Communication method and apparatus

By checking and obtaining a valid intermediate key after replacing the USIM card on the terminal device, the problem of abnormal communication between the network side and the terminal device was resolved, and secure communication was restored and replay attacks were prevented.

CN116391376BActive Publication Date: 2026-05-26HUAWEI TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2020-09-30
Publication Date
2026-05-26

Smart Images

  • Figure CN116391376B_ABST
    Figure CN116391376B_ABST
Patent Text Reader

Abstract

A communication method and apparatus, relating to the field of communication technology, are used to ensure normal communication between a network side and a terminal device. The communication method is applied to a terminal device configured with a (U)SIM card, the (U)SIM card storing a key set identifier. The method includes: when the terminal device needs to initiate an initial registration process, determining whether a valid intermediate key exists; if no valid intermediate key exists, deleting the key set identifier; the terminal device sending an initial registration request message to a mobility management network element, the initial registration request message not carrying the key set identifier to trigger an authentication process for the terminal device; and the terminal device obtaining authentication key information during the authentication process, the authentication key information including a valid intermediate key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0002] The 3rd Generation Partnership Project (3GPP) defines mobile communication networks that introduce security mechanisms to ensure the security of mobile communications (e.g., confidentiality and integrity). For example, after the authentication process, the network side (e.g., the unified data management network element) and the terminal device can each store the same intermediate key (e.g., K). AUSF Information sent from the network side to the terminal device can be secured using an intermediate key; correspondingly, the terminal device can use this intermediate key to perform security verification on the information after it has been secured by the network side, in order to verify the security of the information.

[0003] However, in some scenarios (e.g., when the Universal Subscriber Identity Module (USIM) card currently inserted in the terminal device has been removed from another terminal device), the terminal device does not store a valid intermediate key. The network side cannot determine whether the terminal device stores a valid intermediate key. Therefore, the network side still uses the intermediate key to securely protect the information to be sent to the terminal device according to the normal procedure, but because the terminal device does not store the intermediate key, it cannot perform security verification on the protected information. This affects normal communication between the network side and the terminal device. Summary of the Invention

[0004] This application provides a communication method for ensuring normal communication between the network side and the terminal device.

[0005] In a first aspect, a communication method is provided, which is applied to a terminal device configured with a (U)SIM card, wherein the (U)SIM card stores a key set identifier. The method includes: when the terminal device needs to initiate an initial registration process, determining whether a valid intermediate key exists; if no valid intermediate key exists, deleting the key set identifier; the terminal device sending an initial registration request message to a mobility management network element, wherein the initial registration request message does not carry the key set identifier to trigger an authentication process for the terminal device; and the terminal device obtaining authentication key information, which includes a valid intermediate key, during the authentication process.

[0006] Based on the above technical solution, when a terminal device needs to initiate an initial registration process, the terminal device first checks whether a valid intermediate key exists. If no valid intermediate key exists, the terminal device deletes the key set identifier from the (U)SIM card, so that the initial registration request message sent by the terminal device does not carry the key set identifier. Since the initial registration request message does not carry the key set identifier, the mobility management network element initiates an authentication process with the terminal device. During the authentication process, the terminal device and the network side can synchronously obtain the same intermediate key. Thus, in subsequent processes (such as the SOR process or the UPU process), the network side can use the intermediate key to securely protect the information sent to the terminal device; correspondingly, the terminal device can use the same intermediate key to securely verify the protected information. Therefore, the embodiments of this application can guarantee secure communication between the terminal device and the network side.

[0007] In one possible design, the key set identifier is the key set identifier generated when the terminal device accesses the network through the first access technology; the terminal device sends an initial registration request message to the mobility management network element, including: the terminal device sending an initial registration request message to the mobility management network element using the first access technology.

[0008] In one possible design, the terminal device deletes the key set identifier by setting the value of the key set identifier to a first value, which indicates "no key is available".

[0009] In one possible design, the initial registration request message does not carry a key set identifier, but includes: the initial registration request message includes first indication information, which indicates that no key is available.

[0010] In one possible design, the terminal device is also equipped with non-volatile memory; the terminal device determines whether a valid intermediate key exists, including: the terminal device determining whether the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the (U)SIM card are consistent; if the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the (U)SIM card are consistent, the terminal device determines whether a valid intermediate key exists in the non-volatile memory and the (U)SIM card; or, if the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the (U)SIM card are inconsistent, the terminal device determines whether a valid intermediate key exists in the (U)SIM card.

[0011] In one possible design, the authentication key information also includes: the value of the steering of roaming (SOR) counter, and / or the value of the user equipment parameters update (UPU) counter.

[0012] In one possible design, a valid intermediate key includes Kausf.

[0013] In one possible design, the key set identifier is the next-generation radio access network key set identifier (ngKSI).

[0014] Secondly, a communication method is provided, the method comprising: a terminal device determining whether the value of a first counter in authentication key information is greater than or equal to a preset value; when the value of the first counter is greater than or equal to the preset value, the terminal device deleting a key set identifier; the terminal device sending a registration request message to a mobility management network element, the registration request message not carrying a key set identifier to trigger an authentication process for the terminal device; the terminal device obtaining updated authentication key information in the authentication process, the updated authentication key information including an updated intermediate key and a first counter with a value of 0.

[0015] Based on the above technical solution, when the counter in the authentication key information of the terminal device is greater than or equal to a preset value (i.e., the counter is about to flip), the key set identifier is deleted so that the registration request message sent by the terminal device does not carry the key set identifier. Since the registration request message does not carry the key set identifier, the mobility management network element initiates an authentication process with the terminal device. During the authentication process, the terminal device and the network side can synchronously obtain updated authentication key information, which includes an updated intermediate key and a counter with a value of 0. In this way, since the information sent by the network side to the terminal device before the authentication process is not protected by the updated intermediate key, even if a network attacker uses the information sent by the network side to the terminal device before the authentication process, they cannot pass the terminal device's security verification and cannot launch a replay attack. Therefore, the embodiments of this application can ensure normal communication between the terminal device and the network side.

[0016] In one possible design, the key set identifier is the key set identifier generated when the terminal device accesses the network through the first access technology; the terminal device sends a registration request message to the mobility management network element, including: the terminal device sending a registration request message to the mobility management network element using the first access technology.

[0017] In one possible design, the terminal device deletes the key set identifier by setting the value of the key set identifier to a first value, which indicates "no key is available".

[0018] In one possible design, the terminal device deletes the key set identifier by: when the terminal device is in a connected state, the terminal device releases the connection with the network device; after releasing the connection with the network device, the terminal device deletes the key set identifier.

[0019] In one possible design, the registration request message does not carry a key set identifier, but includes: the registration request message includes first indication information, which indicates that no key is available.

[0020] In one possible design, the method further includes: the terminal device receiving first information, the first information including data, the value of a second counter, and a message authentication code (MAC); the terminal device comparing whether the value of the second counter is greater than the value of the first counter; when the value of the second counter is greater than the value of the first counter, the terminal device verifying the MAC based on the data in the first information and the value of the second counter; when the MAC passes verification, the terminal device updating the value of the first counter with the value of the second counter.

[0021] In one possible design, the terminal device determines whether the value of the first counter in the authentication key information is greater than or equal to a preset value, including: the terminal device determines whether the updated value of the first counter is greater than or equal to the preset value.

[0022] In one possible design, the first counter includes: an SOR counter, and / or a UPU counter.

[0023] In one possible design, the intermediate key includes Kausf.

[0024] In one possible design, the key set identifier is ngKSI.

[0025] Thirdly, a communication method is provided, which includes: when a unified data management network element needs to send data to a terminal device, determining that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data; in response to the determination result, the unified data management network element triggers the authentication process for the terminal device.

[0026] Based on the above technical solution, for situations where data sent from the unified data management network element to the terminal device cannot be securely protected using an intermediate key, the unified data management network element triggers an authentication process, thereby enabling the terminal device and the network side to synchronously update the intermediate key and related parameters (such as the SOR counter and / or UPU counter). Thus, data sent from the unified data management network element to the terminal device can be securely protected using a valid intermediate key, and the terminal device can also perform corresponding security verification on the protected data. This ensures normal communication between the unified data management network element and the terminal device.

[0027] In one possible design, it is determined that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data, including: the unified data management network element cannot obtain the identifier of the authentication service network element involved in the terminal device authentication process.

[0028] In one possible design, determining that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data includes: the unified data management network element sending a request message to the authentication service network element involved in the terminal device authentication process, the request message including data; and the unified data management network element receiving a response message from the authentication service network element, the response message indicating that the data security protection has failed.

[0029] In one possible design, the response message includes a second indication message, which indicates the reason for the failure of data security protection.

[0030] In one possible design, the failure to secure data could be due to a missing intermediate key or a counter that is protecting the data flipping.

[0031] In one possible design, the counter could be either a counter for the SOR or a counter for the UPU.

[0032] In one possible design, before the unified data management network element sends a request message to the authentication service network element involved in the authentication process of the terminal device, it also includes: the unified data management network element obtaining the identifier of the authentication service network element based on the identifier of the terminal device.

[0033] In one possible design, determining that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data includes: the unified data management network element sending a request message to the authentication service network element involved in the terminal device authentication process, the request message including data; the unified data management network element receiving a response message from the authentication service network element, the response message including a first MAC and the value of a first counter; the unified data management network element sending first information to the terminal device, the first information including data, the first MAC, and the value of the first counter; if no confirmation message is received from the terminal device within a preset time, the unified data management network element determines that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data.

[0034] In one possible design, determining that the intermediate key generated during the terminal device's primary authentication process cannot be used to securely protect the data includes: the unified data management network element sending a request message to the authentication service network element involved in the terminal device's authentication process, the request message including data; the unified data management network element receiving a response message from the authentication service network element, the response message including a first MAC address and the value of a first counter; the unified data management network element sending first information to the terminal device, the first information including data, the first MAC address, and the value of the first counter; and the unified data management network element receiving an acknowledgment message, and if the verification of the acknowledgment message fails, then it is determined that the intermediate key generated during the terminal device's authentication process cannot be used to securely protect the data.

[0035] In one possible design, determining that the intermediate key generated during the terminal device's primary authentication process cannot be used to securely protect the data includes: the unified data management network element sending a request message to the authentication service network element involved in the terminal device's authentication process, the request message including data; the unified data management network element receiving a response message from the authentication service network element, the response message including a first MAC address and the value of a first counter; the unified data management network element sending first information to the terminal device, the first information including data, the first MAC address, and the value of the first counter; the unified data management network element receiving an acknowledgment message, the acknowledgment message including third indication information, the third indication information being used to indicate the reason for the failure of the data security verification; and the unified data management network element determining, based on the third indication information, that the intermediate key generated during the terminal device's authentication process cannot be used to securely protect the data.

[0036] In one possible design, the failure to securely verify the data could be due to a missing intermediate key or a counter that is protecting the data flipping.

[0037] In one possible design, the unified data management network element triggers the authentication process for the terminal device, including: the unified data management network element sending a fourth instruction information to the mobility management network element that provides services to the terminal device, the fourth instruction information being used to trigger the authentication process for the terminal device.

[0038] In one possible design, the unified data management network element sends a fourth instruction message to the mobility management network element that provides services to the terminal device, including: the unified data management network element sending a deregistration request message to the mobility management network element, the deregistration request message being used to request deregistration of the terminal device.

[0039] In one possible design, the unified data management network element triggers the authentication process for the terminal device, including: the unified data management network element sends a fifth instruction message to the authentication service network element, the fifth instruction message being used to instruct the authentication service network element to trigger the mobility management network element to initiate the authentication process for the terminal device.

[0040] In one possible design, the aforementioned data could be SOR data, UPU data, terminal device subscription data, terminal device routing data, or routing identifier.

[0041] In one possible design, the intermediate key includes K AUSF .

[0042] Fourthly, a communication method is provided, the method comprising: a mobility management network element receiving a registration request message sent by a terminal device for switching from a 4G network to a 5G network, the registration request message including a key set identifier, the key set identifier including a security context type parameter; when the type of the security context indicated by the security context type parameter is not native, the mobility management network element initiates an authentication process with the terminal device.

[0043] Specifically, the mobility management network element determines whether a native security context exists on the terminal device based on the security context type parameter. For example, if the registration request message includes ngKSI, and the type of ngKSI is mapped, and the registration request does not carry the information element "Non-currentnative NAS key setidentifier", then the mobility management network element determines that the terminal device does not have a native security context locally, thereby triggering the terminal's authentication process.

[0044] Based on the above technical solution, in scenarios where a terminal device switches from a 4G network to a 5G network, when the type of the security context indicated by the security context type parameter is not native, the mobility management network element (MLE) can determine that the terminal device has not undergone an authentication process in the 5G network. Therefore, the unified data management network element (UDL) does not store the identifiers of the authentication service network elements involved in the terminal device's authentication process. Consequently, the MLE initiates the terminal device's authentication process so that the UDL can store the identifiers of the authentication service network elements involved in the terminal device's authentication process, thereby ensuring normal communication between the UDL and the terminal device.

[0045] In one possible design, the key set identifier is ngKSI.

[0046] Fifthly, a communication device is provided, including a processing module and a communication module. The processing module is used to determine whether a valid intermediate key exists when an initial registration process needs to be initiated; if a valid intermediate key does not exist, it deletes the key set identifier stored in the (U)SIM card. The communication module is used to send an initial registration request message to a mobility management network element (MMI), the initial registration request message not carrying the key set identifier, to trigger an authentication process between the MMI and the communication device. The processing module is used to obtain authentication key information during the authentication process, the authentication key information including a valid intermediate key.

[0047] In one possible design, the key set identifier is a key set identifier generated when the communication device accesses the network through the first access technology; the communication module is specifically used to send an initial registration request message to the mobility management network element using the first access technology.

[0048] In one possible design, the processing module is specifically used to set the value of the key set identifier to a first value, which indicates "no key is available".

[0049] In one possible design, the initial registration request message does not carry a key set identifier, but includes: the initial registration request message includes first indication information, which indicates that no key is available.

[0050] In one possible design, the communication device further includes a storage module; and a processing module, specifically configured to determine whether the terminal identity identifier in the storage module and the terminal identity identifier in the (U)SIM card are consistent; if the terminal identity identifier in the storage module and the terminal identity identifier in the (U)SIM card are consistent, determine whether a valid intermediate key exists in the storage module and the (U)SIM card; or, if the terminal identity identifier in the storage module and the terminal identity identifier in the (U)SIM card are inconsistent, determine whether a valid intermediate key exists in the (U)SIM card.

[0051] In one possible design, the authentication key information may also include: the value of the SOR counter, and / or the value of the UPU counter.

[0052] In one possible design, a valid intermediate key includes Kausf.

[0053] In one possible design, the key set identifier is ngKSI.

[0054] Sixthly, a communication device is provided, including a processing module and a communication module. The processing module is used to determine whether the value of a first counter in authentication key information is greater than or equal to a preset value; when the value of the first counter is greater than or equal to the preset value, the key set identifier is deleted. The communication module is used to send a registration request message to a mobility management network element, the registration request message not carrying the key set identifier to trigger an authentication process for the communication device. The processing module is also used to obtain updated authentication key information during the authentication process, the updated authentication key information including an updated intermediate key and a first counter with a value of 0.

[0055] In one possible design, the key set identifier is a key set identifier generated when the communication device accesses the network through the first access technology; the communication module specifically uses the first access technology to send a registration request message to the mobility management network element.

[0056] In one possible design, the processing module is specifically used to set the value of the key set identifier to a first value, which indicates "no key is available".

[0057] In one possible design, the processing module is specifically used to release the connection with the network device when the communication device is in a connected state; and to delete the key set identifier after releasing the connection with the network device.

[0058] In one possible design, the registration request message does not carry a key set identifier, but includes: the registration request message includes first indication information, which indicates that no key is available.

[0059] In one possible design, the communication module is further configured to receive first information, which includes data, the value of a second counter, and a MAC. The processing module is further configured to compare whether the value of the second counter is greater than the value of the first counter; when the value of the second counter is greater than the value of the first counter, verify the MAC based on the data in the first information and the value of the second counter; when the MAC passes verification, update the value of the first counter with the value of the second counter.

[0060] In one possible design, the processing module is specifically used to determine whether the updated value of the first counter is greater than or equal to a preset value.

[0061] In one possible design, the first counter includes: an SOR counter, and / or a UPU counter.

[0062] In one possible design, the intermediate key includes Kausf.

[0063] In one possible design, the key set identifier is ngKSI.

[0064] A seventh aspect provides a communication device, including a processing module and a communication module. The processing module is used to determine, when data needs to be sent to a terminal device, that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data. The communication module is used to trigger an authentication process for the terminal device in response to the determination result.

[0065] In one possible design, the processing module is specifically used to determine that the intermediate key generated during the terminal device authentication process cannot be used to protect the data when the identifier of the authentication service network element involved in the terminal device authentication process cannot be obtained.

[0066] In one possible design, the communication module is further configured to send a request message, including data, to the authentication service network element involved in the terminal device authentication process; and to receive a response message from the authentication service network element, the response message indicating that data security protection has failed. The processing module is specifically configured to determine, based on the response message, that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data.

[0067] In one possible design, the response message includes a second indication message, which indicates the reason for the failure of data security protection.

[0068] In one possible design, the failure to secure data could be due to a missing intermediate key or a counter that is protecting the data flipping.

[0069] In one possible design, the counter includes an SOR counter or a UPU counter.

[0070] In one possible design, the processing module is also used to obtain the identifier of the authentication service network element based on the identifier of the terminal device.

[0071] In one possible design, the communication module is further configured to send a request message, including data, to the authentication service network element involved in the terminal device authentication process; receive a response message from the authentication service network element, including a first MAC address and the value of a first counter; and send first information to the terminal device, including data, the first MAC address, and the value of the first counter. The processing module is specifically configured to determine that if no confirmation message is received from the terminal device within a preset time, the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data.

[0072] In one possible design, the communication module is further configured to send a request message, including data, to the authentication service network element involved in the terminal device authentication process; receive a response message from the authentication service network element, including a first MAC address and the value of a first counter; send first information to the terminal device, including data, the first MAC address, and the value of the first counter; and receive an acknowledgment message. The processing module is configured to determine, if the verification of the acknowledgment message fails, that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data.

[0073] In one possible design, the communication module is further configured to send a request message to the authentication service network element involved in the terminal device authentication process, the request message including data; receive a response message from the authentication service network element, the response message including a first MAC address and the value of a first counter; send first information to the terminal device, the first information including data, the first MAC address, and the value of the first counter; and receive an acknowledgment message, the acknowledgment message including third indication information, the third indication information being used to indicate the reason for the failure of the security verification of the data. The processing module is specifically configured to determine, based on the third indication information, that the intermediate key generated during the terminal device authentication process cannot be used to securely protect the data.

[0074] In one possible design, the failure to securely verify the data could be due to a missing intermediate key or a counter that is protecting the data flipping.

[0075] In one possible design, the communication module is used to send a fourth indication message to the mobility management network element that provides services to the terminal device. The fourth indication message is used to trigger the authentication process for the terminal device.

[0076] In one possible design, the communication module is used to send a deregistration request message to the mobility management network element, the deregistration request message being used to request deregistration of the terminal device.

[0077] In one possible design, the communication module is used to send a fifth instruction message to the authentication service network element. The fifth instruction message is used to instruct the authentication service network element to trigger the mobility management network element to initiate the authentication process for the terminal device.

[0078] In one possible design, the data could be SOR data, UPU data, terminal device subscription data, terminal device routing data, or routing ID.

[0079] In one possible design, the intermediate key includes K AUSF .

[0080] Eighthly, a communication device is provided, including a processing module and a communication module. The communication module is configured to receive a registration request message sent by a terminal device for switching from a 4G network to a 5G network. The registration request message includes a key set identifier, and the key set identifier includes a security context type parameter. The processing module is configured to initiate an authentication process for the terminal device when the type of the security context indicated by the security context type parameter is not native.

[0081] In one possible design, the key set identifier is ngKSI.

[0082] Ninth aspect, a communication device is provided, including a processor and a communication interface, the processor being configured to execute computer program instructions, such that the communication device implements the communication method involved in any design provided by any of the first to fourth aspects.

[0083] In a tenth aspect, a computer-readable storage medium is provided, the computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to implement the communication method involved in any design provided by any of the first to fourth aspects.

[0084] Eleventhly, a computer program product containing computer instructions is provided, which, when run on a computer, enables the computer to implement the communication method involved in any design provided by any of the first to fourth aspects.

[0085] In a twelfth aspect, a chip is provided, the chip including a processor, which, when executing computer program instructions, implements the communication method involved in any design provided by any of the first to fourth aspects.

[0086] The technical effects of any of the design methods in aspects five through twelfth can be found in the beneficial effects of the corresponding methods provided above, and will not be repeated here. Attached Figure Description

[0087] Figure 1 A schematic diagram of a 5G network architecture provided for an embodiment of this application;

[0088] Figure 2This is a schematic diagram of the structure of a terminal device provided in an embodiment of this application;

[0089] Figure 3 A schematic diagram of the hardware structure of a mobile device in a terminal device provided in an embodiment of this application;

[0090] Figure 4 A diagram illustrating the calculation of the MAC address for the sending end;

[0091] Figure 5 A diagram illustrating the calculation of the MAC address for the receiving end;

[0092] Figure 6 This is a schematic diagram of the registration process in related technologies;

[0093] Figure 7 This is a schematic diagram of the EAP-AKA process in related technologies;

[0094] Figure 8 This is a schematic diagram of the 5G-AKA process in related technologies;

[0095] Figure 9 This is a schematic diagram of the SOR process in related technologies;

[0096] Figure 10 This is a schematic diagram of the UPU process in related technologies;

[0097] Figure 11 In related technologies, the terminal device does not store a valid K. AUSF A diagram illustrating the cause;

[0098] Figure 12 A flowchart illustrating a communication method provided in an embodiment of this application;

[0099] Figure 13 A flowchart illustrating another communication method provided in an embodiment of this application;

[0100] Figure 14 A flowchart illustrating another communication method provided in an embodiment of this application;

[0101] Figure 15 A flowchart illustrating another communication method provided in an embodiment of this application;

[0102] Figure 16 A flowchart illustrating another communication method provided in an embodiment of this application;

[0103] Figure 17 A flowchart illustrating another communication method provided in an embodiment of this application;

[0104] Figure 18 A flowchart illustrating another communication method provided in an embodiment of this application;

[0105] Figure 19 A flowchart illustrating another communication method provided in an embodiment of this application;

[0106] Figure 20 A flowchart illustrating another communication method provided in an embodiment of this application;

[0107] Figure 21 A flowchart illustrating another communication method provided in an embodiment of this application;

[0108] Figure 22 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0109] Figure 23 This is a schematic diagram of the hardware structure of a communication device provided in an embodiment of this application. Detailed Implementation

[0110] In the description of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. The "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" means one or more, and "multiple" means two or more. The terms "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply differences.

[0111] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0112] The technical solutions provided in this application can be applied to various communication systems, such as communication systems using 5G technology, future evolution systems, or multiple communication convergence systems. The technical solutions provided in this application can be applied to various application scenarios, such as machine-to-machine (M2M), macro-micro communication, enhanced mobile broadband (eMBB), ultra-reliable and low-latency communication (uRLLC), and massive machine-type communication (mMTC).

[0113] It should be understood that the network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0114] For example, such as Figure 1The diagram illustrates the architecture of a 5G network to which the technical solutions provided in this application are applicable. A 5G network may include: terminal equipment, a radio access network (RAN) or access network (AN) (hereinafter collectively referred to as (R)AN), a core network, and a data network (DN). The core network includes multiple core network elements (or network function elements), such as: access and mobility management function (AMF) elements, session management function (SMF) elements, policy control function (PCF) elements, user plane function (UPF) elements, application function elements, authentication server function (AUSF) elements, and unified data management (UDM) elements. In addition, the core network may also include some other network elements not shown, such as security anchor function (SEAF) network elements, authentication credential repository and processing function (ARPF), which will not be described in detail in the embodiments of this application.

[0115] Specifically, the terminal equipment communicates with the AMF through the Next Generation Network (N)1 interface (N1), the RAN equipment communicates with the AMF through the N2 interface (N2), the RAN equipment communicates with the UPF through the N3 interface (N3), and the UPF communicates with the DN through the N6 interface (N6).

[0116] Control plane network elements such as AMF, SMF, UDM, AUSF, or PCF can also interact using service-oriented interfaces. For example, Figure 1 As shown, the service interface provided by AMF can be Namf; the service interface provided by SMF can be Nsmf; the service interface provided by UDM can be Nudm; the service interface provided by PCF can be Npcf; and the service interface provided by AUSF can be Nausf. These will not be described in detail here.

[0117] It should be noted that the aforementioned core network elements may have other names, and the embodiments in this application are not limited to these. For example, the AMF network element may also be abbreviated as AMF, the UPF network element may also be abbreviated as UPF, and so on.

[0118] The AMF network element is primarily responsible for mobility management processing, such as access control, mobility management, attach and detach, and SMF selection. When the AMF network element provides services to a session in a terminal device, it provides control plane storage resources for that session to store the session identifier and the SMF identifier associated with the session identifier.

[0119] UDM network elements are mainly used to manage user subscription data and authentication data, as well as to perform authentication and credit processing, user identification processing, access authorization, registration / mobility management, subscription management, and SMS management.

[0120] The AUSF network element is used to provide authentication services for terminal devices to the AMF, and to provide security protection for data sent to terminal devices by some network elements (such as UDM).

[0121] SEAF network elements are used to participate in the authentication process of terminal devices and are responsible for transmitting the corresponding authentication information.

[0122] (R)AN can be composed of (R)AN devices. (R)AN devices can be various types of base stations, such as macro base stations, micro base stations (also known as "small stations"), and distributed unit-control units (DU-CUs). A DU-CU is a device deployed in a radio access network that can wirelessly communicate with terminal devices. Additionally, these base stations can also be radio controllers in cloud radio access network (CRAN) scenarios, or relay stations, access points, vehicle-mounted equipment, wearable devices, or network equipment in future evolved public land mobile networks (PLMNs). (R)AN devices can also be broadband network gateways (BNGs), aggregation switches, and non-3rd generation partnership project (3GPP) access devices. (R)AN equipment is primarily responsible for functions such as air interface-side radio resource management, uplink and downlink data classification, quality of service (QoS) management, data compression and encryption, signaling processing with control plane network elements, and data forwarding with user plane function network elements. This application does not limit the specific form and structure of the (R)AN equipment. For example, in systems employing different radio access technologies, the names of equipment with base station functions may differ. For instance, a base station can be an evolved universal terrestrial radio access network (E-UTRAN) device in LTE, such as an evolved NodeB (eNB or e-NodeB), or a next-generation radio access network (NG-RAN) device (such as a gNB) in a 5G system.

[0123] A terminal device can be any device with wireless transceiver capabilities. The terminal device can have various names, such as user equipment (UE), access terminal, terminal unit, terminal station, mobile station, mobile station, remote station, remote terminal, mobile device, wireless communication device, terminal agent, or terminal apparatus. Terminals can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water (such as on ships); and they can be deployed in the air (such as on airplanes, balloons, and satellites). Terminal devices include handheld devices, vehicle-mounted devices, wearable devices, or computing devices with wireless communication capabilities. For example, a terminal device can be a mobile phone, tablet computer, or computer with wireless transceiver capabilities. Terminal devices can also be virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminals in industrial control, wireless terminals in autonomous driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in smart cities, wireless terminals in smart homes, and so on. In this application embodiment, "terminal device" can refer to a device used to implement the functions of a terminal device, such as a chip system. In this application embodiment, the chip system can be composed of chips, or it can include chips and other discrete devices. In this application embodiment, taking a terminal as an example, the technical solutions provided by the embodiments of this application are described.

[0124] For example, Figure 2 This diagram illustrates the structure of a terminal device according to an embodiment of this application. Figure 2 As shown, terminal equipment includes at least a universal integrated circuit card (UICC) and mobile equipment (ME).

[0125] The UICC is primarily used to store and process user information, authentication keys, payment methods, and other information. A UICC is a portable smart card; users can easily transfer information stored in the UICC from one terminal to another simply by removing the card from one terminal and inserting it into another. A UICC can include one or more logical modules, such as a subscriber identity module (SIM), USIM, an IP multimedia service identity module (ISIM), and other non-telecom-related modules such as electronic signature authentication and e-wallets.

[0126] refer to Figure 3 The ME may include the following components: radio frequency (RF) circuitry 110, memory 120, other input devices 130, display screen 140, sensor 150, audio circuitry 160, I / O subsystem 170, processor 180, and power supply 190, etc. Those skilled in the art will understand that... Figure 3 The ME structure shown does not constitute a limitation on the ME. The ME may include more or fewer components than shown, or combine some components, or split some components, or have different component arrangements.

[0127] RF circuit 110 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink information from the base station and processes it with processor 180; additionally, it transmits uplink data to the base station. Typically, RF circuitry includes, but is not limited to, antennas, at least one amplifier, transceiver, coupler, LNA (low noise amplifier), duplexer, etc. Furthermore, RF circuit 110 can also communicate wirelessly with networks and other devices. This wireless communication can use any communication standard or protocol, including but not limited to Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, Short Messaging Service (SMS), etc.

[0128] The memory 120 can be used to store software programs and modules. The processor 180 executes various functional applications and data processing of the ME by running the software programs and modules stored in the memory 120. The memory 120 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the ME (such as audio data, phone book, etc.). In addition, the memory 120 may include high-speed random access memory, and may also include non-volatile memory (NVM), such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0129] Other input devices 130 can be used to receive input numeric or character information, and to generate key signal inputs related to user settings and function control of the ME. Specifically, other input devices 130 may include, but are not limited to, one or more of the following: physical keyboard, function keys (such as volume control buttons, power buttons, etc.), trackball, mouse, joystick, optical mouse (an optical mouse is a touch-sensitive surface that does not display visual output, or an extension of the touch-sensitive surface formed by a touch screen). Other input devices 130 are connected to other input device controllers 171 of I / O subsystem 170, and interact with processor 180 under the control of other input device controllers 171.

[0130] The display screen 140 can be used to display information input by the user or information provided to the user, as well as various menus of the ME, and can also accept user input. Specifically, the display screen 140 may include a display panel 141 and a touch panel 142. The display panel 141 can be configured using a liquid crystal display (LCD), organic light-emitting diode (OLED), or other similar methods. The touch panel 142, also known as a touch screen or touch-sensitive screen, can collect user touch or non-touch operations on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near the touch panel 142, and may also include motion sensing operations; these operations include single-point control operations, multi-point control operations, etc.), and drive corresponding connected devices according to a pre-set program. Optionally, the touch panel 142 may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch position and posture, and detects the signals generated by the touch operation, transmitting the signals to the touch controller. The touch controller receives touch information from the touch detection device, converts it into information that the processor can process, and sends it to the processor 180. It can also receive and execute commands from the processor 180. Furthermore, the touch panel 142 can be implemented using various types of technologies, such as resistive, capacitive, infrared, and surface acoustic waves, or any future-developed technology. Further, the touch panel 142 can cover the display panel 141. The user can operate on or near the touch panel 142 covering the display panel 141 based on the content displayed on the display panel 141 (including but not limited to a soft keyboard, virtual mouse, virtual buttons, icons, etc.). After detecting the operation on or near the touch panel 142, the touch panel 142 transmits the information to the processor 180 through the I / O subsystem 170 to confirm the user input. Subsequently, the processor 180 provides corresponding visual output on the display panel 141 based on the user input through the I / O subsystem 170. Although... Figure 3 In this embodiment, the touch panel 142 and the display panel 141 are two separate components to realize the input and output functions of the ME. However, in some embodiments, the touch panel 142 and the display panel 141 can be integrated to realize the input and output functions of the ME.

[0131] ME may also include at least one sensor 150, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. Other sensors that ME may also be configured with, such as a gyroscope, barometer, hygrometer, thermometer, and infrared sensor, will not be described in detail here.

[0132] The I / O subsystem 170 controls external devices for input and output, and may include an other input device controller 171, a sensor controller 172, and a display controller 173. Optionally, one or more other input device controllers 171 may receive signals from and / or send signals to other input devices 130, which may include physical buttons (press buttons, rocker buttons, etc.), dial pads, slide switches, joysticks, and click wheels. It is worth noting that the other input device controller 171 may be connected to any one or more of the aforementioned devices. The display controller 173 in the I / O subsystem 170 receives signals from and / or sends signals to the display screen 140. After the display screen 140 detects user input, the display controller 173 converts the detected user input into an interaction with the user interface object displayed on the display screen 140, thus realizing human-computer interaction. The sensor controller 172 may receive signals from and / or send signals to one or more sensors 150.

[0133] The processor 180 is the control center of the ME, connecting various parts of the ME through various interfaces and lines. It performs various functions and processes data by running or executing software programs and / or modules stored in the memory 120, and by calling data stored in the memory 120, thereby providing overall monitoring of the ME. Optionally, the processor 180 may include one or more processing units; preferably, the processor 180 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 180.

[0134] ME also includes a power supply 190 (such as a battery) that supplies power to various components. Preferably, the power supply can be logically connected to the processor 180 through a power management system, thereby enabling the power management system to manage functions such as charging, discharging, and power consumption.

[0135] Although not shown, ME may also include a camera, Bluetooth module, etc., which will not be described in detail here.

[0136] To facilitate understanding of the technical solution of this application, the terminology involved in this application will be briefly introduced below.

[0137] 1. (U)SIM card

[0138] In this application embodiment, (U)SIM card is a general term for SIM card and USIM card. That is, (U)SIM card can represent either SIM card or USIM card.

[0139] In mobile communication systems, a (U)SIM card serves as the network identity identifier for a mobile user. The (U)SIM card is used to store user data and perform user authentication. One (U)SIM card corresponds to one mobile user. It should be noted that the (U)SIM card can also store the terminal identity identifier corresponding to the mobile user.

[0140] (U)SIM cards are implemented in the form of physical cards, including but not limited to: standard SIM cards, Mini-SIM cards, Micro SIM cards, and Nano SIM cards.

[0141] Alternatively, (U)SIM cards can be implemented as chips, such as embedded-SIM (eSIM) cards.

[0142] 2. Safety Protection

[0143] Security protection refers to encrypting / decrypting data and / or protecting / verifying its integrity to avoid risks such as data leakage or data tampering.

[0144] 1) Encryption / Decryption

[0145] Encryption / Decryption: Protecting the confidentiality of data during transmission (hence also known as confidentiality protection). Confidentiality means that the true content cannot be directly discerned. Encryption protection is generally achieved by encrypting data using a key and an encryption algorithm. Specific methods for encryption protection can be found in Section 8.2 of 3GPP TS 33.401f50 or Section 6.4.4 of 33.501f50, and will not be elaborated upon here.

[0146] 2) Integrity protection / verification

[0147] Integrity protection / verification is used to determine whether the content of a message has been altered during transmission. It can also be used for authentication to verify the message's origin. Integrity verification and protection require the use of MAC (Machine Access Control). Specific methods for integrity verification and protection can be found in Section 8.1 of 3GPP TS 33.401f50 or Section 6.4.3 of 33.501f50, and will not be elaborated upon here.

[0148] MAC can be used to check whether the content of a message has been altered during transmission; and message authentication codes can be used for authentication to verify the origin of a message.

[0149] like Figure 4As shown, the sending end inputs parameters such as key, counter, length, bearer, message, and direction into the Evolved Packet System Integrity Algorithm (EIA) to obtain either a message authentication code integrity (MAC-I) or NAS-MAC.

[0150] like Figure 5 As shown, the receiving end inputs parameters such as integrity protection key, count, length, bearer, message, and direction into EIA to obtain the desired excepted message authentication code integrity (XMAC-I) or the desired excepted non-access stratum message authentication code (XNAS-MAC).

[0151] For the receiving end, it can compare the received MAC-I with its own generated XMAC-I to verify the integrity of the message. If the MAC-I and XMAC-I are the same, the receiving end determines that the received MAC-I has passed verification, and thus the receiving end can determine that the message sent by the sending end is complete; if the MAC-I and XMAC-I are different, the receiving end determines that the received MAC-I has failed verification, and thus the receiving end can determine that the message sent by the sending end is incomplete.

[0152] 3. Registration Process

[0153] The registration process establishes a connection between the terminal device and the network, enabling the terminal device to access the network. The registration process can be divided into:

[0154] 1) Initial registration process: The first registration process initiated by the terminal device for some reason (such as powering on).

[0155] 2) Mobile update registration process: The registration process initiated when the terminal device moves out of its original service area.

[0156] 3) Periodic registration process: A registration process initiated by the terminal device at preset time intervals. It should be understood that the periodic registration process is similar to a heartbeat mechanism, so that the network side knows that the terminal is still within the service area.

[0157] like Figure 6 As shown, the registration process may include the following steps:

[0158] S1. The terminal device sends a registration request to the access network device.

[0159] S2. The access network equipment executes the AMF selection process.

[0160] S3. The access network device sends a registration request to the first AMF.

[0161] S4. The first AMF determines the second AMF based on the registration request and sends a context transfer request to the second AMF.

[0162] The first AMF is the AMF currently providing services to the terminal device. The second AMF is the AMF that previously provided services to the terminal device.

[0163] S5. The second AMF sends a response message to the first AMF regarding the context transfer request.

[0164] S6. The first AMF sends an identification request (e.g., Identity Request) to the terminal device.

[0165] S7. The terminal device sends an Identity Response message to the first AMF.

[0166] S8. First AMF executes the authentication server function (AUSF) selection process.

[0167] If the first AMF cannot find the security context from the local or second AMF, or if the first AMF fails to perform integrity verification on the information sent by the terminal device, the mobility management network element shall perform the following step S9.

[0168] S9 performs authentication and security processes between the terminal device and the network side.

[0169] S10, the first AMF sends a registration completion notification to the second AMF.

[0170] S11. The first AMF initiates an identifier acquisition process to the UE.

[0171] S12. The first AMF and the equipment identity register (EIR) perform a device identity check.

[0172] S13, the first AMF executes the UDM selection process.

[0173] S14. The first AMF and UDM perform the registration and subscription acquisition process.

[0174] S15. If the first AMF determines that the PCF information provided by the second AMF is unavailable, the first AMF executes the PCF selection process.

[0175] S16. If the first AMF determines that the PCF information provided by the second AMF is available, and the PCF information indicates that the PCF is the PCF used by the second AMF, the first AMF sends a control policy acquisition request to the PCF.

[0176] S17. The first AMF sends an event open notification message to the SMF.

[0177] S18. The first AMF sends an N2 request to the non-3GPP interworking function (N3IWF).

[0178] S19, N3IWF returns a response message to the first AMF for the N2 request.

[0179] S20. The first AMF sends a registration acceptance message (e.g., Registration Accept) to the terminal device.

[0180] The registration receiving message is used to instruct the network side to accept the registration of the terminal device.

[0181] S21. The terminal device sends a registration complete message (e.g., Registration complete) to the first AMF.

[0182] Understandably, the registration completion message is used to indicate that the registration process is complete.

[0183] Among them, steps S4-S19 and S21 are all optional steps, and can be executed or not executed according to the actual situation.

[0184] The above is an introduction to the various steps in the registration process. The registration process may also include other steps, and the embodiments in this application are not limited to these.

[0185] 4. Authentication Process

[0186] The authentication process is used by the network side and the terminal to negotiate information for security protection (such as keys, counters, etc.). In 5G networks, the authentication process can be divided into two types: one is the Extensible Authentication Protocol (EAP)-AKA' process, and the other is the 5G-AKA process.

[0187] 1) EAP-AKA process

[0188] like Figure 7 As shown, the EAP-AKA process includes the following steps:

[0189] S201, UDM generates authentication vector (AV).

[0190] As one possible implementation, when creating a 5G HE AV, the UDM sets the separation bit of the authentication management field to "1". Furthermore, the UDM calculates CK' and IK' and replaces CK and IK with CK' and IK'. Thus, the UDM generates AV'.

[0191] AV' is authentication data consisting of RAND, AUTN, XRES, CK', and IK', used to authenticate terminal devices in the EAP-AKA' process.

[0192] S202, UDM sends a Nudm_UEAuthentication_Get Response message to AUSF.

[0193] The Nudm_UEAuthentication_Get Response message includes AV'.

[0194] Optionally, if the Nudm_Authenticate_Get Request message previously received by the UDM includes SUCI, then the corresponding Nudm_Authentication_Get Response message also includes SUPI.

[0195] S203, AUSF sends a Nausf_UEAuthentication_Authenticate Response message to SEAF.

[0196] The Nausf_UEAuthentication_Authenticate Response message includes the EAP Request / AKA′-Challenge.

[0197] S204, SEAF sends an Authentication Request message to the terminal device.

[0198] The Authentication Request message includes EAP Request / AKA'-Challenge.

[0199] In addition, the Authentication Request message also includes ngKSI.

[0200] After receiving the Authentication Request message, the ME in the terminal device sends ngKSI, RAND from EAPRequest / AKA′-Challenge, and AUTN to the USIM card.

[0201] S205, Terminal device calculates authentication response.

[0202] As one possible implementation, after receiving RAND and AUTN, the USIM card in the terminal device verifies the freshness of the 5GAV. After passing these verifications, the USIM card calculates RES. Then, the USIM card sends RES, CK, and IK to the ME.

[0203] S206. The terminal device sends an Authentication Response message to SEAF.

[0204] The Authentication Response message includes EAP-Response / AKA'-Challenge.

[0205] S207, SEAF sends a Nausf_UEAuthentication_Authenticate Request message to AUSF.

[0206] In this embodiment of the application, the Nausf_UEAuthentication_Authenticate Request message includes EAP-Response / AKA'-Challenge.

[0207] S208, AUSF authentication and authorization response.

[0208] As one possible implementation, AUSF verifies the EAP-Response / AKA'-Challenge. If authentication fails, AUSF should return an authentication failure message to SEAF.

[0209] In addition, AUSF should notify UDM of the authentication results.

[0210] S209 (optional), other EAP messages are exchanged between the terminal device and AUSF.

[0211] S210, AUSF sends a Nausf_UEAuthentication_Authenticate Response message to SEAF.

[0212] If authentication is successful, the Nausf_UEAuthentication_Authenticate Response message includes EAP Success||Anchor Key.

[0213] If authentication is successful, AUSF derives EMSK from CK' and IK', and uses the most significant 256 bits of EMSK as K. AUSF Furthermore, AUSF, according to K AUSF Derive K SEAF .

[0214] S211, SEAF sends an N1 message to the terminal device.

[0215] The N1 message includes the EAP Success message and the ngKSI message.

[0216] After receiving the EAP Success message, the terminal device derives the EMSK from CK' and IK', and uses the most significant 256 bits of the EMSK as K. AUSF Furthermore, the terminal device is based on K. AUSF Derive K SEAF .

[0217] The above is an introduction to the EAP-AKA process. For specific details, please refer to existing technologies, which will not be elaborated here.

[0218] 2) 5G-AKA process

[0219] like Figure 8 As shown, the 5G-AKA process includes the following steps:

[0220] S301, UDM generates authentication vectors.

[0221] For each Nudm_Authenticate_Get Request message received by UDM, UDM / ARPF will create a 5G home environment (HE) AV.

[0222] As one possible implementation, when creating a 5G HEAV, the UDM sets the separation bit of the authentication management field to "1". Then, the UDM can derive K according to Appendix A.2 of TS33.501. AUSF Furthermore, the expected response (XRES*) is derived according to Appendix A.4 of TS33.501. Thus, UDM creates a 5G HEAV.

[0223] 5G HEAV is a product of RAND, AUTN, XRES*, and K AUSF The authentication data is used to authenticate terminal devices in the 5G-AKA process.

[0224] S302, UDM sends a Nudm_Authentication_Get Response message to AUSF.

[0225] The Nudm_Authentication_Get Response message includes: 5G HEAV.

[0226] Optionally, if the Nudm_Authenticate_Get Request message received by the UDM includes SUCI, then the corresponding Nudm_Authentication_Get Response message also includes SUPI.

[0227] S303, AUSF storage XRES*.

[0228] As one possible implementation, AUSF should temporarily store XRES* along with the received SUCI or SUPI.

[0229] S304, AUSF calculates the expected hash response (HXRES*).

[0230] As one possible implementation, AUSF calculates HXRES* based on XRES*, and based on K AUSF Calculate K SEAF .

[0231] S305, AUSF sends a Nausf_UEAuthentication_Authenticate Response message to SEAF.

[0232] The Nausf_UEAuthentication_Authenticate Response message includes 5G SEAV. 5G SEAV includes RAND, AUTN, and HXRES*.

[0233] S306, SEAF sends an Authentication Request message to the terminal device.

[0234] The Authentication Request message includes RAND and AUTN.

[0235] Furthermore, the Authentication Request message also includes ngKSI. It should be noted that the terminal device and AMF use ngKSI to identify the K... AMF And the partial native security context created upon successful authentication.

[0236] The ME in the terminal device forwards the random value (RAND) and authentication token (AUTN) from the Authentication Request message to the USIM card.

[0237] S307. Terminal device calculates authentication response (RES*).

[0238] As one possible implementation, the USIM card in the terminal device verifies the freshness of the 5GAV after receiving RAND and AUTN. After passing these verifications, the USIM card calculates RES.

[0239] In addition, the USIM card will return RES, CK, and IK to the ME. The ME will derive RES* from RES. Furthermore, the ME will also calculate K. AUSF and K SEAF .

[0240] S308. The terminal device sends an Authentication Response message to SEAF.

[0241] The Authentication Response message includes RES*.

[0242] S309, SEAF calculates HRES* and compares whether HRES* is consistent with HXRES.

[0243] HRES* is derived from RES*.

[0244] It should be understood that when HRES* and HXRES are consistent, SEAF considers the authentication successful from the perspective of the service network.

[0245] If HRES* and HXRES are consistent, SEAF performs the following step S310.

[0246] S310, SEAF sends a Nausf_UEAuthentication_Authenticate Request message to AUSF.

[0247] The Nausf_UEAuthentication_Authenticate Request message includes RES*.

[0248] S311, AUSF verifies the received RES*.

[0249] As one possible implementation, when AUSF receives a Nausf_UEAuthentication_Authenticate Request message carrying RES* as authentication confirmation, AUSF can verify whether the AV has expired. If the AV has expired, AUSF considers authentication unsuccessful from the home network's perspective. If the AV has not expired, AUSF should check whether the received RES* is equal to the stored XRES*. If RES* is equal to XRES*, AUSF considers authentication successful from the home network's perspective. Furthermore, AUSF notifies the UDM of the authentication result.

[0250] If authentication is successful, AUSF storage K AUSF .

[0251] S312, AUSF sends a Nausf_UEAuthentication_Authenticate Response message to SEAF.

[0252] The Nausf_UEAuthentication_Authenticate Response message is used to indicate the authentication result from the home network. In other words, the Nausf_UEAuthentication_Authenticate Response message is used to notify SEAF whether authentication was successful from the home network's perspective.

[0253] If authentication is successful, the Nausf_UEAuthentication_Authenticate Response message includes K SEAF And SUPI.

[0254] If authentication is successful, SEAF should, according to K SEAF Calculate K using equal parameters AMF Afterwards, SEAF should provide AMF with ngKSI and K AMF .

[0255] The above is an introduction to the 5G-AKA process. For specific details, please refer to existing technologies, which will not be elaborated here.

[0256] 5. ngKSI

[0257] The ngKSI is used to identify 5G non-access stratum (NAS) security contexts and indicate the type of those contexts. The ngKSI consists of an identifier value and a security context type parameter. The identifier value uniquely corresponds to a single 5G NAS security context. The security context type parameter indicates whether the 5G NAS security context is a native 5G NAS security context or a mapped 5G NAS security context.

[0258] For example, when the 5G NAS security context type is native, the value of the security context type parameter is KSIAMF. When the 5G NAS security context type is mapped, the value of the security context type parameter is KSIASME.

[0259] It should be understood that, for the native security context, the ngKSI is generated and sent to the terminal device by the AMF during the authentication process. Alternatively, for the mapped 5G NAS security context, the ngKSI is derived separately by the terminal device and the AMF during inter-system handover.

[0260] The native 5G NAS security context is generated between the terminal device accessing the 5G network and the 5G core network element through an authentication process.

[0261] The napped 5G NAS security context is obtained by mapping the evolved packet system (EPS) security context generated during the terminal device authentication process in the 4G network.

[0262] 6. 5G NAS Security Context

[0263] 5G NAS security context refers to information that can be used to achieve security protection (e.g., encryption / decryption, and / or integrity protection / verification) of data transmitted between the terminal and the core network.

[0264] Security context may include one or more of the following: root key, encryption key, integrity protection key, specific parameters (such as NAS Count), security algorithm, security indications (such as indications of whether encryption is enabled, indications of whether integrity protection is enabled, indications of key expiration, key length, etc.).

[0265] In this context, the encryption key is the parameter input by the sending end when encrypting the plaintext to generate ciphertext using an encryption algorithm. If a symmetric encryption method is used, the encryption key and decryption key are the same. The receiving end can decrypt the ciphertext using the same encryption algorithm and encryption key. In other words, the sending and receiving ends can encrypt and decrypt using the same key.

[0266] The integrity protection key is a parameter input by the sending end when performing integrity protection on plaintext or ciphertext according to the integrity protection algorithm. The receiving end can perform integrity verification on the integrity-protected data using the same integrity protection algorithm and integrity protection key.

[0267] Specific parameters (such as NAS Count) are input by the sending end when applying anti-replay protection to plaintext or ciphertext according to the anti-replay protection algorithm. The receiving end can perform anti-replay verification on the data protected against replay using the same anti-replay protection algorithm.

[0268] Security algorithms are algorithms used to protect data. Examples include encryption algorithms, decryption algorithms, and integrity protection algorithms.

[0269] 7. SOR

[0270] Roaming guidance enables the home public land mobile network (HPLMN) to guide terminal devices in automatic network selection mode to search for specific visited public land mobile networks (VPLMNs).

[0271] like Figure 9 As shown, the SOR process may include the following steps:

[0272] S401, HPLMN UDM confirms that the steering information list of the terminal equipment has been updated.

[0273] S402, HPLMN UDM sends Nausf_SoRProtection message to HPLMNAUSF.

[0274] The Nausf_SoRProtection message includes SUPI, a boot information list, and a SOR header.

[0275] Optionally, if the HPLMN determines that the terminal device should acknowledge the successful security check of the received boot information list, the UDM needs to make the corresponding settings in the SOR header, and the Nausf_SoRProtection message also includes ACKIndication.

[0276] S403, HPLMNAUSF sends a Nausf_SoRProtection Response message to HPLMN UDM.

[0277] The Nausf_SoRProtection Response message includes: SoR-MAC-I AUSF And SORcounter.

[0278] Optionally, if the Nausf_SoRProtection message includes an ACK Indication, the Nausf_SoRProtection Response message may also include a SoR-XMAC-I. UE .

[0279] In this embodiment of the application, SoR-MAC-I AUSF It is based on the guidance information list, SOR header, SOR counter, and K. AUSF It is calculated using SoR-XMAC-I. UE It is based on the SOR successful confirmation message, the SOR counter, and K. AUSF This was calculated.

[0280] S404, HPLMN UDM sends a Nudm_SDM_Notification message to VPLMNAMF.

[0281] The Nudm_SDM_Notification message includes: a boot information list, a SOR header, and a SoR-MAC-I. AUSF And SOR counter.

[0282] S405 and VPLMNAMF send DLNAS Transport messages to the terminal device.

[0283] The DLNAS Transport message includes: a boot information list, an SOR header, and a SoR-MAC-I header. AUSF And SOR counter.

[0284] S406, Terminal Equipment Verification SoR-MAC-I AUSF.

[0285] As one possible implementation, the terminal device calculates the SoR-MAC-I based on the received boot information list, SOR header, and SOR counter, in a manner related to AUSF. AUSF And verify the calculated SoR-MAC-I AUSF With the received SoR-MAC-I AUSF Are they the same? If the calculated SoR-MAC-I AUSF With the received SoR-MAC-I AUSF If they are the same, it means that the received SoR-MAC-I AUSF Verification passed.

[0286] When the UDM has requested the terminal device to confirm that the security check of the received boot information list was successful, and the terminal device has successfully verified SoR-MAC-I AUSF Afterwards, the terminal device should also perform the following step S407.

[0287] S407. The terminal device sends a ULNAS Transport message to VPLMNAMF.

[0288] The ULNAS Transport message includes a transparent container, which includes SOR-MAC-I. UE .

[0289] S408, VPLMNAMF sends a Nudm_SDM_Info request message to HPLMMN UDM.

[0290] The Nudm_SDM_Info request message includes a transparent container, which includes SOR-MAC-I UE .

[0291] S409, HPLMN UDM compares the received SOR-MAC-I UE and storage of SOR-XMAC-I UE Are they consistent?

[0292] It should be understood that if the received SOR-MAC-I UE and storage of SOR-XMAC-I UE Inconsistencies indicate a security risk on the network.

[0293] The above is a brief introduction to the SOR process. For specific details, please refer to existing technologies, which will not be elaborated here.

[0294] 8. SOR counter

[0295] SOR counter can also be written as Counter. SOR .

[0296] AUSF and terminal devices will connect the SOR counter with K. AUSF Related. The SOR counter is typically a 16-bit counter. The SOR counter is used to prevent replay attacks.

[0297] Derivation of K from the terminal device AUSF At this time, the terminal device will set the SOR counter to 0.

[0298] In the derivation of K in AUSF AUSF At this time, AUSF will set the SOR counter to 1.

[0299] 9. User Equipment Parameter Update (UPU)

[0300] The UPU process enables the network side to update relevant parameters of the terminal device.

[0301] like Figure 10 As shown, the UPU process may include the following steps:

[0302] S501, UDM decides to execute UPU.

[0303] S502, UDM sends a Nausf_UPUProctection message to AUSF.

[0304] The Nausf_UPUProctection message includes SUPI and UPU data.

[0305] Optionally, the Nausf_UPUProctection message may also include an ACK indication to indicate that the UDM requests the terminal device to acknowledge that the received UPU data security check was successful.

[0306] S503, AUSF sends a Nausf_UPUProctection response message to UDM.

[0307] The Nausf_UPUProctection response message includes: UPU counter and UPU-MAC-I. AUSF UPU-MAC-I AUSFIt is the MAC generated after integrity protection of UPU data. The UPU counter is a counter used in the process of integrity protection of UPU data.

[0308] Optionally, if the Nausf_UPUProctection message also includes an ACK indication, the Nausf_UPUProctection response message may also include a UPU-XMAC-I ACK indication. UE .

[0309] It should be noted that UPU-MAC-I AUSF It is based on UPU data, UPU counter, and K. AUSF This was calculated using UPU-XMAC-I. UE It is based on ACK indication, UPU counter and K AUSF This was calculated.

[0310] S504, UDM sends a Nudm_SDM_Notification message to AMF.

[0311] The Nudm_SDM_Notification message includes: UPU data, UPU counter, and UPU-MAC-I. AUSF .

[0312] S505 and AMF send DLNAS Transport messages to the terminal equipment.

[0313] The DLNAS Transport message includes UPU data, UPU counter, and UPU-MAC-I. AUSF .

[0314] S506, Terminal Equipment Verification UPU-MAC-I AUSF .

[0315] As one possible implementation, the terminal device calculates the UPU-MAC-I based on the received UPU data and UPU counter in the same way as AUSF. AUSF And verify the calculated UPU-MAC-I AUSF Is it consistent with the received UPU-MAC-I? AUSF Same. When the calculated UPU-MAC-I AUSF With the received UPU-MAC-I AUSF If they are the same, the verification is successful.

[0316] If the verification is successful, and the UPU data contains parameters protected by a secure packet, the ME in the terminal device will send the secure packet-protected parameters to the USIM card in the terminal device.

[0317] If the verification is successful, and the UPU data does not contain parameters protected by security groups, the ME in the terminal device will update its stored parameters based on the parameters in the UPU data.

[0318] When the UDM has requested the terminal device to confirm that the security check of the received UPU data was successful, and the terminal device has successfully verified the UPU-MAC-I... AUSF After updating the parameters based on the UPU data, the terminal device should perform the following step S507.

[0319] S507, The terminal device sends a ULNAS Transport message to the AMF.

[0320] The ULNAS Transport message includes a transparent container, which includes UPU-MAC-I. UE .

[0321] It should be noted that UPU-MAC-I UE It is based on UPU confirmation, UPU counter, and K. AUSF This was calculated.

[0322] S508 and AMF send a Nudm_SDM_Info request message to UDM.

[0323] The Nudm_SDM_Info request message includes a transparent container, which includes UPU-MAC-I. UE .

[0324] S509, UDM compares the received UPU-MAC-I UE and storage UPU-XMAC-I UE Are they consistent?

[0325] It should be understood that if the received UPU-MAC-I UE and storage UPU-XMAC-I UE Inconsistencies indicate a security risk on the network.

[0326] The above is a brief introduction to the UPU process. For specific details, please refer to existing technologies, which will not be elaborated here.

[0327] 10. UPU counter

[0328] UPU counter can also be written as Counter. UPU .

[0329] AUSF and terminal devices will connect the UPU counter with K AUSF Related. The UPU counter is typically a 16-bit counter. The UPU counter is used to prevent replay attacks.

[0330] Derivation of K from the terminal device AUSF At this time, the terminal device will set the UPU counter to 0.

[0331] In the derivation of K in AUSF AUSF At this time, AUSF will set the UPU counter to 1.

[0332] The above is an introduction to the terminology involved in the embodiments of this application, which will be uniformly explained here and will not be repeated below.

[0333] Currently, after the authentication process between the terminal device and AUSF, both the terminal device and AUSF can store and maintain the same key K. AUSF However, for some reason, the terminal device may not have stored a valid K. AUSF .

[0334] For example, with Figure 11 For example, this illustrates that the terminal device does not store a valid K. AUSF The reason.

[0335] S601, ME1 with USIM card 1 inserted registers under the 5G network, generating a 5GNAS security context of ngKSI=0 and 5G authentication key information.

[0336] It should be understood that ngKSI=0 is just an example.

[0337] Among them, the 5G NAS security context can be stored in EF. 5GS3GPPNSC Card file. 5G authentication key information can be stored in EF. 5GAUTHKEYS Card file. 5G authentication key information includes K AUSF wait.

[0338] S602 and ME1 store 5G authentication key information, while USIM card 1 stores the 5GNAS security context with ngKSI=0.

[0339] After registering with the ME1 after inserting USIM card 1, the network side will still retain the 5G NAS security context with ngKSI=0.

[0340] S603, USIM card 1 is removed from ME1 and inserted into ME2.

[0341] At this time, USIN card 1 still stores the 5GNAS security context with ngKSI=0, but ME2 does not store the corresponding 5G authentication key information.

[0342] S604. After powering on, the ME2 with USIM card 1 inserted sends an initial registration request message.

[0343] Since USIM card 1 stores the 5G NAS security context with ngKSI=0, the initial registration request message carries ngKSI=0.

[0344] S605, AMF enables 5G NAS security context with ngKSI=0.

[0345] ME2 with USIM card 1 inserted has successfully registered on the 5G network.

[0346] It should be understood that, based on the above steps S601-S605, the ME2 with USIM card 1 inserted does not store 5G authentication key information. This results in the ME2 with USIM card 1 being unable to perform security verification on information from some network elements (such as UDM) on the network side, causing the ME2 with USIM card 1 to discard this information. The following explanation uses the SOR process as an example.

[0347] S606, HPLMN UDM confirms that the ME2 boot information list of inserted USIM card 1 has been updated.

[0348] S607 and HPLMN UDM send the Nausf_SoRProtection message to HPLMNAUSF.

[0349] The Nausf_SoRProtection message includes SUPI, a boot information list, and a SOR header.

[0350] S608, HPLMNAUSF sends a Nausf_SoRProtection Response message to HPLMN UDM.

[0351] The Nausf_SoRProtection Response message includes: SoR-MAC-I AUSF And SORcounter.

[0352] S609 and HPLMN UDM send Nudm_SDM_Notification messages to VPLMNAMF.

[0353] The Nudm_SDM_Notification message includes: a boot information list, a SOR header, and a SoR-MAC-I. AUSF And SOR counter.

[0354] S610 and VPLMNAMF send a DLNAS Transport message to ME2, which has USIM card 1 inserted.

[0355] The DLNAS Transport message includes: a boot information list, an SOR header, and a SoR-MAC-I header. AUSF And SOR counter.

[0356] After receiving the DL NAS Transport message, because the ME2 with USIM card 1 inserted does not store 5G authentication key information, the ME2 with USIM card 1 inserted cannot perform SoR-MAC-I authentication. AUSF Perform a security check.

[0357] S611, ME2 with USIM card 1 inserted cannot verify SoR-MAC-I. AUSF DL NAS Transport messages are discarded.

[0358] It should be understood that, in addition to Figure 11 In addition to the reasons indicated, the terminal device did not store a valid K. AUSF Other factors could also cause this, such as storage failure in the terminal device or abnormal software operation in the terminal device; there are no restrictions on this.

[0359] It is evident that currently, the terminal device does not store a valid K. AUSF However, when storing the ngKSI, during the initial registration process after power-on, the terminal device sends an initial registration request message carrying the ngKSI, causing the network side to activate the corresponding 5G NAS security context. However, the network side is unaware that the terminal device has not stored a valid KSI. AUSF This causes the network side to follow the security protection steps in the normal process (such as the SOR process and UPU process) and use K. AUSF The information sent to the terminal device is securely protected. However, the terminal device does not store a valid K. AUSF Therefore, the information after security protection cannot be verified, and the terminal device can only discard the information after security protection. This affects the normal secure communication between relevant network elements (such as UDM) and the terminal device.

[0360] To address this technical problem, embodiments of this application provide a communication method. For example... Figure 12 As shown, the communication method includes the following steps:

[0361] S701. When the terminal device needs to initiate the initial registration process, it determines whether a valid intermediate key exists.

[0362] The terminal device is equipped with a (U)SIM card, which stores a key set identifier.

[0363] For example, the key set identifier can be ngKSI, or a key set identifier used in the future network to identify the security context.

[0364] In this embodiment of the application, the intermediate key may include K AUSF K SEAF For 3GPP access, K SEAF For non-3GPP access.

[0365] Optionally, a scenario where the terminal device needs to initiate the initial registration process could be when the terminal device is first powered on.

[0366] For example, after a new (U)SIM card is inserted into the terminal device, the terminal device powers on in response to the user equipment's operation, preparing to initiate the initial registration process with the inserted (U)SIM card.

[0367] Optionally, step S701 may include the following sub-steps: S7011-S7013.

[0368] S7011. If the terminal device is also equipped with non-volatile memory, the terminal device determines whether the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the (U)SIM card are consistent.

[0369] It should be understood that, when the terminal device is also equipped with non-volatile memory, the terminal device's non-volatile memory stores the terminal identity identifier from the (U)SIM card when the (U)SIM card is removed from the terminal device. Subsequently, if the terminal device inserts another (U)SIM card, it compares the terminal identity identifier in the newly inserted (U)SIM card with the terminal identity identifier in the non-volatile memory.

[0370] If they match, it means that the newly inserted (U)SIM card and the previously removed (U)SIM card are the same SIM card. Therefore, the card file (e.g., EF) stored in the terminal device's non-volatile memory... 5GAUTHKEYS The card file (etc.) is valid for the newly inserted (U)SIM card, so the terminal device should perform the following step S7012.

[0371] If they are inconsistent, it means that the newly inserted (U)SIM card is not the same SIM card as the previously removed (U)SIM card. The card file (e.g., EF) stored in the terminal device's non-volatile memory will then be affected. 5GAUTHKEYS The card file (etc.) is invalid for the newly inserted (U)SIM card, so the terminal device does not need to search for a valid intermediate key in the non-volatile memory, and the terminal device should perform the following step S7013.

[0372] S7012. If the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the (U)SIM card are consistent, the terminal device determines whether a valid intermediate key exists in the non-volatile memory and the (U)SIM card.

[0373] S7013. In the case that the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the (U)SIM card are inconsistent, the terminal device determines whether there is a valid intermediate key in the (U)SIM card.

[0374] Among them, the terminal identity identifier is used to uniquely identify the terminal device in the network.

[0375] In 4G networks, the terminal identification can be: International Mobile Subscriber Identification Number (IMSI).

[0376] In 5G networks, terminal identity can be: a subscription permanent identifier (SUPI), a subscription concealed identifier (SUCI), or a 5G globally unique temporary identity (5G-GUTI). It's important to note that the SUPI represents the true identity of the terminal device, functioning similarly to the IMSI in LTE. The SUCI is generated by encrypting the SUPI with a public key. Transmitting the SUCI between network devices and terminal devices avoids the problem of attackers stealing the plaintext SUPI. Understandably, the SUCI can be decrypted using the private key paired with the public key to obtain the SUCI.

[0377] S702. If a valid intermediate key does not exist, the terminal device deletes the key set identifier.

[0378] In this embodiment of the application, the deletion of the key set identifier by the terminal device can be specifically implemented as follows: the terminal device sets the value of ngKSI to a first value, which is used to indicate "no key is available".

[0379] S703, The terminal device sends an initial registration request message to the mobility management network element.

[0380] As one possible implementation, if the key set identifier previously stored in the (U)SIM card is the same key set identifier generated when the terminal device accesses the network through the first access technology, then the terminal device can use the first access technology to send an initial registration request message to the mobility management network element.

[0381] The first access technology can be either 3GPP access technology or non-3GPP access technology.

[0382] It should be understood that since the terminal device has deleted the key set identifier, the initial registration request message does not carry the key set identifier. Therefore, when the mobility management network element receives the initial registration request message without carrying the key set identifier, it will trigger the authentication process with the terminal device.

[0383] In this embodiment of the application, the initial registration request message does not carry a key set identifier. Specifically, the initial registration request message includes first indication information, which is used to indicate that no key is available.

[0384] For example, the first instruction information can be specifically implemented as follows: the key set identifier information element in the initial registration request message is set to "no key is available".

[0385] S704. The terminal device obtains authentication key information during the authentication process.

[0386] The authentication key information includes a valid intermediate key.

[0387] Optionally, the authentication key information may also include: the value of the SOR counter and / or the value of the UPU counter.

[0388] For specific details regarding the authentication process, please refer to the above text. Figure 7 or Figure 8 The process described is not repeated here.

[0389] based on Figure 12In the illustrated embodiment, when a terminal device needs to initiate an initial registration process, the terminal device first checks whether a valid intermediate key exists. If no valid intermediate key exists, the terminal device deletes the key set identifier from the (U)SIM card, so that the initial registration request message sent by the terminal device does not carry the key set identifier. Since the initial registration request message does not carry the key set identifier, the mobility management network element initiates an authentication process with the terminal device. During the authentication process, the terminal device and the network side can synchronously obtain the same intermediate key. Thus, in subsequent processes (such as the SOR process or the UPU process), the network side can use the intermediate key to securely protect the information sent to the terminal device; correspondingly, the terminal device can use the same intermediate key to securely verify the protected information. Therefore, this embodiment of the application can guarantee secure communication between the terminal device and the network side.

[0390] Currently, after the authentication process, terminal devices store a SOR counter and UPU counter set to 0. Subsequently, in relevant processes (such as the UPU or SOR process), the terminal device updates its stored SOR counter or UPU counter based on the SOR counter or UPU counter sent by the network side. Thus, the value of the SOR counter or UPU counter stored by the terminal device continuously increases. If the SOR counter (or UPU counter) stored by the terminal device is allowed to flip, network attackers can use information previously sent by the network side to the terminal device to perform replay attacks, affecting normal communication between the network side and the terminal device. Existing technologies do not provide a corresponding solution to this problem.

[0391] To address this technical problem, embodiments of this application provide a communication method. For example... Figure 13 As shown, the communication method includes the following steps:

[0392] S801. The terminal device determines whether the value of the first counter in the authentication key information is greater than or equal to a preset value.

[0393] The first counter in the authentication key information can be an SOR counter and / or a UPU counter.

[0394] It should be understood that if the counter is greater than or equal to the preset value, it means that the counter is about to flip.

[0395] Counter flipping refers to the process of a counter restarting its count from 0 after exceeding its maximum counting range.

[0396] For example, for a 16-bit counter, the counting range is 0 to 65535. If the counter value is 65535, incrementing the counter by 1 will cause the counter to flip, making the counter 0.

[0397] In this embodiment, the preset value can be pre-configured when the terminal device leaves the factory, configured by the terminal device according to its own usage, or indicated by the network device to the terminal device. For example, taking a counter with a counting range of 0 to 65535 as an example, the preset value can be 65500.

[0398] Optionally, the triggering condition for the terminal device to execute step S801 can be any one of the following conditions:

[0399] Condition 1: The terminal device has just updated the value of the first counter in the authentication key information.

[0400] Condition 2: The terminal device has just been powered on.

[0401] Condition 3: The terminal device is ready to initiate the registration process.

[0402] Conditions 1-3 above are merely illustrative examples and do not constitute specific limitations.

[0403] S802. When the first counter is greater than or equal to a preset value, the terminal device deletes the key set identifier stored in its own memory.

[0404] For example, the key set identifier can be ngKSI, or a key set identifier used in the future network to identify the security context.

[0405] It should be understood that the terminal device may store the key set identifier in the (U)SIM card configured on the terminal device.

[0406] In this embodiment of the application, the deletion of the key set identifier by the terminal device is specifically implemented as follows: the terminal device sets the key set identifier to a first value, which is used to indicate "no key is available".

[0407] S803, The terminal device sends a registration request message to the mobility management network element.

[0408] As one possible implementation, if the key set identifier previously stored in the (U)SIM card is the same key set identifier generated when the terminal device accesses the network through the first access technology, then the terminal device can use the first access technology to send a registration request message to the mobility management network element.

[0409] The first access technology can be either 3GPP access technology or non-3GPP access technology.

[0410] It should be understood that since the terminal device has deleted the key set identifier, the registration request message does not carry the key set identifier. Therefore, when the mobility management network element receives a registration request message that does not carry the key set identifier, it will trigger the authentication process with the terminal device.

[0411] In this embodiment of the application, the registration request message does not carry a key set identifier. Specifically, the registration request message includes first indication information, which is used to indicate that no key is available.

[0412] For example, the first indication information can be specifically implemented as follows: the ngKSI information element in the registration request message is set to "no key is available".

[0413] The registration request message mentioned above can be an initial registration request message or a registration request message in other registration processes.

[0414] S804. The terminal device obtains the updated authentication key information during the authentication process.

[0415] The updated authentication key information includes the updated intermediate key and a first counter with a value of 0. The intermediate key includes K. AUSF K SEAF For 3GPP access, K SEAF For non-3GPP access.

[0416] It should be understood that after the authentication process, the first counter in the authentication key information is associated with the updated intermediate key.

[0417] For specific details regarding the authentication process, please refer to the above text. Figure 7 or Figure 8 The process described is not repeated here.

[0418] based on Figure 13In the illustrated embodiment, when the counter in the authentication key information of the terminal device is greater than or equal to a preset value (i.e., the counter is about to flip), the key set identifier is deleted so that the registration request message sent by the terminal device does not carry the key set identifier. Since the registration request message does not carry the key set identifier, the mobility management network element initiates an authentication process with the terminal device. During the authentication process, the terminal device and the network side can synchronously obtain updated authentication key information, which includes an updated intermediate key and a counter with a value of 0. Thus, since the information sent by the network side to the terminal device before the authentication process is not protected by the updated intermediate key, even if a network attacker uses the information sent by the network side to the terminal device before the authentication process, they cannot pass the terminal device's security verification and cannot launch a replay attack. Therefore, the embodiments of this application can ensure normal communication between the terminal device and the network side.

[0419] The following will illustrate this with specific application scenarios. Figure 13 The embodiment shown below. The following scenario mainly applies to the case where the triggering condition for step S801 is condition 1.

[0420] based on Figure 13 The illustrated embodiments, such as Figure 14 As shown, the communication method further includes steps S901-S904 before step S801. Accordingly, step S801 can be specifically implemented as step S905.

[0421] S901, The terminal device receives the first information.

[0422] The first piece of information includes data, the value of the second counter, and the MAC.

[0423] For example, taking the SOR process as an example, the data in the first message can be a bootstrap information list and an SOR header, the second counter in the first message can be an SOR counter, and the MAC in the first message can be SoR-MAC-I. AUSF .

[0424] For example, taking the UPU process as an example, the data in the first information can be UPU data, the second counter in the first information can be a UPU counter, and the MAC in the first information can be UPU-MAC-I. AUSF .

[0425] It should be understood that the first information may also be a message from other processes, and this application embodiment does not limit this.

[0426] S902, The terminal device compares whether the value of the second counter in the first information is greater than the value of the first counter in the authentication key information.

[0427] When the value of the second counter in the first information is less than or equal to the value of the first counter in the authentication key information, the terminal device may discard the first information. Otherwise, the terminal device executes the following step S903.

[0428] S903. When the value of the second counter in the first information is greater than the value of the first counter in the authentication key information, the terminal device verifies the MAC in the first information based on the data in the first information and the value of the second counter.

[0429] In one possible implementation, the terminal device generates a desired MAC address based on the data in the first information, the value of the second counter, and the intermediate key included in the authentication key information. The terminal device compares the desired MAC address with the MAC address in the first information. If the MAC address in the first information matches the desired MAC address, the MAC address in the first information is verified. Otherwise, the MAC address in the first information fails verification.

[0430] For example, taking the SOR process as an example, the terminal device generates SoR-MAC-I based on the data in the first information, the value of the second counter, and the intermediate key included in the authentication key information. AUSF Then, the terminal device compares its own generated SoR-MAC-I... AUSF With SoR-MAC-I in the first message AUSF Are they consistent? If they are consistent, it means that the SoR-MAC-I in the first information is consistent. AUSF Verification passed. Otherwise, it indicates that SoR-MAC-I... AUSF Verification failed.

[0431] For example, taking the UPU process as an example, the terminal device generates UPU-MAC-I based on the data in the first information, the value of the second counter, and the intermediate key included in the authentication key information. AUSF Then, the terminal device compares its own generated UPU-MAC-I... AUSF With UPU-MAC-I in the first message AUSF Are they consistent? If they are consistent, it means that the UPU-MAC-I in the first information is consistent. AUSF Verification passed. Otherwise, it indicates that UPU-MAC-I... AUSF Verification failed.

[0432] S904. When the MAC in the first information passes verification, the terminal device updates the value of the first counter in the authentication key information with the value of the second counter in the first information.

[0433] Taking the SOR process as an example, the terminal device updates the value of the SOR counter in the authentication key information with the value of the SOR counter in the first information. For example, assuming the value of the SOR counter in the first information is 20 and the value of the SOR counter in the authentication key information is 4, the terminal device can update the value of the SOR counter in the authentication key information to 20.

[0434] Taking the UPU process as an example, the terminal device updates the value of the UPU counter in the authentication key information with the value of the UPU counter in the first information.

[0435] S905. The terminal device determines whether the updated value of the first counter in the authentication key information is greater than or equal to a preset value.

[0436] based on Figure 14 In the illustrated embodiment, after each update of the value of the first counter in the authentication key information, the terminal device promptly checks whether the updated value of the first counter is greater than or equal to a preset value. If the updated value of the first counter is greater than or equal to the preset value, the terminal device can trigger the network side to initiate an authentication process by sending a registration request message without carrying a key set identifier, thereby obtaining the updated authentication key information. Therefore, Figure 14 The illustrated embodiment can reduce the occurrence of counters nearing a toggle that go undetected, thereby reducing the occurrence of situations where the network side cannot use the corresponding procedures (such as the SOR procedure or the UPU procedure) due to the counters nearing a toggle.

[0437] Currently, to ensure data security, data sent from UDM to terminal devices requires security protection using an intermediate key generated during the terminal device authentication process. However, in some scenarios, data sent from UDM to terminal devices cannot be adequately protected. This will be explained below with examples from various application scenarios.

[0438] Scenario 1: After the authentication process, the terminal device and the AUSF involved in the authentication process will store the same K. AUSF Thus, UDM can send data to the terminal device to request the AUSF involved in the terminal device authentication process using K. AUSF Appropriate security protections should be implemented. However, in some cases, the UDM may not store the identifier of the AUSF involved in the terminal device authentication process, thus the UDM cannot determine which AUSF to request appropriate security protections for the data to be sent to the terminal device.

[0439] For example, the reason why the UDM does not store the identifier of the AUSF involved in the terminal device authentication process is as follows: The terminal device first registers in the 4G network and generates an EPS security context; then, the terminal device switches from the 4G network to the 5G network. Based on the EPS security context, the 5G network derives a mapped 5G NAS security context and enables this mapped 5G NAS security context. In this process, since there is no AUSF in the 4G network, the UDM cannot store the identifier of the AUSF involved in the terminal device authentication process.

[0440] Scenario 2: AUSF fails to store K due to some factors (e.g., AUSF does not store K). AUSF (Or the counter that stores data for security protection in AUSF is about to flip), causing AUSF to be unable to properly protect the data that UDM is about to send to the terminal device.

[0441] Scenario 3: The terminal device fails to store K due to some factors (e.g., the terminal device does not store K). AUSF (Or, the counter stored on the terminal device to protect the data is about to flip), causing the terminal device to be unable to properly perform security verification on the data sent to the terminal device by the UDM. In this case, the terminal device does not store K. AUSF The relevant reasons can be found in the description above, and will not be repeated here.

[0442] When the data sent from the UDM to the terminal device cannot be adequately protected, normal communication between the terminal device and the UDM will fail. The industry urgently needs a solution to this technical problem.

[0443] To address the aforementioned technical problems, embodiments of this application provide a communication method. For example... Figure 15 As shown, the communication method includes the following steps:

[0444] S1001. When the unified data management network element needs to send data to the terminal device, it determines that the intermediate key generated in the terminal device authentication process cannot be used to protect the data.

[0445] The intermediate key includes K AUSF K AUSF The source can be found by referring to Figure 7 or Figure 8 The explanation of the authentication process shown will not be repeated here.

[0446] In this embodiment, the unified data management network element can be a UDM in a 5G network, or a network element in a future network responsible for managing subscription data, authentication data, etc. This is stated here and will not be repeated below.

[0447] The data to be sent by the aforementioned unified data management network element to the terminal device may be SOR data, UPU data, the terminal device's subscription data, the terminal device's routing data, or routing identifiers, etc. This application embodiment does not limit this.

[0448] S1002. In response to the determined result, the unified data management network element triggers the authentication process for the terminal device.

[0449] The result is that the intermediate key generated during the terminal device authentication process cannot be used to protect the data.

[0450] Optionally, in response to the determined result, the unified data management network element can first set a timer for the terminal device, and then trigger the authentication process for the terminal device after the timer expires.

[0451] Optionally, the unified data management network element can trigger the authentication process for terminal devices using any of the following implementation methods:

[0452] Implementation Method 1: The unified data management network element sends a fourth instruction message to the mobility management network element that provides services to the terminal device. This fourth instruction message is used to trigger the authentication process for the terminal device.

[0453] It should be understood that the aforementioned fourth instruction information can be carried in existing signaling or in newly added signaling.

[0454] For example, the fourth authentication instruction information can be carried in the Nudm_SDM_Notification message.

[0455] For example, the unified data management network element sending a fourth instruction message to the mobility management network element providing services to the terminal device can be specifically implemented as follows: the unified data management network element sends a deregistration request message to the mobility management network element. The deregistration request message is used to request deregistration of the terminal device. In this way, during the process of the terminal device re-registering with the network, the mobility management network element can perform an authentication process with the terminal device.

[0456] Implementation Method 2: The unified data management network element sends a fifth instruction message to the authentication service network element. This fifth instruction message instructs the authentication service network element to trigger the mobility management network element to initiate the authentication process for the terminal device.

[0457] In this way, after receiving the fifth instruction information, the authentication service network element can send the sixth instruction information to the mobility management network element to trigger the mobility management network element to initiate the authentication process for the terminal device.

[0458] It should be understood that the aforementioned fifth or sixth instruction information can be carried in existing signaling or in newly added signaling.

[0459] It should be understood that after the authentication process, the network side and the terminal device obtain the same intermediate key, so that the unified data management network element can send data according to the normal process (such as the SOR process or UPU process).

[0460] based on Figure 15 In the illustrated embodiment, for situations where data sent from the unified data management network element to the terminal device cannot be securely protected using an intermediate key, the unified data management network element triggers an authentication process, thereby causing the terminal device and the network side to synchronously update the intermediate key and related parameters (such as the SOR counter and / or UPU counter). Consequently, the data sent from the unified data management network element to the terminal device can be securely protected using a valid intermediate key, and the terminal device can also perform corresponding security verification on the protected data. This ensures normal communication between the unified data management network element and the terminal device.

[0461] The following example illustrates this. Figure 15 The specific implementation method of the illustrated embodiment.

[0462] Implementation Method 1

[0463] like Figure 16 As shown, Figure 15 Step S1001 can be specifically implemented as follows: Figure 16 Step S1101 in the process, Figure 15 Step S1002 shown can be specifically implemented as follows: Figure 16 Step S1102 in the process.

[0464] S1101. The unified data management network element cannot obtain the identifier of the authentication service network element involved in the terminal device authentication process.

[0465] Optionally, during the authentication process, the unified data management network element can establish and store the correspondence between the terminal device's identity identifier and the identifiers of the authentication service network elements involved in the terminal device's authentication process. For example, this correspondence can be stored in the format shown in Table 1.

[0466] Table 1

[0467] Terminal device terminal identity identifier Identifier of authentication service network element …… ……

[0468] It should be understood that each time a terminal device goes through an authentication process, the unified data management network element will update the correspondence between the terminal device's terminal identity identifier and the identifier of the authentication service network element to ensure the validity of this correspondence.

[0469] Therefore, when a unified data management network element is preparing to send data to a terminal device, it can look up the identifier of the corresponding authentication service network element based on the terminal device's identity identifier. If the unified data management network element cannot find the identifier of the corresponding authentication service network element, it determines that it cannot obtain the identifier of the authentication service network element involved in the terminal device's authentication process.

[0470] S1102, The unified data management network element triggers the authentication process for terminal devices.

[0471] based on Figure 16 In the illustrated embodiment, when the unified data management network element is unable to obtain the identifier of the authentication service network element involved in the authentication process of the terminal device, it promptly triggers the authentication process to ensure normal communication between the unified data management network element and the terminal device in subsequent processes.

[0472] It should be understood that Figure 16 The illustrated embodiment can solve the problems existing in the above scenario 1.

[0473] Implementation Method Two

[0474] like Figure 17 As shown, Figure 15 Step S1001 can be specifically implemented as follows: Figure 17 Steps S1201-S1202 in the process, Figure 15 Step S1002 can be specifically implemented as follows: Figure 17 Step S1203 in the process.

[0475] S1201, The unified data management network element sends a request message to the authentication service network element involved in the authentication process of the terminal device.

[0476] The request message includes the data.

[0477] For example, taking the SOR process as an example, the request message can be a Nausf_SoRProtection message, and the data in the request message can be a list of bootstrap information and an SOR header.

[0478] For example, taking the UPU process as an example, the request message can be a Nausf_UPUProctection message, and the data in the request message can be UPU data.

[0479] Optionally, the request message may also include confirmation information, which instructs the terminal device to return a confirmation message after successfully verifying the data security.

[0480] It should be understood that before executing step S1201, the unified data management network element can find the identifier of the authentication service network element involved in the authentication process of the terminal device based on the terminal identity identifier of the terminal device.

[0481] S1202, The unified data management network element receives the response message sent by the authentication service network element.

[0482] The response message indicates that the data security protection has failed.

[0483] Taking the SOR process as an example, the response message can be a Nausf_SoRProtection Response message.

[0484] Taking the UPU process as an example, the response message can be a Nausf_UPUProctection Response message.

[0485] In one possible design, the response message includes a second indication message that indicates the reason for the security protection failure.

[0486] For example, reasons for security protection failure may include: the intermediate key is missing, or the counter that is protecting the data is about to flip.

[0487] It should be understood that in the SOR process, the counter that protects the data mentioned above is the SOR counter. In the UPU process, the counter that protects the data mentioned above is the UPU counter.

[0488] S1203, the unified data management network element triggers the authentication process for the terminal device based on the response message.

[0489] based on Figure 17 In the embodiment shown, the unified data management network element can promptly trigger the authentication process based on the security protection failure reason returned by the authentication service network element, so as to ensure normal communication between the unified data management network element and the terminal device in the subsequent process.

[0490] It should be understood that Figure 17 The embodiments shown can solve the problems existing in scenario two above.

[0491] Implementation Method 3

[0492] like Figure 18 As shown, Figure 15 Step S1001 can be specifically implemented as follows: Figure 18 Steps S1301-S1304 in the process, Figure 15 Step S1002 can be specifically implemented as follows: Figure 18Step S1305 in the process.

[0493] S1301, The unified data management network element sends a request message to the authentication service network element involved in the authentication process of the terminal device.

[0494] The request message includes the data.

[0495] Optionally, the request message may also include confirmation information, which instructs the terminal device to return a confirmation message after successfully verifying the data security.

[0496] For example, taking the SOR process as an example, the request message can be a Nausf_SoRProtection message, and the data in the request message can be a list of bootstrap information and an SOR header.

[0497] For example, taking the UPU process as an example, the request message can be a Nausf_UPUProctection message, and the data in the request message can be UPU data.

[0498] S1302, The unified data management network element receives the response message sent by the authentication service network element.

[0499] The response message includes the values ​​of the first MAC and the first counter.

[0500] Optionally, if the request message also includes confirmation indication information, the response message may also include a second expected MAC.

[0501] For example, in the SOR process, the first MAC is SoR-MAC-I. AUSF The first counter is an SOR counter, and the second expected MAC is SoR-XMAC-I. UE The method for determining the above three parameters can be found by referring to... Figure 9 The SOR process described herein will not be repeated here.

[0502] For example, in the UPU process, the first MAC is UPU-MAC-I. AUSF The first counter is the UPU counter, and the second expected MAC is UPU-XMAC-I. UE The method for determining the above three parameters can be found by referring to... Figure 10 The UPU process described herein will not be repeated here.

[0503] S1303, The unified data management network element sends the first information to the terminal device.

[0504] The first information includes: data, the first MAC, and the value of the first counter.

[0505] As one possible implementation, the unified data management network element first sends the first information to the mobility management network element that provides services to the terminal device. Then, the mobility management network element sends the first information to the terminal device.

[0506] For example, in the SOR process, step S1303 can be specifically implemented as follows: Figure 9 Steps S404-S405 in the process.

[0507] For example, in the UPU process, step S1303 can be specifically implemented as follows: Figure 10 Steps S504-S505 in the process.

[0508] S1304. If the unified data management network element does not receive an acknowledgment message from the terminal device within a preset time, the unified data management network element determines that it cannot use the intermediate key generated during the terminal device authentication process to securely protect the data.

[0509] The duration of the aforementioned preset time can be configured by the unified data management system according to the instructions of the operation administration and maintenance (OAM) system, or configured by the unified data management network element according to the actual situation. This application embodiment does not limit this.

[0510] As one possible implementation, after sending the first information, the unified data management network element sets a timer for the terminal device. If the timer expires and the unified data management network element has not received an acknowledgment message from the terminal device, the unified data management network element determines that it cannot use the intermediate key generated during the terminal device's authentication process to securely protect the data.

[0511] It should be understood that the timer's duration is the same as the preset time mentioned above.

[0512] S1305. In response to the determined result, the unified data management network element triggers the authentication process for the terminal device.

[0513] based on Figure 18 In the illustrated embodiment, if the unified data management network element does not receive an acknowledgment message from the terminal device within a preset time, the unified data management network element can determine that the terminal device has failed to successfully perform security verification on the first information, and consequently, the unified data management network element can determine that the terminal device may not have stored a valid intermediate key. In this case, the unified data management network element promptly triggers an authentication process to ensure normal communication between the unified data management network element and the terminal device in subsequent processes.

[0514] It should be understood that Figure 18The illustrated embodiment can solve the problems existing in scenario three above.

[0515] Implementation Method 4

[0516] like Figure 19 As shown, Figure 15 Step S1001 can be specifically implemented as follows: Figure 19 Steps S1401-S1405 in the process, Figure 15 Step S1002 can be specifically implemented as follows: Figure 19 Step S1406 in the process.

[0517] S1401-S1403 are similar to steps S1301-S1403; for details, please refer to [link / reference]. Figure 18 The embodiments shown are not described in detail here.

[0518] S1404. The unified data management network element receives a confirmation message from the terminal device.

[0519] The confirmation message includes a second MAC address.

[0520] In the SOR process, the second MAC is SoR-MAC-I. UE Alternatively, in the UPU process, the second MAC address is UPU-MAC-I. UE .

[0521] For example, in the SOR process, step S1304 can be specifically implemented as follows: Figure 9 Steps S407-S408 in the process.

[0522] For example, in the UPU process, step S1304 can be specifically implemented as follows: Figure 9 Steps S507-S508 in the process.

[0523] After receiving the confirmation message, the unified data management network element can verify the confirmation message.

[0524] For example, the unified data management network element verifies the acknowledgment message by comparing the received second MAC address with the stored second expected MAC address. If the second MAC address matches the second expected MAC address, the verification of the acknowledgment message is successful. Otherwise, the verification of the acknowledgment message fails.

[0525] S1405. If the message verification fails, the unified data management network element determines that the intermediate key generated during the terminal device authentication process cannot be used to protect the data.

[0526] S1406. In response to the determined result, the unified data management network element triggers the authentication process for the terminal device.

[0527] based on Figure 19 In the illustrated embodiment, when the security verification of the confirmation message from the terminal device fails, the unified data management network element can know that the terminal device cannot successfully perform security verification on the first information, and thus the unified data management network element can know that the terminal device may not have stored a valid intermediate key. In this case, the unified data management network element promptly triggers the authentication process to ensure normal communication between the unified data management network element and the terminal device in subsequent processes.

[0528] It should be understood that Figure 19 The illustrated embodiment can solve the problems existing in scenario three above.

[0529] Implementation Method 5

[0530] like Figure 20 As shown, Figure 15 Step S1001 can be specifically implemented as follows: Figure 20 Steps S1501-S1505 in the process, Figure 15 Step S1002 can be specifically implemented as follows: Figure 20 Step S1506 in the process.

[0531] S1501-S1503 are similar to steps S1301-S1304; for details, please refer to [link / reference]. Figure 18 The embodiments shown are not described in detail here.

[0532] S1504. The unified data management network element receives a confirmation message from the terminal device.

[0533] The confirmation message includes a second MAC address.

[0534] In the SOR process, the second MAC is SoR-MAC-I. UE Alternatively, in the UPU process, the second MAC address is UPU-MAC-I. UE .

[0535] For example, in the SOR process, step S1304 can be specifically implemented as follows: Figure 9 Steps S407-S408 in the process.

[0536] For example, in the UPU process, step S1304 can be specifically implemented as follows: Figure 9 Steps S507-S508 in the process.

[0537] After receiving the confirmation message, the unified data management network element can verify the confirmation message.

[0538] For example, the unified data management network element verifies the acknowledgment message by comparing the received second MAC address with the stored second expected MAC address. If the second MAC address matches the second expected MAC address, the verification of the acknowledgment message is successful. Otherwise, the verification of the acknowledgment message fails.

[0539] Optionally, if the message verification is successful, the unified data management network element can perform the following step S1505.

[0540] In this embodiment of the application, the confirmation message includes third indication information. This third indication information is used to indicate the reason for the security verification failure.

[0541] For example, reasons for security verification failure may include: the intermediate key is missing, or the counter that secures the data is about to flip.

[0542] It should be understood that in the SOR process, the counter that protects the data is the SOR counter. In the UPU process, the counter that protects the data is the UPU counter.

[0543] S1505. The unified data management network element confirms, based on the third instruction information, that it is impossible to use the intermediate key generated during the terminal device authentication process to securely protect the data.

[0544] S1506. In response to the determined result, the unified data management network element triggers the authentication process for the terminal device.

[0545] based on Figure 20 In the embodiment shown, the unified data management network element can promptly trigger the authentication process based on the security verification failure reason returned by the terminal device, so as to ensure normal communication between the unified data management network element and the terminal device in subsequent processes.

[0546] It should be understood that Figure 20 The illustrated embodiment can solve the problems existing in scenario three above.

[0547] Currently, terminal devices first register in the 4G network, generating an Evolved Packet System (EPS) security context. Then, the terminal device switches from the 4G network to the 5G network. Based on the EPS security context, the 5G network derives a mapped 5G NAS security context and enables this mapped 5G NAS security context. During this process, because there is no AUSF (Automatic User Security Provider) in the 4G network, the UDM (User Device Manager) cannot store the AUSF identifiers involved in the terminal device authentication process. As a result, when the UDM needs to send data to the terminal device, it cannot determine which AUSF to request security protection for the data to be sent to the terminal device, thus affecting normal communication between the UDM and the terminal device.

[0548] To address this technical problem, embodiments of this application provide a communication method. For example... Figure 21 As shown, the communication method includes the following steps:

[0549] S1601, The mobility management network element receives a registration request message from the terminal device.

[0550] This registration request message is used to switch from a 4G network to a 5G network.

[0551] Optionally, switching from a 4G network to a 5G network can be described as switching from the S1 interface to the N1 interface.

[0552] In this embodiment of the application, the mobility management network element can be the AMF in a 5G network.

[0553] It should be understood that when the registration request message includes the seventh indication information, the mobility management network element can know that the terminal device has switched from a 4G network to a 5G network. The seventh indication information indicates that the network the terminal device previously accessed was a 4G network.

[0554] Optionally, when the EMM state in the UE status information element of the registration request message is set to EMM-REGISTERED, it indicates that the registration request message carries the seventh indication information.

[0555] The registration request message includes a key set identifier, which includes a security context type parameter.

[0556] The security context type parameter is used to indicate the type of security context.

[0557] Optionally, the security context type can be either native or mapped.

[0558] For example, the security context mentioned above is a 5G NAS security context.

[0559] S1602. When the type of the security context indicated by the security context type parameter is not native, the mobility management network element initiates the authentication process for the terminal device.

[0560] Specifically, the mobility management network element determines whether a native security context exists on the terminal device based on the security context type parameter. For example, if the registration request message includes ngKSI, and the type of ngKSI is mapped, and the registration request does not carry the information element "Non-currentnative NAS key setidentifier", then the mobility management network element determines that the terminal device does not have a native security context locally, thereby triggering the terminal's authentication process.

[0561] based on Figure 21 In the illustrated embodiment, when a terminal device switches from a 4G network to a 5G network, if the security context type indicated by the security context type parameter is not native, the mobility management network element (MLE) can determine that the terminal device has not undergone an authentication process in the 5G network. Therefore, the unified data management network element (UDL) does not store the identifiers of the authentication service network elements involved in the terminal device's authentication process. Consequently, the MLE initiates the terminal device's authentication process so that the UDL can store the identifiers of the authentication service network elements involved in the terminal device's authentication process, thereby ensuring normal communication between the UDL and the terminal device.

[0562] The foregoing mainly describes the solutions provided by the embodiments of this application from a methodological perspective. It is understood that, in order to achieve the above functions, the terminal includes the corresponding hardware structure and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the algorithm steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0563] This application embodiment can divide the terminal device, mobility management network element, and unified data management network element into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. The following description uses the example of dividing each function into a separate functional module:

[0564] like Figure 22 As shown, a communication device provided in an embodiment of this application is provided. The communication device includes a processing module 201 and a communication module 202.

[0565] In one example, the communication device is a terminal device, or a chip used in a terminal device. Processing module 201 is used to support the terminal device in performing... Figure 12 Steps S701, S702, and S704 in the process, Figure 13 Steps S801, S802, and S804 in the process, Figure 14 Steps S902-S905 in the process. Communication module 202 is used to support the terminal device in performing... Figure 12 Step S702 in the process, Figure 13 Step S803 in the process, Figure 14 Step S901 in the process.

[0566] In another example, the communication device is a unified data management network element, or a chip applied within a unified data management network element. Processing module 201 is used to support the unified data management network element in performing... Figure 15 Step S1001 in the process, Figure 16 Step S1101 in the process, Figure 18 Step S1304 in the process, Figure 19 Step S1405 in the process, Figure 20 Step S1505. The communication module 202 is used to support the unified data management network element in execution. Figure 15 Step S1002 in the process, Figure 17 Steps S1201-S1202 in the process, Figure 18 Steps S1301-S1303 in the process, Figure 19 Steps S1401-S1404 in the process, Figure 20 Steps S1501-S1504 in the process.

[0567] In another example, the communication device is a mobility management network element, or a chip applied within a mobility management network element. Processing module 201 is used to support the mobility management network element in performing [operations / functions]. Figure 21Step S1602. The communication module 202 is used to support the mobility management network element in performing... Figure 21 Step S1601 in the process.

[0568] Optionally, the communication device may also include a storage module 203 for storing the program code and data of the communication device, and the data may include, but is not limited to, raw data or intermediate data.

[0569] The processing module 201 can be a processor or controller, such as a CPU, general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, transistor logic device, hardware component, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor can also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0570] The communication module 202 may be a communication interface, transceiver, or transceiver circuit, etc. Here, "communication interface" is a general term. In a specific implementation, the communication interface may include multiple interfaces, such as the interface between the base station and the terminal equipment and / or other interfaces.

[0571] Storage module 203 can be a memory.

[0572] When the processing module 201 is a processor, the communication module 202 is a communication interface, and the storage module 203 is a memory, the communication device involved in the embodiments of this application can be... Figure 23 As shown.

[0573] See Figure 23 As shown, the communication device includes a processor 301, a communication interface 302, and a memory 303. Optionally, the communication device may also include a bus 304. The communication interface 302, processor 301, and memory 303 can be interconnected via the bus 304; the bus 304 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus 304 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 23 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0574] Optionally, embodiments of this application also provide a computer-readable storage medium having instructions stored thereon, which, when executed, perform the methods described in the above method embodiments.

[0575] Optionally, embodiments of this application also provide a computer program product containing instructions that, when executed, perform the methods described in the above method embodiments.

[0576] Optionally, this application embodiment further provides a chip, which includes a processor for implementing the technical methods of this application embodiment. In one possible design, the chip further includes a memory for storing necessary program instructions and / or data for the communication device of this application embodiment. In another possible design, the chip further includes a memory for the processor to call application code stored in the memory. This chip may be composed of one or more chips, or may include chips and other discrete devices; this application embodiment does not specifically limit this.

[0577] The steps of the methods or algorithms described in this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in RAM, flash memory, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, read-only optical discs (CD-ROMs), or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a core network interface device. Of course, the processor and storage medium can also exist as discrete components in the core network interface device. Alternatively, the memory can be coupled to the processor; for example, the memory can exist independently and be connected to the processor via a bus. The memory can also be integrated with the processor. The memory can be used to store application code that executes the technical solutions provided in the embodiments of this application, and its execution is controlled by the processor. The processor is used to execute application code stored in memory, thereby implementing the technical solutions provided in the embodiments of this application.

[0578] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0579] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0580] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0581] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0582] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0583] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A communication method, characterized in that, The method is applied to a terminal device configured with a Global Subscriber Identity Module (USIM) card or a Subscriber Identity Module (SIM) card, wherein the USIM or SIM card stores a key set identifier, and the method includes: When the terminal device needs to initiate the initial registration process, it determines whether a valid intermediate key exists. If no valid intermediate key exists, the terminal device deletes the key set identifier; The terminal device sends an initial registration request message to the mobility management network element. The initial registration request message does not carry the key set identifier to trigger the authentication process for the terminal device. The terminal device obtains authentication key information during the authentication process, and the authentication key information includes the valid intermediate key.

2. The method according to claim 1, characterized in that, The key set identifier is a key set identifier generated when the terminal device accesses the network through the first access technology; The terminal device sends an initial registration request message to the mobility management network element, including: The terminal device uses the first access technology to send the initial registration request message to the mobility management network element.

3. The method according to claim 1 or 2, characterized in that, The terminal device deletes the key set identifier, including: The terminal device sets the value of the key set identifier to a first value, which indicates "no key is available".

4. The method according to claim 3, characterized in that, The initial registration request message does not carry the key set identifier, and includes: The initial registration request message includes a first indication message, which indicates that no key is available.

5. The method according to claim 4, characterized in that, The terminal device is also equipped with non-volatile memory; The terminal device determines whether a valid intermediate key exists, including: The terminal device determines whether the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the USIM or SIM card are consistent; If the terminal identity identifier in the non-volatile memory matches the terminal identity identifier in the USIM or SIM card, the terminal device determines whether the valid intermediate key exists in the non-volatile memory and the USIM or SIM card; or, If the terminal identity identifier in the non-volatile memory is inconsistent with the terminal identity identifier in the USIM or SIM card, the terminal device determines whether the valid intermediate key exists in the USIM or SIM card.

6. The method according to claim 5, characterized in that, The authentication key information also includes: the value of the counter for the roaming guidance SOR, and / or the value of the counter for the user equipment parameter update UPU.

7. The method according to claim 6, characterized in that, The valid intermediate key includes Kausf.

8. The method according to claim 7, characterized in that, The key set identifier is the next-generation network key set identifier ngKSI.

9. The method according to claim 1 or 2, characterized in that, The initial registration request message does not carry the key set identifier, and includes: The initial registration request message includes a first indication message, which indicates that no key is available.

10. The method according to claim 9, characterized in that, The terminal device is also equipped with non-volatile memory; The terminal device determines whether a valid intermediate key exists, including: The terminal device determines whether the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the USIM or SIM card are consistent; If the terminal identity identifier in the non-volatile memory matches the terminal identity identifier in the USIM or SIM card, the terminal device determines whether the valid intermediate key exists in the non-volatile memory and the USIM or SIM card; or, If the terminal identity identifier in the non-volatile memory is inconsistent with the terminal identity identifier in the USIM or SIM card, the terminal device determines whether the valid intermediate key exists in the USIM or SIM card.

11. The method according to claim 10, characterized in that, The authentication key information also includes: the value of the counter for the roaming guidance SOR, and / or the value of the counter for the user equipment parameter update UPU.

12. The method according to claim 11, characterized in that, The valid intermediate key includes Kausf.

13. The method according to claim 12, characterized in that, The key set identifier is the next-generation network key set identifier ngKSI.

14. The method according to claim 1 or 2, characterized in that, The terminal device is also equipped with non-volatile memory; The terminal device determines whether a valid intermediate key exists, including: The terminal device determines whether the terminal identity identifier in the non-volatile memory and the terminal identity identifier in the USIM or SIM card are consistent; If the terminal identity identifier in the non-volatile memory matches the terminal identity identifier in the USIM or SIM card, the terminal device determines whether the valid intermediate key exists in the non-volatile memory and the USIM or SIM card; or, If the terminal identity identifier in the non-volatile memory is inconsistent with the terminal identity identifier in the USIM or SIM card, the terminal device determines whether the valid intermediate key exists in the USIM or SIM card.

15. The method according to claim 14, characterized in that, The authentication key information also includes: the value of the counter for the roaming guidance SOR, and / or the value of the counter for the user equipment parameter update UPU.

16. The method according to claim 15, characterized in that, The valid intermediate key includes Kausf.

17. The method according to claim 16, characterized in that, The key set identifier is the next-generation network key set identifier ngKSI.

18. The method according to claim 1 or 2, characterized in that, The authentication key information also includes: the value of the counter for the roaming guidance SOR, and / or the value of the counter for the user equipment parameter update UPU.

19. The method according to claim 18, characterized in that, The valid intermediate key includes Kausf.

20. The method according to claim 19, characterized in that, The key set identifier is the next-generation network key set identifier ngKSI.

21. The method according to claim 1 or 2, characterized in that, The valid intermediate key includes Kausf.

22. The method according to claim 21, characterized in that, The key set identifier is the next-generation network key set identifier ngKSI.

23. The method according to claim 1 or 2, characterized in that, The key set identifier is the next-generation network key set identifier ngKSI.

24. A communication device, characterized in that, Includes a module for performing the method described in any one of claims 1-23.

25. A communication device, characterized in that, Includes a processor for executing computer program instructions, causing the communication device to implement the communication method according to any one of claims 1 to 23.

26. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to implement the communication method according to any one of claims 1 to 23.

27. A computer program product containing computer instructions, characterized in that, When the computer program product is run on a computer, it causes the computer to implement the communication method according to any one of claims 1 to 23.