of this application;
[0067] Figure 5 Implementation process of an information transmission method provided in this application embodiment Figure 2 ;
[0068] Figure 6 Implementation process of an information transmission method provided in this application embodiment Figure 3 ;
[0069] Figure 7 A schematic diagram of an information transmission device provided in an embodiment of this application;
[0070] Figure 8 A schematic diagram of another information transmission device provided in the embodiments of this application;
[0071] Figure 9 A schematic diagram of another information transmission device provided in the embodiments of this application;
[0072] Figure 10 This is a schematic diagram of a communication device provided in an embodiment of this application. Detailed Implementation
[0073] The terms "first," "second," and "third," etc., used in the specification, claims, and drawings of this application are used to distinguish different objects, not to limit a specific order. In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0074] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0075] First, to facilitate understanding of this application, the relevant technologies involved in the embodiments of this application will now be described.
[0076] 4G and 5G network interoperability architecture:
[0077] like Figure 1The diagram illustrates the existing 4G and 5G network interoperability architecture. Specifically, the 4G and 5G networks share the following network elements: User Plane Function (UPF) network element, PDN Gateway User Plane Function (PGW-U) network element, Session Management Function (SMF) network element, PDN Gateway Control Plane Function (PGW-C) network element, Policy Control Function (PCF) network element, Policy and Charging Rules Function (PCRF) network element, Home Subscriber Server (HSS) network element, and Unified Data Management (UDM) network element. Here, "+" indicates co-location. UPF stands for User Plane Function of 5G Network, PGW-U is the Gateway User Plane Function of 4G Network corresponding to UPF, SMF is the Session Management Function of 5G Network, PGW-C is the Gateway Control Plane Function of 4G Network corresponding to SMF, PCF is the Policy Control Function of 5G Network, and PCRF is the Policy Charging Rule Function of 4G Network corresponding to PCF. In this embodiment, for ease of description, the HSS+UDM network element is referred to as the User Data Management Network Element, and the PGW-C network element+SMF network element is referred to as the Control Plane Function Network Element. This is a unified explanation and will not be repeated below. Of course, the network device after the above co-location can also be called by other names, and this embodiment does not specifically limit it.
[0078] In addition, such as Figure 1 As shown, the aforementioned 4G and 5G network interoperability architecture may further include an MME and a Serving Gateway (SGW) in the 4G network, and an AMF network element in the 5G network. Optionally, the 4G and 5G network interoperability architecture may also include a network slice selection function (NSSF) network element. Wherein, when the AMF network element cannot select a network slice for the terminal, the AMF network element may request the NSSF network element to select a network slice for the terminal; this embodiment does not specifically limit this.
[0079] Specifically, terminals access the 4G network through Evolved Universal Terrestrial Radio Access Network (E-UTRAN) equipment, and the 5G network through Next Generation Radio Access Network (NG-RAN) equipment. E-UTRAN equipment communicates with the MME via the S1-MME interface, with the SGW via the S1-U interface, with the SGW via the S11 interface, with the user data management network element via the S6a interface, with the AMF network element via the N26 interface, with the PGW-U network element + UPF network element via the S5-U interface, with the PGW-C network element + SMF network element via the S5-C interface, with the PGW-U network element + UPF network element via the N3 interface, and with the NG-RAN equipment via the N3 interface. The N4 interface communicates with the PGW-C network element and the SMF network element. The PGW-C network element and the SMF network element communicate with the PCRF network element and the PCF network element through the N7 interface. The HSS+UDM network element communicates with the PGW-C network element and the SMF network element through the N10 interface. The HSS+UDM network element communicates with the AMF network element through the N8 interface. The PCRF network element and the PCF network element communicate with the AMF network element through the N15 interface. The PGW-C network element and the SMF network element communicate with the AMF network element through the N11 interface. The AMF network element communicates with the NG-RAN equipment through the N2 interface. The AMF network element communicates with the terminal through the N1 interface.
[0080] It should be noted that, Figure 1 The interface names between the various network elements are just examples. In actual implementations, the interface names may be different. This application does not specifically limit this.
[0081] It should be noted that NG-RAN equipment in a 5G network can also be called access equipment. This access equipment refers to equipment that accesses the core network, such as base stations, broadband network gateways (BNGs), aggregation switches, and non-3GPP access equipment. Base stations can include various forms, such as macro base stations, micro base stations (also known as small stations), relay stations, and access points. This application embodiment does not specifically limit these types.
[0082] Of course, there can be other network elements in 4G and 5G networks. For example, 4G networks can also include serving GPRS support nodes (SGSN), and 5G networks can also include authentication server function (AUSF) network elements. This application does not specifically limit these.
[0083] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0084] In combination with the above Figure 1 The communication system architecture shown in this application is mainly applied to scenarios where 5G and 4G networks interoperate. When a user equipment (UE) switches from a 5G network to a 4G network, if the UE then undergoes another handover between MMEs, access may be denied due to a lack of security context synchronization. Here, handover refers to the process where, when a UE moves from one base station coverage area to another during communication, or when communication quality degrades due to external interference, it needs to switch to a new channel to continue service.
[0085] The handover between MMEs for a user equipment (UE) mainly includes two scenarios: Scenario 1 and Scenario 2. Scenario 1 refers to a situation where a UE moves from the 5G network's AMF to the 4G network's MME1. When MME1 determines that the UE's movement necessitates a handover to MME2, the security context carried in the relocation request message sent by MME1 to MME2 is a mapped security context. However, in existing implementations, MME2 does not obtain the type of this security context. Based on the fact that the relocation request message originates from MME1 in the 4G network, it assumes the security context is a native security context and saves it as such. Therefore, when MME2 receives a TAU request from the UE, it rejects the UE's TAU request and sends a rejection indication (e.g., TAU#9) because the mapped security context in the TAU request does not match the locally saved native security context for the UE. This results in the UE needing to wait a period of time before being able to reconnect, severely impacting the continuity of UE services.
[0086] Scenario 2 involves a user equipment (UE) moving from the 5G network's AMF to the 4G network's MME1. The UE establishes a non-access stratum (NAS) connection with MME1, then enters an idle state. While in idle state, the UE moves again. When it moves outside MME1's coverage area, it sends a TAU request message to MME2. MME2, based on the user identifier carried in the TAU request message, determines that the UE originated from MME1 and therefore actively requests a security context from MME1. MME1 replies with a security context response message. However, in existing implementations, MME2 does not obtain the type of the security context; it does not know whether the received security context is of a native or mapped type. Since the security context response message originates from the 4G network MME1, MME2 classifies it as a native context and saves it as such. Therefore, if the mapped security context carried in the TAU request is inconsistent with the native security context corresponding to the user equipment stored locally, the MME2 will reject the user equipment's TAU request and send a rejection indication, such as TAU#9, causing the user equipment to need to wait for a period of time before it can access the network again, which seriously affects the continuity of UE services.
[0087] Combination Figure 1 Based on the existing communication network structure and the aforementioned implementation scenarios, this application provides an information transmission method to address the issue of security context synchronization during MME handover for user equipment, thereby preventing access denial due to security context asynchrony. Figure 2 As shown, the method may include:
[0088] 201: The first mobility management network element receives a Tracking Area Update (TAU) request message from the user equipment.
[0089] The user equipment is switching from the second network to the first network, and the first mobility management network element belongs to the first network.
[0090] In one implementation, the first network can be a 4G network, the second network can be a 5G network, and the first mobility management element can be an MME1, meaning the user equipment switches from a 5G network to a 4G network MME1 for connectivity. Alternatively, in one implementation, the first network can be a 5G network, and the second network can be a next-generation or previous-generation mobile communication network, such as a sixth-generation (6G) network or a 4G network. This application does not impose specific limitations on this.
[0091] In one implementation, the mobility management network element may specifically be as described above. Figure 1 The MME shown may be another network element with similar functionality. This application does not specifically limit this.
[0092] 202: The first mobility management network element sets the security context used between the first mobility management network element and the user equipment to the native security context according to the TAU request message.
[0093] Specifically, step 202 above, setting the security context used between the first mobility management network element and the user equipment as a native security context, may include:
[0094] The first mobility management network element triggers authentication of the user equipment, so that the security context between the first MME and the user equipment is unified as a native security context.
[0095] In one implementation, the TAU request message may include the status information of the user equipment, then the first mobility management network element determines to trigger authentication of the user equipment, which may specifically include at least one of the following:
[0096] 1. If the status information of the user equipment indicates that the user equipment is switching from the second network to the first network, the first mobility management network element authenticates the user equipment.
[0097] For example, the TAU request message may include indication information, which may be used to indicate that the user equipment is switching from a 5G network to a 4G network, or the indication information may be used to indicate that the TAU request message is a TAU request after the user equipment has switched from a 5G network to a 4G network. Then MME1 will trigger authentication for the UE.
[0098] Specifically, authentication can be performed using an authentication and key agreement (AKA). For example, if MME1 does not possess the UE's International Mobile Subscriber Identity (IMSI), MME1 sends an identity request message to the UE, obtains the IMSI from the UE, sends the IMSI to the Home Subscriber Server (HSS), obtains the authentication vector, and then performs authentication. Alternatively, if MME1 possesses the IMSI or obtains it from another MME, it sends the IMSI to the HSS, obtains the authentication vector, and then performs authentication.
[0099] The specific process for certification can be found in the description of the relevant technologies; this application does not impose any specific limitations on it.
[0100] 2. If the status information of the user equipment indicates the mobility management registration information of the second network of the user equipment, then the first mobility management network element authenticates the user equipment.
[0101] For example, the status information in the TAU request message can be mobility management registration information. This includes, for instance, UE status, which indicates whether the UE has registered with 5G Mobility Management (MM). If the UE has registered with 5G MM, the MME1 determines that the security context corresponding to the UE is mapped.
[0102] 3. If the status information of the user equipment indicates that the user equipment has the network security capabilities of the second network, then the first mobility management network element authenticates the user equipment.
[0103] For example, the TAU request message may include the network security capabilities of the user equipment, such as UE 5G security capabilities or next-generation wireless security capabilities.
[0104] 4. If the status information of the user equipment indicates that the user equipment has the capability of the N1 interface of the second network, then the first mobility management network element authenticates the user equipment.
[0105] For example, the N1 interface is the interface between the UE and the AMF.
[0106] In another implementation, step 202 above, where the first mobility management network sets the security context used between the first mobility management network element and the user equipment to a native security context based on the TAU request message, may further include:
[0107] Step 1: The first mobility management network element determines the identifier of the user equipment based on the TAU request message.
[0108] The TAU request message may carry the identifier of the user equipment, such as the globally unique temporary UE identity (GUTI) or the international mobile subscriber identity (IMSI).
[0109] Step 2: The first mobility management network element determines the first instruction information corresponding to the identifier based on the identifier.
[0110] Specifically, the first indication information may be authentication indication information, tunnel identifier, or access type.
[0111] The authentication indication information, or tunnel identifier, or access type, is used to indicate the authentication of the user equipment, and the first indication information comes from the AMF network element.
[0112] The MME1 can determine whether to trigger authentication for the user based on the authentication indication information, the tunnel identifier, or the access type. For example, if the tunnel identifier indicates that the peer is a 5G network, or the access type indicates that it is a 5G network access method, then authentication for the user will be triggered.
[0113] It should be noted that this authentication indication information can be carried in the forward relocation request message from the AMF before the first mobility management network receives the TAU request from the user equipment. This authentication indication information can be used to indicate that the user equipment is from the 5G network and can trigger authentication for the device to synchronize the security context. The specific implementation process will be described in detail in the embodiments below, and will not be repeated here.
[0114] Alternatively, the authentication indication information can also be carried in the context response message sent by the AMF after the first mobile management network receives a TAU request from the user equipment. This authentication indication information can be used to indicate that the user equipment is from a 5G network and can trigger authentication for the device to synchronize the security context. The specific implementation process will be described in detail in the embodiments below, and will not be repeated here.
[0115] In one implementation, the first indication information may also be a tunnel identifier, which includes a tunnel identifier used to indicate that the AMF is an AMF within the 5G network; it may be a GTP-C tunnel identifier.
[0116] In addition, the first indication information can also be the access type, which indicates whether the current network is a 5G network or a 5G wireless network; or it can be a RAT type.
[0117] Step 3: The first mobility management network element determines to authenticate the user equipment based on the first instruction information.
[0118] Based on the UE's identifier, MME1 determines the first indication information corresponding to the UE, triggers authentication with the UE, establishes a unified native security context between MME1 and the UE, and then executes the handover process from MME1 to MME2.
[0119] Through the above embodiments of this application, when a user equipment (UE) switches from a second network to a first network and its location changes, requiring a handover between Mobility Management Elements (MMEs), the MME can trigger authentication of the UE. For example, when the UE switches from MME1 to MME2, MME1 can trigger authentication of the UE. In the prior art, this authentication process is not mandatory, but in the embodiments of this application, it is determined that in this scenario, the MME triggers authentication of the UE to synchronize the security context type.
[0120] After authentication, the security context between the user equipment and MME1 is saved as native. When the handover process from MME1 to MME2 is executed later, the problem of inconsistent security context types will not occur. This avoids the user equipment being rejected by MME2 due to inconsistent security contexts, thereby improving the service continuity of the user equipment.
[0121] Below, using the above scenario as an example, with the first network being a 4G network, the second network being a 5G network, and the first mobility management element being MME1, the communication process corresponding to the above-described implementation method of this application will be explained. Figure 3 As shown, the base station for the 4G network can be an eNB, and the base station for the 5G network can be a gNB or an ng-eNB.
[0122] 301: gNB / ng-eNB sends a handover request message to AMF.
[0123] When a 5G network base station detects that a user equipment needs to be handed over, it sends a handover request message (handoverrequired) to the AMF.
[0124] 302: AMF sends a forward relocation request message to MME1, including eKSI.
[0125] When the AMF determines that the user equipment needs to switch to the 4G network, it obtains the eKSI based on the AMF's local 5G KSI (abbreviated as ngKSI) to indicate that the security context corresponding to the user equipment is the mapped security context.
[0126] AMF sends a forward relocation request message to MME1. This message includes an eKSI, which indicates that the security context type is a mapped security context. The eKSI identifies the corresponding security context; for example, it may include the Kasme key, or the NAS protection key and protection algorithm. It should be noted that the eKSI information may include a counter identifying the security context and the type of security context flag (TSC). The TSC identifies the type of security context, which can be either native or mapped.
[0127] Depending on the specific implementation of the standard, the forward relocation request message only sends a counter that identifies the security context, excluding the TSC portion. Therefore, MME1 does not know whether the received security context is of native type or mapped type.
[0128] In addition, as shown in Step 2 of the aforementioned implementation, the forward relocation request message sent by the AMF to the MME1 may also include first indication information, which instructs the MME1 to authenticate the user equipment.
[0129] Specifically, the first indication information can be authentication indication information. According to Step 2 in the aforementioned implementation, the first indication information can also be a tunnel identifier. That is, the forward relocation request message sent by the AMF to the MME1 may also include a tunnel identifier. Here, the tunnel identifier includes a tunnel identifier used to indicate that the AMF is an AMF in the 5G network; it can be a GTP-C tunnel identifier.
[0130] In addition, as shown in Step 2 of the aforementioned implementation, the first indication information may also be an access type, that is, the forward relocation request message sent by the AMF to the MME1 may also include an access type, which is used to indicate that the current network is a 5G network access or a 5G wireless network access type; or the first indication information may also be an access type, such as RATtype.
[0131] 303: MME1 sends an S1 handover request to eNB.
[0132] 304: The eNB sends an S1 handover response to the MME1.
[0133] This includes the configuration of the eNB, and the specific details can be found in the relevant descriptions in the existing technology. This application does not impose any restrictions on this.
[0134] 305: MME1 sends a forward relocation response message to AMF.
[0135] MME1 sends a forward relocation response message to AMF.
[0136] 306: The AMF sends a handover response message to the gNB / ng-eNB.
[0137] 307: gNB / ng-eNB sends a handover response message to the user equipment.
[0138] 308: The user equipment generates eKSI information, and the security context corresponding to the eKSI is the mapped security context.
[0139] Specifically, the UE generates an eKSI indicating a mapped security context based on the indication that the local ngKSI (used to identify the security context of the 5G network) is a native security context. The location where the UE generates the eKSI is not limited; it can also be generated when sending a TAU request message to the MME1.
[0140] 309: The user equipment sends a handover completion message to the eNB.
[0141] 310: The eNB sends a handover request message to MME1.
[0142] 311: The user equipment sends a TAU request message to MME1.
[0143] The TAU request message can carry the user equipment's GUTI identifier and the corresponding eKSI. The eKSI indicates the mapped context. Here, the GUTI can be generated by the MME1 steps mentioned above (e.g., generated by step 305) and sent to the UE via the AMF.
[0144] According to the possible implementations of step 202 in the above embodiments, the TAU request message may include user equipment status information. For example, the user equipment status information indicates that the user equipment has switched from a 5G network to a 4G network. Alternatively, the user equipment status information is UE status, indicating whether the UE has registered in 5GMM. Alternatively, the user equipment status information indicates the user equipment's 5G radio security capabilities, or next-generation network radio security capabilities, etc. Alternatively, the user equipment status information is used to indicate that the TAU request message is a TAU message after switching from 5G to 4G.
[0145] Furthermore, as shown in Steps 1 to 3 of the above embodiments, MME1 may also obtain the authentication indication information corresponding to the user equipment based on the user equipment's GUTI identifier carried in the TAU request message. Thus, MME1 can determine whether to trigger authentication for the user based on the authentication indication information, the tunnel identifier, or the access type. For example, if the tunnel identifier determines that the peer is a 5G network, or the access type determines that it is a previous 5G network access method, then authentication for the user is triggered.
[0146] 312: MME1 triggers authentication of the user equipment based on the TAU request message, generates a new security context, and thus determines the security context used between MME1 and the user equipment as the native security context.
[0147] After authentication and NAS security mode control (SMC) are completed between the user equipment and MME1, the user equipment and MME1 share the native security context. According to existing technology, the security context determined by both parties after authentication and NAS security mode control is the native security context.
[0148] In another implementation, after the user equipment switches from the second network to the first network, the user equipment establishes a NAS connection with the first mobility management network element, which is in a connected state, i.e., scenario two applicable to the aforementioned embodiments of this application. Then, in step 202 above, the first mobility management network element sets the security context used between the first mobility management network element and the user equipment to a native security context based on the TAU request message, which may further include:
[0149] The first mobility management network element can trigger authentication of the user equipment based on the location change of the user equipment, so that the security context used between the first mobility management network element and the user equipment is set to the native security context.
[0150] In conjunction with specific implementation methods, such as Figure 3 As shown, after step 311 in the above embodiment, the user equipment can establish a NAS connection with the first mobility management network element (MME1), and the user equipment then enters the connected state. At this time, the MME1 in step 312 can trigger authentication of the user equipment based on the TAU request message, which may further include:
[0151] The first mobility management element can trigger authentication of user devices based on changes in the user's location.
[0152] The first mobility management network element triggers authentication of the user equipment based on the user's location change, which may specifically include:
[0153] Step 1: The first mobility management network element determines the identifier of the user equipment based on the TAU request message.
[0154] For example, taking MME1 as the first mobility management network element, after the UE switches from a 5G network to a 4G network, the UE establishes a NAS connection with MME1, which is in a connected state. MME1 can obtain the identifier of the user equipment based on the GUTI identifier carried in the TAU request message. Optionally, the identifier of the user equipment can be a permanent identifier or a GUTI identifier.
[0155] Step 2: The first mobility management network element determines that the location of the user equipment has changed based on the user equipment's identifier.
[0156] Specifically, the first mobility management network element determines that the location information of the user equipment has changed based on the user equipment's identifier. This mainly refers to the first mobility management network element determining that the user equipment needs to be switched to the second mobility management network element based on the user equipment's identifier.
[0157] For example, a change in the location of a user equipment can specifically mean that the user equipment moves outside the range of MME1, and the user equipment needs to perform a handover between MMEs, such as a handover from MME1 to MME2.
[0158] The location information of the user equipment (UE) can come from information reported by network devices received by the first mobility management element. Specifically, the UE's location information can be obtained from the base station; for example, the base station periodically reports changes in the UE's location information. For instance, the base station reports the tunnel identifier between the base station and the MME bound to the UE, along with measurement information. The tunnel identifier between the base station and the MME is related to the UE and can be distributed by either the MME or the base station without restriction. The MME determines the UE's identifier based on the tunnel identifier between the base station and the MME, and then determines whether an MME handover needs to be performed based on the measurement information. The specific information content uploaded by the base station and the operation method by which the MME1 determines that an MME handover needs to be performed can refer to existing technologies without restriction.
[0159] Alternatively, the location information of the user equipment can come from a location management network element, which monitors the location information of the user equipment. For example, the UE's GUTI or IMSI can be sent to the location management network element for the MME1. When the location management network element detects a change in the UE's location, it sends the UE's location information to the MME1.
[0160] Additionally, MME1 may also determine whether an MME handover needs to be performed, such as a handover from MME1 to MME2, based on the UE location information carried in the handover request (handover required) sent by the network device eNB. The method for determining whether an MME handover needs to be performed can refer to existing technologies, and this application does not impose any limitations on it.
[0161] Step 3: The first mobility management network element authenticates the user equipment.
[0162] When MME1 determines that an MME handover needs to be performed, MME1 triggers authentication of the user equipment.
[0163] Optionally, if MME1 determines that an MME handover needs to be performed, and MME1 has already performed two-way authentication with the user equipment, then it is not necessary to trigger authentication for the user equipment again.
[0164] Optionally, if MME1 determines that an MME switch needs to be performed, and MME1 has already been unified with the user equipment into a native security context, then it is not necessary to trigger authentication for the user equipment again.
[0165] When MME1 determines that the UE's location is about to exceed the tracking area (TA) or the area covered by MME1, MME1 triggers authentication with the UE. MME1 and the UE are unified into a native security context, and then the handover process from MME1 to MME2 is executed.
[0166] Through the implementation methods provided in this application, when a user equipment switches from a second network to a first network, the user equipment undergoes location movement, and when it is determined that the user equipment is about to undergo a handover between mobility management network elements, authentication of the user equipment is triggered, resulting in the user equipment needing to handover between mobility management network elements. In such scenarios, the mobility management network element can trigger authentication of the user equipment to synchronize the security context between the user equipment and the mobility management network element. Afterwards, when the handover process between mobility management network elements is executed, the problem of inconsistent security context types will not occur, avoiding the problem of the user equipment's TAU request being rejected, thereby improving the service continuity of the user equipment.
[0167] Optionally, the determination of whether authentication is required can also be made by combining the user equipment status information carried in the previous TAU message with the indication information 1 received by MME1 from AMF. Here, indication information 1 can be authentication indication information, tunnel identifier, or access type. For example, authentication is performed only when MME handover is required, and the TAU carries the user equipment status information, or after receiving indication information 1 from AMF.
[0168] In another implementation, when a user equipment switches from a second network to a first network, causing a location change, and when it is determined that a handover between mobility management network elements is about to occur, for example, when the user equipment requests a handover from MME1 to MME2, specific indication information can be used to enable MME2 to still synchronize the security context with the user equipment, thereby improving the service continuity of the user equipment.
[0169] This application provides another method for information transmission, such as... Figure 4 As shown, the method may include:
[0170] 401: The first mobility management network element determines that the user equipment is switching from the second network to the first network.
[0171] The first network includes a first mobility management network element and a second mobility management network element.
[0172] For example, the first network can be a 4G network, and the second network can be a 5G network. The first mobility management element can be MME1, and the second mobility management element can be MME2. The UE switches from the 5G network to the 4G network.
[0173] In addition, the first mobility management network element determines that the user equipment needs to switch from the first mobility management network element to the second mobility management network element. In other words, the first mobility management network element determines that the user equipment has moved and a handover between mobility management network elements is required.
[0174] 402: The first mobility management network element sends a second instruction message to the second mobility management network element.
[0175] In one implementation, the second indication information may indicate that the security context corresponding to the user equipment is a mapped security context. Alternatively, the second indication information may indicate that a second mobility management network element authenticates the user equipment.
[0176] In one implementation, if the second network is a 5G network, the second indication information may include at least one of the following: a 5G security algorithm, a 5G wireless access type, a 5G wireless security capability, or a tunnel identifier.
[0177] 403: The second mobility management network element receives a second instruction information from the first mobility management network element.
[0178] 404: The second mobility management element determines the security context used between the second mobility management element and the user equipment based on the second instruction information.
[0179] The second mobility management network element determines the security context used between itself and the user equipment based on the second instruction information, which may specifically include the following three methods.
[0180] If, in Method 1, the second indication information indicates that the security context of the user equipment is a mapped security context, then the second mobility management network element determines that the security context used between it and the user equipment is a mapped security context.
[0181] Method 2: The second indication information can be obtained based on some parameters of the user equipment sent by the first mobility management network element. For example, if the second indication information includes at least one of the following: 5G security algorithm, 5G wireless access type, 5G or next-generation network security capabilities, or tunnel identifier, then the security context used between the second mobility management network element and the user equipment is determined to be the mapped security context.
[0182] Method 3: If the second instruction information instructs the second mobility management network element to authenticate the user equipment, then the second mobility management network element authenticates the user equipment according to the second instruction information, and sets or unifies the security context used between the second mobility management network element and the user equipment to the local security context.
[0183] Through the embodiments provided in this application, when a user equipment switches from a second network to a first network, and the user equipment undergoes a location change, and when it is determined that the user equipment is about to switch from a first mobility management element to a second mobility management element, the second mobility management element can determine and synchronize the security context with the user equipment through the second indication information carried by the first mobility management element, or the second mobility management element can authenticate the user equipment through the second indication information carried by the first mobility management element, so that the security context between the second mobility management element and the user equipment is synchronized to a native security context. In this way, the second mobility management element will not reject the user equipment's TAU request due to the inconsistency of security context types, thereby improving the service continuity of the user equipment.
[0184] Below, using the above scenario as an example, taking the first network as a 4G network, the second network as a 5G network, the first mobility management network element as MME1, and the second mobility management network element as MME2, and the implementation scenario as a situation where the user equipment switches from the 5G network to the 4G network, and then the user equipment moves and needs to switch from MME1 to MME2, the communication process corresponding to the above implementation method of this application will be explained. Figure 5 As shown, the base station for the 4G network can be an eNB, and the base station for the 5G network can be a gNB or an ng-eNB.
[0185] Steps 301 to 310 can be referred to the relevant descriptions in the above embodiments.
[0186] 501: The eNB sends a handover request message to MME1.
[0187] This is used to indicate that the user equipment needs to perform a handover.
[0188] 502: MME1 has determined that the user equipment needs to be switched to MME2.
[0189] This step corresponds to step 401 described in the above embodiment: the first mobility management element determines that the user equipment needs to switch from the first mobility management element to the second mobility management element.
[0190] Specifically, MME1 can determine whether the user equipment needs to switch to MME2 based on the location movement of the user equipment. The specific implementation method can be referred to the relevant description of the prior art. This application embodiment does not make specific limitations on this.
[0191] 503: MME1 sends a forward relocation request message to MME2, which carries second indication information.
[0192] This step can correspond to step 402 in the above embodiment. The second instruction information may specifically include:
[0193] 1. The second indication information indicates that the security context of the user equipment is a mapped security context.
[0194] 2. The second indication information includes at least one of the following: 5G security algorithm, 5G wireless access type, 5G or next-generation network security capabilities, or tunnel identifier. It is used to instruct the MME2 to determine the security context based on the first indication information.
[0195] 3. The second instruction information may specifically be authentication instruction information, which is used to instruct MME2 to authenticate the user equipment corresponding to the forward relocation request message.
[0196] 504: MME2 replies to MME1 with a forward relocation response message.
[0197] 505: MME2 determines the security context used by this user.
[0198] This step corresponds to step 404 in the above embodiment, that is, MME2 can determine the security context used between MME2 and the user equipment based on the second indication information from MME1.
[0199] Specifically, MME2 determines whether the security context used with the user equipment is of type mapped or native, which may include:
[0200] 1. When the second indication information indicates that the security context corresponding to the user equipment is a mapped security context, then MME2 determines that the security context used with the user equipment is a mapped security context.
[0201] 2. When the second indication information includes at least one of the following indication information: 5G security algorithm, 5G wireless access type, 5G or next-generation network security capability, or tunnel identifier, the MME2 determines that the security context used with the user equipment is the mapped security context.
[0202] 3. When the second indication information is authentication indication information, the MME2 saves the authentication indication information corresponding to the user equipment.
[0203] When MME2 receives a TAU request message from a user equipment, it can obtain the corresponding authentication instruction information based on the user equipment's identifier, thereby authenticating the user equipment.
[0204] Alternatively, after MME2 receives a TAU request message from the user equipment, it first determines whether the user equipment's eKSI has a corresponding security context based on the user equipment's identifier, such as GUTI (e.g., if the eKSI indicates a mapped type security context, but the local storage is a native type security context, then the security context corresponding to the eKSI is not saved). If there is no corresponding security context, but the authentication indication information corresponding to the user equipment is saved, then the authentication of the user equipment is directly triggered based on the authentication indication, so that the security context used between MME2 and the user equipment is set to the local native security context.
[0205] Alternatively, a forward relocation request message may be sent, which does not carry the second indication information. MME2 will by default treat the security context received from MME1 as a native type security context. After MME2 receives a TAU request message from the user equipment, it may perform the following actions:
[0206] Method 1: MME2 updates the local security context corresponding to the user device to the mapped security context, ignoring the locally saved security context, in order to maintain synchronization with the user device's security context.
[0207] Method 2: MME2 can ignore the type of security context indicated by eKSI in the TAU request message. By default, the eKSI and the locally stored context type are consistent, that is, the security context synchronization between MME2 and the user equipment is determined to be of the native type.
[0208] Method 3: When the received type is mapped, but the local storage is native, MME2 triggers authentication of the user device to synchronize the security context used by MME2 and the user device to the native security context.
[0209] Method 4: MME2 triggers authentication of the user equipment based on the authentication indication information carried in the TAU request message sent by the user equipment, so that the security context used between MME2 and the user equipment is synchronized to the native security context.
[0210] Any of the above methods can achieve security context synchronization. The communication system can pre-select at least one of the strategies to configure the network elements designed in the above implementation methods to enable user equipment to achieve security context synchronization in the above scenarios. This application does not limit the specific configuration method.
[0211] Through the embodiments provided in this application, by configuring the second indication information in the location request message sent by the MME, when the user equipment switches from a 5G network to a 4G network, the user equipment moves its location, and when it is determined that the user equipment is about to switch from MME1 to MME2, MME2 can use the second indication information carried by MME1 to determine and synchronize the security context with the user equipment, or MME2 can use the second indication information carried by MME1 to authenticate the user equipment, so that the security context between MME2 and the user equipment is synchronized to a native security context. In this way, MME2 will not reject the user equipment's TAU request due to the inconsistency of security context types, thereby improving the service continuity of the user equipment.
[0212] In addition, this application embodiment also provides another information transmission method applicable to the above-mentioned scenario two, namely, after the user equipment moves from the AMF of the 5G network to the MME1 of the 4G network, the user equipment establishes a non-access stratum (NAS) connection with the MME1. Subsequently, the user equipment enters an idle state. If movement occurs while in the idle state, and the user equipment moves outside the coverage area of the MME1, the user equipment sends a TAU request message to the MME2. This application provides another information transmission method that allows the MME2 to determine the secure context synchronization used between the MME2 and the user equipment based on the message obtained from the MME1, thereby avoiding the rejection of the user equipment's TAU request and affecting the user's service continuity.
[0213] like Figure 6 As shown, the specific communication process may include:
[0214] Steps 301 to 311 can be referred to the relevant descriptions in the above embodiments.
[0215] 601: The user equipment establishes a NAS connection with the MME1.
[0216] At this point, MME1 receives a TAU request message from the user equipment in step 311, where the TAU request message includes the user equipment's GUTI representation and eKSI. MME1 determines that the security context used between MME1 and the user is a mapped security context, and then establishes a NAS connection with the user equipment.
[0217] After the user equipment enters the idle state, its location moves to the area covered by MME2.
[0218] 602: The user equipment sends a TAU request message to MME2.
[0219] The TAU request message may include the user equipment's GUTI and eKSI.
[0220] 603: MME2 sends a context request message to MME1.
[0221] MME2 requests the security context corresponding to the user equipment from MME1 based on the GUTI, that is, it sends a context request message to MME1.
[0222] The context request message includes the user device's GUTI.
[0223] 603: MME1 sends a context response message to MME2.
[0224] MME1 responds to MME2 with the security context corresponding to the user equipment based on the GUTI, that is, it sends a context response message to MME1. This context response message includes the eKSI; however, the eKSI does not include TSC information. If MME2 determines that the security context was received from the 4G MME1, then it determines that this security context is of native type.
[0225] 604: MME2 determines the security context used between MME2 and the user equipment.
[0226] MME2 first determines whether the security context corresponding to the user equipment is stored based on GUTI and eKSI. If the security context corresponding to the user equipment is stored, but the eKSI in the TAU request message sent by the user equipment indicates that the corresponding security context is of type "mapped", while the security context corresponding to the user equipment stored by MME2 is of type "native", then MME2 determines the security context to be used with the user equipment. Specifically, this can include the following methods:
[0227] Method 1: MME2 updates the local security context corresponding to the user device to the mapped security context, ignoring the locally saved security context, in order to maintain synchronization with the user device's security context.
[0228] Method 2: MME2 can ignore the type of security context indicated by eKSI in the TAU request message. By default, the eKSI and the locally stored context type are consistent, that is, the security context synchronization between MME2 and the user equipment is determined to be of the native type.
[0229] Method 3: When the received type is mapped, but the local storage is native, MME2 triggers authentication of the user device to synchronize the security context used by MME2 and the user device to the native security context.
[0230] Method 4: MME2 triggers authentication of the user equipment based on the authentication indication information carried in the TAU request message sent by the user equipment, so that the security context used between MME2 and the user equipment is synchronized to the native security context.
[0231] In another implementation, when a user equipment switches from a 5G network to a 4G network and from MME1 to MME2, the TAU request message sent by the user equipment to MME2 may include authentication indication information, so that MME2 can directly trigger authentication of the user equipment according to the authentication indication, thereby achieving synchronization of the security context.
[0232] Any of the above methods can achieve security context synchronization. The communication system can pre-select at least one of the strategies to configure the network elements designed in the above implementation methods to enable user equipment to achieve security context synchronization in the above scenarios. This application does not limit the specific configuration method.
[0233] Through the above-described embodiments provided in this application, when a user equipment switches from a 5G network to a 4G network and a handover occurs between MMEs, and the user equipment sends a TAU request to MME2, MME2 can determine, through pre-configuration, the default native secure downlink message type or the mapped security context indicated by eKSI, and update it to the mapped security context, or trigger authentication for the user equipment and update it to the native security context. This avoids MME2 rejecting the user equipment's TAU request due to inconsistencies in security context types, thereby improving the service continuity of the user equipment.
[0234] In another implementation, if the security context corresponding to the eKSI indication in the TAU request message sent by the user equipment (UE) received by MME2 is of type "mapped," while the security context corresponding to the UE stored by MME2 is of type "native," then MME2 sends a TAU rejection message to the UE. This TAU rejection message may carry third indication information, such as a TAU failure indication indicating a mismatch in the security context corresponding to the UE; or an indication that the UE should initiate initial access; or an indication that the UE should send an IMSI identifier; or other indications not related to TAU#9 failure. After receiving the third indication information included in the TAU rejection message, the UE can send an IMSI to MME2 to perform initial registration, thereby establishing a native security context with MME2. This primarily refers to not sending a rejection indication that requires the UE to wait for a period of time before accessing, thus allowing the UE to immediately perform access and maximizing service continuity.
[0235] Another implementation involves including a fourth indication in the handover completion message when the user equipment completes the handover from the second network to the first network. This fourth indication is stored by the first mobility management element. When the user equipment undergoes a handover between mobility management elements, the first mobility management element can trigger authentication of the user equipment based on the fourth indication to achieve security context synchronization.
[0236] Specifically, in combination with the above Figure 3As shown, in step 309 above, the user equipment sends a handover completion message to the eNB, which includes the fourth indication information. Then, the handover response message sent by the eNB to the MME1 may include this fourth indication information, and the MME1 can save the user equipment corresponding to this fourth indication information.
[0237] Subsequently, when a user equipment requests a handover from MME1 to MME2, after receiving the TAU request message (including GUTI and eKSI) from the user equipment, MME1 determines the locally stored fourth indication information based on the GUTI and triggers authentication for the user equipment. After authentication is completed, the user equipment and MME1 will share the native security context. Therefore, even if another MME handover occurs, there will be no inconsistency in the security context between the user equipment and MME2.
[0238] It should be noted that the idle state mentioned in this invention can be used to store context information between the UE and AMF, including a secure context. However, the NAS is currently inactive. Subsequent NAS messages can be used to securely activate the NAS connection, after which it will be in the connected state.
[0239] Based on the above Figure 2 and Figure 3 In addition to the aforementioned implementation methods, this application also provides an information transmission device, such as... Figure 7 As shown, the device 700 includes a receiving module 701 and a processing module 702.
[0240] The receiving module 701 is used to receive a Tracking Area Update (TAU) request message from a user equipment, whereby the user equipment switches from the second network to the first network, and the device belongs to the first network.
[0241] The processing module 702 is used to set the security context used between the device 700 and the user equipment to a native security context according to the TAU request message.
[0242] The processing module 702 can perform the processing other than sending and receiving performed by the first mobility management network element in the aforementioned method embodiment. Correspondingly, the receiving module 701 can perform the message receiving processing performed by the first mobility management network element in the aforementioned method embodiment.
[0243] In one implementation, the processing module 702 is specifically used to authenticate the user equipment.
[0244] In one implementation, the TAU request message includes the status information of the user equipment. The processing module 702 can be specifically used to: authenticate the user equipment if the status information indicates that the user equipment is switching from the second network to the first network, or if the status information indicates the mobility management registration information of the user equipment in the second network, or if the status information indicates that the user equipment has the network security capabilities of the second network, or if the status information indicates that the user equipment has the N1 interface capabilities of the second network.
[0245] In one implementation, based on the TAU request message, the processing module 702 may specifically be used to determine the identifier of the user equipment based on the TAU request message; determine that the location of the user equipment has changed based on the identifier of the user equipment; and authenticate the user equipment.
[0246] In one implementation, the processing module 702 can be specifically used to determine, based on the identifier of the user equipment, that the user equipment needs to switch to the second mobility management network element.
[0247] In one implementation, the processing module 702 may be specifically used to determine the identifier of the user equipment based on the TAU request message, the TAU request message including the identifier of the user equipment; determine the first indication information corresponding to the identifier based on the identifier, the first indication information being from the AMF; and determine to authenticate the user equipment based on the first indication information.
[0248] In one implementation, the first indication information is at least one of authentication indication information, 5G access type, or tunnel identifier.
[0249] In one implementation, the first network is a 4G network and the second network is a 5G network.
[0250] In addition, based on the above Figure 4 and Figure 5 The first mobility management network element in the illustrated embodiment, this application also provides an information transmission device, such as... Figure 8 As shown, the device 800 includes a transmitting module 801 and a processing module 802.
[0251] The processing module 801 is used to determine whether the user equipment switches from the second network to the first network and whether the user equipment switches from the first mobility management network element to the second mobility management network element. The first network includes the device 800 and the second mobility management network element.
[0252] The sending module 801 is also used to send second indication information to the second mobility management network element, the second indication information indicating the mapped security context of the user equipment, or instructing the second mobility management network element to authenticate the user equipment.
[0253] The processing module 801 can perform the processing other than sending and receiving performed by the first mobility management network element in the aforementioned method embodiment. Correspondingly, the sending module 801 can perform the message sending processing performed by the first mobility management network element in the aforementioned method embodiment.
[0254] In one implementation, the second indication information includes at least one of the following: 5G security algorithm, 5G wireless access type, 5G or next-generation wireless security capability, or tunnel identifier.
[0255] In one implementation, the first network is a 4G network and the second network is a 5G network.
[0256] Accordingly, based on the above Figure 4 and Figure 5 The second mobility management network element in the illustrated embodiment, this application also provides an information transmission device, such as... Figure 9 As shown, the device 900 includes a receiving module 901 and a processing module 902.
[0257] The receiving module 901 is used to receive second indication information from the first mobility management network element. The second indication information indicates that the security context of the user equipment is a mapped security context, or indicates that the device 900 authenticates the user equipment.
[0258] The processing module 902 is used to determine the security context used between the device 900 and the user equipment based on the second instruction information.
[0259] The processing module 902 can perform the processing other than sending and receiving performed by the second mobility management network element in the aforementioned method embodiment. Correspondingly, the receiving module 901 can perform the message receiving processing performed by the second mobility management network element in the aforementioned method embodiment.
[0260] In one embodiment, the processing module 902 is specifically used to: when the second indication information indicates that the security context of the user equipment is a mapped security context, determine that the security context used between the device 900 and the user equipment is a mapped security context.
[0261] In one implementation, the processing module 902 is specifically used to: when the second indication information includes at least one of the following indication information: 5G security algorithm, or 5G wireless access type, 5G or next-generation network security capability, or tunnel identifier, determine that the security context used between the device 900 and the user equipment is a mapped security context.
[0262] In one embodiment, the processing module 902 is specifically used to: when the second indication information indicates that the device 900 authenticates the user equipment, authenticate the user equipment and set the security context used between the device 900 and the user equipment to a local security context.
[0263] In one implementation, the first network is a 4G network and the second network is a 5G network.
[0264] It should be noted that the sending or receiving actions performed by the sending module or receiving module described in the above embodiments of this application may be executed under the control of a processing module (e.g., a processor). Therefore, in the embodiments of this application, the sending or receiving actions may also be described as being performed by the processing module (processor), which does not affect the understanding of the solution by those skilled in the art.
[0265] Figure 10 This is another structural schematic diagram of the communication device (any network element in the above embodiments) provided in the embodiments of this application. For example... Figure 10 As shown, the communication device 1000 includes a processor 1001 and a transceiver 1002. Optionally, the communication device 1000 also includes a memory 1003. The processor 1001, transceiver 1002, and memory 1003 can communicate with each other via internal connections to transmit control and / or data signals. The memory 1003 stores computer programs, and the processor 1001 retrieves and runs the computer programs from the memory 1003 to control the transceiver 1002 to transmit and receive signals. The communication device 1000 may also include an antenna for transmitting the signaling output by the transceiver 1002 via wireless signals.
[0266] The processor 1001 and memory 1003 described above can be combined into a single processing device. The processor 1001 executes the program code stored in the memory 1003 to achieve the aforementioned functions. In specific implementations, the memory 1003 can be integrated into the processor 1001 or be independent of the processor 1001.
[0267] Specifically, the communication device 1000 may correspond to various embodiments of the method according to the embodiments of this application. Furthermore, each unit in the communication device 1000 and the other operations and / or functions described above are respectively for implementing the corresponding processes in the various embodiments of the method.
[0268] The processor 1001 described above can be used to execute one or more actions implemented by the first mobility management network element or the second mobility management network element as described in the preceding method embodiments, while the transceiver 1002 can be used to execute one or more transmission or reception actions of the first mobility management network element or the second mobility management network element as described in the preceding method embodiments. For details, please refer to the descriptions in the preceding method embodiments; they will not be repeated here.
[0269] Optionally, the communication device 1000 may also include a power supply for providing power to various devices or circuits in the communication device.
[0270] The information transmission devices in the above-described apparatus embodiments can completely correspond to the first or second mobility management network element in the method embodiments, with corresponding modules or units executing corresponding steps. For example, when the device is implemented as a chip, the receiving module described above can be an interface circuit of the chip for receiving signals from other chips or devices. The transmitting unit described above is an interface circuit of the device used to transmit signals to other devices. For example, when the device is implemented as a chip, the transmitting module described above is an interface circuit of the chip used to transmit signals to other chips or devices.
[0271] It should be understood that the processor in the embodiments of this application can be a CPU, but it can also be other general-purpose processors, digital signal processing (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0272] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0273] This application also provides a communication system, which includes any of the first mobility management network elements or the second mobility management network elements provided in the above embodiments of this application.
[0274] This application also provides a computer-readable medium for storing computer program code, the computer program including instructions for executing the methods executed in the first mobility management network element or the second mobility management network element described above. The readable medium may be ROM or RAM, and this application does not limit its use.
[0275] This application also provides a computer program product including instructions that, when executed, cause a first mobility management network element or a second mobility management network element to perform operations corresponding to the above-described method.
[0276] This application also provides a system-on-a-chip (SoC) comprising a processing unit and a communication unit. The processing unit may be, for example, a processor, and the communication unit may be, for example, an input / output interface, pins, or circuitry. The processing unit can execute computer instructions to cause the communication device to which the chip is applied to perform the operations of the first mobility management network element or the second mobility management network element in the method provided in the above-described embodiments of this application.
[0277] Optionally, any of the communication devices provided in the above embodiments of this application may include the system chip.
[0278] Optionally, the computer instructions are stored in a storage unit.
[0279] Optionally, the storage unit can be an internal storage unit within the chip, such as a register or cache. Alternatively, it can be an external storage unit within the communication device, such as a ROM or other type of static storage device capable of storing static information and instructions, such as RAM. The processor mentioned above can be a CPU, microprocessor, ASIC, or one or more integrated circuits executing a program for controlling the aforementioned feedback information transmission method. The processing unit and the storage unit can be decoupled and disposed on different physical devices, connected via wired or wireless means to realize their respective functions, thereby supporting the system chip in implementing the various functions described in the above embodiments. Alternatively, the processing unit and the memory can be coupled to the same device. It should be understood that the processor in the embodiments of this application can be a CPU, but it can also be other general-purpose processors, DSPs, ASICs, FPGAs, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0280] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0281] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0282] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0283] In the several embodiments provided in this application, it should be understood that the disclosed systems, communication devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0284] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0285] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0286] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.
[0287] Finally, it should be noted that the above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An information transmission method, applied to a first mobility management network element, characterized in that, The method includes: The tracking area update (TAU) request message is received from the terminal device, which switches from the second network to the first network, and the first mobility management element belongs to the first network. According to the TAU request message, the security context used between the first mobility management network element and the terminal device is set to a native security context. Specifically, this includes: the first mobility management network element determining the identifier of the terminal device according to the TAU request message; and triggering the first mobility management network element to authenticate the terminal device if the first mobility management network element determines that the location of the terminal device has changed according to the identifier of the terminal device.
2. The method according to claim 1, characterized in that, Setting the security context used between the first mobility management network element and the terminal device as a native security context includes: The first mobility management network element authenticates the terminal device.
3. The method according to claim 1, characterized in that, The first mobility management network element determines that the location information of the terminal device has changed based on the identifier of the terminal device, specifically including: The first mobility management network element determines that the terminal device needs to switch to the second mobility management network element based on the identifier of the terminal device.
4. The method according to any one of claims 1-3, characterized in that, The TAU request message includes the status information of the terminal device. The first mobility management network element authenticates the terminal device, specifically including: If the status information indicates that the terminal device switches from the second network to the first network, or if the status information indicates the mobility management registration information of the terminal device in the second network, or if the status information indicates that the terminal device has network security capabilities in the second network, or if the status information indicates that the terminal device has N1 interface capabilities in the second network, then the first mobility management network element authenticates the terminal device.
5. The method according to claim 1, characterized in that, The step of setting the security context used between the first mobility management network element and the terminal device as a native security context according to the TAU request message includes: The identifier of the terminal device is determined based on the TAU request message, wherein the TAU request message includes the identifier; The first indication information corresponding to the identifier is determined based on the identifier, and the first indication information comes from the core access and mobility management function network element; The terminal device is to be authenticated based on the first indication information.
6. The method according to claim 5, characterized in that, The first indication information is at least one of authentication indication information, 5G access type, or tunnel identifier.
7. The method according to any one of claims 1-6, characterized in that, The first network is a 4G network, and the second network is a 5G network.
8. An information transmission method, applied to a first mobility management network element, characterized in that, The method includes: The first mobility management network element determines that the terminal device switches from the second network to the first network, and determines that the terminal device switches from the first mobility management network element to the second mobility management network element. The first network includes the first mobility management network element and the second mobility management network element. The first mobility management network element sends a second indication information to the second mobility management network element. The second indication information indicates the mapped security context of the terminal device or instructs the second mobility management network element to authenticate the terminal device. The second indication information includes at least one of the following: 5G security algorithm, 5G radio access type, 5G or next-generation radio security capabilities, or tunnel identifier.
9. The method according to claim 7, characterized in that, The first network is a 4G network, and the second network is a 5G network.
10. An information transmission method, applied to a second mobility management network element, characterized in that, The second mobility management network element belongs to the first network, and the first network further includes the first mobility management network element. The terminal device is a terminal device that switches from the second network to the first network. The method includes: Determine that the terminal device switches from the first mobility management network element to the second mobility management network element; The system receives a second indication from the first mobility management network element. The second indication indicates that the security context of the terminal device is a mapped security context, or instructs the second mobility management network element to authenticate the terminal device. The second indication includes at least one of the following: 5G security algorithm, 5G radio access type, 5G or next-generation radio security capabilities, or tunnel identifier. The security context used between the second mobility management network element and the terminal device is determined based on the second instruction information.
11. The method according to claim 10, characterized in that, The second indication information indicates that the security context of the terminal device is a mapped security context. Determining the security context used between the second mobility management network element and the terminal device based on the second indication information includes: The security context used between the second mobility management network element and the terminal device is determined to be a mapped security context.
12. The method according to claim 10, characterized in that, The step of determining the security context used between the second mobility management network element and the terminal device based on the second indication information includes: The security context used between the second mobility management network element and the terminal device is determined to be a mapped security context.
13. The method according to claim 10, characterized in that, The second indication information instructs the second mobility management network element to authenticate the terminal device. Based on the second indication information, the security context used between the second mobility management network element and the terminal device is determined, including: The second mobility management network element authenticates the terminal device and sets the security context used between the second mobility management network element and the terminal device as a local security context.
14. The method according to any one of claims 10-13, characterized in that, The first network is a 4G network, and the second network is a 5G network.
15. An information transmission device, characterized in that, The device includes: A receiving module is used to receive a Tracking Area Update (TAU) request message from a terminal device, wherein the terminal device switches from a second network to a first network, and the device belongs to the first network. The processing module is configured to set the security context used between the device and the terminal device to a native security context based on the TAU request message. The processing module is specifically used to: determine the identifier of the terminal device based on the TAU request message; and trigger authentication of the terminal device if the location of the terminal device has changed based on the identifier of the terminal device.
16. The apparatus according to claim 15, characterized in that, The processing module is specifically used for: The terminal device is authenticated.
17. The apparatus according to claim 15, characterized in that, The processing module is specifically used for: Based on the identifier of the terminal device, it is determined that the terminal device needs to switch to the second mobility management network element.
18. The apparatus according to any one of claims 15-16, characterized in that, The TAU request message includes the status information of the terminal device. The processing module is specifically used to: authenticate the terminal device if the status information indicates that the terminal device switches from the second network to the first network, or if the status information indicates the mobility management registration information of the second network of the terminal device, or if the status information indicates that the terminal device has the network security capability of the second network, or if the status information indicates that the terminal device has the capability of the N1 interface of the second network.
19. The apparatus according to claim 15, characterized in that, The processing module is specifically used for: The identifier of the terminal device is determined based on the TAU request message, wherein the TAU request message includes the identifier; The first indication information corresponding to the identifier is determined based on the identifier, and the first indication information comes from the core access and mobility management function (AMF) network element; The terminal device is to be authenticated based on the first indication information.
20. The apparatus according to claim 19, characterized in that, The first indication information is at least one of authentication indication information, 5G access type, or tunnel identifier.
21. The apparatus according to any one of claims 15-20, characterized in that, The first network is a 4G network, and the second network is a 5G network.
22. An information transmission device, characterized in that, The device includes: A processing module is configured to determine that a terminal device switches from a second network to a first network, and to determine that the terminal device switches from the device to a second mobility management network element, wherein the first network includes the device and the second mobility management network element; The sending module is configured to send second indication information to the second mobility management network element. The second indication information indicates the mapped security context of the terminal device or instructs the second mobility management network element to authenticate the terminal device. The second indication information includes at least one of the following: 5G security algorithm, 5G radio access type, 5G or next-generation radio security capabilities, or tunnel identifier.
23. The apparatus according to claim 22, characterized in that, The first network is a 4G network, and the second network is a 5G network.
24. An information transmission apparatus, the apparatus belonging to a first network, the first network further comprising a first mobility management network element, the terminal device being a terminal device switching from a second network to the first network, characterized in that, The device includes: The processing module is used to determine when the terminal device switches from the first mobility management network element to the device; The receiving module is configured to receive second indication information from the first mobility management network element, wherein the second indication information indicates that the security context of the terminal device is a mapped security context, or indicates that the device authenticates the terminal device; the second indication information includes at least one of the following: 5G security algorithm, or 5G wireless access type, 5G or next-generation wireless security capability, or tunnel identifier. The processing module is further configured to determine the security context used between the device and the terminal device based on the second indication information.
25. The apparatus according to claim 24, characterized in that, The processing module is specifically used to: when the second indication information indicates that the security context of the terminal device is a mapped security context, determine that the security context used between the device and the terminal device is a mapped security context.
26. The apparatus according to claim 25, characterized in that, The processing module is specifically used to: determine that the security context used between the device and the terminal device is a mapped security context.
27. The apparatus according to claim 24, characterized in that, The processing module is specifically used to: when the second indication information instructs the device to authenticate the terminal device, authenticate the terminal device and set the security context used between the device and the terminal device to a local security context.
28. The apparatus according to any one of claims 24-27, characterized in that, The first network is a 4G network, and the second network is a 5G network.
29. A communication device, characterized in that, The communication device includes a processor and a transmission interface; The processor is configured to execute instructions stored in memory to cause the apparatus to perform the method as described in any one of claims 1 to 7.
30. A computer-readable storage medium, characterized in that, Includes a program or instructions that, when executed by a processor, cause the method described in any one of claims 1 to 7 to be performed.
31. A computer program product, characterized in that, When the computer program product is run on a computer or processor, it causes the computer or processor to perform the method as described in any one of claims 1 to 7.
32. A communication device, characterized in that, The communication device includes a processor and a transmission interface; The processor is configured to execute instructions stored in memory to cause the device to perform the method as described in any one of claims 8 to 9.
33. A computer-readable storage medium, characterized in that, Includes a program or instructions that, when executed by a processor, cause the method described in any one of claims 8 to 9 to be performed.
34. A computer program product, characterized in that, When the computer program product is run on a computer or processor, it causes the computer or processor to perform the method as described in any one of claims 8 to 9.
35. A communication device, characterized in that, The communication device includes a processor and a transmission interface; The processor is configured to execute instructions stored in memory to cause the device to perform the method as described in any one of claims 10 to 14.
36. A computer-readable storage medium, characterized in that, Includes a program or instructions that, when executed by a processor, cause the method described in any one of claims 10 to 14 to be performed.
37. A computer program product, characterized in that, When the computer program product is run on a computer or processor, it causes the computer or processor to perform the method as described in any one of claims 10 to 14.
38. A communication system, characterized in that, Includes the apparatus as described in any one of claims 22-23 and the apparatus as described in any one of claims 24-28.
Citation Information
Patent Citations
Switching method and terminal equipment
CN110913393A
Context fetching after inter-system handover
US20100177737A1