Key acquisition method and communication device
By sending identification and service codes between the remote terminal device and the relay terminal device, combining the shared key and freshness parameter to generate a root key, the problem of the remote terminal device and the relay terminal device being unable to share the key is solved, and secure device-to-device communication is achieved.
Patent Information
- Application Number
- CN202080106820.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-30
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2040-10-30
AI Technical Summary
In device-to-device communication, the remote terminal device and the relay terminal device cannot pre-configure shared security information, resulting in the inability to establish a secure connection.
The remote terminal device and the relay terminal device generate a root key by sending the first identification and relay service code in combination with the first shared key and the freshness parameter to achieve key sharing.
A secure connection is achieved between the remote terminal device and the relay terminal device, ensuring the encryption and integrity of data transmission.
Smart Images

Figure CN116458109B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a key acquisition method and a communication device. Background Art
[0002] With the rapid development of mobile communications, the widespread use of new data services such as video chat and virtual reality (VR) has increased user demand for bandwidth. Device-to-device (D2D) communication allows direct communication between devices, sharing spectrum resources with users in the cell under the control of the cell network, effectively improving spectrum resource utilization.
[0003] When the terminal device is out of network coverage or the communication signal between it and the radio access network (RAN) network element is poor, the remote terminal device (Remote UE) can perform auxiliary communication through the relay terminal device (Relay UE), that is, a PC5 connection is established between the remote terminal device and the relay terminal device, and the relay terminal device establishes a connection with the mobile network, thereby enabling the remote terminal device to establish a connection with the mobile network through the PC5 connection and the relay terminal device and obtain services.
[0004] During the indirect communication connection establishment process, to ensure communication security, a secure connection must be established between the remote terminal device and the relay terminal device. This means that the data transmitted between the remote terminal device and the relay terminal device is encrypted and / or integrity-protected. Because indirect communication connections are established dynamically on demand, it is impossible to pre-configure shared security information (such as keys) between the remote terminal device and the relay terminal device, and therefore it is impossible to establish a secure connection between the remote terminal device and the relay terminal device based on pre-configured shared security information. Summary of the Invention
[0005] The embodiments of the present application provide a key acquisition method and a communication device for sharing a key between a remote terminal device and a relay terminal device.
[0006] To achieve the above objectives, the embodiments of the present application adopt the following technical solutions:
[0007] In a first aspect, a key acquisition method is provided, including: a remote terminal device sends a first identifier and a relay service code to a relay terminal device, the first identifier being an identifier of the remote terminal device corresponding to the relay service code or the first identifier being an anonymous identifier of the remote terminal device; the remote terminal device generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter, the remote authentication service function network element being an authentication service function network element serving the remote terminal device, and the first shared key being a key shared by the remote terminal device and the remote authentication service function network element.
[0008] In the key acquisition method provided by the embodiment of the present application, a remote terminal device sends a first identifier and a relay service code to a relay terminal device, wherein the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device. The remote terminal device generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter. The first identifier is used by the remote AUSF network element to determine the corresponding first shared key, or is used by the PKMF network element to determine the corresponding second shared key, and the second shared key is also generated by the first shared key and / or the relay service code, so that the remote terminal device and the remote AUSF network element or PKMF network element can use the same method to generate the root key for communication between the remote terminal device and the relay terminal device, thereby realizing key sharing between the remote terminal device and the relay terminal device.
[0009] In a possible implementation, the first identifier is a subscription concealment identifier (SUCI) of the remote terminal device. The SUPI of the remote terminal device will not be exposed during air interface transmission.
[0010] In a possible implementation, the further step includes: the remote terminal device acquiring the first identifier.
[0011] In a possible implementation, the remote terminal device obtains the first identifier, including: the remote terminal device sends a relay service code; the remote terminal device receives the first identifier corresponding to the relay service code. The first identifier corresponding to the relay service code can be obtained from a remote AUSF network element.
[0012] In a possible implementation, the method further includes: the remote terminal device generates a temporary identifier based on the first shared key and the relay service code; and the remote terminal device obtains the first identifier based on the temporary identifier. This implementation discloses a method for generating the first identifier.
[0013] In one possible implementation, the remote terminal device generates a temporary identifier based on the first shared key and the relay service code, including: the remote terminal device generates the temporary identifier based on the first shared key, the relay service code, and the second freshness parameter. This implementation discloses a method for generating a temporary identifier.
[0014] In a possible implementation, the remote terminal device obtains the first identifier, including: the remote terminal device generates the first identifier according to the second freshness parameter, the routing indication, and the home network identifier. This implementation discloses a method for generating the first identifier.
[0015] In one possible implementation, the method further includes: the remote terminal device sending a relay service code; and the remote terminal device receiving a second freshness parameter corresponding to the relay service code. The second freshness parameter may come from a remote AUSF network element and be used to generate the first identifier. The second freshness parameter may be a random number generated by the remote AUSF network element or the value of a counter locally maintained by the remote AUSF network element.
[0016] In one possible implementation, the second freshness parameter is the value of a counter maintained locally by the remote terminal device. When the remote AUSF network element and the remote terminal device respectively maintain their respective counters locally, they use the same initial value and counting rule to keep the values of the two counters consistent.
[0017] In a possible implementation, the first identifier includes a routing indication and a home network identifier, so that the PKMF network element can determine the UDM network element or the remote AUSF network element through the routing indication and the home network identifier.
[0018] In one possible implementation, the method further includes: the remote terminal device sends first verification information to the relay terminal device, the first verification information being generated by a first temporary key and all or part of the information elements of a message carrying the first verification information, and the first temporary key being generated by a first shared key. The first verification information is used to be sent to a remote AUSF network element, and after receiving the first verification information, the remote AUSF network element generates third verification information in the same manner as the remote terminal device. The remote AUSF network element compares the first verification information and the third verification information to verify the remote terminal device and whether the remote terminal device is authorized to access the network and obtain services through the relay terminal device.
[0019] In one possible implementation, the first temporary key is generated using the relay service code, a third freshness parameter, at least one of the second identifier and the first identifier of the remote terminal device, and the first shared key, where the third freshness parameter is generated by the remote terminal device. This implementation discloses a method for generating the first temporary key.
[0020] In one possible implementation, the method further includes: the remote terminal device sending second verification information to the relay terminal device, where the second verification information is generated using the first freshness parameter, the relay service code, and the first shared key. The second verification information is sent to a PKMF network element. Upon receiving the second verification information, the PKMF network element generates fourth verification information in the same manner as the remote terminal device. The PKMF network element compares the second verification information with the fourth verification information to authenticate the remote terminal device and verify whether the remote terminal device is authorized to access the network and obtain services through the relay terminal device.
[0021] In a possible implementation, the at least one first freshness parameter includes a first random number, further comprising: the remote terminal device sending the first random number to the relay terminal device, and the first random number is sent to the remote AUSF network element or the PKMF network element.
[0022] In a possible implementation, the at least one first freshness parameter includes a second random number, and further includes: the remote terminal device receives the second random number from the relay terminal device. The second random number may come from a remote AUSF network element or a PKMF network element.
[0023] In one possible implementation, at least one first freshness parameter is a value of a counter maintained locally by the remote terminal device. When one of the remote AUSF network element or the PKMF network element and the terminal device maintain their respective counters locally, they use the same initial value and counting rule to keep the values of the two counters consistent.
[0024] In a possible implementation manner, the first shared key is a key Kausf (or another key generated from the key) negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0025] In one possible implementation, a remote terminal device generates a root key for communication between the remote terminal device and the relay terminal device based on a first shared key, a relay service code, and at least one first freshness parameter. The method includes: the remote terminal device generates a second shared key based on the first shared key and the relay service code; and generates a root key based on the second shared key and at least one first freshness parameter, where the second shared key is a key shared between the remote terminal device and a proximity service key management function network element. The remote terminal device and the PKMF network element generate the root key in the same manner.
[0026] In a second aspect, a key acquisition method is provided, including: a remote authentication service function network element obtains one of the first identifier or the second identifier of a remote terminal device, and a relay service code; the second identifier is a permanent identity identifier of the remote terminal device, and the first identifier is an identifier of the remote terminal device corresponding to the relay service code; the remote authentication service function network element obtains a first shared key corresponding to the first identifier or the second identifier; the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; the remote authentication service function network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter; the remote authentication service function network element sends the root key.
[0027] The key acquisition method provided in the embodiment of the present application is as follows: the remote AUSF network element obtains one of the first identifier or the second identifier of the remote terminal device, and the relay service code; the second identifier is the permanent identity identifier of the remote terminal device, and the first identifier is the identifier of the remote terminal device corresponding to the relay service code; the remote AUSF network element obtains the first shared key corresponding to the first identifier or the second identifier; the first shared key is the key shared by the remote terminal device and the remote AUSF network element; the remote AUSF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter; the remote AUSF sends the root key. The first identifier is used by the remote AUSF network element to determine the corresponding first shared key, so that the remote terminal device and the remote AUSF network element can use the same method to generate the root key for communication between the remote terminal device and the relay terminal device, thereby realizing key sharing between the remote terminal device and the relay terminal device.
[0028] In one possible implementation, the remote authentication service function network element obtains one of the first identifier or the second identifier of the remote terminal device, including: the remote authentication service function network element receives one of the first identifier or the second identifier of the remote terminal device. One of the first identifier or the second identifier of the remote terminal device may come from the remote terminal device or the PKMF network element.
[0029] In one possible implementation, a remote authentication service function network element obtains one of a first identifier or a second identifier of a remote terminal device, including: the remote authentication service function network element generating a temporary identifier based on a first shared key and a relay service code; and the remote authentication service function network element generating the first identifier based on the temporary identifier. This implementation discloses a method for generating the first identifier. After the first identifier is generated, it can be sent to the remote terminal device.
[0030] In one possible implementation, the remote authentication service function network element generates a temporary identifier based on the first shared key and the relay service code, including: the remote terminal device generates the temporary identifier based on the first shared key, the relay service code, and the second freshness parameter. This implementation discloses a method for generating a temporary identifier.
[0031] In one possible implementation, a remote authentication service function network element obtains one of a first identifier or a second identifier of a remote terminal device, including: the remote authentication service function network element generates the first identifier based on a second freshness parameter, a routing indication, and a home network identifier of the remote terminal device. This implementation discloses a method for generating the first identifier. After the first identifier is generated, it can be sent to the remote terminal device.
[0032] In one possible implementation, the second freshness parameter is the value of a counter maintained locally by the remote authentication service function network element. When the remote AUSF network element and the remote terminal device respectively maintain their respective counters locally, they use the same initial value and counting rule to keep the values of the two counters consistent.
[0033] In one possible implementation, the method further includes: the remote authentication service function network element receiving the relay service code; and the remote authentication service function network element sending a second freshness parameter. The second freshness parameter may be sent to the remote terminal device for generating the first identifier, and the second freshness parameter may be a random number generated by the remote AUSF network element or the value of a counter locally maintained by the remote AUSF network element.
[0034] In a possible implementation, the method further includes: the remote authentication service function network element receiving a relay service code; and the remote authentication service function network element sending a first identifier, wherein the relay service code comes from the remote terminal device and the first identifier is sent to the remote terminal device.
[0035] In a possible implementation, the first identifier includes a routing indication and a home network identifier, so that the PKMF network element can determine the UDM network element or the remote AUSF network element through the routing indication and the home network identifier.
[0036] In one possible implementation, the method further includes: the remote authentication service function network element receives the first authentication information; the remote authentication service function network element generates a first temporary key based on the first shared key; and obtains third authentication information based on the first temporary key and all or part of the information element of the message carrying the first authentication information; and the remote authentication service function network element compares the first authentication information with the third authentication information to authenticate the remote terminal device, that is, to verify whether the remote terminal device is authorized to access the network and obtain services through the relay terminal device.
[0037] In one possible implementation, the remote authentication service function network element generates the first temporary key based on the first shared key, including: the remote authentication service function network element generates the first temporary key based on at least one of the relay service code, the third freshness parameter, the second identifier, and the first identifier of the remote terminal device, and the first shared key, where the third freshness parameter is generated by the remote terminal device. This implementation discloses a method for generating the first temporary key.
[0038] In a possible implementation, the at least one first freshness parameter includes a first random number, and the further step includes: the remote authentication service function network element receives the first random number, and the first random number comes from the remote terminal device.
[0039] In a possible implementation, the at least one first freshness parameter includes a second random number, and further includes: the remote authentication service function network element sends the second random number to the remote terminal device.
[0040] In one possible implementation, at least one first freshness parameter is a value of a counter maintained locally by a remote authentication service function network element. When the remote AUSF network element and the remote terminal device respectively maintain their respective counters locally, they use the same initial value and counting rule to keep the values of the two counters consistent.
[0041] In a possible implementation, the further step includes: the remote authentication service function network element sending a first identifier to the unified data management network element. This is used for other network elements (e.g., PKMF network element) to obtain the remote AUSF network element instance identifier and / or the SUPI of the remote terminal device from the UDM network element. The remote AUSF network element instance identifier is used to determine the remote AUSF network element serving the remote terminal device.
[0042] In a possible implementation manner, the first shared key is the key Kausf (or other keys generated from the key) negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0043] On the third aspect, a key acquisition method is provided, including: a proximity service key management function network element receives a first identifier and a relay service code of a remote terminal device, the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; the proximity service key management function network element obtains a root key for communication between the remote terminal device and the relay terminal device based on the first identifier, the root key is generated by a first shared key, a relay service code, and at least one first freshness parameter, the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; the proximity service key management function network element sends the root key.
[0044] The key acquisition method provided by the embodiment of the present application is as follows: a PKMF network element receives a first identifier and a relay service code of a remote terminal device, wherein the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; the PKMF network element obtains a root key for communication between the remote terminal device and the relay terminal device based on the first identifier, wherein the root key is generated by a first shared key, a relay service code, and at least one first freshness parameter, and the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; the PKMF network element sends the root key. The first identifier is used by the PKMF network element to determine the corresponding second shared key, so that the remote terminal device and the PKMF network element can generate the root key for communication between the remote terminal device and the relay terminal device in the same manner, thereby realizing key sharing between the remote terminal device and the relay terminal device.
[0045] In one possible implementation, a proximity service key management function network element obtains a root key for communication between a remote terminal device and a relay terminal device based on a first identifier, including: the proximity service key management function network element sends the first identifier to a unified data management function network element; the proximity service key management function network element receives identification information of a remote authentication service function network element from the unified data management function network element; the proximity service key management function network element sends the first identifier to a corresponding remote authentication service function network element based on the identification information; and the proximity service key management function network element receives the root key from the remote authentication service function network element. This implementation discloses a method for a PKMF network element to obtain a root key.
[0046] In one possible implementation, a proximity service key management function network element obtains a root key for communication between a remote terminal device and a relay terminal device based on a first identifier, including: the proximity service key management function network element sends the first identifier to a unified data management function network element; the proximity service key management function network element receives identification information of a remote authentication service function network element and a permanent identity identifier of the remote terminal device from the unified data management function network element; the proximity service key management function network element sends the permanent identity identifier of the remote terminal device to a corresponding remote authentication service function network element based on the identifier information; and the proximity service key management function network element receives the root key from the remote authentication service function network element. This implementation discloses a method for a PKMF network element to obtain a root key.
[0047] In one possible implementation, a proximity service key management function network element obtains a root key for communication between a remote terminal device and a relay terminal device based on a first identifier, including: the proximity service key management function network element receives at least one second shared key from a remote authentication service function network element, where the second shared key is a key shared between the remote terminal device and the proximity service key management function network element, and the second shared key is generated from the first shared key and a relay service code; and the proximity service key management function network element generates a root key for communication between the remote terminal device and the relay terminal device based on the second shared key corresponding to the first identifier and at least one first freshness parameter. This implementation discloses a method for a PKMF network element to obtain a root key.
[0048] In one possible implementation, the method further includes: a proximity service key management function network element receiving the second verification information; the proximity service key management function network element generating fourth verification information based on the first freshness parameter and the second shared key; and the proximity service key management function network element comparing the second verification information with the fourth verification information to authenticate the remote terminal device, that is, to verify whether the remote terminal device is authorized to access the network and obtain services through the relay terminal device.
[0049] In a possible implementation, the at least one first freshness parameter includes a first random number, and further includes: the proximity service key management function network element receives the first random number. The first random number comes from a remote terminal device.
[0050] In a possible implementation, the at least one first freshness parameter includes a second random number, and further includes: the proximity service key management function network element sends the second random number, and the second random number is sent to the remote terminal device.
[0051] In one possible implementation, at least one first freshness parameter is a value of a counter maintained locally by a neighboring service key management function network element. When the PKMF network element and the remote terminal device respectively maintain their respective counters locally, they use the same initial value and counting rule to keep the values of the two counters consistent.
[0052] In a possible implementation manner, the first shared key is a key Kausf (or another key generated from the key) negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0053] In a fourth aspect, a communication device is provided, including a transceiver module and a processing module; the transceiver module is used to send a first identifier and a relay service code to a relay terminal device, the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; the processing module is used to generate a root key for communication between the remote terminal device and the relay terminal device based on a first shared key, the relay service code, and at least one first freshness parameter, the remote authentication service function network element is an authentication service function network element serving the remote terminal device, and the first shared key is a key shared by the remote terminal device and the remote authentication service function network element.
[0054] In a possible implementation manner, the first identifier is the SUCI of the remote terminal device.
[0055] In a possible implementation, the processing module and the transceiver module are further configured to obtain a first identifier.
[0056] In a possible implementation manner, the transceiver module is further configured to send a relay service code; and receive a first identifier corresponding to the relay service code.
[0057] In a possible implementation manner, the processing module is further configured to generate a temporary identifier according to the first shared key and the relay service code; and obtain the first identifier according to the temporary identifier.
[0058] In a possible implementation, the processing module is further configured to generate a temporary identifier according to the first shared key, the relay service code, and the second freshness parameter.
[0059] In a possible implementation, the processing module is further configured to generate the first identifier according to the second freshness parameter, the routing indication, and the home network identifier.
[0060] In a possible implementation manner, the transceiver module is further configured to send a relay service code; and receive a second freshness parameter corresponding to the relay service code.
[0061] In a possible implementation, the second freshness parameter is the value of a counter maintained locally by the remote terminal device.
[0062] In a possible implementation, the first identifier includes a routing indication and a home network identifier.
[0063] In one possible embodiment, the transceiver module is also used to send first verification information to the relay terminal device, the first verification information is generated by the first temporary key and all or part of the information elements of the message carrying the first verification information, and the first temporary key is generated by the first shared key.
[0064] In one possible implementation, the first temporary key is generated using the relay service code, a third freshness parameter, at least one of the second identifier and the first identifier of the remote terminal device, and the first shared key, where the third freshness parameter is generated by the remote terminal device. This implementation discloses a method for generating the first temporary key.
[0065] In a possible implementation, the transceiver module is further configured to send second verification information to the relay terminal device, where the second verification information is generated by the first freshness parameter, the relay service code, and the first shared key.
[0066] In a possible implementation, the at least one first freshness parameter includes a first random number, and the transceiver module is further configured to send the first random number to the relay terminal device. The first random number is sent to a remote AUSF network element or a PKMF network element.
[0067] In a possible implementation, at least one first freshness parameter includes a second random number, and the transceiver module is further configured to receive the second random number from the relay terminal device. The second random number may come from a remote AUSF network element or a PKMF network element.
[0068] In a possible implementation, the at least one first freshness parameter is a value of a counter maintained locally by the remote terminal device.
[0069] In a possible implementation manner, the first shared key is a key Kausf negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0070] In one possible embodiment, the processing module is also used to generate a second shared key based on the first shared key and the relay service code, and generate a root key based on the second shared key and at least one first freshness parameter, where the second shared key is a key shared by the remote terminal device and the adjacent service key management function network element.
[0071] In the fifth aspect, a communication device is provided, including a transceiver module and a processing module; the processing module is used to obtain one of the first identifier or the second identifier of the remote terminal device, and a relay service code; the second identifier is the permanent identity identifier of the remote terminal device, and the first identifier is the identifier of the remote terminal device corresponding to the relay service code; the processing module is also used to obtain a first shared key corresponding to the first identifier or the second identifier; the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; the remote authentication service function network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter; the transceiver module is used to send the root key.
[0072] In a possible implementation manner, the transceiver module is further configured to receive one of the first identifier or the second identifier of the remote terminal device.
[0073] In a possible implementation manner, the processing module is further configured to generate a temporary identifier based on the first shared key and the relay service code; and the remote authentication service function network element generates the first identifier based on the temporary identifier.
[0074] In a possible implementation, the processing module is further configured to generate a temporary identifier according to the first shared key, the relay service code, and the second freshness parameter.
[0075] In a possible implementation manner, the processing module is further configured to generate the first identifier according to the second freshness parameter, the routing indication, and the home network identifier of the remote terminal device.
[0076] In a possible implementation, the second freshness parameter is the value of a counter maintained locally by the remote authentication service function network element.
[0077] In a possible implementation, the transceiver module is further configured to receive a relay service code; and send a second freshness parameter.
[0078] In a possible implementation manner, the transceiver module is further configured to receive a relay service code; and send a first identifier.
[0079] In a possible implementation, the first identifier includes a routing indication and a home network identifier.
[0080] In one possible embodiment, the transceiver module is also used to receive first verification information; the processing module is also used to generate a first temporary key based on the first shared key; and obtain third verification information based on the first temporary key and all or part of the information elements of the message carrying the first verification information; compare the first verification information and the third verification information to verify the remote terminal device.
[0081] In one possible embodiment, the processing module is also used to generate a first temporary key based on the relay service code, the third freshness parameter, the second identifier and at least one of the first identifier of the remote terminal device, and the first shared key, and the third freshness parameter is generated for the remote terminal device.
[0082] In a possible implementation, the at least one first freshness parameter includes a first random number, and the transceiver module is further configured to receive the first random number.
[0083] In a possible implementation, at least one first freshness parameter includes a second random number, and the transceiver module is further configured to send the second random number.
[0084] In a possible implementation, the at least one first freshness parameter is a value of a counter maintained locally by the remote authentication service function network element.
[0085] In a possible implementation manner, the transceiver module is further configured to send the first identifier to the unified data management network element.
[0086] In a possible implementation manner, the first shared key is a key Kausf negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0087] In the sixth aspect, a communication device is provided, including a transceiver module and a processing module; the transceiver module is used to receive a first identifier and a relay service code of a remote terminal device, the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; the processing module is used to obtain a root key for communication between the remote terminal device and the relay terminal device based on the first identifier, the root key is generated by a first shared key, a relay service code, and at least one first freshness parameter, the first shared key being a key shared by the remote terminal device and the remote authentication service function network element; the transceiver module is also used to send the root key.
[0088] In one possible implementation, the transceiver module is also used to send a first identifier to a unified data management function network element; receive identification information of a remote authentication service function network element from the unified data management function network element; send a first identifier to a corresponding remote authentication service function network element based on the identification information; and receive a root key from the remote authentication service function network element.
[0089] In one possible implementation, the transceiver module is also used to send a first identifier to a unified data management function network element; receive identification information of a remote authentication service function network element and a permanent identity identifier of a remote terminal device from the unified data management function network element; send the permanent identity identifier of the remote terminal device to a corresponding remote authentication service function network element based on the identification information; and receive a root key from the remote authentication service function network element.
[0090] In one possible embodiment, the transceiver module is also used to receive at least one second shared key from a remote authentication service function network element, where the second shared key is a key shared by the remote terminal device and the adjacent service key management function network element, and the second shared key is generated by the first shared key and the relay service code; the processing module is also used to generate a root key for communication between the remote terminal device and the relay terminal device based on the second shared key corresponding to the first identifier, and at least one first freshness parameter.
[0091] In a possible implementation, it further includes: the transceiver module is further used to receive second verification information; the processing module is further used to generate fourth verification information based on the first freshness parameter and the second shared key; and the second verification information and the fourth verification secret information are compared to verify the remote terminal device.
[0092] In a possible implementation, the at least one first freshness parameter includes a first random number, and the transceiver module is further configured to receive the first random number.
[0093] In a possible implementation, at least one first freshness parameter includes a second random number, and the transceiver module is further configured to send the second random number.
[0094] In a possible implementation manner, the at least one first freshness parameter is a value of a counter locally maintained by a neighboring service key management function network element.
[0095] In a possible implementation manner, the first shared key is a key Kausf negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0096] In the seventh aspect, a communication device is provided, comprising a processor connected to a memory, the memory being used to store a computer program, and the processor being used to execute the computer program stored in the memory, so that the communication device executes the method of the first aspect and any one of its embodiments.
[0097] In an eighth aspect, a communication device is provided, comprising a processor connected to a memory, the memory being used to store a computer program, and the processor being used to execute the computer program stored in the memory so that the communication device executes the method described in the second aspect and any one of its embodiments.
[0098] In the ninth aspect, a communication device is provided, comprising a processor connected to a memory, the memory being used to store a computer program, and the processor being used to execute the computer program stored in the memory, so that the communication device executes the method described in the third aspect and any one of its embodiments.
[0099] In a tenth aspect, a computer-readable storage medium is provided, in which a computer program is stored. When the computer-readable storage medium is run on a computer, the computer executes the method described in the first aspect and any one of its embodiments.
[0100] In the eleventh aspect, a computer-readable storage medium is provided, in which a computer program is stored. When the computer-readable storage medium is run on a computer, the computer executes the method described in the second aspect and any one of its embodiments.
[0101] In the twelfth aspect, a computer-readable storage medium is provided, in which a computer program is stored. When the computer-readable storage medium is run on a computer, the computer executes the method described in the third aspect and any one of its embodiments.
[0102] In a thirteenth aspect, a computer program product comprising instructions is provided, which, when the instructions are executed on a computer or a processor, enables the computer or the processor to execute the method as described in the first aspect and any one of the embodiments.
[0103] In a fourteenth aspect, a computer program product comprising instructions is provided, which, when the instructions are executed on a computer or a processor, enables the computer or the processor to execute the method as described in the second aspect and any one of its embodiments.
[0104] In a fifteenth aspect, a computer program product comprising instructions is provided, which, when the instructions are executed on a computer or a processor, enables the computer or the processor to execute the method as described in the third aspect and any one of its embodiments.
[0105] In the sixteenth aspect, a communication system is provided, comprising the communication device as described in the fourth aspect and any one of the items, the communication device as described in the fifth aspect and any one of the items, and the communication device as described in the sixth aspect and any one of the items; or, comprising the communication device as described in the seventh aspect, the communication device as described in the eighth aspect and any one of the items, and the communication device as described in the ninth aspect and any one of the items.
[0106] The technical effects of the fourth to sixteenth aspects refer to the contents of the first to third aspects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0107] Figure 1 A schematic diagram of the architecture of a communication system provided in an embodiment of the present application;
[0108] Figure 2 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 1 ;
[0109] Figure 3 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 2 ;
[0110] Figure 4 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 3 ;
[0111] Figure 5 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 4 ;
[0112] Figure 6 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 5 ;
[0113] Figure 7 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 6 ;
[0114] Figure 8 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 7 ;
[0115] Figure 9 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 8 ;
[0116] Figure 10 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 9 ;
[0117] Figure 11 A schematic diagram of a key acquisition method provided in an embodiment of the present application Figure 10 ;
[0118] Figure 12 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 1 ;
[0119] Figure 13 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 2 ;
[0120] Figure 14 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 3 ;
[0121] Figure 15 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 4 ;
[0122] Figure 16 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 5 ;
[0123] Figure 17 A schematic diagram of the structure of a communication device provided in an embodiment of the present application Figure 6 . DETAILED DESCRIPTION
[0124] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0125] In the embodiment of the present application, “ / ” indicates that the two symbols before and after it are in an “or” relationship.
[0126] The embodiments of the present application can be applied to both time division duplexing (TDD) scenarios and frequency division duplexing (FDD) scenarios without limitation.
[0127] The embodiments of the present application are described based on the scenario of a 5G network in a wireless communication network. It should be noted that the solutions in the embodiments of the present application can also be applied to other wireless communication networks, and the corresponding names can also be replaced by the names of corresponding functions in other wireless communication networks.
[0128] Figure 1A 5G communication system architecture is provided, including an access network and a core network. The access network is used to implement functions related to wireless access, and includes 3GPP access networks and non-3GPP access networks. The communication system includes: a terminal device 101, a (radio) access network (R)AN) network element 102, a user plane function (UPF) network element 103, a data network (DN) 104, an access and mobility management function (AMF) network element 105, a session management function (SMF) network element 106, a policy control function (PCF) network element 107, a unified data management (UDM) network element 108, an application function (AF) network element 109, an authentication server function (AUSF) network element 110, a network slice selection function (NSSF) network element 111, a network exposure function (NEF) network element 112, a network function repository function (NRF) network element 113, a network slice specific authentication and authorization function (NSSF) network element 114, a network slice specific authentication and authorization function (NSSF) network element 115, a network slice specific authentication and authorization function (NSSF) network element 116, a network slice specific authentication and authorization function (NSSF) network element 117, a network exposure function (NEF) network element 118, a network function repository function (NRF) network element 119, a network slice specific authentication and authorization function (NSSF) network element 120, a network slice specific authentication and authorization function (NSSF) network element 121, a network exposure function (NEF) network element 122, a network function repository function (NRF) network element 123, a network slice specific authentication and authorization function (NSSF) network element 124, a network slice specific authentication and authorization function (NSSF) network element 125, a network slice specific authentication and authorization function (NSSF) network element 126, a network function, NSSAAF) 114 and service communication proxy (SCP) 115.
[0129] It should be noted that Figure 1The interface names between the various network elements in the protocol are only examples. In specific implementations, the interface names may be other names without limitation. For example, the interface between the terminal device 101 and the AMF network element 105 may be the N1 interface, the interface between the (R)AN network element 102 and the AMF network element 105 may be the N2 interface, the interface between the (R)AN network element 102 and the UPF network element 103 may be the N3 interface, the interface between the UPF network element 103 and the SMF network element 106 may be the N4 interface, and the interface between the UPF network element 103 and the DN 104 may be the N6 interface. The AMF network element 105 provides a service interface Namf to the network, the SMF network element 106 provides a service interface Nsmf to the network, the PCF network element 107 provides a service interface Npcf to the network, the UDM network element 108 provides a service interface Nudm to the network, the AF network element provides a service interface Naf to the network, the AUSF network element 110 provides a service interface Nausf to the network, the NSSF network element 111 provides a service interface Nnssf to the network, the NEF network element 112 provides a service interface Nnef to the network, the NRF network element 113 provides a service interface Nnrf to the network, and the NSSAAF network element 114 provides a service interface Nnssaaf to the network.
[0130] The terminal device 101 and the (R)AN network element 102 communicate with each other using a certain air interface technology. The terminal device 101 may include various handheld devices with wireless communication functions, vehicle-mounted devices, wearable devices, computing devices, or other processing devices connected to a wireless modem; it may also include a subscriber unit, a cellular phone, a smart phone, a wireless data card, a personal digital assistant (PDA), a tablet computer, a wireless modem, a handheld device, a laptop computer, a cordless phone, or a wireless local loop (WLL) station, a machine type communication (MTC) terminal, a user equipment (UE), a mobile station (MS), a terminal device, or a relay user device. Among them, the relay user device may be a 5G residential gateway (RG). For the convenience of description, the above-mentioned devices may be collectively referred to as terminal devices.
[0131] In the embodiment of the present application, a remote terminal device (remote UE) can access the 3GPP network through a relay terminal device (relay UE) and communicate indirectly with the network device and the application server.
[0132] (R)AN network element 102 provides wireless access for terminal device 101 and includes RAN network elements and AN network elements. RAN network elements are primarily 3GPP network wireless network devices, while AN network elements can be non-3GPP access network devices. This application uses RAN network elements as an example, but is not intended to be limiting.
[0133] The RAN network element is primarily responsible for radio resource management, quality of service (QoS) management, data compression, and encryption on the air interface side. It can include various forms of base stations, such as macro base stations, micro base stations (also known as small stations), relay stations, and access points. In systems using different wireless access technologies, the names of devices with base station functions may vary. For example, in fifth-generation (5G) communication systems, they are called RAN network elements or gNBs (5G NodeBs); in long-term evolution (LTE) systems, they are called evolved NodeBs (eNBs or eNodeBs); and in third-generation (3G) communication systems, they are called NodeBs.
[0134] AN network elements allow terminal devices and the 3GPP core network to interconnect and communicate using non-3GPP technologies, including wireless fidelity (Wi-Fi), worldwide interoperability for microwave access (WiMAX), and code division multiple access (CDMA) networks.
[0135] The UPF network element 103 is primarily responsible for user message processing, including forwarding and billing. It receives user data from the data network and transmits it to the terminal device via the RAN network element. The UPF network element also receives user data from the terminal device via the RAN network element and forwards it to the DN. The transmission resources and scheduling functions provided by the UPF network element to the terminal device are managed and controlled by the SMF network element.
[0136] DN 104 is a network that provides data transmission services to users, such as IP Multimedia Service (IMS) and the Internet. Terminal device 101 accesses DN 104 by establishing a protocol data unit (PDU) session between the terminal device, RAN network element 102, UPF network element 103, and DN 104. The user plane path is from the terminal device to the (R)AN network element, to the UPF network element, and then to the DN.
[0137] The AMF network element 105 is mainly responsible for mobility management in the mobile network, such as user location update, user network registration, user switching, etc.
[0138] The SMF network element 106 is primarily responsible for session management in the mobile network, such as session establishment, modification, and release. For example, specific functions include allocating IP addresses to users and selecting UPF network elements that provide packet forwarding functions.
[0139] The PCF network element 107 provides a unified policy framework to control network behavior and provides policy rules to the control layer network functions, such as QoS policy, slice selection policy, etc. It is also responsible for obtaining user subscription information related to policy decisions.
[0140] The UDM network element 108 is used to generate authentication credentials, user identification processing (such as storing and managing user permanent identities, etc.), access authorization control and contract data management, etc.
[0141] The AF network element 109 may also be referred to as a server, which is responsible for interacting with the 3GPP core network to provide services, such as influencing data routing decisions, policy control functions, or providing some third-party services to the network side.
[0142] The AUSF network element 110 is used to authenticate and authorize users.
[0143] NSSF network element 111 is used to centrally manage slicing functions.
[0144] The NEF network element 112 is responsible for isolating the internal and external networks and is used to support the opening of capabilities and events, including open monitoring capabilities, policy / billing capabilities, and analysis and reporting capabilities.
[0145] The NRF network element 113 is responsible for maintaining the context of available network function instances and the services supported by the network functions, which are used by other network function network elements for service discovery or network function network element discovery.
[0146] The NSSAAF network element 114 is used to support network slice-specific authentication and authorization processes and can communicate with an AAA (authentication, authorization and accounting) server or AAA agent.
[0147] The SCP network element 115 is used to support indirect communication, proxy discovery, and sending routing messages to a target network function network element or a next-hop SCP.
[0148] In the research on Proximity-based Services (ProSe), in order to support Proximity-based services communications, the 5G Direct Discovery Name Management Function (DDNMF) network element was introduced to allocate and process Proximity-based services (ProSe) application identifiers and Proximity-based service code mappings.
[0149] like Figure 2 As shown, in the indirect communication in the 5G communication system, the indirect communication connection establishment process based on layer 3 (for IP type PDU session, the relay terminal device forwards data based on the IP address) includes:
[0150] S201. The remote terminal device and the relay terminal device register with the network respectively and obtain authorization information from the network side.
[0151] For remote terminal devices, the obtained authorization information includes:
[0152] Indication information, used to indicate whether to authorize access to 5GC through the relay terminal device.
[0153] Parameters used for ProSe Relay Discovery, which are used to enable connection establishment with relay terminal devices, including, for example, relay service code, PDU session parameters (such as data network name (DNN), single network slice selection assistance information (S-NSSAI), access type preference, PDU session type, session and service continuity mode).
[0154] Security-related content for ProSe Relay Discovery based on the relay service code.
[0155] For relay terminal devices, the obtained authorization information includes:
[0156] The authorization policy for the relay terminal device includes authorizing the public land mobile network (PLMN) to provide relay services to the remote terminal device.
[0157] Parameters used for ProSe Relay Discovery, including: indication information used to indicate authorization to act as a relay between the UE and the network (UE-to-Network relay); relay service code, PDU session parameters (such as DNN, S-NSSAI, access type preference, PDU session type, session and service continuity mode).
[0158] Security-related content for ProSe Relay Discovery based on the relay service code.
[0159] S202: The relay terminal device establishes a PDU session.
[0160] The session can be a PDU session specifically serving remote terminal devices; for IP type PDU sessions, the network side SMF network element allocates an IP address for the PDU session (which can be an IPv4 address or IPv6 prefix, etc.), and the relay terminal device uses the PDU session to transmit data to the remote terminal device.
[0161] This step is optional.
[0162] S203: The remote terminal device discovers the relay terminal device through the relay discovery process.
[0163] S204: The remote terminal device establishes a PC5 communication link with the relay terminal device.
[0164] If the PDU session already established by the relay terminal device cannot meet the session requirements of the remote terminal device (such as DNN, S-NSSAI, etc.), the relay terminal device will establish a new PDU session for the remote terminal device, and this PDU session will be used to transmit data between the remote terminal device and the application server. Alternatively, if the relay terminal device has not established a PDU session for transmitting the services of the remote terminal device, a new PDU session will be established, and this PDU session will be used to transmit data between the remote terminal device and the application server.
[0165] S205: The relay terminal device allocates an IP address for PC5 communication to the remote terminal device.
[0166] S206. The relay terminal device sends the ID and IP information (IP info) of the remote terminal device to the AMF network element and the SMF network element.
[0167] The IP information is the address allocated by the relay terminal device to the remote terminal device for network-side communication.
[0168] This step can be performed through the PDU session modification process. For example, if the SMF network element assigns an IPv4 IP address to the relay terminal device, the IP information is represented as a specific port number (TCP / UDP port), which means that the relay terminal device uses the IPv4 address and the specific port number to transmit data from the remote terminal device. If the SMF network element assigns an IPv6 prefix to the relay terminal device, the IP information is represented as a longer IPv6 prefix, which means that the relay terminal device uses the longer IPv6 prefix to transmit data from the remote terminal device.
[0169] S207: The relay terminal device forwards the uplink and downlink data of the remote terminal device according to the IP address.
[0170] For example, the remote terminal device uses IP3 on the PC5 communication link, the relay terminal device's PDU session corresponds to IP1, and the relay terminal device assigns IP info to the remote terminal device as IP1-1. The remote terminal device then uses IP3 to transmit data to the server, and the server uses IP1-1 to transmit data to the remote terminal device. The relay terminal device then binds the association between IP3 and IP1-1.
[0171] In the downstream direction, the relay terminal device receives the IP1-1 data packet from the UPF network element, learns that the data is for the remote terminal, and then modifies the IP address to IP3 and sends it to the remote terminal device through the PC5 link.
[0172] In the uplink direction, after the relay terminal device receives the IP3 data packet, it modifies the IP address to IP1-1, sends it to the UPF network element through the PDU session, and then sends it to the server.
[0173] During the aforementioned indirect communication connection establishment process, to ensure communication security, a secure connection needs to be established between the remote terminal device and the relay terminal device. This means that the data transmitted between the remote terminal device and the relay terminal device is encrypted and / or integrity protected. Because indirect communication connections are established dynamically on demand, it is impossible to pre-configure shared security information (e.g., a key) between the remote terminal device and the relay terminal device to establish a secure connection between the remote terminal device and the relay terminal device based on the pre-configured shared security information. Therefore, it is necessary to dynamically establish shared security information (e.g., a key) between the remote terminal device and the relay terminal device.
[0174] The present invention provides a method for obtaining a key. Figure 3Shown, including:
[0175] S301. A remote terminal device accesses a 3GPP network and obtains relay discovery and key materials. A relay terminal device accesses a 3GPP network and obtains discovery and key materials.
[0176] S302. The remote terminal device sends a key request to the AUSF network element through the AMF network element.
[0177] The key request includes a proximity service remote access indication, a 5G globally unique temporary identity (GUTI) or a subscription concealed identifier (SUCI).
[0178] S303. The AUSF network element sends an authentication request to the UDM network element.
[0179] The authentication request includes the proximity service remote access indication, 5G-GUTI or SUCI.
[0180] S304. The UDM network element sends an authentication response to the AUSF network element.
[0181] The authentication response includes the user's subscription permanent identifier (SUPI).
[0182] S305. The AUSF network element uses the latest key (Kausf) shared between the remote terminal device and the AUSF network element to generate a root key (REAR Key).
[0183] S306. The AUSF network element sends a key response to the remote terminal device.
[0184] The key response includes the root key and the identifier of the relay terminal device.
[0185] S307: The remote terminal device discovers the relay terminal device.
[0186] S308: The remote terminal device sends a direct communication request to the relay terminal device.
[0187] The direct communication request includes a relay service code, a 5G-GUTI and a message authentication code (MAC).
[0188] S309. The relay terminal device sends a key request to the AUSF network element.
[0189] The key request includes the relay service code, 5G-GUTI and MAC.
[0190] S310. The AUSF network element performs authentication and authorization checks.
[0191] S311, after authorization, the AUSF network element generates the key K of the remote terminal device NR_ProSe .
[0192] K NR_ProSe = KDF (root key REAR key, 5G-GUTI, relay service code or service identifier, freshness parameter, other possible parameters). The key derivation function (KDF) is an algorithm for generating a key.
[0193] S312. The AUSF network element sends a key response to the relay terminal device.
[0194] The key response includes KNR_ProSe and freshness parameters.
[0195] S313: The relay terminal device sends a direct security mode command to the remote terminal device.
[0196] The direct security mode command includes generating K NR_ProSe Freshness parameter.
[0197] S314: The remote terminal device generates a key K according to the direct security mode command. NR_ProSe .
[0198] S315. The remote terminal device sends a direct security mode command completion message to the relay terminal device according to the direct security mode command.
[0199] In this solution, the identity of the relay terminal device is used in the key derivation process. However, since there are one or more terminal devices that can provide relay services, the network cannot obtain the identity of the terminal device providing the relay service before the remote terminal device discovers the relay terminal device, and therefore cannot deduce the corresponding key. In addition, it is not defined how the AUSF network element from which the key is deduced is determined, nor is it defined how the relay terminal device discovers the AUSF network element from which the remote terminal device derives the key. If the relay terminal device arbitrarily selects an AUSF network element, and if the AUSF network element does not store the key obtained by the remote terminal device, the MAC generated by the remote terminal device cannot be verified.
[0200] The present invention provides a method for obtaining a key. Figure 4 Shown, including:
[0201] S401: The remote terminal device and the relay terminal device respectively obtain discovery key materials.
[0202] Specifically, they include:
[0203] The remote terminal device interacts with a Proximity Service (ProSe) function network element to obtain relay discovery parameters and an address of a Proximity Service Key Management Function (PKMF) network element.
[0204] The remote terminal device obtains the discovery key material from the relayed PKMF network element.
[0205] The relay terminal device interacts with the Proximity Services (ProSe) function network element to obtain relay discovery parameters and the address of the PKMF network element.
[0206] The relay terminal device obtains the network element discovery key material from the PKMF.
[0207] S402: The remote terminal device sends a key request to the PKMF network element.
[0208] The key request includes instruction information for requesting a relay communication key and optionally includes a key identifier of a previously obtained key, namely a ProSe relay user key (PRUK) ID.
[0209] Correspondingly, the PKMF network element sends a response message to the remote terminal device, where the response message includes the PRUK and the corresponding PRUK Id.
[0210] S403: The remote terminal device discovers the relay terminal device.
[0211] S404: The remote terminal device sends a direct communication request to the relay terminal device.
[0212] The direct communication request includes one of a PRUK ID or an international mobile subscriber identity (IMSI), and a relay service code.
[0213] S405: The relay terminal device sends a key request to the PKMF network element.
[0214] The key request includes one of the PRUK ID or the IMSI, a relay service code, and a first random number.
[0215] S406. The PKMF network element identifies the terminal device according to the PRUK ID or IMSI and performs an authorization check.
[0216] After the authorization check passes, the PKMF network element determines whether the remote terminal device requires a new PRUK. If so, the PKMF network element interacts with the home subscriber server (HSS) network element to obtain the user's generic bootstrapping information (GPI) (generic bootstrapping architecture (GBA) Push Info, GBA Push Information) or authentication vector.
[0217] S407. The PKMF network element sends a key response to the relay terminal device.
[0218] The key response includes the key Kd, the random number used to generate the key Kd, the GPI, and the remote terminal device identifier.
[0219] S408: The relay terminal device sends a direct security mode command to the remote terminal device.
[0220] The direct security mode command includes a random number for generating a key Kd and GPI.
[0221] Accordingly, the remote terminal device sends a direct security mode completion to the relay terminal device.
[0222] This solution is based on the 4G communication system, and the key derivation is based on the GBA mechanism. Currently, 5G does not support the GBA mechanism. When communicating with the relay terminal device, the remote terminal device may use the user's permanent identity (IMSI), which may cause the user's privacy to be leaked.
[0223] To this end, embodiments of the present application provide another key acquisition method. On the one hand, by using a shared key established between a remote terminal device and the 3GPP network, the remote terminal device and the relay terminal device establish a root key for communication. On the other hand, by using the remote terminal device's temporary identifier or anonymous identifier (SUCI) to obtain the root key, the relay terminal device can obtain the root key used to establish PC5 interface security while ensuring user privacy.
[0224] In the embodiment of the present application, the remote AUSF network element refers to the AUSF network element serving the remote terminal device, and the remote AUSF network element stores a key shared with the remote terminal device. The relay AUSF network element refers to the AUSF network element serving the relay terminal device. The remote AMF network element refers to the AMF network element serving the remote terminal device, and the relay AMF network element refers to the AMF network element serving the relay terminal device. The remote PCF network element refers to the PCF network element serving the remote terminal device, and the relay PCF network element refers to the PCF network element serving the relay terminal device. The remote NRF network element refers to the NRF network element serving the remote terminal device. The remote UDM network element refers to the UDM network element serving the remote terminal device.
[0225] In the embodiments of the present application, unless otherwise specified, generating an identifier, a key, or verification information based on parameter A refers to inputting parameter A into an algorithm (e.g., a key derivation function (KDF)) to calculate and obtain the identifier, key, or verification information.
[0226] The PKMF network element is a new functional module that can be deployed independently or in conjunction with other functional network elements. The PKMF network element is used to manage the security information of adjacent services, such as obtaining the shared key between the remote terminal device and the relay terminal device and performing authorization checks.
[0227] like Figure 5 As shown, the key acquisition method on the terminal side includes:
[0228] S501: The remote terminal device sends a first identifier of the remote terminal device and a relay service code to the relay terminal device.
[0229] Optionally, the remote terminal device sends first verification information to the relay terminal device.
[0230] Optionally, the remote terminal device sends second verification information to the relay terminal device.
[0231] The above information can be carried in the same message (such as direct communication request) or different messages, and finally forwarded by the relay terminal device to the remote AUSF network element, relay AUSF network element or PKMF network element.
[0232] The following is an explanation of the information involved:
[0233] Relay service code
[0234] Used to identify a connection service that provides a relay with a connection to an application. The same terminal device can be configured with different relay service codes to access different applications or services.
[0235] First logo
[0236] The first identifier can be an identifier of the remote terminal device corresponding to the relay service code (e.g., P-KID) (e.g., in the format of Username@realm), or the first identifier can be an anonymous identifier of the remote terminal device (e.g., SUCI), so that the permanent identity identifier of the remote terminal device (e.g., SUPI) is not exposed during air interface transmission. The first identifier can correspond one-to-one with the relay service code, that is, the remote terminal device can use different first identifiers for communication for different relay service codes.
[0237] Since the AUSF network element or PKMF network element can serve multiple terminal devices, the first identifier of the remote terminal device is used by the AUSF network element or PKMF network element to determine the corresponding remote terminal device, thereby determining the corresponding first shared key, or determining other identifiers of the remote terminal device (such as SUPI). The first shared key is a key shared by the remote terminal device and the remote AUSF network element (or other keys generated by the key). The first shared key can be Kausf, which is negotiated and shared in advance with the remote AUSF network element when the remote terminal device accesses the network. Alternatively, the first shared key can be a key for proximity service communication further deduced based on Kausf.
[0238] If the first identifier is an identifier of the remote terminal device corresponding to the relay service code, the remote terminal device may obtain the first identifier in the following ways:
[0239] Method 1: The remote terminal device can send at least one relay service code to the remote authentication service function network element through the remote AMF network element; the remote AUSF network element generates a first identifier corresponding to the relay service code, and sends the first identifier to the remote terminal device through the remote AMF network element; accordingly, the remote terminal device receives the first identifier corresponding to the relay service code from the remote authentication service function network element.
[0240] Method 2: The remote terminal device generates a temporary identifier according to the first shared key (eg Kausf) and the relay service code, and then obtains the first identifier according to the temporary identifier.
[0241] The remote terminal device generates a temporary identifier according to the first shared key (e.g., Kausf) and the relay service code in the following manner:
[0242] In a possible implementation, a first shared key (eg, Kausf) and a relay service code are input into an algorithm (eg, a key derivation function (KDF)) to calculate and obtain a temporary identifier.
[0243] Optionally, the remote terminal device may further generate a temporary identifier based on at least one of the second freshness parameter, the remote terminal device's SUPI, the first shared key (e.g., Kausf), and the relay service code. That is, the input parameters for calculating the temporary identifier may further include the second freshness parameter or other parameters (e.g., the remote terminal device's SUPI, etc.).
[0244] Alternatively, in another possible implementation, the remote terminal device generates a proximity service root key based on the first shared key, and then generates a temporary identifier based on the proximity service root key and the relay service code.
[0245] For example, the remote terminal device first derives a proximate service root key based on the first shared key (e.g., Kausf). Optionally, the input parameters of the algorithm for generating the proximate service root key may include the string "ProSe" and the remote terminal device's SUPI. The remote terminal device then uses the proximate service root key and the relay service code as inputs to a KDF to generate a temporary identifier.
[0246] Optionally, the remote terminal device may further generate a temporary identifier based on at least one of the second freshness parameter, the SUPI of the remote terminal device, the proximity service root key, and the relay service code. That is, the input parameters for calculating the temporary identifier may further include the second freshness parameter or other parameters (e.g., the SUPI of the remote terminal device). That is, the manner in which the remote terminal device obtains the first identifier based on the temporary identifier includes:
[0247] In one possible implementation, the remote terminal device generates a first identifier based on the temporary identifier, the routing indication, and the remote terminal device's home network identifier. The first identifier may include the routing indication and the home network identifier. For example, the temporary identifier, the routing indication, and the remote terminal device's home network identifier may be combined to generate a string to serve as the temporary identifier. For example, taking the format of the first identifier being Username@realm, the username in the first identifier Username@realm may include the temporary identifier and the routing indication, and the realm may include the remote terminal device's home network identifier.
[0248] Alternatively, in another possible implementation, the remote terminal device uses the temporary identifier as the first identifier.
[0249] Method 3: The remote terminal device generates a first identifier based on the second freshness parameter, the routing indication, and the remote terminal device's home network identifier. The first identifier may include the routing indication and the home network identifier. For example, the second freshness parameter, the routing indication, and the remote terminal device's home network identifier may be combined to generate a string that serves as the temporary identifier. For example, taking the format of the first identifier being Username@realm, the Username in the first identifier Username@realm may include the second freshness parameter and the routing indication, and the Realm may include the remote terminal device's home network identifier.
[0250] Method 4: The remote terminal device generates a second shared key based on the first shared key (for example, Kausf) and the relay service code. The second shared key is the key Kp shared by the remote terminal device and the PKMF network element; the remote terminal device then generates a first identifier based on the second shared key Kp and the second freshness parameter.
[0251] In the process of generating the first identifier, the relay service code is used to generate a key based on the relay service code granularity to ensure that different relay service codes (services) correspond to different temporary identifiers, thereby preventing attackers from associating two different ongoing services of a terminal device based on the same first identifier over the air interface.
[0252] In the process of generating the first identifier, the second freshness parameter is used to ensure that for the same relay service code at different times, when no new master authentication occurs to generate a new key (such as Kausf), the network can generate different temporary identifiers, thereby preventing attackers from associating a terminal device with the same first identifier on the air interface to perform the same service at different times.
[0253] Second freshness parameter
[0254] The second freshness parameter may include the values of counters maintained locally by the remote terminal device and the remote AUSF network element respectively. When the remote terminal device and the remote AUSF network element maintain their respective counters locally, they adopt the same initial value and counting rule to keep the values of the two counters consistent. In this case, the remote AUSF network element does not need to send the second freshness parameter to the remote terminal device.
[0255] Alternatively, the remote terminal device may send a relay service code to the remote AUSF network element; the remote AUSF network element generates a first identifier based on the second freshness parameter for the relay service code and sends the second freshness parameter to the remote terminal device; accordingly, the remote terminal device receives the second freshness parameter corresponding to the relay service code from the remote AUSF network element. The second freshness parameter may include a random value generated by the remote AUSF network element or the value of a counter locally maintained by the remote AUSF network element, and the specific generation method is not limited.
[0256] First verification information
[0257] The first verification information is generated from the first temporary key and all or part of the information element of the message (e.g., direct communication request) carrying the first verification information. The first temporary key is generated from the first shared key (e.g., Kausf). Specifically, the first temporary key can be directly derived from Kausf, or an intermediate key can be derived from Kausf, and the first temporary key can be further derived based on the intermediate key.
[0258] Optionally, the first temporary key is calculated using the relay service code, the third freshness parameter, at least one of the second identifier of the remote terminal device (e.g., SUPI), and the first identifier, as well as a first shared key (e.g., Kausf). The third freshness parameter is generated by the remote terminal device and may be, for example, a third random number. For example, the relay service code, the third freshness parameter, at least one of the second identifier of the remote terminal device and the first identifier of the remote terminal device, as well as the first shared key (e.g., Kausf), are input and the first temporary key Kt is calculated using a certain algorithm.
[0259] The first verification information is used to be sent to a remote AUSF network element. After receiving the first verification information, the remote AUSF network element generates third verification information in the same manner as the remote terminal device. The remote AUSF network element compares the first verification information and the third verification information to verify the remote terminal device to verify whether the remote terminal device is authorized to access the network through the relay terminal device to obtain services.
[0260] Second verification information
[0261] The second verification information is generated using the first freshness parameter, the relay service code, and the first shared key (e.g., Kausf). For example, the remote terminal device generates the second shared key Kp based on the relay service code and the first shared key (e.g., Kausf), and then generates the second verification information based on the first freshness parameter and the second shared key Kp.
[0262] Optionally, the remote terminal device generates a second shared key Kp based on the remote terminal device's second identifier (e.g., SUPI), at least one of the proximity service (ProSe) characters, the relay service code, and the first shared key (e.g., Kausf). Alternatively, the remote terminal device generates the second shared key Kp based on the first shared key (e.g., Kausf) and other parameters, and then generates the second verification information based on the first freshness parameter, the relay service code, and the second shared key Kp.
[0263] The second verification information is used to be sent to the PKMF network element. After receiving the second verification information, the PKMF network element generates fourth verification information in the same manner as the remote terminal device. The PKMF network element compares the second verification information and the fourth verification information to verify the remote terminal device to verify whether the remote terminal device is authorized to access the network through the relay terminal device to obtain services.
[0264] S502: The remote terminal device generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key (eg, Kausf), the relay service code, and at least one first freshness parameter.
[0265] For example, a first shared key (eg, Kausf), a relay service code, and at least one first freshness parameter are used as inputs of a key derivation function KDF to output a root key for communication between a remote terminal device and a relay terminal device.
[0266] Alternatively, the first shared key (e.g., Kausf) is used as input to a KDF to output an intermediate key. Furthermore, the intermediate key, the relay service code, and at least one first freshness parameter are used as input to a KDF to output a root key for communication between the remote terminal device and the relay terminal device.
[0267] The remote terminal device can also generate a second shared key Kp based on the first shared key (such as Kausf) and the relay service code, and then generate a root key for communication between the remote terminal device and the relay terminal device based on the second shared key Kp and at least one first freshness parameter.
[0268] The remote terminal device can also generate a second shared key Kp based on the first shared key (such as Kausf), and then generate a root key for communication between the remote terminal device and the relay terminal device based on the relay service code, the second shared key Kp and at least one first freshness parameter.
[0269] First freshness parameter
[0270] Optionally, at least one first freshness parameter may include a value of a counter maintained locally by one of the remote AUSF network element or the PKMF network element and the terminal device, respectively. When the remote AUSF network element or the PKMF network element and the terminal device maintain their respective counters locally, they adopt the same initial value and counting rule to keep the values of the two counters consistent. Optionally, the remote AUSF network element or the PKMF network element and the terminal device maintain a counter for each relay server code.
[0271] Optionally, at least one first freshness parameter includes a first random number. Optionally, the remote terminal device may further send the first random number to the relay terminal device. The first random number is ultimately sent to the remote AUSF network element or PKMF network element, and accordingly, the remote AUSF network element or PKMF network element receives the first random number.
[0272] Optionally, at least one first freshness parameter includes a second random number, and the remote terminal device may also receive the second random number from the relay terminal device. The second random number may come from a remote AUSF network element or a PKMF network element, that is, the remote AUSF network element or the PKMF network element may send the second random number.
[0273] In the key acquisition method provided by the embodiment of the present application, a remote terminal device sends a first identifier and a relay service code to a relay terminal device, wherein the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device. The remote terminal device generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter. The first identifier is used by the remote AUSF network element to determine the corresponding first shared key, or is used by the PKMF network element to determine the corresponding second shared key, and the second shared key is also generated by the first shared key and / or the relay service code, so that the remote terminal device and the remote AUSF network element or PKMF network element can use the same method to generate the root key for communication between the remote terminal device and the relay terminal device, thereby realizing key sharing between the remote terminal device and the relay terminal device.
[0274] like Figure 6 As shown, the key acquisition method on the network side is performed by the remote AUSF network element, including the following steps:
[0275] S601. The remote AUSF network element obtains one of the first identifier or the second identifier of the remote terminal device, and a relay service code.
[0276] Optionally, the remote AUSF network element receives the first random number.
[0277] Optionally, the remote AUSF network element may also receive first verification information. For details about the first verification information, refer to the previous description and will not be repeated here.
[0278] As mentioned above, the second identifier may be a permanent identity identifier of the remote terminal device (eg, SUPI), and the first identifier may be an identifier of the remote terminal device corresponding to the relay service code (eg, P-KID).
[0279] The remote AUSF network element can receive the relay service code from the remote terminal device, which is forwarded by, for example, the remote AMF network element, the relay terminal device, the PKMF network element, etc. The relay service code is described above and will not be repeated here.
[0280] The remote AUSF network element obtains one of the first identifier or the second identifier of the remote terminal device in the following ways:
[0281] In a possible implementation, the remote AUSF network element receives one of the first identifier or the second identifier of the remote terminal device. For example, the remote AUSF network element may receive one of the first identifier or the second identifier of the remote terminal device from a PKMF network element.
[0282] In the case where the remote AUSF network element receives the first identifier of the remote terminal device, the method also includes: the remote AUSF network element can generate the first identifier using the same method as the remote terminal device in step S501 (for example, method two, method three).
[0283] In another possible implementation, the remote AUSF network element may generate the first identifier in the same manner as the remote terminal device in step S501 (eg, manner 2 or manner 3).
[0284] For example, the remote AUSF network element may generate a temporary identifier based on the first shared key and the relay service code, and then generate the first identifier based on the temporary identifier. Specific reference may be made to how the remote terminal device generates the first identifier in the second method of step S501 above.
[0285] Similar to the remote terminal device, the remote AUSF network element generates a temporary identifier based on the first shared key and the relay service code, which may include: the remote terminal device generates a temporary identifier based on the first shared key, the relay service code, and the second freshness parameter. For details, please refer to how the remote terminal device generates the temporary identifier in the second method of the previous step S501.
[0286] For another example, the remote AUSF network element may generate a first identifier based on the second freshness parameter, the routing indication, and the home network identifier of the remote terminal device. For details, please refer to how the remote terminal device generates the first identifier in method 3 of step S501 above. The second freshness parameter is described above and will not be repeated here.
[0287] In addition, the remote AUSF network element can send a second freshness parameter, which is forwarded to the remote terminal device via the relay terminal device, so that the remote terminal device receives the second freshness parameter.
[0288] After generating the first identifier, the remote AUSF network element can send the first identifier corresponding to the relay service code to the relay terminal device, which is forwarded by the relay terminal device to the remote terminal device, so that the remote terminal device obtains the first identifier, which corresponds to method one of the remote terminal device obtaining the first identifier in step S501.
[0289] The remote AUSF network element may also send a first identifier to the UDM network element, so that other network elements (e.g., PKMF network element) can obtain the remote AUSF network element instance identifier and / or the SUPI of the remote terminal device from the UDM network element. The remote AUSF network element instance identifier is used to determine the remote AUSF network element serving the remote terminal device.
[0290] S602. The remote AUSF network element obtains a first shared key corresponding to the first identifier or the second identifier.
[0291] The first shared key has been described above and will not be repeated here.
[0292] The remote AUSF network element can query the first shared key corresponding to the first identifier or the second identifier locally.
[0293] S603. The remote AUSF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter.
[0294] The description of the first freshness parameter is as described above and will not be repeated here. It should be noted that the first freshness parameter here can be the value of the counter maintained locally by the remote terminal device and the remote AUSF network element respectively.
[0295] The remote AUSF network element can generate the root key in the same way as the remote terminal device. Please refer to the relevant description in step S502 for details, which will not be repeated here.
[0296] After the remote AUSF network element receives the first verification information, before generating the root key, similar to the remote terminal device, it can generate a first temporary key based on the first shared key; and obtain third verification information based on the first temporary key and all or part of the information element of the message carrying the first verification information; by comparing the first verification information and the third verification information to verify the remote terminal device, the root key can be generated if the verification is successful. For how the remote AUSF network element performs verification, please refer to the previous description of the first verification information, which will not be repeated here.
[0297] Similarly, similar to the remote terminal device, the remote AUSF network element can generate a first temporary key based on the relay service code, the third freshness parameter, the second identifier, at least one of the first identifier of the remote terminal device, and the first shared key. Specific reference is made to the relevant description of the remote terminal device, which will not be repeated here.
[0298] Optionally, the remote AUSF network element generates a second shared key Kp in the same manner as the remote terminal device. For example, based on the relay service code and the first shared key (e.g., Kausf), the second shared key Kp is generated and sent to the PKMF network element. For details, refer to the method for generating the second shared key Kp by the remote terminal device mentioned above.
[0299] S604. The remote AUSF network element sends the root key.
[0300] The remote AUSF network element can send the root key to the PKMF network element, and send the root key to the relay terminal device through the PKMF network element.
[0301] Optionally, the remote AUSF network element may also send at least one first freshness parameter for generating the root key. For example, the at least one first freshness parameter includes a second random number, and the remote AUSF network element may send the second random number and forward it to the remote terminal device via the relay remote device.
[0302] The key acquisition method provided in the embodiment of the present application is as follows: the remote AUSF network element obtains one of the first identifier or the second identifier of the remote terminal device, and the relay service code; the second identifier is the permanent identity identifier of the remote terminal device, and the first identifier is the identifier of the remote terminal device corresponding to the relay service code; the remote AUSF network element obtains the first shared key corresponding to the first identifier or the second identifier; the first shared key is the key shared by the remote terminal device and the remote AUSF network element; the remote AUSF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter; the remote AUSF sends the root key. The first identifier is used by the remote AUSF network element to determine the corresponding first shared key, so that the remote terminal device and the remote AUSF network element can use the same method to generate the root key for communication between the remote terminal device and the relay terminal device, thereby realizing key sharing between the remote terminal device and the relay terminal device.
[0303] like Figure 7 As shown, the key acquisition method on the network side is performed by the PKMF network element, including the following steps:
[0304] S701. A PKMF network element receives a first identifier and a relay service code of a remote terminal device.
[0305] Optionally, the PKMF network element receives the first random number.
[0306] Optionally, the PKMF network element receives the second verification information. The second verification information is described above and will not be repeated here.
[0307] The first identifier may be an identifier of the remote terminal device corresponding to the relay service code (eg, P-KID), or the first identifier may be an anonymous identifier of the remote terminal device (eg, SUCI).
[0308] In a possible implementation manner, the PKMF network element may receive the first identifier and the relay service code from the remote terminal device through the relay terminal device.
[0309] S702. The PKMF network element obtains a root key for communication between the remote terminal device and the relay terminal device according to the first identifier.
[0310] In one possible implementation, the PKMF network element sends a first identifier to the UDM network element; accordingly, it receives identification information of the remote AUSF (e.g., the remote AUSF network element instance identifier) from the UDM network element; the PKMF network element sends a first identifier to the corresponding remote AUSF network element based on the identification information; accordingly, it receives a root key from the remote AUSF network element.
[0311] In another possible implementation, the PKMF network element sends a first identifier to the UDM network element; accordingly, the identification information of the remote AUSF network element and the permanent identity identifier (e.g., SUPI) of the remote terminal device are received from the UDM network element; the PKMF network element sends the permanent identity identifier of the remote terminal device to the corresponding remote AUSF network element based on the identification information; accordingly, the root key is received from the remote AUSF network element.
[0312] The above two implementations correspond to the remote AUSF network element obtaining one of the first identifier or the second identifier of the remote terminal device in step S601.
[0313] In another possible implementation, the PKMF network element receives at least one second shared key from the remote AUSF network element; the PKMF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the second shared key corresponding to the first identifier and at least one first freshness parameter. Optionally, the PKMF network element generates the root key for communication between the remote terminal device and the relay terminal device based on the relay service code, the second shared key corresponding to the first identifier, and at least one first freshness parameter.
[0314] After receiving the second verification information, the PKMF network element, similar to the remote terminal device, can generate fourth verification information based on the first freshness parameter and the second shared key before generating the root key. The remote terminal device is verified by comparing the first and third verification information. If verification is successful, the root key can be generated. The PKMF network element performs verification as described above regarding the second verification information and will not be repeated here.
[0315] The description of the first freshness parameter is as described above and will not be repeated here. It should be noted that the first freshness parameter here can be the value of a counter maintained locally by the remote terminal device and the PKMF network element respectively.
[0316] S703. The PKMF network element sends the root key.
[0317] Optionally, the PKMF network element may further send at least one first freshness parameter for generating the root key. For example, the at least one first freshness parameter includes a second random number, and the PKMF network element may send the second random number and forward it to the remote terminal device via the relay remote device.
[0318] The key acquisition method provided by the embodiment of the present application is as follows: a PKMF network element receives a first identifier and a relay service code of a remote terminal device, wherein the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; the PKMF network element obtains a root key for communication between the remote terminal device and the relay terminal device based on the first identifier, wherein the root key is generated by a first shared key, a relay service code, and at least one first freshness parameter, and the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; the PKMF network element sends the root key. The first identifier is used by the PKMF network element to determine the corresponding second shared key, so that the remote terminal device and the PKMF network element can generate the root key for communication between the remote terminal device and the relay terminal device in the same manner, thereby realizing key sharing between the remote terminal device and the relay terminal device.
[0319] An embodiment of the present application provides another key acquisition method, in which the remote terminal device actively requests the remote AUSF network element for the first identifier corresponding to the relay service code, so that the remote AUSF network element can generate the corresponding first identifier based on the relay service code, and the first identifier is used to discover the remote UDM network element, and the generated first identifier is stored in the remote UDM network element. During the indirect communication process, the remote terminal device initiates a direct communication request to the relay terminal device, and the direct communication request includes the first identifier. The relay terminal device initiates a key request containing the first identifier to the network side through signaling, and the PKMF network element determines the remote AUSF network element corresponding to the first identifier through the remote UDM network element, and obtains the root key for communication between the remote terminal device and the relay terminal device from the remote AUSF network element.
[0320] like Figure 8 As shown, the key acquisition method includes:
[0321] S801. A remote terminal device accesses a network and obtains information for communicating through a relay terminal device from a remote PCF network element or other related network elements.
[0322] The above information includes: indication information used to indicate whether the terminal device is authorized to access 5GC through the relay (that is, the terminal device serves as a remote terminal device); relay service code, etc.
[0323] S802: The relay terminal device accesses the network and obtains information about providing communication as a relay terminal device from the relay PCF network element or other related network elements.
[0324] The above information includes: indication information for indicating whether the terminal device is authorized to act as a relay; relay service code, etc.
[0325] It should be noted that the execution order of steps S801 and S802 is not limited.
[0326] S803. The remote terminal device sends a key request to the remote AUSF network element through the remote AMF network element.
[0327] The key request includes at least one relay service code.
[0328] Optionally, the remote AMF network element performs an authorization check to check whether the remote terminal device is authorized to serve as the remote terminal device of the relay terminal device or to check whether the remote terminal device is authorized to obtain the service corresponding to the relay service code through the relay terminal device.
[0329] S804. The remote AUSF network element generates a first identifier (eg, P-KID) for the remote terminal device corresponding to each relay service code.
[0330] The process of generating the first identifier refers to step S601.
[0331] S805. The remote AUSF network element sends the first identifier of the remote terminal device to the remote UDM network element.
[0332] The remote UDM network element stores the first identifier of the remote terminal device locally as the context of the remote terminal device. Optionally, if the remote UDM network element stores the context of the remote terminal device in a unified data repository (UDR) network element, the first identifier of the remote terminal device is also stored in the terminal device context of the UDR network element.
[0333] S806. The remote AUSF network element sends a key request response to the remote terminal device through the remote AMF network element.
[0334] The key request response includes: a first identifier corresponding to the relay service code, or a second freshness parameter used to generate the first identifier.
[0335] Correspondingly, the remote terminal device receives a first identifier corresponding to the relay service code from the remote AUSF network element through the remote AMF network element, or a second freshness parameter used to generate the first identifier.
[0336] If the second freshness parameter is used in the process of generating the first identifier, the key request response may include the first identifier corresponding to the relay service code, or the second freshness parameter used to generate the first identifier. If the second freshness parameter is not used in the process of generating the first identifier, the key request response includes the first identifier corresponding to the relay service code.
[0337] Optionally, if the received key request includes multiple relay service codes, that is, there are multiple first identifiers requested, the key request response may also include multiple relay service codes corresponding to the multiple first identifiers (or second freshness parameters), that is, the first identifier (or second freshness parameter) and the relay service code in the key request response correspond one to one; or, the key request response includes multiple first identifiers (or second freshness parameters), which do not correspond to the relay service codes, and the remote terminal device can freely select and correspond them.
[0338] S807: The remote terminal device obtains a first identifier.
[0339] If the first identifier is received in step S806, the remote terminal device directly stores it.
[0340] If the second freshness parameter is received in step S806, the remote terminal device generates the first identifier in the same manner as the remote AUSF network element, for example, in accordance with the second or third manner in step S501. It should be noted that the process of generating the first identifier by the remote terminal device can be performed before step S809.
[0341] S808: The remote terminal device executes a discovery process to discover the relay terminal device.
[0342] S809: The remote terminal device sends a direct communication request to the relay terminal device.
[0343] The direct communication request includes a first identifier of the remote terminal device (eg, P-KID) and a relay service code. If there are multiple relay service codes, the remote terminal device can determine the corresponding first identifier through the relay service code.
[0344] Optionally, the direct communication request may further include a first random number (Nonce 1).
[0345] Optionally, the direct communication request may further include first verification information.
[0346] Refer to step S501 for how to generate the first verification information.
[0347] S810. The relay terminal device sends a key request to the relay AMF network element.
[0348] The key request includes a first identifier (eg, P-KID) and a relay service code.
[0349] Optionally, the key request may also include a first random number.
[0350] Optionally, the key request may also include first verification information (eg MAC-I).
[0351] S811. The relay AMF network element selects the relay AUSF network element and sends a proximity service key request to the relay AUSF network element.
[0352] The proximity service key request includes a first identifier (eg, P-KID), a relay service code, and an identifier of a relay terminal device (relay UE ID) (eg, SUPI).
[0353] Optionally, the adjacent service key request may further include a first random number.
[0354] Optionally, the adjacent service key request may further include first verification information (eg MAC-I).
[0355] Optionally, the relay AMF network element performs an authorization check, that is, checks whether the relay terminal device is authorized to act as a relay terminal device or checks whether the relay terminal device is authorized to provide the connection service corresponding to the relay service code to the remote terminal device.
[0356] S812. The relay AUSF network element selects a PKMF network element and sends a proximity service key request to the PKMF network element.
[0357] The information carried in the proximity service key request is the same as the information carried in the proximity service key request in step S811.
[0358] S813. The PKMF network element selects a remote UDM network element according to the first identifier (eg, P-KID) in the adjacent service key request, and sends a network element discovery request to the remote UDM network element.
[0359] The network element discovery request includes a first identifier (eg, P-KID).
[0360] The remote UDM network element obtains the remote AUSF network element instance identifier based on the first identifier (e.g., P-KID) and sends it to the PKMF network element. The AUSF network instance identifier can be an identifier that can uniquely identify the remote AUSF, such as a fully qualified domain name (FQDN) or the address of the AUSF, and is not limited here.
[0361] Optionally, the PKMF network element may also obtain a second identifier (eg, SUPI) of the remote terminal device.
[0362] S814. The PKMF network element authorizes the remote terminal device and the relay terminal device.
[0363] If the PKMF network element obtains the second identifier of the remote terminal device in step S813, the PKMF network element determines whether to authorize the remote terminal device to obtain the service corresponding to the relay service code through the relay terminal device based on the second identifier of the remote terminal device (such as SUPI) and the relay service code.
[0364] The PKMF network element determines whether to authorize the relay terminal device to provide the service corresponding to the relay service code based on the relay terminal device's identifier (relay UE ID, such as SUPI) and the relay service code. If authorization is passed, the subsequent process will continue; otherwise, a rejection process will be initiated.
[0365] It should be noted that the above PKMF authorization process is optional and may occur after step S815.
[0366] S815. The PKMF network element sends a proximity service key request to the remote AUSF network element.
[0367] The proximity service key request includes the second identifier (eg, SUPI) or the first identifier of the remote terminal device and the relay service code.
[0368] Optionally, the adjacent service key request may further include a first random number.
[0369] Optionally, the adjacent service key request may further include first verification information (eg MAC-I).
[0370] S816. The remote AUSF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter.
[0371] The at least one first freshness parameter here may include a first random number (Nonce 1), or may include a second random number (Nonce 2) generated by a remote AUSF network element, or may include the first random number and the second random number, or may include the value of a counter maintained locally by the remote AUSF network element, and the counter maintained locally by the remote AUSF network element and the counter maintained locally by the remote terminal device use the same initial value and counting rule to keep the values of the two counters consistent. There is no restriction on the specific implementation method of the first freshness parameter.
[0372] The process of generating the root key refers to step S603.
[0373] It should be noted that if the adjacent service key request includes the first verification information, the remote AUSF network element generates the third verification information in the same manner as the terminal device, and performs verification by comparing the first verification information with the third verification information. After the verification is successful, the root key is generated.
[0374] S817. The remote AUSF network element sends a proximity service key response to the PKMF network element.
[0375] The adjacent service key response may include a root key, and optionally, may also include a second random number.
[0376] S818. The PKMF network element sends an adjacent service key response to the relay AUSF network element.
[0377] The adjacent service key response may include a root key, and optionally, may also include a second random number.
[0378] S819. The relay AUSF network element sends a proximity service key response to the relay terminal device through the relay AMF network element.
[0379] The adjacent service key response may include a root key, and optionally, may also include a second random number.
[0380] S820: The relay terminal device sends a security mode command to the remote terminal device.
[0381] Optionally, the security mode command includes a second random number.
[0382] Optionally, the relay terminal device generates a fourth random number and includes the fourth random number in the security mode command message.
[0383] The remote terminal device generates the root key using the same method as the remote AUSF network element.
[0384] Optionally, the relay terminal device can generate a session key between the relay terminal device and the remote terminal device based on the received root key. Further optionally, the relay terminal device can generate an encryption key and / or integrity protection key for the signaling plane and / or user plane based on the session key.
[0385] Alternatively, optionally, the relay terminal device may generate an encryption key and / or an integrity protection key for the signaling plane and / or user plane based on the received root key.
[0386] Optionally, the security mode command message includes a message authentication code, which is generated based on the integrity protection key of the signaling plane.
[0387] S821. The remote terminal device sends a complete security mode command message to the relay terminal device.
[0388] In the key acquisition method described above, the remote terminal device obtains a first identifier corresponding to the relay service code. Using this first identifier, the relay terminal device can obtain the root key for communication between the remote terminal device and the relay terminal device from the network via the signaling plane. Optionally, the PKMF network element performs an authorization check on the remote terminal device and the relay terminal device before obtaining the root key to ensure that only authorized terminal devices obtain the root key. The root key is generated based on parameters such as the first shared key Kausf and the relay service code.
[0389] An embodiment of the present application provides another key acquisition method, in which the remote terminal device actively requests the remote AUSF network element for the first identifier corresponding to the relay service code, so that the remote AUSF network element can generate the corresponding first identifier and second shared key according to the relay service code, and send them to the PKMF network element. In the indirect communication process, the remote terminal device initiates a direct communication request to the relay terminal device, and the direct communication request includes the first identifier. The relay terminal device initiates a key request containing the first identifier to the network side through signaling, and the PKMF network element obtains the corresponding second shared key Kp according to the first identifier, and generates a root key for communication between the remote terminal device and the relay terminal device. Figure 8 The difference is that the remote AUSF network element pushes the first identifier and the second shared key Kp of the remote terminal device to the PKMF network element in advance. Or the remote AUSF network element pushes the second shared key Kp to the PKMF network element in advance, and the PKMF generates the first identifier of the remote terminal device.
[0390] like Figure 9 As shown, the key acquisition method includes:
[0391] S901. A remote terminal device accesses a network and obtains information for communicating through a relay terminal device from a remote PCF network element or other related network elements.
[0392] This step is the same as step S801 and will not be repeated here.
[0393] S902: The relay terminal device accesses the network and obtains information about providing communication as a relay terminal device from the relay PCF network element or other related network elements.
[0394] This step is the same as step S802 and will not be repeated here.
[0395] S903. The remote terminal device sends a key request to the remote AUSF network element through the remote AMF network element.
[0396] This step is the same as step S803 and will not be repeated here.
[0397] S904. The remote AUSF network element generates a second shared key Kp.
[0398] The process of generating the second shared key Kp refers to step S603.
[0399] Optionally, the remote AUSF network element generates a first identifier (eg, P-KID) corresponding to each relay service code of the terminal device. The process of generating the first identifier refers to step S601.
[0400] S905. The remote AUSF network element selects a PKMF network element and sends a proximity service information provision message to the PKMF network element.
[0401] The ways in which the remote AUSF network element selects the PKMF network element include but are not limited to the following possible ways:
[0402] Method 1: The remote AUSF network element determines the PKMF network element based on the relay service code. For example, the remote AUSF network element sends the relay service code to the remote NRF network element or remote PCF network element to obtain the PKMF network element corresponding to the relay service code. Alternatively, the relay service code includes routing information, and the remote AUSF network element selects the PKMF network element based on the routing information.
[0403] Method 2: The remote terminal device includes the discovery information of the PKMF network element in the key request (the information is obtained from the remote PCF network element or other related network elements in step S901), and the remote AMF network element forwards it to the remote AUSF network element.
[0404] Method 3: The remote AMF network element includes the discovery information of the PKMF network element in the key request (the information is obtained from the remote PCF network element or other relevant network elements in step S901).
[0405] The above-mentioned discovery information of the PKMF network element is used by the AUSF network element to determine the PKMF network element. The discovery information of the PKMF network element may be routing information, address information of the PKMF network element, or an identifier of the PKMF network element.
[0406] The proximity service information provision message includes the second identifier (eg SUPI) of the remote terminal device and the second shared key Kp, and optionally, may also include a relay service code and the first identifier of the remote terminal device.
[0407] The PKMF network element stores the received second identifier of the remote terminal device (eg SUPI), the first identifier of the remote terminal device (if received), the second shared key Kp, and optionally, the relay service code.
[0408] Optionally, the PKMF network element may store the above information only after determining that the remote terminal device is authorized to obtain the relay service code.
[0409] Optionally, if the proximity service information provision message does not include the first identifier, the PKMF network element generates the first identifier. In this case, the PKMF network element optionally sends the generated first identifier or the second freshness parameter to the remote AUSF network element.
[0410] S906. The remote AUSF network element sends a key request response to the remote terminal device through the remote AMF network element.
[0411] This step is the same as step S806.
[0412] S907: The remote terminal device obtains a first identifier.
[0413] This step is the same as step S807. It should be noted that the process of the remote terminal device generating the first identifier can be performed before step S909.
[0414] S908: The remote terminal device executes a discovery process to discover the relay terminal device.
[0415] This step is the same as step S808.
[0416] S909: The remote terminal device sends a direct communication request to the relay terminal device.
[0417] This step differs from step S809 in that the remote terminal device can generate second verification information instead of the first verification information. The process of generating the second verification information is similar to step S501. Furthermore, the direct communication request may optionally include the second verification information instead of the first verification information. Other details are the same.
[0418] S910. The relay terminal device sends a key request to the relay AMF network element.
[0419] The difference between this step and step S810 is that the key request optionally includes the second verification information instead of the first verification information. The other contents are the same.
[0420] S911. The relay AMF network element selects the relay AUSF network element and sends a proximity service key request to the relay AUSF network element.
[0421] The difference between this step and step S811 is that the adjacent service key request optionally includes the second verification information instead of the first verification information. The other contents are the same.
[0422] S912. The relay AUSF network element selects a PKMF network element and sends a proximity service key request to the PKMF network element.
[0423] The difference between this step and step S812 is that the relay AUSF network element selects the PKMF network element in the same way as the remote AUSF network element selects the PKMF network element in step S905; in addition, the adjacent service key request optionally includes the second verification information instead of the first verification information. Other contents are the same.
[0424] S913. The PKMF network element authorizes the remote terminal device and the relay terminal device.
[0425] This step is the same as step S814 and is optional.
[0426] S914. The PKMF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the second shared key Kp and at least one first freshness parameter.
[0427] The first freshness parameter here may include a first random number (Nonce 1), or may include a second random number (Nonce 2) generated by PKMF, or may include the first random number and the second random number, or may include the values of counters maintained locally by the remote terminal device and the PKMF network element respectively. When the remote terminal device and the PKMF network element maintain their respective counters locally, they use the same initial value and counting rule to keep the values of the two counters consistent.
[0428] The process of generating the root key refers to step S702.
[0429] It should be noted that if the adjacent service key request includes the second verification information, the PKMF network element generates the fourth verification information in the same manner as the terminal device, performs verification by comparing the second verification information with the fourth verification information, and then generates the root key after the verification is successful.
[0430] It should be noted that the execution order of the above verification process and step S913 is not limited.
[0431] S915. The PKMF network element sends an adjacent service key response to the relay AUSF network element.
[0432] This step is the same as step S818.
[0433] S916. The relay AUSF network element sends a proximity service key response to the relay terminal device through the relay AMF network element.
[0434] This step is the same as step S819.
[0435] S917: The relay terminal device sends a security mode command to the remote terminal device.
[0436] This step is the same as step S820.
[0437] S918. The remote terminal device sends a complete security mode command message to the relay terminal device.
[0438] This step is the same as step S821.
[0439] In the key acquisition method described above, the remote terminal device obtains a first identifier corresponding to the relay service code. Using this first identifier, the relay terminal device obtains the root key for communication between the remote terminal device and the relay terminal device from the network via the signaling plane. Furthermore, before obtaining the root key, the PKMF network element performs an authorization check on the remote terminal device and the relay terminal device to ensure that only authorized terminal devices obtain the root key. The root key is generated based on parameters such as the first shared key Kausf and the relay service code.
[0440] An embodiment of the present application provides another key acquisition method, in which the remote terminal device actively requests the first identifier corresponding to the relay service code from the PKMF network element through the remote AMF network element, and then the PKMF network element requests the first identifier from the remote AUSF network element, so that the remote AUSF network element can generate the corresponding first identifier and second shared key according to the relay service code, and send them to the PKMF network element. In the indirect communication process, the remote terminal device initiates a direct communication request to the relay terminal device, and the direct communication request includes the first identifier. The relay terminal device initiates a key request containing the first identifier to the network side through signaling, and the PKMF network element obtains the corresponding second shared key according to the first identifier, and generates a root key for communication between the remote terminal device and the relay terminal device. Figure 9 The difference is that the remote AMF network element communicates directly with the PKMF network element.
[0441] like Figure 10 As shown, the key acquisition method includes:
[0442] S1001. A remote terminal device accesses a network and obtains information for communicating through a relay terminal device from a remote PCF network element or other related network elements.
[0443] This step is the same as step S801 and will not be repeated here.
[0444] S1002. The relay terminal device accesses the network and obtains information about providing communication as a relay terminal device from the relay PCF network element or other related network elements.
[0445] This step is the same as step S802 and will not be repeated here.
[0446] S1003. The remote terminal device sends a key request to the remote AMF network element.
[0447] The key request includes at least one relay service code.
[0448] Optionally, the remote AMF network element performs an authorization check, i.e., checks whether the remote terminal device is authorized to serve as the remote terminal device of the relay terminal device or checks whether the remote terminal device is authorized to obtain the service corresponding to the relay service code through the relay terminal device.
[0449] S1004. The remote AMF network element selects a PKMF network element and sends a key request to the PKMF network element.
[0450] The way in which the remote AMF network element selects the PKMF network element is the same as the way in which the remote AUSF network element selects the PKMF network element in step S905.
[0451] The key request includes the relay service code, the remote AUSF network element instance identifier, and the second identifier of the remote terminal device (such as SUPI).
[0452] If the key request in step S1003 includes multiple relay service codes and corresponds to different PKMF network elements, the remote AMF network element sends a key request to each PKMF network element respectively.
[0453] S1005. The PKMF network element sends a proximity service security information request to the remote AUSF network element.
[0454] The request includes the second identification of the remote terminal device (eg SUPI) and the relay service code.
[0455] Optionally, before sending the message, the PKMF network element determines whether to authorize the remote terminal device to obtain the service corresponding to the relay service code through the relay terminal device based on the second identifier (eg, SUPI) of the remote terminal device and the relay service code.
[0456] S1006. The remote AUSF network element generates a first identifier (eg, P-KID) of the terminal device corresponding to each relay service code, and generates a second shared key Kp.
[0457] This step is the same as step S904.
[0458] S1007. The remote AUSF network element sends a proximity service security information response to the PKMF network element.
[0459] The proximity service security information response includes the second shared key Kp, and optionally may also include a relay service code, a second identifier of the remote terminal device (eg, SUPI), and a first identifier of the remote terminal device.
[0460] S1008. The PKMF network element sends a key request response to the remote terminal device through the remote AMF network element.
[0461] For information included in the key request response, please refer to step S806 and will not be repeated here.
[0462] S1009: The remote terminal device obtains a first identifier.
[0463] This step is the same as step S807. It should be noted that the process of the remote terminal device generating the first identifier can be performed before step S1011.
[0464] S1010: The remote terminal device executes a discovery process to discover the relay terminal device.
[0465] This step is the same as step S808.
[0466] S1011. The remote terminal device sends a direct communication request to the relay terminal device.
[0467] This step is the same as step S909.
[0468] S1012. The relay terminal device sends a key request to the relay AMF network element.
[0469] This step is the same as step S910.
[0470] S1013. The relay AMF network element selects a PKMF network element and sends a proximity service key request to the PKMF network element.
[0471] The way in which the relay AMF network element selects the PKMF network element is the same as the way in which the remote AMF network element selects the PKMF network element in step S1004.
[0472] The information carried in the proximity service key request is the same as the information carried in the proximity service key request in step S912.
[0473] Optionally, the relay AMF network element performs an authorization check, i.e., checks whether the relay terminal device is authorized to serve as a relay terminal device of the remote relay device or checks whether the relay terminal device is authorized to provide the connection service corresponding to the relay service code to the remote terminal device.
[0474] S1014. Optionally, the PKMF network element authorizes the remote terminal device and the relay terminal device.
[0475] This step is the same as step S814.
[0476] S1015. The PKMF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the second shared key Kp and at least one first freshness parameter.
[0477] This step is the same as step S914.
[0478] S1016. The PKMF network element sends a proximity service key response to the relay terminal device through the relay AMF network element.
[0479] The information carried in the adjacent service key response is the same as the information carried in the adjacent service key response in step S818.
[0480] S1017. The relay terminal device sends a security mode command to the remote terminal device.
[0481] This step is the same as step S820.
[0482] S1018. The remote terminal device sends a complete security mode command message to the relay terminal device.
[0483] This step is the same as step S821.
[0484] In the key acquisition method described above, the remote terminal device obtains a first identifier corresponding to the relay service code. Using this first identifier, the relay terminal device obtains the root key for communication between the remote terminal device and the relay terminal device from the network via the signaling plane. Furthermore, before obtaining the root key, the PKMF network element performs an authorization check on the remote terminal device and the relay terminal device to ensure that only authorized terminal devices obtain the root key. The root key is generated based on parameters such as the first shared key Kausf and the relay service code.
[0485] The embodiment of the present application provides another key acquisition method. During indirect communication, the remote terminal device initiates a direct communication request to the relay terminal device. The direct communication request includes the SUCI of the remote terminal device. The relay terminal device initiates a key request including the SUCI to the network side through signaling. The PKMF network element determines the remote AUSF network element corresponding to the SUCI through the remote UDM network element, and obtains the root key for communication between the remote terminal device and the relay terminal device from the remote AUSF network element. Figure 8 The difference is that the PKMF network element determines the remote AUSF network element through the SUCI of the remote terminal device.
[0486] like Figure 11 As shown, the key acquisition method includes:
[0487] S1101. A remote terminal device accesses a network and obtains information for communicating through a relay terminal device from a remote PCF network element or other related network elements.
[0488] This step is the same as step S801 and will not be repeated here.
[0489] S1102: The relay terminal device accesses the network and obtains information about providing communication as a relay terminal device from the relay PCF network element or other related network elements.
[0490] This step is the same as step S802 and will not be repeated here.
[0491] S1103: The remote terminal device executes a discovery process to discover the relay terminal device.
[0492] This step is the same as step S808.
[0493] S1104: The remote terminal device sends a direct communication request to the relay terminal device.
[0494] The difference between this step and step S809 is that the first identifier in the direct communication request may be the SUCI of the remote terminal device.
[0495] S1105. The relay terminal device sends a key request to the relay AMF network element.
[0496] The difference between this step and step S810 is that the first identifier in the key request may be the SUCI of the remote terminal device.
[0497] S1106. The relay AMF network element selects the relay AUSF network element and sends a proximity service key request to the relay AUSF network element.
[0498] The difference between this step and step S811 is that the first identifier in the proximity service key request may be the SUCI of the remote terminal device.
[0499] S1107. The relay AUSF network element selects a PKMF network element and sends a proximity service key request to the PKMF network element.
[0500] The difference between this step and step S812 is that the first identifier in the proximity service key request may be the SUCI of the remote terminal device.
[0501] S1108. The PKMF network element selects a remote UDM network element according to the first identifier (eg, SUCI) in the adjacent service key request, and sends a terminal equipment identifier (UE ID) request to the remote UDM network element.
[0502] The terminal device identification request includes a first identification (eg, SUCI).
[0503] The remote UDM network element obtains the second identifier (eg SUPI) of the remote terminal device and the instance identifier of the remote AUSF network element serving the remote terminal device according to the first identifier (eg SUCI), and sends them to the PKMF network element.
[0504] S1109. The PKMF network element authorizes the remote terminal device and the relay terminal device.
[0505] This step is the same as step S814.
[0506] S1110. The PKMF network element sends a proximity service key request to the remote AUSF network element.
[0507] This step is the same as step S815.
[0508] S1111. The remote AUSF network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter.
[0509] This step is the same as step S816.
[0510] S1112. The remote AUSF network element sends a proximity service key response to the PKMF network element.
[0511] This step is the same as step S817.
[0512] S1113. The PKMF network element sends an adjacent service key response to the relay AUSF network element.
[0513] This step is the same as step S818.
[0514] S1114. The relay AUSF network element sends a proximity service key response to the relay terminal device through the relay AMF network element.
[0515] This step is the same as step S819.
[0516] S1115. The relay terminal device sends a security mode command to the remote terminal device.
[0517] This step is the same as step S820.
[0518] S1116. The remote terminal device sends a complete security mode command message to the relay terminal device.
[0519] This step is the same as step S821.
[0520] It should be noted that steps S811 and S812 are optional. The remote AMF network element can directly select the PKMF network element and send a proximity service key request to the PKMF network element. The content carried in the proximity service key request is the same as the information carried in the proximity service key request in step S811.
[0521] In the key acquisition method described above, the remote terminal device generates a SUCI, which the relay terminal device uses to obtain the root key for communication between the remote terminal device and the relay terminal device from the PKMF network element. Specifically, the PKMF network element determines the remote AUSF network element based on the SUCI and obtains the root key for communication between the remote terminal device and the relay terminal device from the remote AUSF network element.
[0522] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between various network elements. Accordingly, the embodiment of the present application also provides a communication device, which is used to implement the above various methods. The communication device can be the remote terminal device in the above method embodiment, or a device including the above remote terminal device, or a chip or functional module in the remote terminal device. Alternatively, the communication device can be the remote AUSF network element in the above method embodiment, or a device including the above remote AUSF network element, or a chip or functional module in the remote AUSF network element. Alternatively, the communication device can be the PKMF network element in the above method embodiment, or a device including the above PKMF network element, or a chip or functional module in the PKMF network element.
[0523] It is understandable that, in order to realize the above functions, the communication device includes hardware structures and / or software modules corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0524] The embodiment of the present application can divide the functional modules of the communication device according to the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, there may be other division methods.
[0525] For example, take the communication device as the remote terminal equipment in the above method embodiment as an example. Figure 12 A schematic diagram of the structure of a communication device 120 is shown. The communication device 120 may be Figure 1 The communication device 120 includes a processing module 1201 and a transceiver module 1202. The processing module 1201 can also be called a processing unit, which is used to implement the processing function of the remote terminal device in the above method embodiment. For example, Figure 5 Step S502 in Figures 8-11 The transceiver module 1202, which can also be called a transceiver unit, is used to implement the transceiver function of the remote terminal device in the above method embodiment. Figure 5 Step S501 in Figures 8-11 The transceiver module 1202 can be called a transceiver circuit, a transceiver, a transceiver, or a communication interface.
[0526] Exemplarily, the transceiver module 1202 is used to send a first identifier and a relay service code to the relay terminal device, where the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; the processing module 1201 is used to generate a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter, where the remote authentication service function network element is an authentication service function network element serving the remote terminal device, and the first shared key is a key shared by the remote terminal device and the remote authentication service function network element.
[0527] In a possible implementation manner, the first identifier is the SUCI of the remote terminal device.
[0528] In a possible implementation, the processing module 1201 and the transceiver module 1202 are further configured to obtain a first identifier.
[0529] In a possible implementation, the transceiver module 1202 is further configured to send a relay service code; and receive a first identifier corresponding to the relay service code.
[0530] In a possible implementation, the processing module 1201 is further configured to generate a temporary identifier according to the first shared key and the relay service code; and obtain the first identifier according to the temporary identifier.
[0531] In a possible implementation, the processing module 1201 is further configured to generate a temporary identifier according to the first shared key, the relay service code, and the second freshness parameter.
[0532] In a possible implementation, the processing module 1201 is further configured to generate a first identifier according to the second freshness parameter, the routing indication, and the home network identifier.
[0533] In a possible implementation, the transceiver module 1202 is further configured to send a relay service code; and receive a second freshness parameter corresponding to the relay service code.
[0534] In a possible implementation, the second freshness parameter is the value of a counter maintained locally by the remote terminal device.
[0535] In a possible implementation, the first identifier includes a routing indication and a home network identifier.
[0536] In one possible implementation, the transceiver module 1202 is also used to send first verification information to the relay terminal device, where the first verification information is generated by a first temporary key and all or part of the information elements of the message carrying the first verification information, and the first temporary key is generated by a first shared key.
[0537] In one possible implementation, the first temporary key is generated using the relay service code, a third freshness parameter, at least one of the second identifier and the first identifier of the remote terminal device, and the first shared key, where the third freshness parameter is generated by the remote terminal device. This implementation discloses a method for generating the first temporary key.
[0538] In a possible implementation, the transceiver module 1202 is further configured to send second verification information to the relay terminal device, where the second verification information is generated by the first freshness parameter, the relay service code, and the first shared key.
[0539] In a possible implementation, the at least one first freshness parameter includes a first random number, and the transceiver module 1202 is further configured to send the first random number to the relay terminal device. The first random number is sent to a remote AUSF network element or a PKMF network element.
[0540] In a possible implementation, the at least one first freshness parameter includes a second random number, and the transceiver module 1202 is further configured to receive the second random number from the relay terminal device. The second random number may come from a remote AUSF network element or a PKMF network element.
[0541] In a possible implementation, the at least one first freshness parameter is a value of a counter maintained locally by the remote terminal device.
[0542] In a possible implementation manner, the first shared key is a key Kausf negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0543] In a possible embodiment, the processing module 1201 is also used to generate a second shared key based on the first shared key and the relay service code, and generate a root key based on the second shared key and at least one first freshness parameter, where the second shared key is a key shared by the remote terminal device and the adjacent service key management function network element.
[0544] For example, take the communication device as the remote AUSF network element in the above method embodiment as an example. Figure 13 A schematic diagram of the structure of a communication device 130 is shown. The communication device 130 may be Figure 1 The communication device 130 includes a processing module 1301 and a transceiver module 1302. The processing module 1301 can also be called a processing unit, which is used to implement the processing function of the remote AUSF network element in the above method embodiment. Figures 8-11 Processing functions of mid- and remote AUSF network elements. For example, Figure 6 The transceiver module 1302, which may also be referred to as a transceiver unit, is used to implement the transceiver function of the remote AUSF network element in the above method embodiment. For example, Figure 6 Steps S601 and S604 in Figures 8-11 The transceiver module 1302 can be called a transceiver circuit, a transceiver, a transceiver, or a communication interface.
[0545] Exemplarily, the processing module 1301 is used to obtain one of the first identifier or the second identifier of the remote terminal device, and the relay service code; the second identifier is the permanent identity identifier of the remote terminal device, and the first identifier is the identifier of the remote terminal device corresponding to the relay service code; the processing module 1301 is also used to obtain the first shared key corresponding to the first identifier or the second identifier; the first shared key is the key shared by the remote terminal device and the remote authentication service function network element; the remote authentication service function network element generates a root key for communication between the remote terminal device and the relay terminal device based on the first shared key, the relay service code, and at least one first freshness parameter; the transceiver module 1302 is used to send the root key.
[0546] In a possible implementation, the transceiver module 1302 is further configured to receive one of the first identifier or the second identifier of the remote terminal device.
[0547] In a possible implementation, the processing module 1301 is further configured to generate a temporary identifier according to the first shared key and the relay service code; and the remote authentication service function network element generates the first identifier according to the temporary identifier.
[0548] In a possible implementation, the processing module 1301 is further configured to generate a temporary identifier according to the first shared key, the relay service code, and the second freshness parameter.
[0549] In a possible implementation, the processing module 1301 is further configured to generate a first identifier according to the second freshness parameter, the routing indication, and the home network identifier of the remote terminal device.
[0550] In a possible implementation, the second freshness parameter is the value of a counter maintained locally by the remote authentication service function network element.
[0551] In a possible implementation, the transceiver module 1302 is further configured to receive a relay service code and send a second freshness parameter.
[0552] In a possible implementation, the transceiver module 1302 is further configured to receive a relay service code and send a first identifier.
[0553] In a possible implementation, the first identifier includes a routing indication and a home network identifier.
[0554] In one possible embodiment, the transceiver module 1302 is also used to receive first verification information; the processing module 1301 is also used to generate a first temporary key based on the first shared key; and obtain third verification information based on the first temporary key and all or part of the information elements of the message carrying the first verification information; compare the first verification information and the third verification information to verify the remote terminal device.
[0555] In one possible embodiment, the processing module 1301 is also used to generate a first temporary key based on the relay service code, the third freshness parameter, the second identifier and at least one of the first identifier of the remote terminal device, and the first shared key, and the third freshness parameter is generated for the remote terminal device.
[0556] In a possible implementation, the at least one first freshness parameter includes a first random number, and the transceiver module 1302 is further configured to receive the first random number.
[0557] In a possible implementation, the at least one first freshness parameter includes a second random number, and the transceiver module 1302 is further configured to send the second random number.
[0558] In a possible implementation, the at least one first freshness parameter is a value of a counter locally maintained by the remote authentication service function network element.
[0559] In a possible implementation, the transceiver module 1302 is further configured to send the first identifier to the unified data management network element.
[0560] In a possible implementation manner, the first shared key is a key Kausf negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0561] For example, take the communication device as the PKMF network element in the above method embodiment as an example. Figure 14 FIG1 shows a schematic diagram of the structure of a communication device 140. The communication device 140 includes a processing module 1401 and a transceiver module 1402. The processing module 1401 can also be called a processing unit, which is used to implement the processing function of the PKMF network element in the above method embodiment. For example, Figure 7 Step S702 in Figures 8-11 The transceiver module 1402, which may also be referred to as a transceiver unit, is used to implement the transceiver function of the PKMF network element in the above method embodiment. Figure 7 Steps S701-S703 in Figures 8-11 The transceiver module 1402 may be referred to as a transceiver circuit, a transceiver, a transceiver, or a communication interface.
[0562] Exemplarily, the transceiver module 1402 is used to receive a first identifier and a relay service code of a remote terminal device, where the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; the processing module 1401 is used to obtain a root key for communication between the remote terminal device and the relay terminal device based on the first identifier, where the root key is generated by a first shared key, a relay service code, and at least one first freshness parameter, where the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; the transceiver module 1402 is also used to send the root key.
[0563] In one possible implementation, the transceiver module 1402 is also used to send a first identifier to a unified data management function network element; receive identification information of a remote authentication service function network element from the unified data management function network element; send a first identifier to a corresponding remote authentication service function network element based on the identification information; and receive a root key from the remote authentication service function network element.
[0564] In one possible implementation, the transceiver module 1402 is also used to send a first identifier to a unified data management function network element; receive identification information of a remote authentication service function network element and a permanent identity identifier of a remote terminal device from the unified data management function network element; send the permanent identity identifier of the remote terminal device to a corresponding remote authentication service function network element based on the identification information; and receive a root key from the remote authentication service function network element.
[0565] In one possible embodiment, the transceiver module 1402 is also used to receive at least one second shared key from a remote authentication service function network element, where the second shared key is a key shared by the remote terminal device and the adjacent service key management function network element, and the second shared key is generated by the first shared key and the relay service code; the processing module 1401 is also used to generate a root key for communication between the remote terminal device and the relay terminal device based on the second shared key corresponding to the first identifier, and at least one first freshness parameter.
[0566] In a possible implementation, it further includes: the transceiver module 1402 is further used to receive second verification information; the processing module 1401 is further used to generate fourth verification information based on the first freshness parameter and the second shared key; and compare the second verification information and the fourth verification secret information to verify the remote terminal device.
[0567] In a possible implementation, the at least one first freshness parameter includes a first random number, and the transceiver module 1402 is further configured to receive the first random number.
[0568] In a possible implementation, the at least one first freshness parameter includes a second random number, and the transceiver module 1402 is further configured to send the second random number.
[0569] In a possible implementation manner, the at least one first freshness parameter is a value of a counter locally maintained by a neighboring service key management function network element.
[0570] In a possible implementation manner, the first shared key is a key Kausf negotiated between the remote terminal device and the remote authentication service function network element when the remote terminal device accesses the network.
[0571] In this embodiment, the communication device is presented in the form of various functional modules divided in an integrated manner. Here, "module" can refer to a specific ASIC, circuit, processor and memory executing one or more software or firmware programs, integrated logic circuit, and / or other devices that can provide the above functions.
[0572] Specifically, the functions / implementation process of the processing module can be implemented by the processor in the communication device calling the computer execution instructions stored in the memory. The functions / implementation process of the transceiver module can be implemented by the transceiver or communication interface in the communication device.
[0573] Since the communication device provided in this embodiment can execute the above method, the technical effects that can be obtained can be referred to the above method embodiment and will not be repeated here.
[0574] like Figure 15 As shown, the embodiment of the present application further provides a communication device, the communication device 150 includes a processor 1501, a memory 1502 and a transceiver 1503, the processor 1501 is coupled to the memory 1502, when the processor 1501 executes the computer program or instruction in the memory 1502, Figure 2-Figure 11 The corresponding method of the remote terminal device is executed.
[0575] like Figure 16 As shown, the embodiment of the present application further provides a communication device, the communication device 160 includes a processor 1601, a memory 1602 and a communication interface 1603, the processor 1601 is coupled to the memory 1602, when the processor 1601 executes the computer program or instruction in the memory 1602, Figure 2-Figure 11 The corresponding method of the AUSF network element (such as the remote AUSF network element, the relay AUSF network element) is executed.
[0576] like Figure 17 As shown, the embodiment of the present application further provides a communication device, the communication device 170 includes a processor 1701, a memory 1702 and a communication interface 1703, the processor 1701 is coupled to the memory 1702, when the processor 1701 executes the computer program or instruction in the memory 1702, Figure 2-Figure 11 The corresponding method of the PKMF network element is executed.
[0577] The present invention also provides a computer-readable storage medium in which a computer program is stored. When the computer-readable storage medium is run on a computer or a processor, the computer or processor executes Figure 2-Figure 11 Methods corresponding to mid- and remote terminal devices.
[0578] The present invention also provides a computer-readable storage medium in which a computer program is stored. When the computer-readable storage medium is run on a computer or a processor, the computer or processor executes Figure 2-Figure 11 The method corresponding to the AUSF network element (such as the remote AUSF network element and the relay AUSF network element).
[0579] The present invention also provides a computer-readable storage medium in which a computer program is stored. When the computer-readable storage medium is run on a computer or a processor, the computer or processor executes Figure 2-Figure 11 The corresponding method of PKMF network element.
[0580] The present application also provides a computer program product comprising instructions, which, when executed on a computer or processor, causes the computer or processor to execute Figure 2-Figure 11 Methods corresponding to mid- and remote terminal devices.
[0581] The present application also provides a computer program product comprising instructions, which, when executed on a computer or processor, causes the computer or processor to execute Figure 2-Figure 11 The method corresponding to the AUSF network element (such as the remote AUSF network element and the relay AUSF network element).
[0582] The present application also provides a computer program product comprising instructions, which, when executed on a computer or processor, causes the computer or processor to execute Figure 2-Figure 11 The corresponding method of PKMF network element.
[0583] The embodiment of the present application provides a chip system, which includes a processor for executing a communication device. Figure 2-Figure 11 The corresponding method of the remote terminal device, or execute Figure 2-Figure 11 AUSF network element (e.g. remote AUSF network element, relay AUSF network element) corresponding method, or, execute Figure 2-Figure 11 The corresponding method of PKMF network element.
[0584] In one possible design, the chip system also includes a memory for storing necessary program instructions and data. The chip system may include a chip, an integrated circuit, or a chip and other discrete devices, which are not specifically limited in this embodiment of the present application.
[0585] Among them, the communication device, chip, computer storage medium, computer program product or chip system provided in this application are all used to execute the method described above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the implementation methods provided above and will not be repeated here.
[0586] The processor involved in the embodiments of the present application may be a chip. For example, it may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0587] The memory involved in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct RAM bus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0588] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0589] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0590] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0591] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0592] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0593] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0594] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When loading and executing computer program instructions on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode to another website, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or includes one or more servers, data centers and other data storage devices that can be integrated with media. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state disk (SSD)).
[0595] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A key acquisition method, characterized in that: include: The communication device sends a first identifier and a relay service code to the relay terminal device, where the first identifier is an anonymous identifier of the remote terminal device; The communication device generates a second shared key based on the first shared key and the relay service code, and generates a root key for communication between the remote terminal device and the relay terminal device based on the second shared key and at least one first freshness parameter. The second shared key is a key shared by the remote terminal device and the adjacent service key management function network element, and the first shared key is a key shared by the remote terminal device and the remote authentication service function network element. The remote authentication service function network element is an authentication service function network element serving the remote terminal device.
2. The method according to claim 1, characterized in that The first identifier is a subscription concealment identifier SUCI of the remote terminal device.
3. The method according to claim 1, characterized in that Also includes: The communication device obtains the first identifier.
4. The method according to claim 3, characterized in that The communication device acquiring the first identifier includes: The communication device sends the relay service code; The communication device receives the first identifier corresponding to the relay service code.
5. The method according to claim 3, characterized in that Also includes: The communication device generates a temporary identifier according to the first shared key and the relay service code; The communication device obtains the first identifier according to the temporary identifier.
6. The method according to claim 5, characterized in that The communication device generates a temporary identifier according to the first shared key and the relay service code, including: The communication device generates the temporary identifier according to the first shared key, the relay service code and the second freshness parameter.
7. The method according to claim 3, characterized in that The communication device acquiring the first identifier includes: The communication device generates the first identifier according to the second freshness parameter, the routing indication and the home network identifier.
8. The method according to claim 6 or 7, characterized in that Also includes: The communication device sends the relay service code; The communication device receives the second freshness parameter corresponding to the relay service code.
9. The method according to claim 6 or 7, characterized in that The second freshness parameter is a value of a counter maintained locally by the communication device.
10. The method according to any one of claims 3 to 7, characterized in that: The first identifier includes a routing indication and a home network identifier.
11. The method according to any one of claims 1 to 7, characterized in that: Also includes: The communication device sends first verification information to the relay terminal device, where the first verification information is generated by a first temporary key and all or part of the information elements of a message carrying the first verification information, and the first temporary key is generated by the first shared key.
12. The method according to claim 11, characterized in that The first temporary key is generated by the relay service code, a third freshness parameter, at least one of the second identifier of the remote terminal device and the first identifier, and the first shared key, wherein the third freshness parameter is generated by the communication device.
13. The method according to any one of claims 1 to 7 and 12, characterized in that: Also includes: The communication device sends second verification information to the relay terminal device, where the second verification information is generated by the first freshness parameter, the relay service code, and the first shared key.
14. The method according to any one of claims 1 to 7 and 12, characterized in that: The at least one first freshness parameter includes a first random number, and further includes: The communication device sends the first random number to the relay terminal device.
15. The method according to any one of claims 1 to 7 and 12, characterized in that: The at least one first freshness parameter includes a second random number, further comprising: The communication device receives the second random number from the relay terminal device.
16. The method according to any one of claims 1 to 7 and 12, characterized in that: The at least one first freshness parameter is a value of a counter maintained locally by the communication device.
17. The method according to any one of claims 1 to 7 and 12, characterized in that: The first shared key is the key Kausf negotiated between the remote terminal device and the remote authentication service function network element when accessing the network.
18. The method according to any one of claims 1 to 7 and 12, characterized in that: The communication device is the remote terminal device, or a device including the remote terminal device, or a chip or functional module in the remote terminal device.
19. A key acquisition method, characterized in that: include: The communication device obtains the second identification of the remote terminal device and the relay service code; The second identifier is a permanent identifier of the remote terminal device; The communication device obtains a first shared key corresponding to the second identifier; the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; The communication device generates a second shared key based on the first shared key and the relay service code, and generates a root key for communication between the remote terminal device and the relay terminal device based on the second shared key and at least one first freshness parameter, where the second shared key is a key shared by the remote terminal device and the proximity service key management function network element; The communication device sends the root key.
20. The method according to claim 19, characterized in that Also includes: The communication device sends the second shared key to the proximity service key management function network element.
21. The method according to claim 20, characterized in that Also includes: The proximity service key management function network element receives the second shared key.
22. The method according to any one of claims 19 to 21, characterized in that Also includes: The communication device receives the relay service code.
23. The method according to any one of claims 19 to 21, characterized in that The communication device sending the root key includes: The communication device sends the root key to the relay terminal device.
24. The method according to any one of claims 19 to 21, characterized in that The at least one first freshness parameter includes a first random number, and further includes: The communication device receives the first random number.
25. The method according to any one of claims 19 to 21, characterized in that The at least one first freshness parameter includes a second random number, further comprising: The communication device sends the second random number.
26. The method according to any one of claims 19 to 21, characterized in that The first shared key is the key Kausf negotiated between the remote terminal device and the remote authentication service function network element when accessing the network.
27. The method according to any one of claims 19 to 21, characterized in that The communication device obtains a second identifier of the remote terminal device, including: The communication device receives a second identifier of the remote terminal device.
28. The method according to any one of claims 19 to 21, characterized in that Also includes: The communication device generates a temporary identifier according to the first shared key and the relay service code; The communication device generates a first identifier according to the temporary identifier, where the first identifier is an identifier of the remote terminal device corresponding to the relay service code.
29. The method according to claim 28, characterized in that The communication device generates a temporary identifier according to the first shared key and the relay service code, including: The remote terminal device generates the temporary identifier according to the first shared key, the relay service code and the second freshness parameter.
30. The method according to claim 28, wherein Also includes: The communication device sends the first identifier.
31. The method according to claim 29 or 30, characterized in that The first identifier includes a routing indication and a home network identifier.
32. The method according to any one of claims 19-21, 29-30, characterized in that Also includes: The communication device receives first verification information; The communication device generates a first temporary key based on the first shared key; and obtaining third verification information based on the first temporary key and all or part of the information elements of the message carrying the first verification information; The communication device compares the first verification information and the third verification information to verify the remote terminal device.
33. The method according to claim 32, characterized in that The communication device generates a first temporary key according to the first shared key, including: The communication device generates the first temporary key based on the relay service code, the third freshness parameter, the second identifier and at least one of the first identifier of the remote terminal device, and the first shared key, and the third freshness parameter is generated for the remote terminal device.
34. The method according to any one of claims 19 to 21, characterized in that The at least one first freshness parameter is a value of a counter maintained locally by the communication device.
35. The method according to claim 29, 30 or 33, wherein: Also includes: The communication device sends the first identifier to the unified data management network element.
36. The method according to any one of claims 19-21, 29-30, and 33, wherein: The communication device is the remote authentication service function network element, or a device including the remote authentication service function network element, or a chip or functional module within the remote authentication service function network element.
37. A key acquisition method, characterized in that: include: The proximity service key management function network element receives a first identifier of a remote terminal device and a relay service code, where the first identifier is an identifier of the remote terminal device corresponding to the relay service code or the first identifier is an anonymous identifier of the remote terminal device; The proximity service key management function network element receives at least one second shared key from the remote authentication service function network element, where the second shared key is a key shared by the remote terminal device and the proximity service key management function network element, and the second shared key is generated by the first shared key and the relay service code; The proximity service key management function network element generates a root key for communication between the remote terminal device and the relay terminal device based on the second shared key corresponding to the first identifier and at least one first freshness parameter, where the first shared key is a key shared by the remote terminal device and the remote authentication service function network element; The proximity service key management function network element sends the root key.
38. The method according to claim 37, wherein Also includes: The proximity service key management function network element receives the second verification information; The proximity service key management function network element generates fourth verification information according to the first freshness parameter and the second shared key; The proximity service key management function network element compares the second verification information with the fourth verification information to verify the remote terminal device.
39. The method according to claim 37 or 38, characterized in that The at least one first freshness parameter includes a first random number, and further includes: The proximity service key management function network element receives the first random number.
40. The method according to claim 37 or 38, characterized in that The at least one first freshness parameter includes a second random number, further comprising: The proximity service key management function network element sends the second random number.
41. The method according to claim 37 or 38, characterized in that The at least one first freshness parameter is a value of a counter locally maintained by the proximity service key management function network element.
42. The method according to claim 37 or 38, characterized in that The first shared key is the key Kausf negotiated between the remote terminal device and the remote authentication service function network element when accessing the network.
43. A communication device, characterized in that The communication device comprises a processor connected to a memory, the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the communication device performs the method according to any one of claims 1 to 18.
44. A communication device, characterized in that The communication device comprises a processor connected to a memory, the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the communication device performs the method according to any one of claims 19 to 36.
45. A communication device, characterized in that The communication device comprises a processor connected to a memory, the memory being used to store a computer program, and the processor being used to execute the computer program stored in the memory so that the communication device executes the method according to any one of claims 37 to 42.
46. A communication device, characterized in that The method comprises a functional module for executing the method according to any one of claims 1 to 18.
47. A communication device, characterized in that The method comprises a functional module for executing the method according to any one of claims 19 to 36.
48. A communication device, characterized in that The method comprises a functional module for executing the method according to any one of claims 37 to 42.
49. A communication system, characterized in that The communication device according to claim 44 or the communication device according to claim 47 further comprises a proximity service key management function network element for receiving the second shared key.
50. The system according to claim 49, wherein Also includes: The communication device according to claim 43 or the communication device according to claim 46.
51. A computer-readable storage medium, characterized in that The method comprises instructions which, when executed on a communication device, cause the communication device to execute the method according to any one of claims 1 to 42.
52. A computer program product, characterized in that The method comprises instructions which, when executed on a communication device, cause the communication device to execute the method according to any one of claims 1 to 42.