Key distribution methods, apparatus, communication devices and storage media
By collaborating with terminal and network functions, the SLPP signaling key is obtained and used for data encryption, which solves the problem of information integrity protection in SL positioning services and achieves security and privacy protection for data transmission.
Patent Information
- Application Number
- CN202380008185.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-10
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2043-02-10
AI Technical Summary
In wireless communication, the SL positioning capabilities and location information of SL positioning services require integrity protection and encryption to prevent tampering. Existing technologies have failed to effectively solve the problems of how to provide security keys and protect the integrity of broadcast messages.
The terminal sends a request to the first network function to request the SLPP signaling key in the side link SL communication, and through the cooperation of the network functions, the key is distributed and the data is encrypted and protected.
It ensures the security of data transmission in SL location services, prevents information tampering, and protects terminal privacy.
Smart Images

Figure CN116349267B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to, but is not limited to, the field of wireless communication technology, and particularly to a key distribution method, apparatus, communication device, and storage medium. Background Technology
[0002] In wireless communication technology, broadcasting some SL positioning signaling is feasible for ranging or sidelink (SL) positioning services. Since SL positioning capabilities and SL positioning auxiliary data are used to obtain ranging results, they need to be protected for integrity to ensure they are not tampered with. SL positioning capabilities and location information are related to the privacy of the involved terminals, requiring encryption to protect their privacy. Therefore, after enabling SL positioning broadcasting, how to provide a security key and how to protect and encrypt the broadcast messages are issues that need to be considered. Summary of the Invention
[0003] This disclosure presents a key distribution method, apparatus, communication device, and storage medium.
[0004] According to a first aspect of the present disclosure, a key distribution method is provided, wherein the method is executed by a terminal, and the method includes:
[0005] Send the first request information to the first network function;
[0006] Wherein, the first request information is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication; the first network function is the network function of the network where the terminal is currently located.
[0007] According to a second aspect of the present disclosure, a key distribution method is provided, wherein the method is performed by a first network function, the method comprising:
[0008] Receive the first request information sent by the terminal;
[0009] The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0010] According to a third aspect of the present disclosure, a key distribution method is provided, wherein the method is performed by a second network function or a third network function, the method comprising:
[0011] Send a third request message to the fourth network function;
[0012] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0013] According to a fourth aspect of the present disclosure, a key distribution method is provided, wherein the method is performed by a fourth network function, the method comprising:
[0014] The receiving terminal sends a third request message via its second or third network function;
[0015] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0016] According to a fifth aspect of the present disclosure, a system is provided, wherein the system includes at least one of a first network function, a second network function, a third network function, and a fourth network function; the first network function is used to implement a method for implementing the first network function; the second network function is used to implement a method for implementing the second network function; and the third network function is used to implement a method for implementing the third network function.
[0017] According to a sixth aspect of the present disclosure, a key distribution apparatus is provided, wherein the apparatus includes:
[0018] The sending module is configured to send a first request message to the first network function;
[0019] The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication; the first network function is the network function of the network where the terminal is currently located.
[0020] According to a seventh aspect of the present disclosure, a key distribution apparatus is provided, wherein the apparatus includes:
[0021] The receiving module is configured to receive the first request information sent by the terminal;
[0022] The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0023] According to an eighth aspect of the present disclosure, a key distribution apparatus is provided, wherein the apparatus includes:
[0024] The sending module is configured to send a third request message to the fourth network function;
[0025] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0026] According to a ninth aspect of the present disclosure, a key distribution apparatus is provided, wherein the apparatus includes:
[0027] The receiving module is configured to receive third request information sent by the terminal's second or third network function;
[0028] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0029] According to a tenth aspect of the present disclosure, a communication device is provided, the communication device comprising:
[0030] processor;
[0031] Memory used to store the processor's executable instructions;
[0032] The processor is configured to implement the method described in any embodiment of this disclosure when running the executable instructions.
[0033] According to an eleventh aspect of the present disclosure, a computer storage medium is provided, the computer storage medium storing a computer executable program, which, when executed by a processor, implements the methods described in any embodiment of the present disclosure.
[0034] In this embodiment, a first request message is sent to a first network function. This first request message requests a key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication. The first network function is the network function of the network where the terminal is currently located. Here, the terminal sends a request to the first network function to obtain the key for broadcasting or receiving broadcast SLPP signaling in sidelink SL communication. This allows the key to be obtained, and encryption and integrity protection of the data to be transmitted can be performed based on the key, thereby ensuring data transmission security. Attached Figure Description
[0035] Figure 1 This is a schematic diagram illustrating the structure of a wireless communication system according to an exemplary embodiment.
[0036] Figure 2 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0037] Figure 3 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0038] Figure 4 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0039] Figure 5 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0040] Figure 6 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0041] Figure 7 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0042] Figure 8 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0043] Figure 9 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0044] Figure 10 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0045] Figure 11 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0046] Figure 12 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0047] Figure 13 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0048] Figure 14 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0049] Figure 15 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0050] Figure 16 This is a schematic diagram of a system according to an exemplary embodiment.
[0051] Figure 17 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0052] Figure 18 This is a flowchart illustrating a key distribution method according to an exemplary embodiment.
[0053] Figure 19 This is a schematic diagram illustrating a key distribution device according to an exemplary embodiment.
[0054] Figure 20 This is a schematic diagram illustrating a key distribution device according to an exemplary embodiment.
[0055] Figure 21 This is a schematic diagram illustrating a key distribution device according to an exemplary embodiment.
[0056] Figure 22 This is a schematic diagram illustrating a key distribution device according to an exemplary embodiment.
[0057] Figure 23 This is a schematic diagram of the structure of a terminal according to an exemplary embodiment.
[0058] Figure 24 This is a block diagram illustrating a base station according to an exemplary embodiment. Detailed Implementation
[0059] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this disclosure as detailed in the appended claims.
[0060] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. The singular forms “a” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0061] It should be understood that although the terms first, second, third, etc., may be used to describe various information in embodiments of this disclosure, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first information may also be referred to as second information without departing from the scope of embodiments of this disclosure, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."
[0062] For the sake of brevity and ease of understanding, the terms “greater than” or “less than” are used in this document to characterize size relationships. However, it will be understood by those skilled in the art that the term “greater than” also includes the meaning of “greater than or equal to”, and “less than” also includes the meaning of “less than or equal to”.
[0063] Please refer to Figure 1 This illustration shows a schematic diagram of the structure of a wireless communication system provided in an embodiment of this disclosure. Figure 1 As shown, the wireless communication system is a communication system based on mobile communication technology. The wireless communication system may include: several user equipment 110 and several base stations 120.
[0064] User equipment 110 may be a device that provides voice and / or data connectivity to users. User equipment 110 may communicate with one or more core networks via a Radio Access Network (RAN). User equipment 110 may be an Internet of Things (IoT) user equipment, such as sensor devices, mobile phones, and computers with IoT user equipment capabilities. For example, it may be a fixed, portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted device. Examples include a station (STA), subscriber unit, subscriber station, mobile station, mobile station, remote station, access point, remote terminal, access terminal, user terminal, user agent, user device, or user equipment. Alternatively, user equipment 110 may also be a device from an unmanned aerial vehicle (UAV). Alternatively, user equipment 110 may also be a vehicle-mounted device, such as a vehicle computer with wireless communication capabilities, or a wireless user equipment connected to an external vehicle computer. Alternatively, user equipment 110 can also be a roadside device, such as a street light, traffic light, or other roadside device with wireless communication capabilities.
[0065] Base station 120 can be a network-side device in a wireless communication system. This wireless communication system can be a fourth-generation mobile communication (4G) system, also known as a Long Term Evolution (LTE) system; or it can be a 5G system, also known as a New Radio (NR) system; or it can be the next generation after 5G. In this case, the access network in the 5G system can be called NG-RAN (New Generation-Radio Access Network).
[0066] The base station 120 can be an evolved NB (eNB) used in a 4G system. Alternatively, the base station 120 can also be a gNB (gNB) using a centralized-distributed architecture in a 5G system. When the base station 120 adopts a centralized-distributed architecture, it typically includes a central unit (CU) and at least two distributed units (DUs). The central unit is equipped with a protocol stack of the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, and the Media Access Control (MAC) layer; the distributed units are equipped with a physical (PHY) layer protocol stack. This disclosure does not limit the specific implementation of the base station 120.
[0067] Base station 120 and user equipment 110 can establish a wireless connection via a wireless air interface. In different implementations, the wireless air interface is a wireless air interface based on the fourth-generation mobile communication network technology (4G) standard; or, the wireless air interface is a wireless air interface based on the fifth-generation mobile communication network technology (5G) standard, such as a new air interface; or, the wireless air interface can also be a wireless air interface based on a next-generation mobile communication network technology standard based on 5G.
[0068] In some embodiments, user equipment 110 can also establish E2E (End to End) connections. Examples include V2V (vehicle to vehicle), V2I (vehicle to Infrastructure), and V2P (vehicle to pedestrian) communication scenarios in vehicle-to-everything (V2X) communication.
[0069] Here, the user equipment mentioned above can be considered as the terminal equipment in the following embodiments.
[0070] In some embodiments, the wireless communication system described above may further include a network management device 130.
[0071] Several base stations 120 are connected to network management device 130. Network management device 130 can be a core network device in a wireless communication system, such as a Mobility Management Entity (MME) in an Evolved Packet Core (EPC). Alternatively, it can be other core network devices, such as a Serving Gateway (SGW), a Public Data Network Gateway (PGW), a Policy and Charging Rules Function (PCRF), or a Home Subscriber Server (HSS). The implementation of network management device 130 is not limited in this embodiment.
[0072] To facilitate understanding by those skilled in the art, this disclosure provides multiple embodiments to clearly illustrate the technical solutions of the embodiments of this disclosure. Of course, those skilled in the art will understand that the multiple embodiments provided in this disclosure can be executed individually, or in combination with the methods of other embodiments in this disclosure, or individually or in combination with some methods in other related technologies; this disclosure does not limit these aspects.
[0073] like Figure 2 As shown, this embodiment provides a key distribution method, wherein the method is executed by a terminal, and the method includes:
[0074] Step 21: Send the first request information to the first network function;
[0075] Wherein, the first request information is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication; the first network function is the network function of the network where the terminal is currently located.
[0076] Here, the terminal involved in this disclosure may be, but is not limited to, a mobile phone, wearable device, vehicle terminal, roadside unit (RSU), smart home terminal, industrial sensing device and / or medical device, etc. In some embodiments, the terminal may be a Redcap terminal or a predetermined version of a New Radio (NR) terminal (e.g., an R17 NR terminal).
[0077] The first network function in this disclosure may be an Access and Mobility Management Function (AMF), but is not limited to an AMF. The second network function in this disclosure may be a Policy Control Function (PCF), but is not limited to a PCF. The third network function in this disclosure may be a Location Management Function (LMF), but is not limited to an LMF. The fourth network function in this disclosure may be a Central Key Management Function, but is not limited to a Central Key Management Function.
[0078] In one embodiment, a first request message is sent to a first network function; wherein the first request message is used to request a key for the terminal to broadcast Sidelink Position Protocol (SLPP) signaling or receive broadcast SLPP signaling in sidelink SL communication; the first request message indicates the identity of the terminal and an indicator for requesting to obtain the key.
[0079] In one embodiment, a first request message is sent to the first network function via a registration request message; wherein the first request message is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication.
[0080] In one embodiment, a first request message is sent to a first network function; wherein the first request message is used to request a key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication. A first response message is received from the first network function; wherein the first response message indicates the key.
[0081] In one embodiment, a first request message is sent to a first network function; wherein the first request message is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication. The first response message sent by the first network function is received via a registration accept message.
[0082] In this embodiment of the disclosure, a first request message is sent to a first network function. This first request message is used to request a key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication. Here, the terminal sends a request to the first network function to obtain the key for broadcasting or receiving broadcast SLPP signaling in sidelink SL communication. This allows the key to be obtained, and encryption and integrity protection of the data to be transmitted can be performed based on the key, thereby ensuring the security of data transmission.
[0083] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0084] like Figure 3 As shown, this embodiment provides a key distribution method, wherein the method is executed by a terminal, and the method includes:
[0085] Step 31: Receive the first response information sent by the first network function;
[0086] The first response information indicates the key for the terminal to broadcast or receive broadcast SLPP signaling in the sidelink SL communication.
[0087] In one embodiment, a first request message is sent to a first network function; wherein the first request message is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication; the first request message indicates the identity of the terminal and an indicator for requesting the key; the first network function is the network function of the network where the terminal is currently located.
[0088] In one embodiment, a first request message is sent to the first network function via a registration request message; wherein the first request message is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication.
[0089] In one embodiment, a first request message is sent to a first network function; wherein the first request message is used to request a key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication. A first response message is received from the first network function; wherein the first response message indicates the key.
[0090] In one embodiment, a first request message is sent to a first network function; wherein the first request message is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication. The first response message sent by the first network function is received via a registration accept message.
[0091] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0092] like Figure 4 As shown, this embodiment provides a key distribution method, wherein the method is executed by a first network function, and the method includes:
[0093] Step 41: Receive the first request information sent by the terminal;
[0094] The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0095] Here, the terminal involved in this disclosure may be, but is not limited to, a mobile phone, wearable device, vehicle terminal, roadside unit (RSU), smart home terminal, industrial sensing device and / or medical device, etc. In some embodiments, the terminal may be a Redcap terminal or a predetermined version of a New Radio (NR) terminal (e.g., an R17 NR terminal).
[0096] The first network function in this disclosure may be an Access and Mobility Management Function (AMF), but is not limited to an AMF. The second network function in this disclosure may be a Policy Control Function (PCF), but is not limited to a PCF. The third network function in this disclosure may be a Location Management Function (LMF), but is not limited to an LMF. The fourth network function in this disclosure may be a Central Key Management Function, but is not limited to a Central Key Management Function.
[0097] In one embodiment, a receiving terminal sends a first request message; wherein the first request message is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the first request message indicates the identity of the terminal and an indicator for requesting the key.
[0098] In one embodiment, the first request information sent by the terminal is received via a registration request message; wherein the first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication.
[0099] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is then determined whether the terminal is permitted to broadcast or receive the broadcast SLPP signaling.
[0100] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. Based on the terminal's subscription information, it is determined whether the terminal is allowed to broadcast the SLPP signaling or receive the broadcast SLPP signaling.
[0101] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second request message is sent to a second network function; wherein the second request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the second network function is the network function of the network where the terminal is currently located.
[0102] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second request message is sent to a second network function; wherein the second request message indicates a key for requesting a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the second request message indicates the terminal's identity and an indicator for requesting the key.
[0103] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request obtaining a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is determined whether the terminal is allowed to broadcast or receive the broadcast SLPP signaling. In response to allowing the terminal to broadcast or receive the broadcast SLPP signaling, a second request message is sent to a second network function; wherein the second request message indicates a request to obtain a key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication.
[0104] In one embodiment, a first request message is received from a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is determined whether the terminal is allowed to broadcast or receive the broadcast SLPP signaling. In response to allowing the terminal to broadcast the SLPP signaling, the second request message is sent to the second network function; or, in response to allowing the terminal to receive the broadcast SLPP signaling, the second request message is sent to the second network function.
[0105] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second request message is sent to a second network function; wherein the second request message indicates a key for requesting a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second response message is received from a second network function or a third network function; wherein the second response message indicates the key.
[0106] In one embodiment, a first request message is received from a receiving terminal; wherein the first request message is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second response message is received from the third network function via a notification message (e.g., Nlmf_Broadcast_CipheringKeyData); wherein the second response message indicates the key.
[0107] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second request message is sent to a second network function; wherein the second request message indicates a key for requesting a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second response message is received from a second network function or a third network function; wherein the second response message indicates the key. The key is stored.
[0108] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A first response message is sent to the terminal; wherein the first response message indicates the key.
[0109] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A first response message is sent to the terminal via a registration accept message; wherein the first response message indicates the key.
[0110] In one embodiment, a first request message is received from a terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is then determined whether the terminal is permitted to broadcast or receive the broadcast SLPP signaling. In response to determining that the terminal is permitted to broadcast the SLPP signaling, the first response message is sent to the terminal; or, in response to determining that the terminal is permitted to receive the broadcast SLPP signaling, the first response message is sent to the terminal.
[0111] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0112] like Figure 5 As shown, this embodiment provides a key distribution method, wherein the method is executed by a first network function, and the method includes:
[0113] Step 51: Determine whether to allow the terminal to broadcast the SLPP signaling or receive the broadcast SLPP signaling.
[0114] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is then determined whether the terminal is permitted to broadcast or receive the broadcast SLPP signaling.
[0115] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. Based on the terminal's subscription information, it is determined whether the terminal is allowed to broadcast the SLPP signaling or receive the broadcast SLPP signaling.
[0116] In one embodiment, a first request message is received from a receiving terminal; wherein the first request message is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is determined whether the terminal is allowed to broadcast or receive the broadcast SLPP signaling. In response to allowing the terminal to broadcast or receive the broadcast SLPP signaling, a second request message is sent to a second network function; wherein the second request message indicates a request to obtain the key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication; the second network function is the network function of the network where the terminal is currently located.
[0117] In one embodiment, a first request message is received from a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is determined whether the terminal is allowed to broadcast or receive the broadcast SLPP signaling. In response to allowing the terminal to broadcast the SLPP signaling, the second request message is sent to the second network function; or, in response to allowing the terminal to receive the broadcast SLPP signaling, the second request message is sent to the second network function.
[0118] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0119] like Figure 6 As shown, this embodiment provides a key distribution method, wherein the method is executed by a first network function, and the method includes:
[0120] Step 61: Send a second request message to the second network function;
[0121] The second request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the second network function is the network function of the network where the terminal is currently located.
[0122] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request obtaining a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is determined whether the terminal is allowed to broadcast or receive the broadcast SLPP signaling. In response to allowing the terminal to broadcast or receive the broadcast SLPP signaling, a second request message is sent to a second network function; wherein the second request message indicates a request to obtain a key for the terminal to broadcast or receive broadcast SLPP signaling in sidelink SL communication.
[0123] In one embodiment, a first request message is received from a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is determined whether the terminal is allowed to broadcast or receive the broadcast SLPP signaling. In response to allowing the terminal to broadcast the SLPP signaling, the second request message is sent to the second network function; or, in response to allowing the terminal to receive the broadcast SLPP signaling, the second request message is sent to the second network function.
[0124] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0125] like Figure 7 As shown, this embodiment provides a key distribution method, wherein the method is executed by a first network function, and the method includes:
[0126] Step 71: Receive the second response information sent by the second network function or the third network function;
[0127] The second response information indicates the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0128] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second request message is sent to a second network function; wherein the second request message indicates a key for requesting a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second response message is received from a second network function or a third network function; wherein the second response message indicates the key; the second network function is a network function of the network where the terminal is currently located.
[0129] In one embodiment, a first request message is received from a receiving terminal; wherein the first request message is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second response message is received from the third network function via a notification message (e.g., Nlmf_Broadcast_CipheringKeyData); wherein the second response message indicates the key.
[0130] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second request message is sent to a second network function; wherein the second request message indicates a key for requesting a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A second response message is received from a second network function or a third network function; wherein the second response message indicates the key. The key is stored.
[0131] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0132] like Figure 8 As shown, this embodiment provides a key distribution method, wherein the method is executed by a first network function, and the method includes:
[0133] Step 81: Send the first response information to the terminal;
[0134] The first response information indicates the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0135] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A first response message is sent to the terminal; wherein the first response message indicates the key.
[0136] In one embodiment, a first request message is sent by a receiving terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A first response message is sent to the terminal via a registration accept message; wherein the first response message indicates the key.
[0137] In one embodiment, a first request message is received from a terminal; wherein the first request message is used to request a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. It is then determined whether the terminal is permitted to broadcast or receive the broadcast SLPP signaling. In response to determining that the terminal is permitted to broadcast the SLPP signaling, the first response message is sent to the terminal; or, in response to determining that the terminal is permitted to receive the broadcast SLPP signaling, the first response message is sent to the terminal.
[0138] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0139] like Figure 9 As shown, this embodiment provides a key distribution method, wherein the method is executed by a second network function or a third network function, and the method includes:
[0140] Step 91: Send a third request message to the fourth network function;
[0141] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0142] Here, the terminal involved in this disclosure may be, but is not limited to, a mobile phone, wearable device, vehicle terminal, roadside unit (RSU), smart home terminal, industrial sensing device and / or medical device, etc. In some embodiments, the terminal may be a Redcap terminal or a predetermined version of a New Radio (NR) terminal (e.g., an R17 NR terminal).
[0143] The first network function in this disclosure may be an Access and Mobility Management Function (AMF), but is not limited to an AMF. The second network function in this disclosure may be a Policy Control Function (PCF), but is not limited to a PCF. The third network function in this disclosure may be a Location Management Function (LMF), but is not limited to an LMF. The fourth network function in this disclosure may be a Central Key Management Function, but is not limited to a Central Key Management Function.
[0144] In one embodiment, a third request message is sent to a fourth network function; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is received from the fourth network function; wherein the third response message indicates the key.
[0145] In one embodiment, a third request message is sent to a fourth network function; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is received from the fourth network function; wherein the third response message indicates the key. A second response message is sent to the first network function; wherein the second response message indicates the key.
[0146] In one embodiment, a third request message is sent to a fourth network function; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is received from the fourth network function; wherein the third response message indicates the key. A second response message is sent to the first network function via a notification message (e.g., Nlmf_Broadcast_CipheringKeyData); wherein the second response message indicates the key.
[0147] In one embodiment, a second request message is sent by a first network function of the receiving terminal; wherein the second request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third request message is sent to a fourth network function; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication.
[0148] In one embodiment, a second request message is sent by a first network function of the receiving terminal; wherein the second request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the second request message indicates the identity of the terminal and an indicator for requesting to obtain the key. A third request message is sent to a fourth network function; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication.
[0149] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0150] like Figure 10 As shown, this embodiment provides a key distribution method, wherein the method is executed by a second network function or a third network function, and the method includes:
[0151] Step 101: Receive the third response information sent by the fourth network function;
[0152] The third response information indicates the key used by the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0153] In one embodiment, a third request message is sent to a fourth network function; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is received from the fourth network function; wherein the third response message indicates the key.
[0154] In one embodiment, a third request message is sent to a fourth network function; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is received from the fourth network function; wherein the third response message indicates the key. A second response message is sent to the first network function; wherein the second response message indicates the key.
[0155] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0156] like Figure 11As shown, this embodiment provides a key distribution method, wherein the method is executed by a second network function or a third network function, and the method includes:
[0157] Step 111: Send the second response information to the first network function;
[0158] The second response information indicates the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0159] In one embodiment, a third request message is sent to a fourth network function; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is received from the fourth network function; wherein the third response message indicates the key. A second response message is sent to the first network function; wherein the second response message indicates the key.
[0160] In one embodiment, a third request message is sent to a fourth network function; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is received from the fourth network function; wherein the third response message indicates the key. A second response message is sent to the first network function via a notification message (e.g., Nlmf_Broadcast_CipheringKeyData); wherein the second response message indicates the key.
[0161] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0162] like Figure 12 As shown, this embodiment provides a key distribution method, wherein the method is executed by a second network function or a third network function, and the method includes:
[0163] Step 121: Receive the second request information sent by the first network function of the terminal;
[0164] The second request information indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication.
[0165] In one embodiment, a second request message is sent by a first network function of the receiving terminal; wherein the second request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third request message is sent to a fourth network function; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication.
[0166] In one embodiment, a second request message is sent by a first network function of the receiving terminal; wherein the second request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the second request message indicates the identity of the terminal and an indicator for requesting to obtain the key. A third request message is sent to a fourth network function; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication.
[0167] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0168] like Figure 13 As shown, this embodiment provides a key distribution method, wherein the method is executed by a fourth network function, and the method includes:
[0169] Step 131: Receive the third request information sent by the terminal's second or third network function;
[0170] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0171] Here, the terminal involved in this disclosure may be, but is not limited to, a mobile phone, wearable device, vehicle terminal, roadside unit (RSU), smart home terminal, industrial sensing device and / or medical device, etc. In some embodiments, the terminal may be a Redcap terminal or a predetermined version of a New Radio (NR) terminal (e.g., an R17 NR terminal).
[0172] The first network function in this disclosure may be an Access and Mobility Management Function (AMF), but is not limited to an AMF. The second network function in this disclosure may be a Policy Control Function (PCF), but is not limited to a PCF. The third network function in this disclosure may be a Location Management Function (LMF), but is not limited to an LMF. The fourth network function in this disclosure may be a Central Key Management Function, but is not limited to a Central Key Management Function.
[0173] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. In response to receiving the third request message, the key is generated.
[0174] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. In response to receiving the third request message, the key is generated. The key includes one of the following: an asymmetric private key and a public key; or a symmetric integrity and encryption key.
[0175] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is sent to the second or third network function; wherein the third response message indicates the key.
[0176] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. In response to receiving the third request message, the key is generated. The key includes one of the following: an asymmetric private key and a public key symmetric integrity and encryption key. A third response message is sent to the second or third network function; wherein the third response message indicates the key.
[0177] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0178] like Figure 14 As shown, this embodiment provides a key distribution method, wherein the method is executed by a fourth network function, and the method includes:
[0179] Step 141: Generate a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0180] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. In response to receiving the third request message, the key is generated.
[0181] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. In response to receiving the third request message, the key is generated. The key includes one of the following: an asymmetric private key and a public key; or a symmetric integrity and encryption key.
[0182] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is sent to the second or third network function; wherein the third response message indicates the key.
[0183] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. In response to receiving the third request message, the key is generated. The key includes one of the following: an asymmetric private key and a public key; or a symmetric integrity and encryption key. A third response message is sent to the second or third network function; wherein the third response message indicates the key.
[0184] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0185] like Figure 15 As shown, this embodiment provides a key distribution method, wherein the method is executed by a fourth network function, and the method includes:
[0186] Step 151: Send a third response message to the second network function or the third network function;
[0187] The third response information indicates the key used by the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0188] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. A third response message is sent to the second or third network function; wherein the third response message indicates the key.
[0189] In one embodiment, a third request message is sent by a second or third network function of the receiving terminal; wherein the third request message indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication. In response to receiving the third request message, the key is generated. The key includes one of the following: an asymmetric private key and a public key; or a symmetric integrity and encryption key. A third response message is sent to the second or third network function; wherein the third response message indicates the key.
[0190] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0191] like Figure 16 As shown, this embodiment provides a system, wherein the system includes at least one of a first network function 161, a second network function 162, a third network function 163, and a fourth network function 164; the first network function 161 is used to implement the method implemented by the first network function 161; the second network function 162 is used to implement the method implemented by the second network function 162; and the third network function 163 is used to implement the method implemented by the third network function 163.
[0192] To better understand the embodiments of this disclosure, the following two exemplary embodiments will further illustrate the technical solutions of this disclosure:
[0193] In one embodiment, a terminal capable of ranging or SL positioning should be able to broadcast SLPP signaling without having to perform discovery and link establishment procedures. Therefore, a security key can be provided to the terminal during the registration process.
[0194] In one embodiment, to perform SLPP signaling broadcasting, it is assumed that information regarding whether terminals with ranging or SL positioning capabilities are allowed to broadcast and / or receive SLPP signaling is included in the UE subscription information. Based on this information in the subscription information, the core network can then determine the necessary security key to provide to the UE when the UE registers with the network.
[0195] In one embodiment, for ranging or SL positioning services, the two or more UEs involved in the service may be subscribed to different operators. If the involved UEs are subscribed to different operators, it is impossible for a 5GC NF in a Public Land Mobile Network (PLMN) to create the same security key for all involved UEs belonging to different PLMNs. Therefore, it is recommended to use a centralized key management function that can connect to different PLMNs to create and provide security keys to the 5GC NFs in different PLMNs. The 5GC NF then provides the security key to the UE in its own PLMN.
[0196] In one embodiment, the 5GC NF that provides the security key may be a PCF that sends the key to the UE as part of the UE security policy configuration information; or it may be an LMF that sends the key to the UE using the existing procedure defined in Clause 6.14.2 of 3GPP TS 23.273 [3].
[0197] Example 1:
[0198] like Figure 17 As shown, this embodiment provides a key distribution method, the method including:
[0199] Step 1701: The UE (B-UE) to be broadcast SLPP signaling sends a registration request message (corresponding to the first request information in this disclosure) to its AMF (which may be periodically). The registration request message contains the B-UE ID and an indicator of the requested broadcast key (corresponding to the key in this disclosure).
[0200] Step 1702: The B-UE's AMF and Unified Data Management (UDM) check whether the B-UE is allowed to broadcast SLPP signaling based on the UE subscription information.
[0201] Step 1703: If B-UE is allowed to broadcast SLPP signaling, B-UE's AMF sends a UE policy creation request (corresponding to the second request information in this disclosure) to B-UE's PCF, indicating that it requests the broadcast key of the broadcaster.
[0202] Step 1704: The PCF of the B-UE sends a key request (corresponding to the third request information in this disclosure) to the central key management function, requesting a broadcast key for broadcasting SLPP signaling.
[0203] Step 1705: The central key management function (or centralized key management function) generates a broadcast key for broadcasting SLPP signaling. The broadcast key can be, for example, an asymmetric private key and public key pair, or a symmetric integrity and encryption key pair.
[0204] Step 1706: The central key management function returns the broadcast key (e.g., private key) in the key response (corresponding to the third response information in this disclosure) to the PCF of the B-UE.
[0205] Step 1707: The PCF of B-UE returns the broadcast key to the AMF of B-UE in the UE policy creation response (corresponding to the second response information in this disclosure).
[0206] Step 1708: The AMF of B-UE sends a broadcast key to B-UE in the registration acceptance message (corresponding to the first response information in this disclosure).
[0207] Step 1709: The UE (R-UE) to receive the broadcast SL positioning signaling sends a registration request message (corresponding to the first request information in this disclosure) to its AMF (which may be periodically). The registration request message contains the R-UE ID and an indicator for requesting the broadcast key.
[0208] Step 1710: Check whether the R-UE is allowed to receive broadcast SLPP signaling by comparing the R-UE's AMF and UDM with the UE subscription information.
[0209] Step 1711: If R-UE is allowed to receive broadcast SLPP signaling, then R-UE's AMF sends a UE policy creation request (corresponding to the second request information in this disclosure) to R-UE's PCF, indicating that it requests the broadcast key of the receiver.
[0210] Step 1712: The PCF of the R-UE sends a key request (corresponding to the third request information in this disclosure) to the central key management function to request a key for receiving broadcast SLPP signaling.
[0211] Step 1713: The Central Key Management Function returns the key used to receive the broadcast SLPP signaling from the key response (corresponding to the third response information in this disclosure) to the PCF of the R-UE. The key can be, for example, the public key of the asymmetric private / public key created in step 1705.
[0212] Step 1714: In the UE policy creation response (corresponding to the second response information in this disclosure), the PCF of the R-UE returns the key used to receive the broadcast SLPP signaling to the AMF of the R-UE.
[0213] Step 1715: In the registration acceptance message (corresponding to the first response information in this disclosure), the AMF of the R-UE sends a key to the R-UE for receiving broadcast SLPP signaling.
[0214] Step 1716: The B-UE begins broadcasting SLPP signaling protected by the broadcast key received from the network.
[0215] Step 1717: The R-UE begins listening for broadcast messages. When it receives a broadcast signaling from the B-UE, the R-UE uses the key received from the network to verify the broadcast message.
[0216] It should be noted that each broadcast key is assigned a valid timer. When the timer expires, the UE needs to request a new broadcast key by initiating the periodic registration process again.
[0217] In one embodiment, the 5GC NF that provides the security key to the UE can also be the LMF that provides the encryption key for distributing broadcast auxiliary data as defined in Clause 6.14.2 of 3GPP TS 23.273 [3]. This is used when the UE, which is broadcasting SLPP signaling, needs to obtain location auxiliary data from the core network. In this case, the UE sends a request to the AMF, which selects the LMF to invoke the network auxiliary data transmission. The LMF needs to obtain the security key that protects the network auxiliary data before it can begin transmitting the network auxiliary data.
[0218] Example 2:
[0219] like Figure 18 As shown, this embodiment provides a key distribution method, the method including:
[0220] Step 1801: After receiving the network-assisted data transmission request, the LMF of B-UE sends a key request to the central key management function, requesting the broadcast key (corresponding to the key in this disclosure) for the UE to use for broadcasting SLPP signaling.
[0221] Step 1802: The central key management function returns the security key used for SLPP signaling broadcast to the B-UE's LMF.
[0222] Step 1803: The B-UE's LMF calls the Nlmf_Broadcast_CipheringKeyData notification service operation to the B-UE's AMF, which contains the security key received for SLPP signaling broadcast.
[0223] Step 1804: The B-UE's AMF stores the broadcast key received from the B-UE's LMF.
[0224] Step 1805: The B-UE to be broadcast SLPP signaling sends a (periodic) registration request message to its AMF. The registration request message contains the B-UE ID and an indicator requesting the broadcast key.
[0225] Step 1806: The B-UE's AMF and UDM together check whether the B-UE is allowed to broadcast SLPP signaling based on the UE subscription information.
[0226] Step 1807: The B-UE's AMF sends the stored broadcast key to the B-UE in the registration acceptance message.
[0227] Step 1808: As in step 1801, the R-UE's LMF sends a key request to the central key management function to request a key for the UE to receive broadcast SLPP signaling.
[0228] Step 1809: The central key management function returns the security key used to receive broadcast SLPP signaling to the R-UE's LMF.
[0229] Step 1810: The R-UE's LMF calls the Nlmf_Broadcast_CipheringKeyData notification service operation to the R-UE's AMF, which contains the received security key.
[0230] Step 1811: The R-UE's AMF stores the broadcast key received from the R-UE's LMF.
[0231] Step 1812: The R-UE that is to receive broadcast SLPP signaling sends a (periodic) registration request message to its AMF, which contains the R-UE ID and an indicator requesting the broadcast key.
[0232] Step 1813: The R-UE's AMF checks whether the R-UE is allowed to receive broadcast SLPP signaling by referring to the UE's subscription information through the UDM.
[0233] Step 1814: In the registration acceptance message, the R-UE's AMF sends the stored broadcast key to the R-UE.
[0234] Step 1815: The B-UE begins broadcasting SLPP signaling protected by the broadcast key received from the network.
[0235] Step 1816: The R-UE begins listening for broadcast messages. When it receives a broadcast signaling from the B-UE, the R-UE uses the key received from the network to verify the broadcast message.
[0236] It should be noted that when the LMF requests a broadcast key from the central key management function, it can only generate a symmetric key, because the LMF does not know whether the requesting UE intends to broadcast or receive SLPP signaling before sending the registration request.
[0237] like Figure 19 As shown in the embodiments of this disclosure, a key distribution apparatus is provided, wherein the apparatus includes:
[0238] Sending module 191 is configured to send a first request message to a first network function;
[0239] The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication; the first network function is the network function of the network where the terminal is currently located.
[0240] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0241] like Figure 20 As shown in the figure, this disclosure provides a key distribution device, wherein the device includes:
[0242] The receiving module 201 is configured to receive the first request information sent by the terminal;
[0243] The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0244] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0245] like Figure 21 As shown in the embodiments of this disclosure, a key distribution apparatus is provided, wherein the apparatus includes:
[0246] Sending module 211 is configured to send a third request message to a fourth network function;
[0247] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0248] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0249] like Figure 22 As shown in the figure, this disclosure provides a key distribution device, wherein the device includes:
[0250] The receiving module 221 is configured to receive third request information sent by the second network function or the third network function of the terminal;
[0251] The third request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication.
[0252] It should be noted that those skilled in the art will understand that the methods provided in the embodiments of this disclosure can be executed alone or together with some methods in the embodiments of this disclosure or some methods in related technologies.
[0253] This disclosure provides a communication device, which includes:
[0254] processor;
[0255] a memory for storing processor-executable instructions;
[0256] The processor is configured to implement, when running executable instructions, the methods applicable to any embodiment of this disclosure.
[0257] The processor may include various types of storage media, which are non-transitory computer storage media that can continue to store information after the communication device loses power.
[0258] The processor can connect to the memory via a bus or other means to read executable programs stored in the memory.
[0259] This disclosure also provides a computer storage medium storing a computer executable program, which, when executed by a processor, implements the method of any embodiment of this disclosure.
[0260] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.
[0261] like Figure 23 As shown, one embodiment of this disclosure provides a terminal structure.
[0262] Reference Figure 23 The terminal 800 shown in this embodiment is a mobile phone, computer, digital broadcasting terminal, messaging device, game console, tablet device, medical device, fitness device, personal digital assistant, etc.
[0263] Reference Figure 23 Terminal 800 may include one or more of the following components: processing component 802, memory 804, power supply component 806, multimedia component 808, audio component 810, input / output (I / O) interface 812, sensor component 814, and communication component 816.
[0264] Processing component 802 typically controls the overall operation of terminal 800, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 802 may include one or more modules to facilitate interaction between processing component 802 and other components. For example, processing component 802 may include a multimedia module to facilitate interaction between multimedia component 808 and processing component 802.
[0265] Memory 804 is configured to store various types of data to support the operation of device 800. Examples of this data include instructions for any application or method operating on terminal 800, contact data, phonebook data, messages, pictures, videos, etc. Memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0266] Power supply component 806 provides power to various components of terminal 800. Power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to terminal 800.
[0267] Multimedia component 808 includes a screen that provides an output interface between terminal 800 and user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 808 includes a front-facing camera and / or a rear-facing camera. When device 800 is in an operating mode, such as shooting mode or video mode, the front-facing camera and / or rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.
[0268] Audio component 810 is configured to output and / or input audio signals. For example, audio component 810 includes a microphone (MIC) configured to receive external audio signals when terminal 800 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 804 or transmitted via communication component 816. In some embodiments, audio component 810 also includes a speaker for outputting audio signals.
[0269] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.
[0270] Sensor assembly 814 includes one or more sensors for providing status assessments of various aspects of terminal 800. For example, sensor assembly 814 may detect the on / off state of device 800, the relative positioning of components such as the display and keypad of terminal 800, changes in the position of terminal 800 or a component of terminal 800, the presence or absence of user contact with terminal 800, the orientation or acceleration / deceleration of terminal 800, and temperature changes of terminal 800. Sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 814 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 814 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.
[0271] Communication component 816 is configured to facilitate wired or wireless communication between terminal 800 and other devices. Terminal 800 can access wireless networks based on communication standards, such as Wi-Fi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, communication component 816 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 816 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0272] In an exemplary embodiment, terminal 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.
[0273] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, which can be executed by a processor 820 of a terminal 800 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0274] like Figure 24 As shown, one embodiment of this disclosure illustrates the structure of a base station. For example, base station 900 can be provided as a network-side device. (Refer to...) Figure 24The base station 900 includes a processing component 922, which further includes one or more processors, and memory resources represented by a memory 932 for storing instructions, such as application programs, that can be executed by the processing component 922. The application programs stored in the memory 932 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processing component 922 is configured to execute instructions to perform any of the methods described above applied to the base station.
[0275] Base station 900 may also include a power supply component 926 configured to perform power management of base station 900, a wired or wireless network interface 950 configured to connect base station 900 to a network, and an input / output (I / O) interface 958. Base station 900 can operate on an operating system stored in memory 932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or similar.
[0276] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.
[0277] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A key distribution method, wherein, The method is executed by a terminal, and the method includes: Send the first request information to the first network function; Wherein, the first request information is used to request the key for the terminal to broadcast or receive broadcast SLPP signaling in the sidelink SL communication; the terminal does not perform the link establishment process; the first network function is the network function of the network where the terminal is currently located.
2. The method according to claim 1, wherein, Sending the first request information to the first network function includes: The first request information is sent to the first network function through a registration request message.
3. The method according to claim 1, wherein, The first request information indicates the identity of the terminal and an indicator for requesting to obtain the key.
4. The method according to claim 1, wherein, The method further includes: Receive the first response information sent by the first network function; The first response information indicates the key.
5. The method according to claim 4, wherein, The receipt of the first response information sent by the first network function includes: The system receives the first response information sent by the first network function by registering and accepting messages.
6. The method according to any one of claims 1 to 5, wherein, The first network function is the Access and Mobility Management Function (AMF).
7. A key distribution method, wherein, The method is performed by a first network function, and the method includes: Receive the first request information sent by the terminal; The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication; the terminal does not perform the link establishment process.
8. The method according to claim 7, wherein, The first request information sent by the receiving terminal includes: The system receives the first request information sent by the terminal via a registration request message.
9. The method according to claim 7, wherein, The first request information indicates the identity of the terminal and an indicator for requesting to obtain the key.
10. The method according to claim 7, wherein, The method further includes: Determine whether to allow the terminal to broadcast the SLPP signaling or receive the broadcast SLPP signaling.
11. The method according to claim 10, wherein, The step of determining whether to allow the terminal to broadcast the SLPP signaling or receive the broadcast SLPP signaling includes: Based on the terminal subscription information, determine whether to allow the terminal to broadcast the SLPP signaling or receive the broadcast SLPP signaling.
12. The method according to claim 11, wherein, The method further includes: Send a second request message to the second network function; The second request information indicates a key for requesting to obtain the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the second network function is the network function of the network where the terminal is currently located.
13. The method according to claim 12, wherein, The second network function is the Policy Control Function (PCF).
14. The method according to claim 13, wherein, Sending the second request information to the second network function includes: In response to allowing the terminal to broadcast the SLPP signaling, the second request information is sent to the second network function; or, In response to the SLPP signaling that allows the terminal to receive broadcasts, the second request information is sent to the second network function.
15. The method according to claim 12, wherein, The second request information indicates the identity of the terminal and an indicator for requesting to obtain the key.
16. The method according to claim 12, wherein, The method further includes: Receive second response information sent by the second or third network function; The second response information indicates the key.
17. The method according to claim 16, wherein, The third network function is the Location Management Function (LMF).
18. The method according to claim 16, wherein, The receipt of the second response information sent by the third network function includes: The second response information sent by the third network function is received via a notification message.
19. The method of claim 16, wherein, The method further includes: Store the key.
20. The method according to claim 7, wherein, The method further includes: Send the first response information to the terminal; The first response information indicates the key.
21. The method according to claim 20, wherein, Sending the first response information to the terminal includes: In response to determining that the terminal is permitted to broadcast the SLPP signaling, the first response information is sent to the terminal; or, In response to determining that the terminal is permitted to receive the broadcast SLPP signaling, the first response information is sent to the terminal.
22. The method according to claim 20, wherein, Sending the first response information to the terminal includes: The system receives the first response information by registering and sending it to the terminal.
23. The method according to any one of claims 7 to 22, wherein, The first network function is the Access and Mobility Management Function (AMF).
24. A key distribution method, wherein, The method is executed by a second network function or a third network function, and the method includes: Send a third request message to the fourth network function; The third request information indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the terminal does not perform the link establishment process.
25. The method according to claim 24, wherein, The method further includes: Receive the third response information sent by the fourth network function; The third response information indicates the key.
26. The method of claim 25, wherein, The method further includes: Send a second response message to the first network function; The second response information indicates the key.
27. The method of claim 26, wherein in response to the method being performed by a third network function; the sending of the second response information to the first network function comprises: The second response information is sent to the first network function via a notification message.
28. The method according to claim 24, wherein, The method further includes: The receiving terminal sends a second request message via its first network function. The second request information indicates a key for requesting to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication.
29. The method according to claim 28, wherein, The second request information indicates the identity of the terminal and an indicator for requesting to obtain the key.
30. The method according to any one of claims 24 to 29, wherein, The second network function is PCF, the third network function is LMF, and / or the fourth network function is central key management function.
31. A key distribution method, wherein, The method is performed by a fourth network function, and the method includes: The receiving terminal sends a third request message sent by its second or third network function; The third request information indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication; the terminal does not perform the link establishment process.
32. The method according to claim 31, wherein, The method further includes: In response to receiving the third request information, the key is generated.
33. The method according to claim 32, wherein, The key includes one of the following: Asymmetric private and public keys; Symmetric integrity and encryption keys.
34. The method according to claim 31, wherein, The method further includes: Send a third response message to the second network function or the third network function; The third response information indicates the key.
35. The method according to any one of claims 31 to 34, wherein, The second network function is PCF, the third network function is LMF, and / or the fourth network function is central key management function.
36. A communication system, wherein, The system includes a base station, and at least one of a first network function, a second network function, a third network function, and a fourth network function; the first network function is used to implement the method of claims 7 to 23; the second network function is used to implement the method of claims 24 to 30; and the third network function is used to implement the method of claims 31 to 35.
37. The system according to claim 36, wherein, The first network function is AMF, the second network function is PCF, the third network function is LMF, and / or the fourth network function is central key management function.
38. A key distribution device, wherein, The device includes: The sending module is configured to send a first request message to a first network function; The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication; the second network function is the network function of the network where the terminal is currently located; the terminal does not perform the link establishment process.
39. A key distribution device, wherein, The device includes: The receiving module is configured to receive the first request information sent by the terminal; The first request information is used to request the key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication; the terminal does not perform the link establishment process.
40. A key distribution device, wherein, The device includes: The sending module is configured to send a third request message to the fourth network function; The third request information indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in sidelink SL communication; the terminal does not perform the link establishment process.
41. A key distribution device, wherein, The device includes: The receiving module is configured to receive third request information sent by the second or third network function of the terminal; The third request information indicates a request to obtain a key for the terminal to broadcast SLPP signaling or receive broadcast SLPP signaling in the side link SL communication; the terminal does not perform the link establishment process.
42. A communication device, wherein, include: antenna; Memory; The processor, connected to the antenna and the memory respectively, is configured to control the transmission and reception of the antenna by executing computer-executable instructions stored in the memory, and is capable of implementing the method provided by any one of claims 1 to 6, 7 to 23, 24 to 30 or 31 to 35.
43. A computer storage medium storing computer-executable instructions, which, when executed by a processor, enable the implementation of the method provided by any one of claims 1 to 6, 7 to 23, 24 to 30, or 31 to 35.
Citation Information
Patent Citations
Relay side link communication for secure link setup
CN115413413A
Key update method and device
WO2020248749A1