A slice isolation method, device and system
By reacquiring the second key in the first network device, the problem of information leakage between slices by user equipment is solved, ensuring the security of information between slices.
Patent Information
- Application Number
- CN202080106568.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-04
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2040-11-04
AI Technical Summary
In the prior art, the user equipment has a high risk of information leakage between slices, especially when the user equipment connects different slices one after another, it may use the same security context, resulting in information leakage between slices.
By acquiring the first slice information of the user equipment in the first network device, if it does not match the second slice information requested to access, the second key is re-acquired to ensure that the information of the second slice is securely protected by the second key, and avoiding the use of other keys to obtain the information of the second slice.
It effectively avoids information leakage between slices, ensures control signaling and data security between slices, and distinguishes information from different slices by using different keys.
Smart Images

Figure CN116349197B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication technologies, and in particular, to a slice isolation method, apparatus, and system. Background Art
[0002] The Global System for Mobile Communications Association (GSMA) defines the common attributes of a general slice template, simply referred to as the attributes of a slice. The attributes of a slice are used to describe whether a slice can be used simultaneously with other slices, that is, to describe whether a user equipment can use multiple slices simultaneously. Some network resources may be shared among multiple slices. If appropriate isolation is not performed, there is a risk of information leakage between them.
[0003] In the existing 3rd Generation Partnership Project (3GPP) standard, it is allowed that a user equipment can access different slices successively in a time-sharing manner. When the user equipment accesses different slices successively, the user equipment may use the same access and mobility management function (AMF), or may use different AMFs. Therefore, the user equipment may access slice 1 at a certain moment, use and complete the services on slice 1, and then the user equipment exits slice 1 and the network. After that, the user equipment may access slice 2 again. At this time, the security context corresponding to slice 1 may be retained and used in the user equipment and the network. At this time, slice 2 may obtain and use the currently saved security context, resulting in the relevant information of slice 1 being obtained by slice 2, and there is a risk of information leakage in slice 1. Summary of the Invention
[0004] Embodiments of this application provide a slice isolation method, apparatus, and system to avoid information leakage between slices and ensure the security of control signaling and data between slices.
[0005] In a first aspect, a slice isolation method is provided, including: a first network device obtains information of a first slice of a user equipment; if the information of the first slice does not match the information of a second slice requested by the user equipment to access, the first network device obtains a second key, where the second key is used to protect the information of the second slice and / or the information when the user equipment accesses the second slice.
[0006] The second key is the key used by the user equipment and the network when the user equipment accesses the second slice. The second key is used to protect the information of the second slice and / or the information when the user equipment accesses the second slice. A possible understanding is that the second key is the key of the first network device (such as the AMF). Exemplarily, the second key is the key of the first network device when the user equipment accesses the second slice. Another possible understanding is that the second key is the key for the second slice, or the second key is the key of the second slice.
[0007] It can be understood that the "information" involved in the embodiments of the present application includes, but is not limited to, slice-related control signaling and user data.
[0008] Through the above method, when the information of the first slice currently saved by the first network device does not match the information of the second slice requested to be accessed, the first network device can re-obtain the second key, ensuring that the information of the second slice is protected by the second key and can only be correctly decrypted using the second key, avoiding the situation that the information of the second slice can also be obtained using other keys and ensuring the information security between slices.
[0009] In a possible design, the information of the first slice includes the attributes of the first slice, and the information of the second slice includes the attributes of the second slice; if the information of the first slice does not match the information of the second slice requested to be accessed by the user equipment, the first network device obtaining the second key includes:
[0010] If the attributes of the first slice do not match the attributes of the second slice, the first network device obtains the second key.
[0011] The attributes of the slice can be used to describe whether the slice can be shared with other slices. Therefore, when the attributes of the slices do not match, it is determined that the first slice and the second slice cannot be shared by the user equipment, thereby distinguishing the key used by the user equipment when accessing the first slice from the key used by the user equipment when accessing the second slice and avoiding information leakage between slices.
[0012] In a possible design, the first network device obtaining the second key includes:
[0013] The first network device generates the second key according to the first key, where the first key is used to protect the information of the first slice or / and the information when the user equipment accesses the first slice.
[0014] The first key is the key used by the user equipment and the network when the user equipment accesses the first slice. The first key is used to protect the information of the slice and / or the information when the user equipment accesses the first slice. A possible understanding is that the first key is the key of the first network device. Exemplarily, the first key is the key of the first network device when the user equipment accesses the first slice. Another possible understanding is that the first key is the key for the first slice, or the first key is the key of the first slice.
[0015] In this design, generating a second key according to the first key can not only ensure the information security between slices, but also reduce the amount of data exchanged between the user equipment and the network equipment.
[0016] In a possible design, the first network device generates the second key according to the first key, including:
[0017] If the isolation requirement of the first slice is higher than that of the second slice, the first network device generates the second key according to the first key.
[0018] According to different slice isolation requirements, when the isolation requirement of the previously accessed slice is higher than that of the slice to be accessed this time, a new key is generated based on the currently saved key, which can reduce the amount of data exchanged between the user equipment and the network equipment while ensuring the information security between slices.
[0019] In a possible design, the first network device obtains the second key, including:
[0020] The first network device re - authenticates the user equipment;
[0021] If the first network device successfully re - authenticates the user equipment, the first network device generates or receives the second key.
[0022] The first network device re - authenticates the user equipment through network authentication, thereby ensuring the information security between slices. The second key can be generated by the first network device or by other network devices. If the second key is generated by other network devices, the first network device can obtain the second key in the other network devices, that is, the first network device receives the second key from the other network devices.
[0023] In a possible design, the first network device re - authenticates the user equipment, including:
[0024] If the isolation requirement of the first slice is lower than that of the second slice, the first network device re - performs network authentication on the user equipment.
[0025] According to the different slice isolation requirements, when the isolation requirement of the previously accessed slice is lower than that of the slice to be accessed this time, re - performing network authentication and then generating a new key can further improve the security of information between slices.
[0026] In a possible design, the mismatch between the attributes of the first slice and the attributes of the second slice includes:
[0027] The attributes of the first slice or the second slice do not allow sharing with slices of any other attributes; or
[0028] The attributes of the first slice only allow sharing with slices having the same service type SST, and the SST of the attributes of the second slice is different from the SST of the attributes of the first slice; or
[0029] The attributes of the second slice only allow sharing with slices having the same service type SST, and the SST of the attributes of the first slice is different from the SST of the attributes of the second slice; or
[0030] The attributes of the first slice only allow sharing with slices having the same slice differentiation factor SD, and the SD of the attributes of the second slice is different from the SD of the attributes of the first slice; or
[0031] The attributes of the second slice only allow sharing with slices having the same slice differentiation factor SD, and the SD of the attributes of the first slice is different from the SD of the attributes of the second slice.
[0032] In a possible design, if the attributes of the first slice match the attributes of the second slice, the first network device may also send a registration acceptance message to the user equipment.
[0033] When the attributes of the first slice match the attributes of the second slice, the first network device and the user equipment can continue to complete the registration process.
[0034] In a possible design, the match between the attributes of the first slice and the attributes of the second slice includes:
[0035] The attributes of the first slice or the second slice allow sharing with slices of any other attributes; or
[0036] The attributes of the first slice only allow sharing with slices having the same SST, and the SST of the attributes of the second slice is the same as the SST of the attributes of the first slice; or
[0037] The attributes of the second slice only allow slices with the same SST to be shared, and the SST of the attributes of the first slice is the same as the SST of the attributes of the first slice; or
[0038] The attributes of the first slice only allow slices with the same SD to be shared, and the SD of the attributes of the second slice is the same as the SD of the attributes of the first slice; or
[0039] The attributes of the second slice only allow slices with the same SD to be shared, and the SD of the attributes of the first slice is the same as the SD of the attributes of the second slice; or
[0040] The second slice and the first slice are mapped to the same single network slice selection assistance information S-NSSAI.
[0041] In a possible design, the attributes of the first slice do not match the attributes of the second slice, including all cases where the above attribute matching is not satisfied.
[0042] In a second aspect, a slice isolation method is provided, including that a user equipment sends a first request message to a first network device, and the first request message is used to request access to a second slice; the user equipment receives a first indication message from the first network device, and the first indication message is used to instruct the user equipment to obtain a second key; the user equipment obtains the second key, and the second key is used to securely protect the information of the second slice or / and the information when the user equipment accesses the second slice.
[0043] Through the above method, when the information of the first slice currently saved by the first network device does not match the information of the second slice requested to be accessed, the first network device can re-obtain the second key, ensure that the information of the second slice is protected by the second key, and can only be correctly decrypted by using the second key, avoiding the situation that the information of the second slice can also be obtained by using other keys, and ensuring the information security between slices.
[0044] In a possible design, the user equipment obtaining the second key includes:
[0045] The user equipment obtains a first key, and the first key is used to securely protect the information of the first slice or / and the information when the user equipment accesses the first slice;
[0046] The user equipment generates the second key according to the first key.
[0047] Generating the second key according to the first key can not only ensure the information security between slices, but also reduce the amount of data exchanged between the user equipment and the network device.
[0048] In a possible design, the user equipment obtaining the second key includes:
[0049] The user equipment re - authenticates with the first network device;
[0050] If the re - authentication between the user equipment and the first network device is successful, the user equipment generates or receives the second key.
[0051] By re - performing network authentication on the user equipment, the first network device can ensure data security between slices. The second key can be generated by the user equipment or by a network device (such as the first network device). If the second key is generated by the network device, the user equipment can obtain the second key in the network device, that is, the user equipment receives the second key from the network device.
[0052] In a possible design, the user equipment can also receive a registration acceptance message from the first network device. When the attributes of the first slice match the attributes of the second slice, the first network device and the user equipment can continue to complete the registration process.
[0053] In a third aspect, a slice isolation method is provided, including the first network device receiving a deregistration request message or sending a deregistration request message. The first network device deletes the third key of the user equipment, where the third key is used to protect the information of the third slice and / or the information when the user equipment accesses the third slice, and the third slice is the slice that the user equipment last accessed.
[0054] The third key is the key used by the user equipment and the network when the user equipment accesses the third slice. The third key is used to protect the information of the third slice and / or the information when the user equipment accesses the third slice. One possible understanding is that the third key is the key of the first network device. Exemplarily, the third key is the key of the first network device when the user equipment accesses the third slice. Another possible understanding is that the third key is the key for the third slice, or the third key is the key of the third slice.
[0055] Through the above method, the first network device deletes the third key of the deregistered user equipment and regenerates a key for the subsequently accessed slice, thereby avoiding information leakage between slices.
[0056] In a possible design, the first network device deletes the third key of the user equipment, including: if the first network device determines that the third slice attribute does not allow sharing with any attribute slice, the first network device deletes the third key of the user equipment. By deleting the key for the dedicated slice with high isolation requirements, it is avoided that the subsequent accessed slice uses this dedicated key, thereby ensuring data security between slices.
[0057] In a possible design, if the first network device determines that the third slice attribute allows sharing with other attribute slices, the first network device may also send a deregistration acceptance message to the user equipment.
[0058] In a possible design, if the first network device fails to obtain the slice attribute of the third slice, the first network device may also send a deregistration acceptance message to the user equipment.
[0059] Fourthly, a slice isolation method is provided, including that the user equipment sends a deregistration request message or receives a deregistration request message, the user equipment deletes the third key of the user equipment, the third slice is the last accessed slice of the user equipment, and the third key is used to securely protect the information of the third slice and / or the information when the user equipment accesses the third slice. Through the above method, the user equipment deletes the third key of the deregistered user equipment and regenerates a key for the subsequent accessed slice, thereby avoiding information leakage between slices.
[0060] In a possible design, the user equipment deletes the third key of the user equipment, including: if the user equipment determines that the third slice attribute does not allow sharing with any attribute slice, the user equipment deletes the third key of the user equipment. By deleting the key for the dedicated slice with high isolation requirements, it is avoided that the subsequent accessed slice uses this dedicated key, thereby ensuring information security between slices.
[0061] Fifthly, a slice isolation method is provided, including: the second network device receives redirection information from the first network device, and the redirection information includes the information of the fourth slice of the user equipment and / or the information of the fifth slice requested by the user equipment to access;
[0062] If the information of the fourth slice does not match the information of the fifth slice and the fifth slice has isolation requirements, the second network device re-authenticates the user equipment.
[0063] When the slice for which access is requested has isolation requirements, the second network device re - authenticates the user equipment and generates a new key, avoiding information leakage caused by the user equipment using the same key when accessing the fourth slice and the fifth slice, and ensuring information security between slices.
[0064] In a possible design, if the information of the fourth slice does not match the information of the fifth slice, and the fifth slice allows sharing with any other attribute slice, the second network device continues to authenticate the user equipment.
[0065] In a sixth aspect, a communication device is provided, which has the function of implementing the method in any of the above aspects or any implementation method in any of the above aspects. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0066] In a seventh aspect, a communication device is provided, including: a processor and a memory; the memory is used to store computer - executable instructions. When the device runs, the processor executes the computer - executable instructions stored in the memory, so that the device executes the method in any of the above aspects or any implementation method in any of the above aspects.
[0067] In an eighth aspect, a communication device is provided, including: units or means for performing each step in any of the above aspects.
[0068] In a ninth aspect, a communication device is provided, including a processor and an interface circuit. The processor is used to communicate with other devices through the interface circuit and execute any method provided in any of the above aspects. The processor includes one or more.
[0069] In a tenth aspect, a communication device is provided, including a processor for connecting to a memory and for calling a program stored in the memory to execute the method in any implementation manner in any of the above aspects. The memory can be inside the device or outside the device. And the processor includes one or more.
[0070] In an eleventh aspect, a computer - readable storage medium is provided. Instructions are stored in the computer - readable storage medium. When it runs on a computer, it causes the processor to execute the method in any of the above aspects.
[0071] In a twelfth aspect, a computer program product including instructions is provided. When it runs on a computer, it causes the computer to execute the method in any of the above aspects.
[0072] In a thirteenth aspect, a chip system is provided, including: a processor for executing the method in each of the above aspects.
[0073] In a fourteenth aspect, a communication system is provided, including a first network device for implementing the method of the first aspect or any implementation method of the first aspect, and a user equipment for implementing the method of the second aspect or any implementation method of the second aspect.
[0074] In a fifteenth aspect, a communication system is provided, including a first network device for implementing the method of the third aspect or any implementation method of the third aspect, and a user equipment for implementing the method of the fourth aspect or any implementation method of the fourth aspect.
[0075] In a sixteenth aspect, a communication system is provided, including a first network device, a second network device for implementing the method of the fifth aspect or any implementation method of the fifth aspect, and a user equipment.
[0076] In a seventeenth aspect, a chip system is provided. The chip system includes a transceiver for implementing the functions of the network device or the user equipment in the method of any of the above aspects. For example, receiving and / or sending the data and / or information involved in the above method. In a possible design, the chip system further includes a memory for storing program instructions and / or data. The chip system may be composed of chips or may include chips and other discrete devices.
[0077] For the technical effects that can be achieved by any one of the sixth aspect to the seventeenth aspect above and any possible implementation in any one of them, please refer to the description of the technical effects that can be brought by any of the above aspects, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0078] Figure 1 It is a schematic diagram of a possible network architecture of an embodiment of the present application;
[0079] Figure 2A 、 Figure 2B It is a schematic diagram of a slice access scenario;
[0080] Figure 3 、 Figure 4 、 Figure 5 、 Figure 6 、 Figure 7 、 Figure 8 、 Figure 9 、 Figure 10 It is a schematic diagram of a slice isolation process of an embodiment of the present application;
[0081] Figure 11 、 Figure 12 It is a schematic diagram of a communication device of an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0082] The present application will be further described in detail below with reference to the drawings.
[0083] Aspects, embodiments or features of the present application will be presented in the context of a system that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. In addition, combinations of these solutions may also be used.
[0084] In addition, in the embodiments of the present application, the term "exemplary" is used to mean an example, illustration, or demonstration. Any embodiment or design described as "exemplary" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of the term "exemplary" is intended to present concepts in a concrete manner.
[0085] The network architecture and service scenarios described in the embodiments of the present application are for the purpose of more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. As will be understood by those of ordinary skill in the art, as the network architecture evolves and new service scenarios emerge, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0086] The following provides an explanation of some terms used in the embodiments of the present application to facilitate understanding by those skilled in the art.
[0087] 1) User equipment (UE), also known as a terminal device, is a device with wireless transceiver capabilities that can communicate with one or more core network (CN) devices (or also referred to as core devices) via an access network device (or also referred to as an access device) in a radio access network (RAN).
[0088] A user equipment may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile device, remote station, remote terminal, mobile device, user terminal, user agent, or user device, etc. The user equipment can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (such as on a ship); it can also be deployed in the air (such as on an airplane, balloon, and satellite, etc.). The user equipment can be a cellular phone, cordless phone, session initiation protocol (SIP) phone, smart phone, mobile phone, wireless local loop (WLL) station, personal digital assistant (PDA), etc. Alternatively, the user equipment can also be a handheld device with wireless communication capabilities, a computing device, or other devices connected to a wireless modem, a vehicle-mounted device, a wearable device, a drone device, or a terminal in the Internet of Things (IoT), vehicle-to-everything (V2X), a terminal in the fifth-generation (5G) mobile communication network and any form of terminal in future networks, a relay user equipment, or a terminal in a future evolved public land mobile network (PLMN), etc. Among them, the relay user equipment can be, for example, a 5G residential gateway (RG). For example, the user equipment can be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. The embodiments of the present application do not limit the type or category of the terminal device.
[0089] 2) A network device refers to a device that can provide wireless access functions for terminals. Among them, the network device can support at least one wireless communication technology, such as long term evolution (LTE), new radio (NR), wideband code division multiple access (WCDMA), etc.
[0090] For example, network devices may include access network devices. By way of example, network devices include, but are not limited to: next-generation base stations or next-generation node Bs (gNBs) in 5G networks, evolved node Bs (eNBs), radio network controllers (RNCs), node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved node Bs or home node Bs, HNBs), baseband units (BBUs), transmitting and receiving points (TRPs), transmitting points (TPs), mobile switching centers, small stations, micro stations, etc. Network devices may also be radio controllers, centralized units (CUs), and / or distributed units (DUs) in a cloud radio access network (CRAN) scenario, or network devices may be relay stations, access points, vehicle-mounted devices, terminals, wearable devices, and network devices in future mobile communications or network devices in a future evolved public land mobile network (PLMN), etc.
[0091] Again, for example, network devices may include core network (CN) devices, and core network devices include, for example, AMF, etc.
[0092] The “and / or” in this application describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character “ / ” generally indicates that the associated objects before and after are in an “or” relationship.
[0093] The multiple involved in this application refers to two or more.
[0094] In addition, it should be understood that in the description of this application, terms such as “first” and “second” are only used for the purpose of distinguishing descriptions and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying an order.
[0095] The technical solutions of the embodiments of the present application can be applied to various communication systems. In a communication system, the part operated by an operator can be referred to as a public land mobile network (PLMN) (which can also be referred to as an operator network, etc.). A PLMN is a network established and operated by a government or an operator approved by it for the purpose of providing public land mobile communication services. It is mainly a public network where a mobile network operator (MNO) provides mobile broadband access services to users. The PLMN described in the embodiments of the present application can specifically be a network that meets the requirements of the 3GPP standard, abbreviated as a 3GPP network. A 3GPP network generally includes but is not limited to 5G, the fourth-generation mobile communication (4G) network, etc. For the convenience of description, the embodiments of the present application will be described by taking the PLMN as an example. Alternatively, the technical solutions provided by the embodiments of the present application can also be applied to an LTE system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), a universal mobile telecommunication system (UMTS), a worldwide interoperability for microwave access (WiMAX) communication system, a 5G communication system or NR, and other future communication systems such as 6G.
[0096] With the expansion of mobile broadband access services, mobile networks will also develop accordingly to better support diverse business models, meet more diverse application services, and the needs of more industries. In order to provide better and more perfect services to more industries, the 5G network has also adjusted its network architecture compared with the 4G network. For example, the 5G network splits the mobility management entity (MME) in the 4G network into multiple network functions including an AMF and a session management function (SMF).
[0097] For the convenience of understanding the embodiments of the present application, Figure 1 the application scenario used in the present application will be described by taking the 5G network architecture shown as an example. Figure 1 It is a 5G network architecture based on a service-based architecture in a non-roaming scenario defined in the 3GPP standardization process. The network architecture may include: a terminal device (which can also be referred to as a user equipment) part, a PLMN part, and a data network (DN) part.
[0098] The PLMN may include: a Network Exposure Function (NEF) 131, a Network Function Repository Function (NRF) 132, a Policy Control Function (PCF) 133, a Unified Data Management (UDM) 134, an Authentication Server Function (AUSF) 136, an AMF 137, a Session Management Function (SMF) 138, a User Plane Function (UPF) 139, an Access Network (AN) 140, a Network Slice Selection Function (NSSF) 141, a Network Slice Specific Authentication and Authorization Function (NSSAAF) 142, etc. In the above PLMN, the part other than the access network 140 can be referred to as the core network part.
[0099] The data network DN 120, which can also be referred to as a Packet Data Network (PDN), is usually deployed outside the PLMN, such as a third-party network. Exemplarily, the PLMN can access multiple data networks DN 120, and various services can be deployed on the data network DN 120 to provide services such as data and / or voice for the terminal device 110. For example, the data network DN 120 can be a private network of a smart factory, and sensors installed in the workshop of the smart factory can be the terminal device 110. A control server for the sensors is deployed in the data network DN 120, and the control server can provide services for the sensors. The sensors can communicate with the control server, obtain instructions from the control server, and transmit the collected sensor data to the control server according to the instructions. Another example is that the data network DN 120 can be an internal office network of a company, and the mobile phones or computers of the company's employees can be the terminal device 110. The mobile phones or computers of the employees can access information, data resources, etc. on the company's internal office network. The terminal device 110 can pass through the interface provided by the PLMN (such as Figure 1Establish a connection with the PLMN through interfaces such as the N1 interface in [description] and use services such as data and / or voice provided by the PLMN. The terminal device 110 can also access the data network DN 120 through the PLMN and use operator services deployed on the data network DN 120 and / or services provided by third parties. Among them, the above-mentioned third party can be a service provider other than the PLMN and the terminal device 110, and can provide other data and / or voice and other services for the terminal device 110. Among them, the specific manifestation form of the above-mentioned third party can be specifically determined according to the actual application scenario and will not be limited here.
[0100] The application function (AF) 135 can belong to the PLMN or not. However, usually, the AF belongs to a third party rather than the PLMN, but has a protocol relationship with the PLMN. The AF is used to support functions that affect data routing through applications, the access network exposure function NEF, and interact with the policy framework for policy control, etc.
[0101] Exemplarily, the network functions in the PLMN are briefly introduced below.
[0102] AN 140, also known as the Radio AN, is a sub-network of the PLMN and is the implementation system between the service nodes (or network functions) in the PLMN and the terminal device 110. For the terminal device 110 to access the PLMN, it first passes through the AN 140 and then connects to the service nodes in the PLMN through the AN 140. In the embodiments of the present application, the AN 140 can refer to the access network itself or the access network device, and no distinction is made here. The access network device is a device that provides wireless communication functions for the terminal device 110 and can also be called an access device, (R)AN device, or network device, etc. The access network device includes but is not limited to: gNB in the 5G system, eNB in the LTE system, RNC, NB, base station controller BSC, BTS, HNB, BBU, TRP, TP, pico small base station device, mobile switching center, or network devices in future networks, etc. It can be understood that the specific type of the access network device in the present application is not limited. In systems using different radio access technologies, the names of the devices with the functions of the access network device may be different.
[0103] Optionally, in some deployments of the access device, the access device may include a CU, a DU, etc. In some other deployments of the access device, the CU may also be divided into a CU-control plane (CP) and a CU-user plane (UP), etc. In some other deployments of the access device, the access device may also be an open radio access network (O-RAN or Open RAN) architecture, etc. This application does not limit the specific deployment method of the access device.
[0104] The network exposure function NEF (which may also be referred to as the network exposure function entity) 131 is a control plane function provided by the operator. The network exposure function NEF 131 provides a two-way external interface for exposing the capabilities of the network to the third party in a secure manner. When other network functions (such as the application function AF135, etc.) need to communicate with the third party's network, the NEF network function 131 can act as a relay for communicating with the third party's network entity. The NEF network function 131 can also be used for the translation of the identification information of the subscribed user and the identification information of the third party's network function. For example, when the NEF network function 131 sends the subscriber permanent identifier (SUPI) of the subscribed user from the PLMN to the third party, it can translate the SUPI into its corresponding externally publicly used subscription identifier (GPSI). Conversely, the NEF network function 131 forwards the external information to the PLMN network to prevent other network functions within the PLMN from directly contacting the outside.
[0105] The network repository function NRF 132 is a control plane function provided by the operator and can be used to maintain the real-time information of all network function services in the network.
[0106] The policy control function PCF 133 is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provides policy rules, subscription information related to policy decisions, etc. to other control functions.
[0107] The Unified Data Management UDM 134 is a control plane function provided by the operator, responsible for storing information such as the SUPI of subscribed users in the PLMN, the security context, and the subscribed data. The subscribed users of the above PLMN can specifically be users who use the services provided by the PLMN, such as users of terminal device SIM cards of China Telecom, or users of terminal device SIM cards of China Mobile, etc. Exemplarily, the SUPI of the subscribed user can be the number of the terminal device SIM card, etc. The above security context can be data (cookie) or token stored on the local terminal device (such as a mobile phone), etc. The subscribed data of the above subscribed user can be the supporting services of the terminal device SIM card, such as the traffic package of the mobile phone SIM card, etc.
[0108] The Authentication Server Function AUSF 136 is a control plane function provided by the operator, usually used for primary authentication, that is, the network authentication between the terminal device 110 (subscribed user) and the PLMN.
[0109] The Access and Mobility Management Function AMF 137 is a control plane network function provided by the PLMN, responsible for the access control and mobility management of the terminal device 110 accessing the PLMN, such as including functions such as mobile status management, allocation of user temporary identity, authentication and authorization of users, etc.
[0110] The Session Management Function SMF 138 is a control plane network function provided by the PLMN, responsible for managing the protocol data unit (PDU) session of the terminal device 110. The PDU session is a channel for transmitting PDUs, and the terminal device needs to transmit data with the DN 120 through the PDU session. The PDU session can be established, maintained, and deleted by the SMF 138, etc. The SMF 138 includes session management (such as session establishment, modification, and release, including tunnel maintenance between the UPF 139 and the AN 140), selection and control of the UPF 139, service and session continuity (SSC) mode selection, roaming, and other session-related functions.
[0111] The User Plane Function UPF 139 is a gateway provided by the operator and is the gateway for communication between the PLMN and the DN 120. The UPF 139 includes user plane-related functions such as packet routing and transmission, packet detection, service usage reporting, quality of service (QoS) processing, lawful interception, uplink packet detection, and downlink packet storage.
[0112] The Network Slice Selection Function (NSSF) 141 is a control plane network function provided by the PLMN, responsible for determining network slice instances and selecting AMF network functions 137, etc.
[0113] The Network Slice Specific Authentication and Authorization Function (NSSAAF) 142 is a control plane network function provided by the PLMN, used to support slice authentication between the terminal device 110 and the DN.
[0114] Figure 1 The network functions in the PLMN shown may also include a Unified Data Repository (UDR), etc. (not shown in the figure), and the embodiments of this application do not limit other network functions included in the PLMN.
[0115] Figure 1 In Nnef, Nausf, Nnrf, Npcf, Nudm, Naf, Namf, Nsmf, Nnssf, Nnssaaf, N1, N2, N3, N4, and N6 are interface sequence numbers. Exemplarily, the meanings of the above interface sequence numbers can be referred to the meanings defined in the 3GPP standard protocol, and this application does not limit the meanings of the above interface sequence numbers. It should be noted that Figure 1 only an exemplary illustration is made with the terminal device 110 as a UE in Figure 1 The interface names between the various network functions in are only examples. In specific implementations, the interface names of this system architecture may also be other names, and this application does not limit this.
[0116] The mobility management network function in this application may be Figure 1 the AMF 137 shown in , or other network functions with the above access and mobility management functions of the AMF 137 in future communication systems. Alternatively, the mobility management network function in this application may also be a Mobility Management Entity (MME) in the LTE system, etc.
[0117] For ease of description, in the embodiments of the present application, the access and mobility management function AMF 137 is abbreviated as AMF, the unified data management UDM 134 is abbreviated as UDM, and the terminal device 110 is referred to as a user equipment or UE. That is, in the embodiments of the present application, the AMF described hereinafter can be replaced with the mobility management network function, the UDM can be replaced with the unified data management, and the user equipment or UE can be replaced with the terminal device. It can be understood that the same replacement method is applicable to other network functions not shown.
[0118] Figure 1 The network architecture shown (such as the 5G network architecture) adopts a service-based architecture and a common interface. The functions of traditional network elements are split into several self-contained, self-managed, and reusable network function service modules based on network function virtualization (NFV) technology. By flexibly defining the set of service modules, customized network function reconstruction can be achieved, and business processes are formed through a unified service call interface externally. Figure 1 The schematic diagram of the network architecture shown can be understood as a schematic diagram of a service-based 5G network architecture in a non-roaming scenario. In this architecture, according to specific scenario requirements, different network functions can be combined in an orderly manner as needed to achieve customization of network capabilities and services, so as to deploy dedicated networks for different services and implement 5G network slicing. The network slicing technology enables operators to respond to customer needs more flexibly and quickly and supports flexible allocation of network resources.
[0119] The slices in the network device will be described first below.
[0120] A slice, that is, a network slice, can be simply understood as cutting the operator's physical network into multiple virtual end-to-end networks. Each virtual network (including the devices, access network, transmission network, and core network within the network) is logically independent, and the failure of any one virtual network will not affect other virtual networks. To meet diverse requirements and isolation between slices, relatively independent management and operation and maintenance of services are required, and customized service functions and analysis capabilities are provided. Instances of different service types can be deployed on different network slices, and different instances of the same service type can also be deployed on different network slices. A slice can be composed of a group of network functions (NF) and / or sub-networks, etc. For example, Figure 1 the sub-networks AN 140, AMF 137, SMF 138, and UPF 139 in can form a slice. It can be understood that Figure 1Only one of each network function is schematically shown. In actual network deployment, there can be multiple, dozens, or hundreds of each network function or sub-network. Many slices can be deployed in a PLMN, and each slice can have different performances to meet the needs of different applications and different vertical industries. An operator can "customize" a slice according to the needs of different vertical industry customers. The operator can also allow some industry customers to have greater autonomy and participate in some management and control functions of the slice. Among them, slice-level authentication is a network control function in which industry customers participate to a limited extent, that is, to authenticate and authorize the access of a terminal device to a slice, that is, "slice-level authentication", which can also be called "secondary authentication", "second authentication", etc. This application is simply referred to as "slice authentication".
[0121] Before a terminal device is allowed to access a network or a slice, it needs to perform mutual authentication with the network and / or slice and obtain authorization from the network and / or slice. Generally, the network needs to authenticate and authorize the terminal device one or two times before it can access the network or slice. First, the PLMN needs to authenticate based on the SUPI subscribed to by the PLMN used by the terminal device, and this authentication is called primary authentication. Second, the PLMN needs to authenticate based on the subscription identifier of the terminal device used with the DN, that is, slice authentication or secondary authentication, etc.
[0122] For example Figure 1 When a slice is deployed in the core network and the UE 110 needs to access a certain slice, the UE 110 can provide the requested slice to the core network. Among them, the slice requested by the UE 110 can include a requested network slice selection assistance information set (requestedNSSAI). The NSSAI can include one or more single network slice selection assistance information (S-NSSAI), and one S-NSSAI is used to identify a network slice type. It can also be understood that the S-NSSAI is used to identify a slice, or it can be understood that the S-NSSAI is the identification information of the slice. It can be understood that in this application, a slice can also be called a network slice, a network slice instance, or an S-NSSAI, etc. This application does not limit the name of this slice. For ease of understanding, in the following description, this application does not strictly distinguish between a slice and an S-NSSAI, etc., and the two can be equally applicable.
[0123] In the 3GPP standard, the format of the S-NNSAI includes at least two parts:
[0124] 1. Slice type or service type (SST).
[0125] SST is used to distinguish the expected different characteristics of slices in terms of features, services, etc. Currently, the 3GPP standard defines 4 standard slice types, namely enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), massive internet of things (MIoT), and vehicle to everything (V2X).
[0126] 2. Slice differentiator (SD).
[0127] SD refers to the selected optional features used to further distinguish different slices.
[0128] Both SST and SD can have non-standardized, PLMN-customized types.
[0129] Furthermore, after the UE 110 sends a registration request to the network, the core network functions (such as the AMF network function 137 or the NSSF network function 141) select a set of network slices allowed for the UE 110 based on information such as the UE 110's subscribed data, the network slices requested by the UE 110, the roaming protocol, and the local configuration. Among them, the set of allowed network slices can be represented by the allowed NSSAI, and the S-NSSAI included in the allowed NSSAI can be the S-NSSAI allowed by the current PLMN for the UE 110 to access.
[0130] Illustrate the primary authentication and secondary authentication. Exemplarily, with the development of vertical industries and the Internet of Things, for a data network DN 120 outside the PLMN (such as a DN serving vertical industries), there is also a need for authentication and authorization for the UE 110 accessing this DN 120. For example, a commercial company provides a game platform and offers game services to game players through the PLMN. On the one hand, since the UE 110 used by the players accesses the game platform through the PLMN, the PLMN needs to authenticate or authorize the identity (SUPI) of this UE 110, that is, the primary authentication. Game players are customers of the commercial company, and this commercial company also needs to authenticate or authorize the identity of game players. For example, when authenticating or authorizing the identity of game players, this authentication can be slice-based authentication, or in other words, the authentication is based on slices. In this case, this authentication can be called slice authentication, or network slice-specific authentication and authorization (NSSAA). It should be noted that the actual meaning of slice authentication can be, for example, the authentication performed between the terminal device and a third-party network (such as a DN or its authentication server). The slice authentication result will determine whether the PLMN authorizes the terminal device to access the slice provided by this PLMN. It should also be understood that the method applied to slice authentication in this application is also applicable to scenarios such as session-based secondary authentication or slice-based secondary authentication, which will not be elaborated here.
[0131] The following explains the generic network slice template (GST).
[0132] The GSMA has defined the concept of GST. The main role of GST is to formulate a set of standard network slice templates so that operators can, on the basis of ensuring interoperability, customize the network slices to be established, used, and operated as needed, which is convenient for interoperability and improves efficiency and security. The 3GPP standard organization is formulating relevant standards for this generic slice template so that the 5G network can better support and meet the requirements for slice characteristics and slice performance specified by the generic slice template through the evolved system architecture and processes.
[0133] The GSMA currently defines many attributes of the General Slice Template (GST Attributes, or simply GST attributes). One such GST attribute is of concern in the embodiments of this application and is also an attribute being studied and standardized by the 3GPP standards organization. This type of GST attribute is called a shared attribute, or the simultaneous use of the network slice, and can also be called an exclusive attribute, a mutually exclusive attribute, etc. This attribute mainly describes whether the slice can be used simultaneously with other slices. The attributes of the slices involved in the embodiments of this application, also known as slice attributes, refer to GST attributes, including shared attributes. Since the network usually deploys slices of various types and attributes simultaneously, and whether the UE can use multiple slices simultaneously is a security issue that needs to be considered during the communication process, the essence of this shared attribute can also be regarded as an isolation issue between slices.
[0134] There is a possibility that multiple slices may share some network resources to improve the utilization efficiency of network resources. These network resources, such as network elements or NFs, if not properly isolated, pose a risk of information leakage to each other. This issue is relatively important for data with high sensitivity or for users / industries with relatively high requirements for network security and privacy, and usually hopes that their slices can be configured so that they are not used by the UE simultaneously with other slices to prevent information leakage between slices. On the contrary, for some ordinary business data, the security provided by existing network slices is sufficient to meet the requirements, and there is no need to additionally increase security mechanisms or costs to enhance the isolation between slices.
[0135] The GSMA further gives suggestions on the subdivision of the GST shared attribute. For example, in the embodiments of this application, the shared attribute can be divided as follows:
[0136] When the value of the shared attribute is 0: it can be shared with any other slice (abbreviation: "ordinary slice");
[0137] When the value of the shared attribute is 1: it can only be shared with slices of the same SST type (abbreviation: "type 1 slice");
[0138] When the value of the shared attribute is 2: it can only be shared with slices of the same SD (abbreviation: "type 2 slice");
[0139] When the value of the shared attribute is 3: it is not allowed to be shared with any other slice (abbreviation: "exclusive slice");
[0140] When the value of the shared attribute is 4 - 15: it is operator-defined (abbreviation: "customized slice").
[0141] It should be noted that the embodiments of the present application mainly describe by taking the common attributes in the GST attributes as an example. For convenience, in the following description, "attributes" and "common attributes" are not strictly distinguished and they can be interchanged.
[0142] The embodiments of the present application mainly study the problems of resource sharing and security isolation between slices, and do not limit the specific division of the above GST attributes. There are the following access rules for slices in the existing 3GPP standard:
[0143] Rule 1: Allow the UE to access multiple slices simultaneously: The UE can access at most 8 slices simultaneously in the same PLMN. When the UE accesses 2-8 slices in the same PLMN, these slices need to share the same AMF.
[0144] Rule 2: Allow the UE to access different slices successively (time-sharing): When the UE accesses different slices successively, the UE may use the same AMF or different AMFs, depending on many factors such as the movement location of the UE and the load level of the AMF, etc.
[0145] For "dedicated slices", the existing 3GPP standard does not define a unified dedicated slice isolation method, but leaves it to the operator to customize and consider the implementation when deploying slices. For example, a simple method is that for the case of deploying dedicated slices, the operator can adopt a private policy to prohibit the UE from accessing multiple slices. Of course, this method sacrifices the original flexible deployment of network slices and the convenience of the UE.
[0146] In the current standard being studied and formulated by 3GPP, it is being explored how to configure the network and the UE so that the network can make an automated judgment to avoid the situation where a UE accesses a dedicated slice (GST common attribute value = 3) and other slices (any common attribute value) simultaneously, or how to fully meet the limited requirements of the GST common attributes.
[0147] The core security issue of the GST dedicated slice attribute is to ensure the security isolation between slices.
[0148] In the actual communication scenario, there is a scenario where the UE accesses multiple slices simultaneously (Rule 1 above), and there is also a scenario where the UE accesses multiple slices successively (non-simultaneously) (Rule 2 above). In the existing 3GPP, only the scenario described in Rule 1 above is discussed, but in fact, the scenario described in Rule 2 above also needs to ensure the security isolation between slices.
[0149] The following briefly describes the possible information leakage problem between slices in the scenario described in Rule 2 above. It should be noted that the information between slices can include control signaling between slices, user data, etc. The following 2 typical scenarios are taken as examples.
[0150] Scenario A: Shared AMF: The UE accesses different (or the same) slices successively.
[0151] For example, at a certain moment, the UE accesses slice 1, uses and completes the services on slice 1, then the UE exits slice 1 and the network, and completes the de-registration process with the network. After a period of time, the UE needs to use the services of slice 2 and accesses slice 2 through the said network.
[0152] The core network part of the slice usually mainly includes network functions such as AMF, SMF, and UPF. In the existing 3GPP standards, the usual implementation method is that slice 1 and slice 2 use different SMFs and UPFs, but slice 1 and slice 2 will use the same AMF (as described in Rule 1 above). As Figure 2A shown, slice 1 uses SMF1 and UPF1, slice 2 uses SMF2 and UPF2, but slice 1 and slice 2 use the same AMF. Moreover, although there is a time interval (not simultaneous) between the UE's use of slice 1 and slice 2, and the UE has completed the de-registration in the middle, the UE and the network will still retain and use the same set of security contexts, such as including: the AMF key Kamf, which is used to derive the keys for encryption / integrity protection. This is because the network can optimize network performance by reusing the security context.
[0153] It can be seen that although the UE does not access 2 different slices simultaneously, it still uses the same set of security contexts. If one of the slices is a slice that requires isolation from other slices, there is still a risk of information leakage for that slice because its security context is the same as that of another slice, and the information of that slice can also be obtained by using the security context of another slice. Therefore, for the scenario of non-simultaneous access to different slices, security isolation between slices (such as key isolation) should also be carried out.
[0154] Scenario B: Non-shared AMF: The UE accesses different (or the same) slices successively, or an AMF redirection occurs.
[0155] For example, at a certain moment, the UE accesses Slice 1 through AMF1. After using and completing the services on Slice 1, the UE exits Slice 1 and the network, and completes the de-registration process with the network. The UE re-registers to the network through AMF2 and accesses Slice 2. Although the UE accesses through AMF2, due to the requirements of network performance optimization, the network usually requires AMF1 to save the security context of the UE, such as the key Kamf, and transfer it to AMF2. That is to say, even if the UE accesses different slices without simultaneous or shared AMF, the security context used can still be the same, and there is no security isolation at the key level between Slice 1 and Slice 2.
[0156] Another example is the scenario of AMF re-allocation of the UE. This scenario occurs when the UE is in a connected state or has not been de-registered. As Figure 2B shown, when the UE registers to the network, the network device first processes the UE's request by the source AMF and initiates the network authentication process. After the authentication is completed and the slice information (such as NSSAI) that the UE requests to access is obtained, it is determined to use the target AMF to continue processing the slice that the UE requests to access. This process is called the re-allocation process of the UE. The re-allocation process can also be triggered by the movement of the UE's location.
[0157] In the re-allocation process, the UE initially accesses the network using the source AMF, and the information of the UE (including the security context of the UE) is saved in the source AMF. It should be noted that at this time, the UE may have already accessed Slice 1 or may not have accessed Slice 1 yet. When the network decides to switch to use the target AMF to continue serving the UE, the security context stored in the source AMF can be transferred to the target AMF. That is to say, although the UE does not access Slice 1 and Slice 2 simultaneously, the security context used by the UE in Slice 2 can be obtained in both AMFs. Therefore, there is no security isolation at the key level between Slice 2 and Slice 1.
[0158] According to the descriptions of Scenario A and Scenario B, when the UE does not access multiple slices simultaneously, there may be a risk of information leakage between slices.
[0159] In view of this, the present application proposes a slice isolation method to avoid information leakage between slices. During the registration process, the first network device obtains information of the user's first slice. If the information of the first slice does not match the information of the second slice that the user equipment requests to access, the first network device may obtain a second key, and the second key is used to securely protect the information of the second slice and / or the information of the user equipment. Here, it can be ensured that after the user equipment accesses the second slice to be requested for access, the key (i.e., the second key) used by the network and the user equipment is different from the key used by the network and the user when the user equipment accesses other slices (such as the first slice), thus avoiding information leakage between slices. Or during the deregistration process, the first network device receives a deregistration request message from the user equipment, and the first network device deletes a third key, where the third key is the key used by the network and the user equipment when the user equipment accesses a third slice, and the third slice is the slice that the user equipment accessed last time. Here, by deleting the key previously used by the user equipment when accessing other slices, it can be ensured that the key used by the network and the user equipment in the subsequently accessed slices is different from the key used when accessing other slices previously, thus avoiding information leakage between slices. Or during the AMF redirection process, the first network device sends a redirection message of the user equipment to other network devices. If the information of the slice obtained by the first network device does not match the information of the slice that the user equipment requests to access, the first network device may initiate re-authentication for the user equipment. Here, during the AMF redirection process, a re-authentication process is initiated for the user equipment, a new key is generated, and the newly generated key is different from the key saved in the source AMF, thereby avoiding using the same key when accessing different slices and avoiding information leakage between slices.
[0160] The slice isolation method provided by the embodiments of the present application can be applied to Figure 1 the communication system shown in
[0161] The slice isolation process provided during the registration process is as shown in Figure 3 shown, and this process includes:
[0162] S301: The user equipment sends a first request message to the first network device, and the first network device receives the first request message, where the first request message is used to request access to the second slice.
[0163] Exemplarily, the first network device is an AMF.
[0164] The first request message may be a Registration Request message. The first request message includes the identification information of the user equipment and the information of the second slice.
[0165] The identification information of the user equipment is the identifier of the user equipment, such as the globally unique temporary identifier (GUTI) of the user equipment, and / or the subscription concealed identifier (SUCI) of the user equipment. The SUCI may be obtained by performing privacy protection processing (such as encryption processing) on the SUPI.
[0166] The information of the second slice includes the identification information of the second slice. Optionally, the information of the second slice may further include the attributes of the second slice. The identification information of the second slice includes S-NSSAI or NSSAI. The NSSAI is a slice identification set, which may include the identifications of multiple slices (i.e., multiple S-NSSAIs). The second slice may be the slice identified by any one of the multiple S-NSSAIs. The attributes of the second slice may be determined by a common attribute value. For example, when the common attribute value is 0, the second slice is a normal slice; when the common attribute value is 1, the second slice is a type 1 slice; when the common attribute value is 2, the second slice is a type 2 slice; when the common attribute value is 3, the second slice is an exclusive slice.
[0167] In a possible example, after receiving the first request message, the first network device may check whether there is a security context or context (including the security context) of the user equipment. For example, the first network device determines whether the user equipment has accessed the network before (such as determining whether the user's identifier is a GUTI). If it is determined that the user equipment has not accessed the network device before, the first network device determines that the context of the user equipment does not exist, and the first network device may perform network authentication on the user equipment to enable the user equipment to access the network. If it is determined that the user equipment has accessed the network before, the first network device further determines through which network device or which network function the user equipment accessed the network when accessing the network before (such as the network device accessed before can be determined through the GUTI, where the content of the GUTI includes the network identifier and the network function (AMF) identifier).
[0168] S302: The first network device obtains the information of the first slice of the user equipment.
[0169] If the user equipment accessed the network through the first network device most recently, the first network device directly obtains the information of the first slice of the user equipment in the first network device; if the user equipment accessed the network through other network devices (other than the first network device) most recently, the first network device obtains the information of the first slice of the user equipment in other network devices. Optionally, the information of the first slice is included in the context or security context of the user equipment. And optionally, the attributes and / or the first key (such as Kamf) of the first slice are included in the context or security context of the user equipment, and the first key is the key used by the user equipment and the network when the user equipment accesses the first slice.
[0170] The first slice of the user equipment is any one of one or more slices subscribed by the user equipment, or the first slice is a slice that the user equipment accessed before, accessed most recently, or is currently accessing. The information of the first slice includes the identification information of the first slice. Optionally, the information of the first slice may further include at least one of the following: the attributes of the first slice, the security context of the first slice, and / or the first key, and the first key is used to securely protect the information of the first slice or / and the information when the user equipment accesses the first slice.
[0171] In a possible example, the first network device may obtain the information of the first slice when obtaining the context or security context of the user equipment. Optionally, the information of the first slice is included in the context or security context of the user equipment, and the first network device obtains the information of the first slice in the context or security context of the user equipment. Or optionally, the first network device obtains the information of the first slice in the first network device or other network devices.
[0172] S303: If the information of the first slice does not match the information of the second slice that the user equipment requests to access, the first network device obtains a second key, and the second key is used to securely protect the information of the second slice or / and the information when the user equipment accesses the second slice.
[0173] The second key is the key used by the user equipment and the network when the user equipment accesses the second slice.
[0174] If the information of the first slice includes the attributes of the first slice and the information of the second slice includes the attributes of the second slice, then in S303, if the attributes of the first slice do not match the attributes of the second slice, the first network device obtains the second key.
[0175] The attributes of the first slice do not match the attributes of the second slice, including that the attributes of the first slice are incompatible with the attributes of the second slice, or the attributes of the first slice are mutually exclusive with the attributes of the second slice.
[0176] The attributes of the first slice do not match / are incompatible with / are mutually exclusive with the attributes of the second slice, including at least one of the following:
[0177] 11) The common attributes of the first slice and / or the common attributes of the second slice are not allowed to be shared with slices of any other attributes.
[0178] Exemplarily, the first slice and / or the second slice is an exclusive slice. For example, the first slice is an exclusive slice and the second slice is a slice of any attribute. Another example is that the second slice is an exclusive slice and the first slice is a slice of any attribute. Another example is that the first slice is an exclusive slice, the second slice is an exclusive slice, and the first slice and the second slice are different exclusive slices.
[0179] 12) The attributes of the first slice are only allowed to be shared with slices having the same service type SST, and the SST of the attributes of the second slice is different from the SST of the attributes of the first slice.
[0180] 13) The attributes of the second slice are only allowed to be shared with slices having the same service type SST, and the SST of the attributes of the first slice is different from the SST of the attributes of the second slice.
[0181] 14) The attributes of the first slice are only allowed to be shared with slices having the same slice differentiation factor SD, and the SD of the attributes of the second slice is different from the SD of the attributes of the first slice.
[0182] 15) The attributes of the second slice are only allowed to be shared with slices having the same slice differentiation factor SD, and the SD of the attributes of the first slice is different from the SD of the attributes of the second slice.
[0183] Among them, in 12) and 14), the first slice is not an exclusive slice but is incompatible with the common attributes of the second slice. For example, the attributes of the first slice are type 1 slices and the attributes of the second slice are type 2 slices, or the attributes of the first slice are type 2 slices and the attributes of the second slice are type 1 slices. In 13) and 15), the second slice is not an exclusive slice but is incompatible with the common attributes of the first slice. For example, the attributes of the second slice are type 1 slices and the attributes of the first slice are type 2 slices, or the attributes of the second slice are type 2 slices and the attributes of the first slice are type 1 slices.
[0184] In a possible example, when the first network device obtains the second key, the first network device generates the second key according to the first key, where the first key is used to protect the information of the first slice or / and the information when the user equipment accesses the first slice. For example, the first network device is an AMF, and the AMF generates a second slice key according to Kamf (used to protect the information of the first slice or / and the information when the user equipment accesses the first slice).
[0185] In another possible example, when the first network device obtains the second key, the first network device re-initiates network authentication or initiates slice authentication for the user equipment; if the re-authentication initiated by the first network device for the user equipment is successful or the initiated slice authentication is successful, the first network device generates or receives the second key. For example, the first network device is an AMF, and the AMF includes a Security Anchor Function (SEAF). When the network authentication is successful, the SEAF generates the second key. Another example is that the AMF does not include the SEAF function, that is, the AMF and the SEAF are separately deployed in different network devices. When the network authentication is successful, after the SEAF generates the second key, it sends the second key to the AMF. This process ensures that the second key is independent of the first key, and the first key cannot be obtained based on the second key, nor can the second key be obtained based on the first key.
[0186] In yet another possible example, corresponding isolation requirements can be set according to different common attributes, and the isolation requirements corresponding to different common attributes are not limited in the embodiments of the present application. For example, the larger the common attribute value, the higher the isolation requirement. For example, the isolation requirement of the dedicated slice is the highest, the isolation requirement of the type 2 slice is the second highest, the isolation requirement of the type 1 slice is lower than that of the type 2 slice, and the isolation requirement of the common slice is the lowest.
[0187] In this example, when the first network device obtains the second key, if the isolation requirement of the first slice is higher than that of the second slice, the first network device generates the second key according to the first key; if the isolation requirement of the first slice is lower than that of the second slice, the first network device re-performs network authentication on the user equipment. If the re-authentication is successful, the first network device generates or receives the second key.
[0188] Among them, compared with re-authentication, the process of generating the second key according to the first key is simple, with fewer execution steps, and there is also less interaction between the user equipment and the network.
[0189] S304: The first network device sends first indication information to the user equipment, and the user equipment receives the first indication information. The first indication information is used to instruct the user equipment to obtain a second key.
[0190] The first indication information can be used to instruct the user equipment to generate the second key according to the first key.
[0191] In one implementation, the first indication message can be a non-access stratum (NAS) security mode command (SMC) signaling.
[0192] Step S304 is an optional step. If the first network device initiates a re-network authentication for the user equipment, step S304 does not need to be executed. It should be noted that during the process of the first network device initiating a re-network authentication for the user equipment, the first network device (such as including AMF and SEAF) will send one or more other messages, such as an authentication request message, etc., and the user equipment will also reply with one or more messages, which are not limited here.
[0193] S305: The user equipment obtains the second key.
[0194] In one possible example, in this S305, the user equipment obtains a first key, which is used to secure the information of the first slice or / and the information when the user equipment accesses the first slice; the user equipment generates the second key according to the first key.
[0195] The first key can be stored in the user equipment.
[0196] In another possible example, the user equipment performs re-authentication with the first network device; if the re-authentication between the user equipment and the first network device is successful, the user equipment generates the second key, and this key cannot be deduced from the first key.
[0197] It should be noted that the first network device and the user equipment obtain (including generating using the same parameters) the second key in the same way to ensure that the first network device and the user equipment use the same key to secure communication information subsequently.
[0198] During this registration process, if the attributes of the first slice match the attributes of the second slice, the first network device can also send a registration acceptance message to the user equipment, and the user equipment receives the registration acceptance message.
[0199] The attributes of the first slice match the attributes of the second slice, including that the attributes of the first slice are compatible with the attributes of the second slice, or the attributes of the first slice and the attributes of the second slice are not mutually exclusive.
[0200] The attributes of the first slice match / are compatible with / are not mutually exclusive with the attributes of the second slice, including at least one of the following:
[0201] 21) The attributes of the first slice or the second slice allow sharing with slices of any other attributes.
[0202] Exemplarily, the first slice and / or the second slice is a common slice.
[0203] 22) The attributes of the first slice only allow sharing with slices having the same SST, and the SST of the attributes of the second slice is the same as the SST of the attributes of the first slice.
[0204] For example, both the first slice and the second slice are type 1 slices and have the same SST.
[0205] 23) The attributes of the second slice only allow sharing with slices having the same SST, and the SST of the attributes of the first slice is the same as the SST of the attributes of the first slice.
[0206] For example, both the first slice and the second slice are type 1 slices and have the same SST.
[0207] 24) The attributes of the first slice only allow sharing with slices having the same SD, and the SD of the attributes of the second slice is the same as the SD of the attributes of the first slice.
[0208] For example, both the first slice and the second slice are type 2 slices and have the same SD.
[0209] 25) The attributes of the second slice only allow sharing with slices having the same SD, and the SD of the attributes of the first slice is the same as the SD of the attributes of the second slice.
[0210] For example, both the first slice and the second slice are type 2 slices and have the same SD.
[0211] 26) The second slice and the first slice are mapped to the same single network slice selection assistance information S-NSSAI.
[0212] The first slice and the second slice can be mapped to the same S-NSSAI slice in the home network (Home PLMN). The first slice and the second slice can have different slice identifiers S-NSSAI or different SST types, SDs in their respective PLMNs.
[0213] 27) Other possibilities of having multiple types of slices, where the attributes of the slices are compatible.
[0214] If the attribute of the first slice is not identified in the information of the first slice, it can be considered that the attribute of the first slice allows sharing with slices of any other attribute. For example, it can be considered that the first slice is a normal slice. Or if the attribute of the second slice is not identified in the information of the second slice, it can be considered that the attribute of the second slice allows sharing with slices of any other attribute. For example, it can be considered that the second slice is a normal slice.
[0215] If the attribute of the first slice is not identified in the information of the first slice, or the attribute of the second slice is not identified in the information of the second slice, the user equipment is a legacy device, i.e., an original device. For example, the 5G standard has R15, R16, and R17 versions. If the GST shared attribute is newly introduced in the R17 version, devices of the R15 and R16 versions can be called legacy devices. For "backward compatibility", legacy devices can still be used in the network, and the slices accessed by legacy devices can be regarded as normal slices.
[0216] The following uses two specific embodiments to Figure 3 further illustrate the slice isolation process shown.
[0217] When the user equipment last accessed the network, it accessed the network through the first AMF. For the slice isolation process, see Figure 4 (Time-Sharing Shared AMF), including the following steps:
[0218] S401: The user equipment sends a registration request to the first AMF.
[0219] The registration request includes the identity identifier of the user equipment (such as GUTI or SUCI, etc.) and the identification information of the second slice to be accessed (such as S-NSSAI, which can be any one of the S-NSSAIs in the requested NSSAI). Optionally, the registration request includes the attribute of the second slice.
[0220] S402: The first AMF determines whether it stores the security context of the user equipment.
[0221] For example, the first AMF determines whether it has saved the valid security context of the user equipment according to the identity identifier GUTI of the user equipment. If so, skip S403 and execute S404. If not, execute S403.
[0222] The security context is a valid security context, which means that the first AMF can successfully verify the message authentication code (MAC) in the registration request message using the security context (such as the first key Kamf).
[0223] Optional step S403: The AMF initiates network authentication or primary authentication between the user equipment, the first AMF, and the UDM.
[0224] After executing S403, skip S404 - S409, execute S410, and execute other registration steps in the existing standard process.
[0225] Optional step S404: The first AMF obtains information about the slices subscribed by the user equipment, that is, obtains and retrieves subscription information.
[0226] The first AMF obtains information about the slices subscribed by the user equipment (such as slice identifier NSSAI, which may include one or more S-NSSAIs) from local (the storage unit of the first AMF itself) or the UDM (which can also be other NFs). For example, the first AMF first checks locally whether there is information about the slices subscribed by the user equipment. If it exists, the first AMF obtains the information about the slices subscribed by the user equipment locally. If it does not exist, the first AMF sends a request message to the UDM to obtain the information about the slices subscribed by the user equipment in the UDM.
[0227] The first AMF retrieves and obtains the common attribute information of the subscribed slices from the information about the slices subscribed by the user equipment it has obtained.
[0228] Optional step S405: The first AMF checks the attributes of the subscribed slices.
[0229] For example, optionally, check whether the information about the subscribed slices includes the attribute information of the subscribed slices. The subscribed slices can be one or more slices, and each of the one or more slices corresponds to one or more slice attributes. That is to say, each slice corresponds to the attribute information of a slice respectively.
[0230] If the subscribed slices only contain a single slice attribute, the first AMF skips S406 - S409 and executes S410.
[0231] If there are more than one slice attributes included in the signed slice information, and the more than one slice attributes are compatible attributes, the first AMF skips S406 - S409 and executes S410, or the first AMF may also execute S407.
[0232] In other cases, the first AMF executes S406.
[0233] Optional step S406: The first AMF obtains the first slice information (i.e., the information of the first slice), and compares the attributes of the first slice with the attributes of the second slice for which access is requested.
[0234] The first AMF obtains the first slice information from the local (the storage unit of the first AMF itself) or the UDM (it can also be other NFs). The first slice information is the slice information saved in the context of the user equipment. The first slice information includes one or more S-NSSAIs, which are used to represent the slices indicated by the one or more S-NSSAIs to which the user equipment is accessing or has accessed. The first slice information also includes the attribute information of the first slice (corresponding to one or more S-NSSAIs). In an optional way, if it is determined according to the attributes of the first slice and the second slice that the attributes of the first slice and the second slice do not match, and the isolation requirement of the first slice is higher than or not lower than the isolation requirement of the second slice, the first AMF returns to execute S403.
[0235] In an optional way, if it is determined according to the attributes of the first slice and the second slice that the attributes of the first slice and the second slice do not match, the first AMF returns to execute S403.
[0236] In an optional way, if it is determined according to the attributes of the first slice and the second slice that the attributes of the first slice and the second slice do not match, and the isolation requirement of the first slice is lower than or not higher than the isolation requirement of the second slice, the first AMF executes S407.
[0237] In an optional way, if it is determined according to the attributes of the first slice and the second slice that the attributes of the first slice and the second slice do not match, the first AMF executes S407. If it is determined according to the attributes of the first slice and the second slice that the attributes of the first slice and the second slice match, the first AMF skips S407 - S409 and executes S410.
[0238] It should be noted that the attributes of the obtained first slice can be one or more, and the attributes of the obtained second slice can be one or more. The number of the first slices (S-NSSAI) and the number of the second slices (S-NSSAI) can be the same or different. The attribute of each slice corresponds to a slice (S-NSSAI), that is, each slice (S-NSSAI) corresponds to an attribute. For example, the user equipment accessed 2 slices last time, and the identifiers are S-NSSAI-1 and S-NSSAI-2 respectively. The attribute value of slice S-NSSAI-1 is 0, that is, a normal slice, and the attribute value of slice S-NSSAI-2 is 2, that is, a slice that only allows sharing of the same SD value (the last time these 2 slices were shared by the user equipment, it implies that the SD value of slice S-NSSAI-1 is the same as that of slice S-NSSAI-2). In the context of the AMF corresponding to the user equipment, the identifiers and attribute values of slice S-NSSAI-1 and slice S-NSSAI-2 are saved, and the shared key Kamf is also saved. If the user equipment requests to access another slice S-NSSAI-3 this time, and the attribute value of slice S-NSSAI-3 is 3, that is, an exclusive slice. In this example, the first AMF can obtain the attributes of 2 first slices and the attributes of 1 second slice.
[0239] For the scenario where the attribute value is "0" - "3", since the attribute "3" cannot coexist with other attributes (i.e., it is incompatible), while the attribute "0" is compatible with all attributes. Therefore, for the scenario of multiple S-NSSAIs, it includes 4 possible single attributes (when there is 1 attribute) + 3 possible compatible attributes (when there are 2 attributes) + 1 possible compatible attribute (when there are 3 attributes) = 8 possible compatible attribute combinations. For the first slice attribute information and the second slice attribute information that respectively include multiple S-NSSAIs, the combination of the two slice information will have 8 x 8 = 64 possible attribute combinations. For the convenience of description, in the embodiments of the present application, an example is given where the information of 1 first slice is saved and the user equipment requests to access 1 second slice. For the case of multiple slices or multiple attribute values, the situation shown in this scenario can be referred to, and will not be described one by one. Specifically, it can be summarized as the following situations:
[0240] 31) The exclusivity requirement of the second slice requested to be accessed is higher than that of the first slice, that is, the isolation requirement of the second slice is higher than that of the first slice.
[0241] For example, the attribute of the second slice is an exclusive slice (the attribute value is 3), and the attribute of the first slice is a non-exclusive slice (the attribute value is 0 or 1 or 2).
[0242] For another example, the attribute value of the second slice is 1 or 2, and the attribute of the first slice is a normal slice (attribute value is 0).
[0243] 32) The exclusivity requirement of the second slice requesting access is lower than that of the first slice, that is, the isolation requirement of the second slice is lower than that of the first slice.
[0244] For example, if the attribute of the first slice is an exclusive slice (attribute value is 3), the attribute of the second slice is a non-exclusive slice (attribute value is 0 or 1 or 2).
[0245] For another example, the attribute value of the first slice is 1 or 2, and the attribute of the second slice is a normal slice (attribute value is 0).
[0246] 33) Other situations where the second slice requesting access is incompatible with the first slice.
[0247] Among them, 33) includes the situations shown in 31) and 32). For the remaining situations, reference can be made to Figure 3 the relevant descriptions in, which will not be listed one by one here.
[0248] 34) The second slice requesting access and the first slice can be used simultaneously.
[0249] For example, the second slice and the first slice are the same exclusive slice. For another example, the second slice and the first slice are normal slices. And other situations where the second slice and the first slice are attribute-compatible. For other situations, reference can be made to Figure 3 the relevant descriptions in, which will not be listed one by one here.
[0250] For 31) and 33), the first AMF returns to execute S403, adopting a stronger isolation method to ensure the security of information between slices. In another alternative implementation, the first AMF executes S407, that is, using the same execution method as 32).
[0251] For 32), the first AMF executes S407, adopting an isolation method with a lower cost to ensure the security of information between slices. In another alternative implementation, the first AMF executes S40, that is, using the same execution method as 31) and 33).
[0252] For 34), the first AMF skips S407 - S409 and executes S410, and no isolation is required between slices.
[0253] Optional step S407: The first AMF starts a key update process to update the key Kamf stored at the AMF.
[0254] In S407, the first AMF generates the second key (updated key Kamf) based on the first key (such as the key Kamf).
[0255] Optional step S408: The first AMF notifies the user equipment to update the first key Kamf and sends the required key update parameters to the user equipment. The message sent in S408 can be a "non-access stratum" (NAS) security mode command (SMC) message. Optional step S409: The user equipment updates the stored first key Kamf according to the received key update parameters to generate the second key Kamf (that is, the originally stored Kamf key is the first key, and the updated Kamf key is the second key).
[0256] S410: The user equipment completes other sub-processes in the registration process and can participate in relevant standard processes, which will not be introduced in detail here.
[0257] S411: The first AMF sends a registration acceptance message to the user equipment.
[0258] In another possible way, S406 can be simplified to the first AMF checking whether the second slice needs to be isolated. If it does, it returns to execute S403 again, or returns to execute S707 (execute S707 - S709) again. If not, the first AMF executes S410.
[0259] The user equipment accessed the network through the second AMF when it last accessed the network. The user equipment accesses the network through the first network device this time. For the slice isolation process, see Figure 5 (Non-shared AMF), including the following steps:
[0260] The process of S501 refers to S401 above.
[0261] S502: The first AMF determines that the user equipment has accessed the network before (such as including GUTI in the registration request) and has accessed the network through the second AMF before (such as GUTI includes the ID of the AMF). That is, the AMF to which the user equipment accessed before has changed (the second AMF and the first AMF are not the same AMF).
[0262] The first AMF can be regarded as a new AMF or a target AMF. The second AMF can be regarded as an old AMF or a source / initial AMF.
[0263] S503: The first AMF sends a request message (such as a user equipment context transfer request message UE context transfer request) to the second AMF to obtain information about the first slice stored by the second AMF.
[0264] The request message may include information about the second slice to which the user equipment requests access.
[0265] S504: The second AMF compares the attributes of the saved first slice with the attributes of the second slice to which access is requested. In an optional implementation, S504 is optionally executed, that is, the second AMF does not perform this comparison.
[0266] S505: The second AMF sends a response message (such as a user equipment context transfer response message UE context transfer response) to the first AMF.
[0267] The second AMF may determine which information to carry in the response message in S505 according to the comparison result of S504.
[0268] For example, if the attributes of the first slice match the attributes of the second slice, the response message may include the security context of the first slice (such as including the first key Kamf, etc.).
[0269] For another example, if the attributes of the first slice do not match those of the second slice, the response message may include a non-secure context and not include a secure context (such as the first key Kamf). Or the response message may include a context that does not affect slice isolation (either a secure or non-secure context, such as the SUPI of the user equipment, etc.), and not include a context that affects slice isolation (such as the first key Kamf). Optionally, the response message includes the identification information (NSSAI) and attributes of the first slice. Optionally, the response message includes indication information to inform the first AMF that the user equipment has passed the security authentication, the security context of the user equipment exists but does not match the attributes of the second slice, and the secure context (such as the first key Kamf) cannot be sent, indicating that the first AMF should perform re-authentication (network authentication or slice authentication, where network authentication includes primary authentication and optional slice authentication). Or alternatively, the second AMF first updates the first key Kamf (to the second key Kamf after the update) or performs re-authentication, and then carries the updated security context (such as the second key Kamf and the parameters required for key update, and optionally also includes key indication information to indicate that the key has been updated or to indicate that the key is the second key) in the response message and sends it to the first AMF. Possibly, for slice isolation, the first AMF may also update the key or perform re-authentication.
[0270] For another example, if the second AMF cannot determine whether the attributes of the first slice match those of the second slice, such as the second AMF not storing the attributes of the first slice, or the request message sent by the first AMF not including the attributes of the second slice, etc., in this case, the second AMF may consider that the attributes of the first slice do not match those of the second slice.
[0271] In an optional manner, if the second AMF does not execute S504, that is, the second AMF considers that the attributes of the first slice and the second slice match (are compatible), S505 can be executed according to the existing process.
[0272] In an optional manner, the second AMF includes indication information in the S505 message to indicate that the first AMF should perform re-primary authentication (that is, generate a second key without relying on the first key), or perform Kamf key update (that is, send the first key and indicate that the first AMF should generate a second key based on the first key).
[0273] S506: The first AMF processes the response message.
[0274] The first AMF decides and executes the subsequent process according to the response message.
[0275] If the response message includes the first key and / or the second key, the first slice identification information, and attributes, compare the attributes of the first slice with the attributes of the second slice for which access is requested.
[0276] In an alternative manner, if it is determined, based on the attributes of the first slice and the attributes of the second slice, that the attributes of the first slice and the attributes of the second slice do not match, and the isolation requirement of the first slice is higher than or not lower than the isolation requirement of the second slice, the first AMF executes S507.
[0277] In an alternative manner, if it is determined, based on the attributes of the first slice and the attributes of the second slice, that the attributes of the first slice and the attributes of the second slice do not match, and the isolation requirement of the first slice is lower than or not higher than the isolation requirement of the second slice, the first AMF executes S508.
[0278] In an alternative manner, if it is determined, based on the attributes of the first slice and the attributes of the second slice, that the attributes of the first slice and the attributes of the second slice do not match, the first AMF executes S507.
[0279] In an alternative manner, if it is determined, based on the attributes of the first slice and the attributes of the second slice, that the attributes of the first slice and the attributes of the second slice do not match, the first AMF executes S508.
[0280] If it is determined, based on the attributes of the first slice and the attributes of the second slice, that the attributes of the first slice and the attributes of the second slice match, the first AMF skips S507 - S508 and executes S509.
[0281] In an alternative manner, if the response message includes the second key Kamf and the parameters required for key update, the first AMF executes S508.
[0282] In an alternative manner, the first AMF executes according to the indication information included in the S505 message. That is, if it is indicated that the first AMF re - performs primary authentication, then S507 is executed; or if it is indicated that the first AMF performs Kamf key update, then S508 is executed.
[0283] For the process of S507, refer to S403 above.
[0284] The first AMF initiates primary authentication of the user equipment with the network.
[0285] After performing the S507, execute the existing standard process to generate the second key (skipping the key update process in S508), execute S509, and execute other registration steps in the existing standard process.
[0286] For the process of S508, refer to the above S407 - S409.
[0287] For the process of S509 - S510, refer to the above S410 - S411.
[0288] Optionally, either S504 or S506 can be executed, or both can be executed. It should be noted that the first AMF in the above S506 can re - judge independently of the second AMF (S504). This is because the first AMF and the second AMF may be in different PLMNs or different security domains, or the first AMF may not fully trust the judgment result of the second AMF.
[0289] In addition, the first AMF can also obtain the information of the first slice through other NFs (not the second AMF, such as the unstructured data storage function (UDSF)). The first AMF can also indirectly interact with the second AMF through other NFs (such as UDSF), and there is no limitation here.
[0290] The slice isolation process provided during the deregistration process is as Figure 6 shown, and this process includes:
[0291] S601a: The user equipment sends a deregistration request message to the first network device, and the first network device receives the deregistration request message.
[0292] In this S601a, the deregistration process is initiated by the user equipment.
[0293] S601b: The first network device sends a deregistration request message to the user equipment, and the user equipment receives the deregistration request message.
[0294] In this S601b, the deregistration process is initiated by the first network device.
[0295] It can be understood that either S601a or S601b can be executed.
[0296] S602: The first network device deletes the third key in the user equipment context stored locally (i.e., in the first network device). The third key is used to protect the information of the third slice or the information when the user equipment accesses the third slice. The third slice is any / each slice among the last slice (corresponding to an S-NSSAI identifier) or multiple slices (corresponding to multiple S-NSSAI identifiers or an NSSAI including multiple S-NSSAIs) accessed by the user equipment (when multi-slice access is allowed, the attributes of these slices are default compatible and can share a set of keys).
[0297] In S602, the first network device can determine that the attribute of the third slice is not allowed to be shared with any other attribute slices (i.e., the third slice is an exclusive slice with an attribute value of 3). The first network device deletes the third key in the context of the user equipment stored locally.
[0298] Optionally, in S602, the first network device can determine that the user equipment subscribes to slices with multiple attributes (such as the user subscription information stored locally or the user subscription information of the user obtained from the UDM). Among them, there are slices that are incompatible with the attributes of the third slice. The first network device deletes the third key in the context of the user equipment stored locally.
[0299] Optionally, in S602, the first network device can determine that the attribute of the third slice is not allowed to be shared with any other attribute slices (i.e., the third slice is an exclusive slice with an attribute value of 3), and the first network device can determine that the user equipment only subscribes to this slice (such as the user subscription information stored locally or the user subscription information of the user obtained from the UDM). The first network device retains (i.e., does not delete) the third key in the context of the user equipment stored locally.
[0300] The attribute of the third slice is not allowed to be shared with any other attribute slices (i.e., the third slice is an exclusive slice with an attribute value of 3). The first network device deletes the third key in the context of the user equipment stored locally.
[0301] Optionally, the first network device sends indication information to other network devices or network functions (such as the UDM, other AMFs, etc.), indicating that the network device or network function deletes the third key in the context of the user equipment stored.
[0302] Optionally, the first network device sends indication information to the user equipment, indicating that the user equipment deletes the third key stored.
[0303] S603: The user equipment deletes the third key.
[0304] Optionally, the execution order of S602 and S603 is not limited.
[0305] In a possible example, in this S603, the user equipment may determine that the attribute of the third slice does not allow sharing with slices of any other attribute, and the user equipment deletes the third key.
[0306] In another possible example, in this S603, the user equipment receives indication information from the first network device, and the user equipment deletes the third key.
[0307] In this deregistration process, if the attribute of the third slice allows sharing with slices of other attributes or the attribute of the third slice is not obtained, when the user equipment initiates a deregistration process, the first network device may also send a deregistration acceptance message to the user equipment, and the user equipment receives the deregistration acceptance message; or when the first network device initiates a deregistration process, the user equipment may also send a deregistration acceptance message to the first network device, and the first network device receives the deregistration acceptance message.
[0308] It can be understood that S602 and S603 may be executed before, during, or after the deregistration process.
[0309] It should be noted that after the deregistration process is complete, if the user equipment accesses an exclusive slice, the user equipment needs to perform an authentication (optionally, slice authentication) again with the network to generate a new key for accessing the exclusive slice.
[0310] In the embodiment, by deleting sensitive / important security contexts, such security contexts can be prevented from being reused, ensuring the security of information between slices.
[0311] The following uses two specific embodiments to Figure 6 further illustrate the slice isolation process shown.
[0312] The user equipment initiates a deregistration process. The slice isolation process is shown in Figure 7 and includes the following steps:
[0313] S701: The user equipment sends a deregistration request message (Deregistration Request) to the AMF, and the AMF receives the deregistration request message.
[0314] S702: The AMF confirms the attributes of the third slice in the context of the user equipment stored. The third slice is the last accessed slice of the user equipment (corresponding to an S-NSSAI identifier), or any / each slice among multiple slices (corresponding to multiple S-NSSAI identifiers or an NSSAI including multiple S-NSSAIs) (when simultaneous access to multiple slices is allowed, indicating that the attributes of these slices are compatible and can share a set of keys).
[0315] The AMF can obtain the attributes of the third slice locally or in the UDM (which can also be other NFs). For example, the AMF first determines whether the attributes of the third slice exist in the context of the user equipment stored locally. If they exist, the AMF obtains the attributes of the third slice in the context of the user equipment. If they do not exist, the AMF obtains the attributes of the third slice in the UDM.
[0316] S703: Perform processes such as PDU session release, N4 session release, and policy termination.
[0317] S704: The AMF sends a Deregistration Accept message, and the user equipment receives the Deregistration Accept message.
[0318] S705a: The AMF checks the attributes of the third slice.
[0319] S705b: The user equipment checks the attributes of the third slice.
[0320] If only slices with compatible attributes are subscribed (such as the attributes of the third slice being ordinary slices, allowing sharing with slices of other attributes), or the attributes of the third slice are not obtained, the AMF and the user equipment retain the third key and execute S706.
[0321] If slices with incompatible attributes are subscribed (such as the attributes of the third slice being exclusive slices, not allowing sharing with slices of any attributes), the AMF and the user equipment delete the third key and execute S706.
[0322] S706: The user equipment and the AMF release the signaling connection.
[0323] It should be noted that S702 can also be executed during the execution of S703 (with multiple interaction messages), or through the existing messages in S703 (such as by adding information elements), rather than necessarily adding separate interaction messages.
[0324] In addition, the execution order of S705a and S705b is not specified, and S705a and S705b can be executed before S704, or can be executed after S706.
[0325] The network device initiates the deregistration process. For the slice isolation process, see Figure 8 as shown, including the following steps:
[0326] Optional step S801: The UDM sends a deregistration notification message, and the AMF receives the deregistration notification message.
[0327] In S801, the UDM initiates the deregistration process.
[0328] Optionally, the deregistration notification message may include the attributes of the third slice or the attributes of all slices subscribed by the user equipment. Optionally, the deregistration notification message may further include indication information for instructing the AMF to delete the third key. That is, the UDM determines the security sensitivity or isolation requirements based on the information of the third slice or the message of the slices subscribed by the user equipment.
[0329] S802: The AMF sends a deregistration request message to the user equipment, and the user equipment receives the deregistration request message.
[0330] The AMF may also initiate the deregistration process by itself.
[0331] The deregistration request message is an optional message, that is, the deregistration process may or may not notify the user equipment. If the deregistration request message is sent, optionally, the AMF may further instruct the user equipment to delete the third key. Here, the AMF determines whether to delete the third key based on the attributes of the third slice sent by the UDM (see S705a above), or the AMF determines whether to delete the third key based on the indication information of the UDM.
[0332] The process of S803 can be referred to S703 above.
[0333] S804: The user equipment sends a deregistration acceptance message, and the AMF receives the deregistration acceptance message.
[0334] S805a: The AMF checks the attributes of the third slice.
[0335] Refer to S702 and S802 above or S705a above to obtain and check the attributes of the third slice.
[0336] S805b: The user equipment checks the attributes of the third slice.
[0337] Refer to the above S705b.
[0338] The process of S806 can refer to the above S706.
[0339] The S805a can be executed at any step (including before step S801, so the AMF can initiate the deregistration process by itself). The S805b can be executed at any step after S802.
[0340] The Figure 7 and Figure 8 The slice isolation method shown is applicable to both time - shared AMF and non - shared AMF.
[0341] The slice isolation process provided during the AMF redirection is as Figure 9 shown, and this process includes:
[0342] S901: The first network device sends a redirection message to the second network device, and the second network device receives the redirection message.
[0343] During the AMF redirection process, the first network device can be understood as the source network device, and the second network device can be understood as the target network device during the AMF redirection process.
[0344] The redirection message includes the information of the fourth slice of the user equipment and / or the information of the fifth slice that the user equipment requests to access. The fourth slice is the slice that the user previously accessed or is currently accessing and is saved.
[0345] The information of the fourth slice includes the identification information of the fourth slice, and optionally includes the fourth key and / or the attributes of the fourth slice. The fourth key is used to protect the information of the fourth slice or / and the information when the user equipment accesses the fourth slice. The information of the fifth slice includes the identification information of the fifth slice and optionally the attributes of the fifth slice.
[0346] A typical scenario of AMF redirection is: The user equipment has completed network - level authentication (primary authentication) with the first network device and generated a security context (such as the fourth key kamf). The first network device decides that another suitable second AMF will serve the user equipment. At this time, the interaction between the user equipment and the first network device is converted into the interaction between the user equipment and the second network device.
[0347] Before S901, the first network device may also check whether the security context of the user device currently saved has been used to protect the information of a slice (such as the fourth slice) or whether there is information of the fourth slice. If not, that is, there is no fourth slice, the first network device may assume that the attribute of the (non-existent) fourth slice is a common slice that can match any slice, and then execute S901. If so, then there is the fourth slice.
[0348] If the information of the fourth slice matches the information of the fifth slice (similarly, if there is no information of the fifth slice, it is regarded as a common slice that can match any slice), the first network device executes S901;
[0349] If the information of the fourth slice does not match the information of the fifth slice, and the isolation requirement of the fourth slice is higher than or not lower than the isolation requirement of the fifth slice (for example, the fourth slice has an isolation requirement (non-common slice) while the fifth slice is a common slice), the first network device generates the fifth key according to the fourth key, and then executes S901;
[0350] If the information of the fourth slice does not match the information of the fifth slice, and the isolation requirement of the fourth slice is lower than or not higher than the isolation requirement of the fifth slice (for example, the fourth slice is a common slice without an isolation requirement while the fifth slice is an exclusive slice), the first network device executes S901.
[0351] An optional way, if the information of the fourth slice does not match the information of the fifth slice, the first network device generates the fifth key according to the fourth key, and then executes S901.
[0352] S902: If the information of the fourth slice does not match the information of the fifth slice, and the fifth slice has an isolation requirement, the second network device re-authenticates the user device.
[0353] If the second network device successfully re-authenticates the user device, the second network device generates the fifth key.
[0354] If the information of the fourth slice matches the information of the fifth slice, the second network device continues to register the user device.
[0355] If the information of the fourth slice does not match the information of the fifth slice, and the fourth slice does not have an isolation requirement (that is, it is allowed to share with other slices with any attributes), the second network device continues to register the user device.
[0356] It should be noted that the first network device may compare the information of the fourth slice with the information of the fifth slice, and / or the second network device may also compare the information of the fourth slice with the information of the fifth slice, and when the compared slice information does not match, respectively execute S902 to re-authenticate and generate a fifth key (not based on the fourth key) or generate a fifth key according to the fourth key.
[0357] The following uses a specific embodiment to further illustrate Figure 9 the slice isolation process shown.
[0358] The slice isolation process is shown in Figure 10 and is mainly applicable to non-shared AMF, including the following steps:
[0359] S1001: The user equipment sends a registration request message to the access network device.
[0360] The registration request message is used to request access to the fifth slice.
[0361] S1002: The access network device sends an initial message (Initial UE message) to the initial / source (Initial / Source) AMF. The initial / source (Initial / Source) AMF may be the first network device.
[0362] The initial message includes the registration request message.
[0363] S1003: The source AMF initiates network authentication with the user equipment ( Figure 10 not shown in the figure), and establishes a security context (including the key Kamf) of the user equipment to securely protect the messages exchanged between the user equipment and the network (such as encrypting and integrity protecting NAS messages). The source AMF determines that AMF redirection is required, and the target AMF will serve the user equipment. The target AMF may be the second network device. The source AMF compares the information of the fourth slice currently saved with the information of the fifth slice requested by the user to access.
[0364] If the information of the fourth slice matches the information of the fifth slice (if there is no information of the fifth slice, it is regarded as a common slice that can match any slice), the first network device executes S1004. If the information of the fourth slice does not match the information of the fifth slice, and the fourth slice has an isolation requirement (not a common slice), the first network device generates the fifth key according to the fourth key, and then executes S1004. If the information of the fourth slice does not match the information of the fifth slice, and the fourth slice has no isolation requirement (common slice), the first network device executes S1004.
[0365] An optional way is that if the information of the fourth slice does not match the information of the fifth slice, and the isolation requirement of the fourth slice is higher than or not lower than the isolation requirement of the fifth slice (for example, the fourth slice has an isolation requirement (not a common slice) while the fifth slice is a common slice), the first network device (initial AMF) generates the fifth key according to the fourth key, and then executes S1004;
[0366] An optional way is that if the information of the fourth slice does not match the information of the fifth slice, and the isolation requirement of the fourth slice is lower than or not higher than the isolation requirement of the fifth slice (for example, the fourth slice is a common slice without an isolation requirement while the fifth slice is a dedicated slice), the first network device (initial AMF) executes S1004.
[0367] An optional way is that if the information of the fourth slice does not match the information of the fifth slice, the first network device (initial AMF) generates the fifth key according to the fourth key, and then executes S1004.
[0368] S1004: The source AMF sends a rerouted message to the target AMF.
[0369] The rerouted message includes the information of the fourth slice and / or the message of the fifth slice. The information of the fourth slice includes the identification information of the fourth slice, and optionally includes the fourth key and / or the attributes of the fourth slice. The fourth key is used to protect the information of the fourth slice or / and the information when the user equipment accesses the fourth slice. The information of the fifth slice includes the identification information of the fifth slice, and optionally the attributes of the fifth slice.
[0370] Optionally, the source AMF can forward the rerouted message through the access network device. (As shown in S1004a and S1004b). If it is forwarded through the access network device, the rerouted message of S1004b can be different from the rerouted message of S1004.
[0371] S1005: The target AMF compares the information of the currently saved fourth slice with the information of the fifth slice to which the user requests to access.
[0372] If the information of the fourth slice does not match the information of the fifth slice, and the fifth slice has an isolation requirement, the second network device first re - authenticates the user equipment and generates a fifth key, and then executes S1006. The process of this re - authentication is similar to that of S1003, except that the network authentication with the user equipment is initiated by the target AMF.
[0373] An optional method: If the information of the fourth slice does not match the information of the fifth slice, and the isolation requirement of the fourth slice is higher than or not lower than that of the fifth slice (for example, the fourth slice has an isolation requirement (non - ordinary slice) while the fifth slice is an ordinary slice), the target AMF generates the fifth key according to the fourth key, and then executes S1006;
[0374] An optional method: If the information of the fourth slice does not match the information of the fifth slice, and the isolation requirement of the fourth slice is lower than or not higher than that of the fifth slice (for example, the fourth slice is an ordinary slice without an isolation requirement while the fifth slice is an exclusive slice), the target AMF executes S1006.
[0375] An optional method: If the information of the fourth slice does not match the information of the fifth slice, the target AMF generates the fifth key according to the fourth key, and then executes S1006.
[0376] An optional method: If the information of the fourth slice does not match the information of the fifth slice, the target AMF initiates network authentication (primary authentication) with the user equipment and generates a fifth key (not based on the fourth key), and then executes S1006. If the information of the fourth slice matches the information of the fifth slice, the second network device executes S1006.
[0377] If the information of the fourth slice does not match the information of the fifth slice, and the fourth slice does not have an isolation requirement (that is, it is allowed to share with other slices with any attributes), the second network device executes S1006.
[0378] S1006: The second network device continues to register the user equipment.
[0379] The comparison processes of S1003 and S1005 can both be executed, or either one can be selected for execution.
[0380] Combining the above embodiments, it can be seen that the slice isolation provided by the embodiments of the present application is applicable to the scenarios shown in Table 1 below.
[0381] Table 1
[0382]
[0383]
[0384] Based on the above embodiments, it can be known that the slice isolation method provided by the embodiments of the present application can ensure the secure isolation between slices and avoid information leakage between slices. The embodiments of the present application can ensure the security of scenarios under a shared network infrastructure and can also ensure the security of a local network.
[0385] It can be understood that the various embodiments provided by the present application can be used alone or in combination.
[0386] As Figure 11 shown, it is a possible exemplary block diagram of a communication device involved in the present application. The communication device 1100 can exist in the form of software or hardware. The communication device 1100 can include: a processing unit 1102 and a transceiver unit 1103. As an implementation manner, the transceiver unit 1103 can include a receiving unit and a sending unit. The processing unit 1102 is used to control and manage the actions of the communication device 1100. The transceiver unit 1103 is used to support the communication between the communication device 1100 and other network entities. The communication device 1100 can also include a storage unit 1101, which is used to store the program code and data of the communication device 1100.
[0387] Among them, the processing unit 1102 can be a processor or a controller. For example, it can be a CPU, a general-purpose processor, a DSP, an ASIC, an FPGA or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in combination with the disclosure of the present application. The processor can also be a combination that implements a computing function, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and so on. The storage unit 1101 can be a memory. The transceiver unit 1103 is an interface circuit of the device for receiving signals from other devices. For example, when the device is implemented in the form of a chip, the transceiver unit 1103 is an interface circuit of the chip for receiving signals from other chips or devices, or is an interface circuit of the chip for sending signals to other chips or devices.
[0388] The communication device 1100 may be a user equipment and / or a network device in any of the above embodiments, or may also be a chip for the user equipment and / or the network device. For example, when the communication device 1100 is a user equipment and / or a network device, the processing unit 1102 may be a processor, and the transceiver unit 1103 may be a transceiver. Optionally, the transceiver may include a radio frequency circuit, and the storage unit may be a memory. For example, when the communication device 1100 is a chip for the user equipment and / or the network device, the processing unit 1102 may be a processor, and the transceiver unit 1103 may be an input / output interface, a pin, a circuit, etc. The processing unit 1102 may execute computer-executable instructions stored in the storage unit. Optionally, the storage unit is a storage unit within the chip, such as a register, a cache, etc., and the storage unit may also be a storage unit outside the chip within the user equipment and / or the network device, such as a ROM or other types of static storage devices that can store static information and instructions, a RAM, etc.
[0389] In the first embodiment, the communication device 1100 may be applied to a first network device.
[0390] Specifically, the transceiver unit 1103 is configured to obtain information of a first slice of a user equipment;
[0391] The processing unit 1102 is configured to obtain a second key if the information of the first slice does not match the information of a second slice requested by the user equipment to access, where the second key is used to securely protect the information of the second slice or / and the information when the user equipment accesses the second slice.
[0392] In one implementation, the information of the first slice includes the attributes of the first slice, and the information of the second slice includes the attributes of the second slice;
[0393] When the processing unit 1102 determines that the information of the first slice does not match the information of the second slice requested by the user equipment to access, and the first network device obtains the second key, the processing unit 1102 is specifically configured to obtain the second key if the attributes of the first slice do not match the attributes of the second slice.
[0394] In one implementation, when obtaining the second key, the processing unit 1102 is specifically configured to generate the second key according to the first key, where the first key is used to securely protect the information of the first slice or / and the information when the user equipment accesses the first slice.
[0395] In one implementation, when generating the second key according to the first key, the processing unit 1102 is specifically configured to generate the second key according to the first key if the isolation requirement of the first slice is higher than that of the second slice.
[0396] In one implementation, when obtaining the second key, the processing unit 1102 is specifically configured to: re-authenticate the user equipment; if the re-authentication of the user equipment is successful, generate the second key.
[0397] In one implementation, when re-authenticating the user equipment, the processing unit 1102 is specifically configured to re-perform network authentication on the user equipment if the isolation requirement of the first slice is lower than that of the second slice.
[0398] In one implementation, the mismatch between the attributes of the first slice and the attributes of the second slice includes:
[0399] The attributes of the first slice or the second slice do not allow sharing with slices of any other attributes; or
[0400] The attributes of the first slice only allow sharing with slices having the same service type SST, and the SST of the attributes of the second slice is different from the SST of the attributes of the first slice; or
[0401] The attributes of the second slice only allow sharing with slices having the same service type SST, and the SST of the attributes of the first slice is different from the SST of the attributes of the second slice; or
[0402] The attributes of the first slice only allow sharing with slices having the same slice differentiation factor SD, and the SD of the attributes of the second slice is different from the SD of the attributes of the first slice; or
[0403] The attributes of the second slice only allow sharing with slices having the same slice differentiation factor SD, and the SD of the attributes of the first slice is different from the SD of the attributes of the second slice.
[0404] In one implementation, the transceiver unit 1103 is further configured to send a registration acceptance message to the user equipment if the attributes of the first slice match the attributes of the second slice.
[0405] In one implementation, the match between the attributes of the first slice and the attributes of the second slice includes:
[0406] The attributes of the first slice or the second slice allow sharing with slices of any other attributes; or
[0407] The attributes of the first slice only allow slices with the same SST to be shared, and the SST of the attributes of the second slice is the same as the SST of the attributes of the first slice; or
[0408] The attributes of the second slice only allow slices with the same SST to be shared, and the SST of the attributes of the first slice is the same as the SST of the attributes of the first slice; or
[0409] The attributes of the first slice only allow slices with the same SD to be shared, and the SD of the attributes of the second slice is the same as the SD of the attributes of the first slice; or
[0410] The attributes of the second slice only allow slices with the same SD to be shared, and the SD of the attributes of the first slice is the same as the SD of the attributes of the second slice; or
[0411] The second slice and the first slice are mapped to the same single network slice selection assistance information S-NSSAI.
[0412] This communication device 1100 can be applied to a user equipment.
[0413] Specifically, the transceiver unit 1103 is configured to send a first request message to a first network device, where the first request message is used to request access to a second slice; and receive a first indication message from the first network device, where the first indication message is used to instruct the user equipment to obtain a second key;
[0414] The processing unit 1102 is configured to obtain the second key, where the second key is used to securely protect the information of the second slice or / and the information when the user equipment accesses the second slice.
[0415] In one implementation, when obtaining the second key, the processing unit 1102 is specifically configured to obtain a first key, where the first key is used to securely protect the information of the first slice or / and the information when the user equipment accesses the first slice; and generate the second key according to the first key.
[0416] In one implementation, when obtaining the second key, the processing unit 1102 is specifically configured to re-authenticate with the first network device; if the re-authentication with the first network device is successful, the user equipment generates the second key.
[0417] In one implementation, the transceiver unit 1103 is further configured to receive a registration acceptance message from the first network device.
[0418] In a second embodiment, this communication device 1100 can be applied to a first network device.
[0419] Specifically, the transceiver unit 1103 is configured to receive a deregistration request message or send a deregistration request message.
[0420] The processing unit 1102 is configured to delete the third key of the user equipment, where the third slice is the slice that the user equipment last accessed, and the third key is used to protect the information of the third slice and / or the information when the user equipment accesses the third slice.
[0421] In one implementation, when deleting the third key of the user equipment, the processing unit 1102 is specifically configured to delete the third key of the user equipment if it is determined that the third slice attribute does not allow sharing with any attribute slice.
[0422] In one implementation, the transceiver unit 1103 is further configured to send a deregistration acceptance message to the user equipment if it is determined that the third slice attribute allows sharing with other attribute slices.
[0423] In one implementation, the transceiver unit 1103 is further configured to send a deregistration acceptance message to the user equipment if the slice attribute of the third slice is not obtained.
[0424] The communication device 1100 can be applied to a user equipment.
[0425] Specifically, the transceiver unit 1103 is configured to send a deregistration request message or receive a deregistration request message.
[0426] The processing unit 1102 is configured to delete the third key of the user equipment, where the third slice is the slice that the user equipment last accessed, and the third key is used to protect the information of the third slice and / or the information when the user equipment accesses the third slice.
[0427] In one implementation, when deleting the third key of the user equipment, the processing unit 1102 is specifically configured to delete the third key of the user equipment if it is determined that the third slice does not allow sharing with any attribute slice.
[0428] In a third embodiment, the communication device 1100 can be applied to a second network device.
[0429] Specifically, the transceiver unit 1103 is configured to receive redirection information from a first network device, where the redirection information includes information of a fourth slice of the user equipment and / or information of a fifth slice that the user equipment requests to access.
[0430] The processing unit 1102 is configured to re - authenticate the user equipment if the information of the fourth slice does not match the information of the fifth slice and the fifth slice has an isolation requirement.
[0431] In one implementation, the processing unit 1102 is further configured to continue to authenticate the user equipment if the information of the fourth slice does not match the information of the fifth slice and the fifth slice allows sharing with any other attribute slice.
[0432] It can be understood that the specific implementation process and the corresponding beneficial effects of the communication device when used in the above - mentioned slice isolation method can refer to the relevant descriptions in the foregoing method embodiments and will not be elaborated here.
[0433] As Figure 12 shown, it is a schematic diagram of a communication device provided by the present application. The communication device may be the above - mentioned mobility management network element or a terminal device. The communication device 1200 includes: a processor 1202, a communication interface 1203, and a memory 1201. Optionally, the communication device 1200 may further include a communication line 1204. Among them, the communication interface 1203, the processor 1202, and the memory 1201 may be interconnected through the communication line 1204; the communication line 1204 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The communication line 1204 may be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 12 only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0434] The processor 1202 may be a CPU, a microprocessor, an ASIC, or one or more integrated circuits for controlling the execution of the program of the solution of the present application.
[0435] The communication interface 1203 uses any transceiver - like device for communicating with other devices or communication networks, such as Ethernet, RAN, wireless local area networks (WLAN), wired access networks, etc.
[0436] The memory 1201 can be a ROM or other types of static storage devices that can store static information and instructions, a RAM or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processor through the communication line 1204. The memory can also be integrated with the processor.
[0437] Among them, the memory 1201 is used to store the computer execution instructions for executing the solution of this application, and is controlled by the processor 1202 to execute. The processor 1202 is used to execute the computer execution instructions stored in the memory 1201, so as to implement the registration method of the terminal device provided in the above embodiments of this application.
[0438] Optionally, the computer execution instructions in the embodiments of this application can also be referred to as application program codes, and the embodiments of this application do not make specific limitations thereto.
[0439] The embodiments of this application also provide a computer storage medium, storing a computer program, which when executed by a computer, can enable the computer to execute the above slice isolation method.
[0440] The embodiments of this application also provide a computer program product containing instructions, which when running on a computer, can enable the computer to execute the above provided slice isolation method.
[0441] The embodiments of this application also provide a communication system, which includes a first network device and a user device. Optionally, the communication system further includes a second network device.
[0442] Those of ordinary skill in the art can understand that the various numerical numbers such as the first and the second involved in this application are only for the convenience of description and are not used to limit the scope of the embodiments of this application, nor do they represent the order of precedence. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one" means one or more. At least two means two or more. "At least one", "any one" or their similar expressions refer to any combination of these items, including any combination of single item (s) or plural items (s). For example, at least one (item, kind) of a, b, or c can mean: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c can be single or multiple. "Multiple" means two or more, and other quantifiers are similar. In addition, for elements where the singular forms "a", "an", and "the" appear, unless the context clearly stipulates otherwise, they do not mean "one or only one", but mean "one or more than one". For example, "a device" means one or more such devices.
[0443] In the above - mentioned embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are generated in whole or in part. The computer can be a general - purpose computer, a special - purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer - readable storage medium or transmitted from one computer - readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer - readable storage medium can be any available medium that a computer can access or a data storage device such as a server, data center, etc. that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid - state disk (SSD)), etc.
[0444] In the embodiments of the present application, the various illustrative logical units and circuits described can be implemented or operate the described functions through a general-purpose processor, a digital signal processor, an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic, discrete hardware components, or any combination of the above designs. The general-purpose processor can be a microprocessor. Optionally, the general-purpose processor can also be any conventional processor, controller, microcontroller or state machine. The processor can also be implemented through a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other similar configuration.
[0445] The steps of the methods or algorithms described in the embodiments of the present application can be directly embedded in hardware, software units executed by a processor, or a combination of both. The software units can be stored in a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium can be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium can also be integrated into the processor. The processor and the storage medium can be disposed in an ASIC.
[0446] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or boxes Figure 1 one box or multiple boxes.
[0447] Although the present application has been described in conjunction with specific features and their embodiments, it is obvious that various modifications and combinations can be made without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely exemplary illustrations of the present application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.
Claims
1. A slice isolation method, characterized in that: include: The first network device obtains information about a first slice of the user equipment; If the information of the first slice does not match the information of the second slice requested by the user equipment to access, the first network device obtains a second key, where the second key is used to securely protect the information of the second slice or / and the information when the user equipment accesses the second slice; The first network device obtains the second key, including: If the isolation requirement of the first slice is higher than the isolation requirement of the second slice, the first network device generates the second key according to the first key, wherein the first key is used to securely protect information of the first slice or / and information when the user equipment accesses the first slice; If the isolation requirement of the first slice is lower than the isolation requirement of the second slice, the first network device re-authenticates the user equipment. If the first network device successfully re-authenticates the user equipment, the first network device generates the second key.
2. The method according to claim 1, characterized in that The information of the first slice includes attributes of the first slice, and the information of the second slice includes attributes of the second slice; If the information of the first slice does not match the information of the second slice that the user equipment requests to access, the first network device obtains a second key, including: If the attributes of the first slice do not match the attributes of the second slice, the first network device obtains the second key.
3. The method according to claim 1 or 2, characterized in that The attribute of the first slice does not match the attribute of the second slice, including: The attribute of the first slice or the attribute of the second slice is not allowed to be shared with slices of any other attribute; or The attributes of the first slice are only allowed to be shared by slices with the same service type SST, and the SST of the attributes of the second slice is different from the SST of the attributes of the first slice; or The attributes of the second slice are only allowed to be shared by slices with the same service type SST, and the SST of the attributes of the first slice is different from the SST of the attributes of the second slice; or The attribute of the first slice is only allowed to be shared by slices having the same slice differentiation factor SD, and the SD of the attribute of the second slice is different from the SD of the attribute of the first slice; or The attribute of the second slice is only allowed to be shared by slices having the same slice differentiation factor SD, and the SD of the attribute of the first slice is different from the SD of the attribute of the second slice.
4. The method according to claim 1 or 2, characterized in that: Also includes: If the attributes of the first slice match the attributes of the second slice, the first network device sends a registration acceptance message to the user equipment.
5. The method according to claim 4, characterized in that The attributes of the first slice match the attributes of the second slice, including: The attribute of the first slice or the attribute of the second slice allows to be shared with slices of any other attribute; or The attribute of the first slice is only allowed to be shared by slices having the same SST, and the SST of the attribute of the second slice is the same as the SST of the attribute of the first slice; or The attribute of the second slice is only allowed to be shared by slices having the same SST, and the SST of the attribute of the first slice is the same as the SST of the attribute of the first slice; or The attribute of the first slice is only allowed to be shared by slices with the same SD, and the SD of the attribute of the second slice is the same as the SD of the attribute of the first slice; or The attribute of the second slice is only allowed to be shared by slices with the same SD, and the SD of the attribute of the first slice is the same as the SD of the attribute of the second slice; or The second slice and the first slice are mapped to the same single network slice selection assistance information S-NSSAI.
6. A slice isolation method, characterized in that: include: The user equipment sends a first request message to the first network equipment, where the first request message is used to request access to the second slice; The user equipment receives a first indication message from the first network equipment, where the first indication message is used to instruct the user equipment to obtain a second key; Acquiring, by the user equipment, the second key, where the second key is used to securely protect information of the second slice or / and information when the user equipment accesses the second slice; The user equipment obtains the second key, including: If the isolation requirement of the first slice is higher than the isolation requirement of the second slice, the user equipment obtains a first key, and the user equipment generates the second key according to the first key; the first key is used to securely protect information of the first slice or / and information when the user equipment accesses the first slice; If the isolation requirement of the first slice is lower than the isolation requirement of the second slice, the user equipment re-authenticates with the first network device; If the user equipment is successfully re-authenticated with the first network device, the user equipment generates the second key.
7. The method according to claim 6, characterized in that Also includes: The user equipment receives a registration acceptance message from the first network equipment.
8. A communication device, characterized in that: including a transceiver unit and a processing unit; The transceiver unit is used to obtain information about a first slice of a user equipment; The processing unit is configured to obtain a second key if the information of the first slice does not match the information of the second slice requested by the user equipment to access, where the second key is used to securely protect the information of the second slice or / and the information when the user equipment accesses the second slice; When obtaining the second key, the processing unit is specifically used to generate the second key according to the first key if the isolation requirement of the first slice is higher than the isolation requirement of the second slice, wherein the first key is used to securely protect the information of the first slice or / and the information when the user equipment accesses the first slice; if the isolation requirement of the first slice is lower than the isolation requirement of the second slice, the user equipment is re-authenticated, and if the re-authentication of the user equipment is successful, the second key is generated.
9. The device according to claim 8, characterized in that The information of the first slice includes attributes of the first slice, and the information of the second slice includes attributes of the second slice; The processing unit is specifically used to obtain the second key if the attributes of the first slice do not match the attributes of the second slice when the first network device obtains the second key if the information of the first slice does not match the information of the second slice that the user device requests to access.
10. The device according to claim 8 or 9, characterized in that The attribute of the first slice does not match the attribute of the second slice, including: The attribute of the first slice or the attribute of the second slice is not allowed to be shared with slices of any other attribute; or The attributes of the first slice are only allowed to be shared by slices with the same service type SST, and the SST of the attributes of the second slice is different from the SST of the attributes of the first slice; or The attributes of the second slice are only allowed to be shared by slices with the same service type SST, and the SST of the attributes of the first slice is different from the SST of the attributes of the second slice; or The attribute of the first slice is only allowed to be shared by slices having the same slice differentiation factor SD, and the SD of the attribute of the second slice is different from the SD of the attribute of the first slice; or The attribute of the second slice is only allowed to be shared by slices having the same slice differentiation factor SD, and the SD of the attribute of the first slice is different from the SD of the attribute of the second slice.
11. The device according to claim 8 or 9, characterized in that The transceiver unit is also used to send a registration acceptance message to the user equipment if the attributes of the first slice match the attributes of the second slice.
12. The device according to claim 11, characterized in that The attributes of the first slice match the attributes of the second slice, including: The attribute of the first slice or the attribute of the second slice allows to be shared with slices of any other attribute; or The attribute of the first slice is only allowed to be shared by slices having the same SST, and the SST of the attribute of the second slice is the same as the SST of the attribute of the first slice; or The attribute of the second slice is only allowed to be shared by slices having the same SST, and the SST of the attribute of the first slice is the same as the SST of the attribute of the first slice; or The attribute of the first slice is only allowed to be shared by slices with the same SD, and the SD of the attribute of the second slice is the same as the SD of the attribute of the first slice; or The attribute of the second slice is only allowed to be shared by slices with the same SD, and the SD of the attribute of the first slice is the same as the SD of the attribute of the second slice; or The second slice and the first slice are mapped to the same single network slice selection assistance information S-NSSAI.
13. A communication device, characterized in that: including a transceiver unit and a processing unit; The transceiver unit is configured to send a first request message to a first network device, where the first request message is used to request access to a second slice; and receive a first indication message from the first network device, where the first indication message is used to instruct a user equipment to obtain a second key; The processing unit is used to obtain the second key, where the second key is used to securely protect information of the second slice or / and information when the user equipment accesses the second slice; When acquiring the second key, the processing unit is specifically configured to acquire a first key if the isolation requirement of the first slice is higher than the isolation requirement of the second slice, where the first key is used to securely protect information of the first slice; generating the second key according to the first key; If the isolation requirement of the first slice is lower than the isolation requirement of the second slice, re-authenticate with the first network device; If the re-authentication with the first network device is successful, the user equipment generates the second key.
14. The device according to claim 13, characterized in that The transceiver unit is further configured to receive a registration acceptance message from the first network device.
15. A computer-readable storage medium, characterized in that: The method comprises a program or an instruction. When the program or the instruction is run on a computer, the method according to any one of claims 1 to 5 or the method according to any one of claims 6 to 7 is executed.
16. A communication system, characterized in that: The communication system comprises a first network device for executing the method according to any one of claims 1 to 5, and a user device for executing the method according to any one of claims 6 to 7.
Citation Information
Patent Citations
Communication method and related product
CN111465012A